Does Your Print Partner Treat PHI and PII Differently?

PHI and PII are two acronyms that are very important in the field of print and mailing. As important as they are, however, they do create a fair amount of confusion for project managers that need to work with a print services provider. In this blogpost, we’ll try to help by explaining what PHI and PII are, how they differ, and how your print provider should be handling them when printing and sending mail to your customers, patients, or members.

What is PII?

We’ll start with PII because it’s the broader of the two categories. PII stands for Personally Identifiable Information, and it includes any piece of data that could be used to establish the exact identity of an individual person. In the most basic sense, it could be the first and last name of the individual. However, many other pieces of information could be used to narrow down the identity of someone being described in a piece of mail. 

For example, an email address is attached to an individual, as is a driver’s license number, a Social Security number, and a street address. If an unauthorized person gets access to any of those pieces of data, they could theoretically track down what individual is attached to it.

Even demographic and background data such as place of birth, gender, and ethnicity are sometimes considered PII, because in combination with other types of PII, they can be used to narrow the focus and hone in on an individual person. 

What is PHI?

Protected Health Information, or PHI, is more specifically focused on the health history and status of an individual. It’s important to note that all types of PHI also fall under the category of PII, but the specific designation of PHI is important because it is governed by specific federal laws, most notably HIPAA.

PHI includes data such as medical test results, electronic medical records, diagnoses of diseases, insurance claims, prescriptions, and account numbers. In addition to identifying individual people like PII does, this health information carries unique sensitivities and, according to the US government, deserves special protections. In 1996, Congress passed a law that outlined the ways that data considered PHI could and could not be handled. While healthcare organizations, insurance companies, and individuals must communicate PHI to one another in order to provide care to patients, HIPAA provides guidelines for protecting that information from exposure during the course of business.

Rules For Print Providers

HIPAA rules don’t only apply to organizations that actually care for patients, like hospitals, or companies that handle insurance and payments. Any company that handles PHI as part of their operations needs to be in compliance with all applicable HIPAA regulations. As a provider of print and mail services for healthcare and financial organizations, Spectra is also subject to these requirements. Whenever a private medical practice, an insurance company, a hospital, or other client needs Spectra to print documents, address envelopes, and communicate with individuals in regards to their health information, they need to know that our team’s operations are fully HIPAA compliant.

If a hospital, for instance, were to hire a print provider to print account updates for its patients and mail them out without verifying that the provider is HIPAA compliant in its practices, they could themselves be held in violation of HIPAA guidelines. A hacking attack on the print provider’s systems could result in criminals gaining access to patients’ health information, and even an “honest mistake” on the part of employees not trained in HIPAA requirements could lead to sensitive information being exposed to public view.

Facility-Wide HIPAA Compliance

Some print services providers make the choice not to become HIPAA compliant. Why? Because it’s not practical to partition out a HIPAA compliant and a non-compliant section of a print and mailing services facility. The guidelines stipulate how employees work with information in the workplace, how digital networks are firewalled, isolated, and otherwise protected from intrusion, and how visitors to the facility are handled. For a facility to serve clients with PHI, the entire facility must be run in compliance with HIPAA regulations.

Spectra maintains HIPAA compliance throughout its print and mail division, making our team a great choice for insurance, financial, and healthcare clients. Even clients outside these fields that use only PII in their communications can be assured that their projects handled by Spectra are subject to strict data security processes.

HIPAA Compliant Services

For decades, Spectra has been operating within HIPAA regulations. This means that we have navigated the major shifts from direct mail to digital communication that have occurred within most industries. There are still, of course, communications that must be sent by direct mail, and for those projects, we offer pressure seal mailers and other secure mailing solutions. Our mailing systems are subject to strict quality control and accuracy checks, and we utilize technologies that keep us in line with the US Postal Service’s latest updates on addresses throughout the country. 

All of these advantages combine with the practical knowledge of Spectra’s personnel to make our print facility the perfect partner for an organization in need of a HIPAA compliant partner. From projects that involve standard PII such as names and addresses, to projects that include highly sensitive PHI like diagnoses of major diseases, our clients know that they can trust us to follow best practices, keep data security protocols in place, and continually educate our employees on important changes in the industry.

Data security has always been critical for Spectra, and as more databases and address lists are shared in digital form, we are continuing to keep our internal processes fully compliant with HIPAA guidelines. We also hold SOC 2 Type II certification in our print and mailing division, with periodic audits by independent inspectors to verify that our team is following recommended practices and keeping our clients’ data safe while it is in our possession. You can explore the Spectra website to learn more about how we protect the data of our clients and their patients, customers, and members.

Leave a Comment

Your email address will not be published. Required fields are marked *

two − 1 =

Related Posts