The FTC responded to the American Medical Association’s stance that the Red Flags Rule should not apply to physicians and related health care providers. That’s right - your trusty GP must have an Identity Theft Prevention Program. In the FTC’s letter to the AMA, the FTC acknowledges that, yes, doctors take a confidentiality oath, and yes, there’s HIPAA, but that does not cover the “respond to and mitigate identity theft” provision of the Red Flags Rule. In other words, they focus on two scenarios:
To address these scenarios, the FTC suggests that for smaller doctors offices, which are presumably low risk, checking a drivers license and determining what to do if notified of identity theft involving the office would be sufficient.
Sorry, the comment form is closed at this time.