I work at a hospital and I wanted to give everyone a heads up on how HIPAA affects you.
HIPAA allows communication of PHI for legitimate business purposes.
Examples are billing, collections, transfers to other facilities, etc.
WHYCHAT's approach is pulling the HIPAA blanket out from under them.
If the OC accepts payment, then there is no longer any legitimate
business relationship with the CA and the OC, by law, has to
get the PHI removed or they are in violation of HIPAA.
As long as the debt is outstanding, the OC still has a legitimate
purpose for sending your data out (collections) so they are
in the right.
Technically speaking, the OC can only pass on information that
directly relates to the specific transaction.