Is ROI necessary for communication within a care team?

Started by DXM1
This forum made possible through the generous support of SDN members, donors, and sponsors. Thank you.
Get help with your application

Use all the free resources available to you from SDN: articles, guides, expert advising, forums discussions, and school research.

DXM1

Full Member
15+ Year Member
Advertisement - Members don't see this ad
For psychiatric notes and verbal communication (not talking about psychotherapy notes), is it necessary to get patient’s consent to share notes and/or verbal communication with the primary care physician or other members of the care team?

Just wondering how you guys are going about PCP requesting notes and/ or updates on patients they refer to you.
 
This is why the concept of HIPAA and how it is taught in schools and online work training is so dangerous. You're a medical professional and somehow worried about sharing information with other providers treating the same patient. That concern is terrifyingly common and poses such a greater risk to patient safety than any benefit HIPAA ever created. Quite honestly, the opiate crisis lies as much at the feet of HIPAA as it does at big pharma. Personally, I believe there should be far greater liabilities for not actively sharing with other known treating providers than any ever handed down for inappropriate disclosure. The risk to the patient is obviously so much greater.
 
Last edited:
For psychiatric notes and verbal communication (not talking about psychotherapy notes), is it necessary to get patient’s consent to share notes and/or verbal communication with the primary care physician or other members of the care team?

Just wondering how you guys are going about PCP requesting notes and/ or updates on patients they refer to you.
Communication between active treating providers is explicitly not restricted by HIPAA. You do not need an ROI to speak with the patients' PCP - although it would be courteous and appropriate to let the patient know you will be speaking with the PCP.


 
Advertisement - Members don't see this ad
Personally, I believe there should be far greater liabilities for not actively sharing with other known treating providers than any ever handed down for inappropriate disclosure. The risk to the patient is obviously so much greater.
I remember during one my earlier shifts in the psychER during residency, and calling the outpatient mental health clinic of a frothing-at-the-mouth police special, trying to get some basic info about medications, clinical history etc. The clinic front desk connected me with the guy's therapist and BAM - "I CAN'T TELL YOU ANYTHING BECAUSE THE PATIENT DIDN'T SIGN A RELEASE OF INFORMATION!!!" Lesson learned - just B52 and let the social worker handle this bs.
 
The amount of ignorance is scary and the fact that the liability seems almost entirely geared towards inappropriate disclosure is horrific. We have people mixing and matching dangerous drugs, doctor shopping, doing all manner of things, but they get to keep it a secret, so I guess all good.
 
Last edited:
Yes, sorry...I was just so disturbed by the question I had trouble answering it. It's horrific that this question is ever asked by anyone. It's not the problem of the OP. It's a massive failure in our medical education system and to a lesser extent our legal system which has for some reason massively prioritized privacy over the most basic patient safety (regardless of how the law is written). A ROI is so beyond not required. It's the reverse. It is a basic element of the standard of care that you will proactively share information with other members of a patient's healthcare team. If the patient somehow or for some reason opposes this, you should offer them resources for a different provider as you simply cannot ethically treat them. That should be enforced and educated on at least as much as anything about privacy restrictions.
 
Last edited:
I remember during one my earlier shifts in the psychER during residency, and calling the outpatient mental health clinic of a frothing-at-the-mouth police special, trying to get some basic info about medications, clinical history etc. The clinic front desk connected me with the guy's therapist and BAM - "I CAN'T TELL YOU ANYTHING BECAUSE THE PATIENT DIDN'T SIGN A RELEASE OF INFORMATION!!!" Lesson learned - just B52 and let the social worker handle this bs.
In Massachusetts, therapists were required to get a ROI to communicate with other members of the care team. So you could talk to their other doctors without an ROI but not to their therapist. This was not an institutional quirk, it was a difference in regulatory statutes.
 
In Massachusetts, therapists were required to get a ROI to communicate with other members of the care team. So you could talk to their other doctors without an ROI but not to their therapist. This was not an institutional quirk, it was a difference in regulatory statutes.

Some states are a little weird. Massachusetts statutes do not apply broadly to all “therapists”. Only certain types of therapists in Massachusetts have this unique problem.
 
For psychiatric notes and verbal communication (not talking about psychotherapy notes), is it necessary to get patient’s consent to share notes and/or verbal communication with the primary care physician or other members of the care team?

Just wondering how you guys are going about PCP requesting notes and/ or updates on patients they refer to you.

You can even take this a step further if you are an out of network only clinic, hipaa doesn’t apply to you.
 
Not a lawyer, but I am also not seeing laws in MA, specific to physicians, that are more stringent than HIPAA. That said, the immediately above poster is wrong. HIPAA applies to all healthcare providers in the US and many non- healthcare providers as well. In or outside of a "network" does not matter.
 
Last edited:
Not a lawyer, but I am also not seeing laws in MA, specific to physicians, that are more stringent than HIPAA. That said, the immediately above poster is wrong. HIPAA applies to all healthcare providers in the US and many non- healthcare providers as well. In or outside of a "network" does not matter.
Nope. HIPAA only applies to “covered entities”. Cash practices are not covered entities and thus cannot be liable for HIPAA violations. Nevertheless, confidentiality standards apply to all.
 
Not a lawyer, but I am also not seeing laws in MA, specific to physicians, that are more stringent than HIPAA. That said, the immediately above poster is wrong. HIPAA applies to all healthcare providers in the US and many non- healthcare providers as well. In or outside of a "network" does not matter.

That is false. Please don’t spread misinformation.

If you want to check it without researching, try to report someone to hipaa with a cash only practice. It’ll stop you.

Additionally I’ve been reported for a hipaa violation that didn’t happen. I responded that I’m cash only and that the government can’t investigate that claim with me. They agreed.
 
Nope. HIPAA only applies to “covered entities”. Cash practices are not covered entities and thus cannot be liable for HIPAA violations. Nevertheless, confidentiality standards apply to all.

Yeah I think this is what people miss, people get too hung up on talking about HIPAA all the time but many states have their own state confidentiality laws around release of medical/mental health/substance abuse information. These may default to referring to HIPAA as their standard for confidentiality but they still apply to everyone in that state whether a covered entity under HIPAA or not.

That is false. Please don’t spread misinformation.

If you want to check it without researching, try to report someone to hipaa with a cash only practice. It’ll stop you.

Additionally I’ve been reported for a hipaa violation that didn’t happen. I responded that I’m cash only and that the government can’t investigate that claim with me. They agreed.

You don't "report someone to HIPAA" (HIPAA is a law) you report someone to HHS OCR. Yes, they technically can't report you to OCR if you aren't a covered entity but you can still be reported to your state department of health for violating confidentiality.
 
I get the definition of covered entities is often shorthanded to handling health insurance (because that's how the vast, vast, vast majority of healthcare is paid for), but you are going to have to be extremely strict and essentially paper (literally) only if you want to avoid being a covered entity. If you use a billing service for invoices, your EMR has anything remotely accessible or not solely locally stored, have an online patient portal or dozens of other electronic communication means, you're doing electronic transactions and are covered. My point was that it's not related to insurance or "networks." It's about any thing resembling an electronic transmission of PHI. My statement may have been overly broad (I'll grant it's theoretically possible to not be a covered entity and provide healthcare), but saying cash only practices are definitionally exempt is even more incorrect than what I said. About the anecdotes above, of course the vast majority of privacy complaints are unfounded or agencies decide not to be investigate. That's not related to HIPAA, that's related to the patient population.
 
Last edited:
Advertisement - Members don't see this ad
Some states are a little weird. Massachusetts statutes do not apply broadly to all “therapists”. Only certain types of therapists in Massachusetts have this unique problem.
That was my recollection as well but it's been a while since I last looked it up, thanks for the add--serves to show how this topic can be particularly unintuitive in some locations.

Plus a lot of employers have their own rules around ROI's as well.
 
Last edited:
I get the definition of covered entities is often shorthanded to handling health insurance (because that's how the vast, vast, vast majority of healthcare is paid for), but you are going to have to be extremely strict and essentially paper (literally) only if you want to avoid being a covered entity. If you use a billing service for invoices, your EMR has anything remotely accessible or not solely locally stored, have an online patient portal or dozens of other electronic communication means, you're doing electronic transactions and are covered. My point was that it's not related to insurance or "networks." It's about any thing resembling an electronic transmission of PHI. My statement may have been overly broad (I'll grant it's theoretically possible to not be a covered entity and provide healthcare), but saying cash only practices are definitionally exempt is even more incorrect than what I said. About the anecdotes above, of course the vast majority of privacy complaints are unfounded or agencies decide not to be investigate. That's not related to HIPAA, that's related to the patient population.

HIPAA has rather fine rules on what is a covered “transaction”. Cash practices don’t apply without something very unusual. I guess if I owned a cash practice and an insurance clearinghouse, it could draw me in. This is how hard it is to pull in a cash practice.

Give it a shot for fun. Try to start a complaint for a cash only practice regarding a hipaa issue. They don’t want the complaint as it doesn’t apply to them. I’ve tried to report myself multiple ways - can’t be done without a lie. The one complaint I received actually had an area to check out-of-network as an exclusion. I’d have had to submit a response if I accepted insurance.

Not understanding who hipaa applies to is incredibly common. Just another way hipaa does more harm than good.

My take on hipaa has been reviewed with 3 law firms all in agreement.
 
This is why the concept of HIPAA and how it is taught in schools and online work training is so dangerous. You're a medical professional and somehow worried about sharing information with other providers treating the same patient. That concern is terrifyingly common and poses such a greater risk to patient safety than any benefit HIPAA ever created. Quite honestly, the opiate crisis lies as much at the feet of HIPAA as it does at big pharma. Personally, I believe there should be far greater liabilities for not actively sharing with other known treating providers than any ever handed down for inappropriate disclosure. The risk to the patient is obviously so much greater.

I can’t tell you how often I try to contact another office about a pt, and I’m told that they can’t talk to me because the pt hasn’t signed a release yet. It’s so stupid.
 
To some degree I assume small private practice folks, especially MSWs who perhaps haven't had as much exposure to HIPAA compared to physicians, are overly cautious because they are nowhere near as well equipped as a doctor employed by a major health system if there is an accusation of HIPAA violation. Also, these small private practices are in business and need to keep patients happy, sending records, even though totally legal, without patient given formal consent could piss off a patient and then you've got a spot to fill in the schedule and maybe a 1 star review. So it's safer for the small private practice folks to require ROIs before sending records to doubly assure they are not violating privacy or alienating their patients
 
As noted above, HIPAA specifically does not impede communication between care team members. However, sometimes another law or regulation can come into play, e.g. per 38 U.S.C §7332 the VA cannot disclose information related to substance abuse, HIV, or sickle-cell anemia without the patient's written consent outside of specific circumstances.
 
The VA regulation above was initially indeed horrific and likely lead to many unnecessary deaths due to lack of disclosure about substance abuse amongst medical providers. Fortunately, it was updated with the MISSION Act to more closely align with HIPAA, primarily a result of the opioid crisis. Check out Section (H)(i)
 
Last edited:
While we are mentioning exceptions, 42 CFR part 2 applies to addiction treatment programs that receive "federal assistance." I believe even taking Medicare or Medicaid qualifies as receiving federal assistance.

I am pretty sure 42 CFR part 2 technically requires a signed release of information for addiction providers to talk with other treatment providers about SUD treatment.

In general though I agree with what has been posted here, HIPAA does not stop us from talking to other treatment providers and in most situations it is the right call to do so.
 
The VA regulation above was initially indeed horrific and likely lead to many unnecessary deaths due to lack of disclosure about substance abuse amongst medical providers. Fortunately, it was updated with the MISSION Act to more closely align with HIPAA, primarily a result of the opioid crisis. Check out Section (H)(i)

Let’s go a step further and talk about how it is practically impossible to get ANY records from the VA as an outside provider. I have requested VA records dozens of times on different patients and never heard so much as a peep back from them. This nonsense was going on back when I was a resident too. It is absolutely ridiculous and an impediment to patient care. I have to have patients physically get a printed copy of their VA records and bring them to me.
 
Last edited:
I am sorry to hear that. Usually the reverse is the issue, community care has problems getting records from the outside provider. I would recommend calling the patient's doctor directly to discuss the issue or if you are being paid by the VA to care for the patient, community care. It is likely more records will be available immediately to non-VA clinicians as the transition to Cerner progresses.
 
Last edited:
I am sorry to hear that. Usually the reverse is the issue, community care has problems getting records from the outside provider. I would recommend calling the patient's doctor directly to discuss the issue or if you are being paid by the VA to care for the patient, community care. It is likely more records will be available immediately to non-VA clinicians as the transition to Cerner progresses.

I find this very interesting. I have a number of community care pts, but I don’t think I’ve ever heard that a VA physician has requested my notes.

Really the only time I’ve had much success with communicating with VA physicians is if they’re residents/attendings at a VA affiliated academic medical center. Then I can usually see their notes (nearby academic centers use Epic, as does our practice) and they make a much better effort at contacting me to discuss things. But the VA itself has always felt like a black hole from which it’s seemingly impossible to get information. Sometimes I literally can’t even tell who the pts VA physicians are; half the time it the pt can’t remember the names of their providers there, and if the VA won’t give me notes I have no way to figure that out.
 
If they are paying you, request medical records directly from community care. Hopefully that will be easier than trying to go through medical records. You probably won't be alerted to record requests if you have any sort of billing service. And unfortunately I can only really comment on VAs with academic affiliations, but I do feel like they are pretty good. I can definitely relate to patients not knowing the names of their providers, but someone referred then to you if they are at a community care provider.
 
It may not be an issue, but can still piss a patient off. I had a colleague get a board complaint for not getting ROI to speak with a patients PCP in regards to something.
 
Advertisement - Members don't see this ad
Will just add that a signed release is required for disclosure of any records or information about drug use or HIV, outside of emergencies.
 
Will just add that a signed release is required for disclosure of any records or information about drug use or HIV, outside of emergencies.
I'm unclear how you came to that conclusion with the information above in other posts. You might be referring to CFR 42 Part 2 facilities? I hope you're not because if you work at one, you should be familiar with their rules. Indeed, they do require written consent to disclose, which is stricter than HIPAA and quite honestly inappropriate. HOWEVER, under 2020 updates to that law, Part 2 facilities can (and should) have ALL patients under their care sign written paper global authorizations for "treatment, payment and operations" when first admitted. This would authorize disclosure to other treating providers (without being individually named) outside the Part 2 facility. If the Part 2 facility doesn't do this, they aren't really meeting the standard of care, much like any other provider who avoids disclosure of substance abuse to other treating providers of a shared patient. If the patient for some reason declines to do this for a Part 2 facility, you cannot safely (or honestly financially) treat them and should refer them elsewhere. The literal point of the CFR 42 Part 2, as described in much commentary by Congress, is to avoid disclosure to law enforcement, civil courts and educational institutions. The other treating providers part got caught up in this goal initially, but was at least mostly mitigated by the global authorization change in 2020.
 
Last edited:
I'm unclear how you came to that conclusion with the information above in other posts. You might be referring to CFR 42 Part 2 facilities? I hope you're not because if you work at one, you should be familiar with their rules. Indeed, they do require written consent to disclose, which is stricter than HIPAA and quite honestly inappropriate. HOWEVER, under 2020 updates to that law, Part 2 facilities can (and should) have ALL patients under their care sign written paper global authorizations for "treatment, payment and operations" when first admitted. This would authorize disclosure to other treating providers (without being individually named) outside the Part 2 facility. If the Part 2 facility doesn't do this, they aren't really meeting the standard of care, much like any other provider who avoids disclosure of substance abuse to other treating providers of a shared patient. If the patient for some reason declines to do this for a Part 2 facility, you cannot safely (or honestly financially) treat them and should refer them elsewhere. The literal point of the CFR 42 Part 2, as described in much commentary by Congress, is to avoid disclosure to law enforcement, civil courts and educational institutions. The other treating providers part got caught up in this goal initially, but was at least mostly mitigated by the global authorization change in 2020.
Yes, i was referring to part 2 programs that require a written consent to share or disclose info.
 
Okay, that's a teeny tiny part of overall psychiatry work and as above, it should ALWAYS be covered under a global signed authorization as soon as the patient enters such a program. Otherwise, the program is going to have a major problem even getting paid. You want to double check that the signed (global TPO) consent is obtained at admission if you work at a Part 2 program (it should be), but of course the vast majority of psychiatrists will never work at one. Once that is signed (and again, it always should be), you can and should provide substance abuse information with other treating providers.
 
Last edited:
Most of the legal side is well covered here, so I'll add the practical side, since the original question was about how people handle PCP requests day to day. I'd put one line in the intake paperwork saying you routinely coordinate with the patient's other treating providers as part of their care. That one step prevents most of the patient surprise that actually drives board complaints, which is a relationship problem rather than a legal one. When you do share, document a line or two noting the treatment purpose so your own chart stays clean. And when you're the one requesting records and the other office's front desk insists on an ROI anyway, it's usually faster to just get the form signed than to win the HIPAA argument over the phone.
 
Most of the legal side is well covered here, so I'll add the practical side, since the original question was about how people handle PCP requests day to day. I'd put one line in the intake paperwork saying you routinely coordinate with the patient's other treating providers as part of their care. That one step prevents most of the patient surprise that actually drives board complaints, which is a relationship problem rather than a legal one. When you do share, document a line or two noting the treatment purpose so your own chart stays clean. And when you're the one requesting records and the other office's front desk insists on an ROI anyway, it's usually faster to just get the form signed than to win the HIPAA argument over the phone.
Are any humans involved with these posts?
Screenshot_20260929-072919.png