Patient Confidentiality and Record Release
Customize your policy alerts
Sign up for sanfranciscohealthplan Policy FSR-A_III H_PP_Patient Confidentiality Record Release alerts
Get alerted when Policy FSR-A_III H_PP_Patient Confidentiality Record Release changes without checking for updates manually.
Monitor payer policy activity
Governs protection, storage, release, and retention of patient medical information for San Francisco Health Plan and its provider sites; applies to plan personnel and contracted providers/sites participating in Facility Site Reviews.
No material clinical or coverage changes in this revision.
Confidentiality and Record Handling Requirements
Confidentiality and Record Handling Criteria
Operational requirements and protections for patient privacy, confidentiality, electronic security, record release, storage, and retention.
ALL of the following
- Patients have the right to privacy for dressing/undressing, physical examination, and medical consultation; site reviewers will make site-specific determinations due to variable dressing/exam room configurations.
- Personnel must follow site policies and procedures to maintain confidentiality; individual patient conditions or information must not be discussed in front of other patients or visitors or displayed or left unattended in reception or patient flow areas (this includes unattended electronic devices and patient registration sign-in sheets with more than one unique patient identifier).
ALL of the following
- Electronic record-keeping systems must prevent unauthorized access, authenticate electronic signatures, and maintain computer system upkeep.
Includes at least one of
- Security protections must include an off-site backup storage system, an image mechanism with ability to copy documents, a mechanism to ensure recorded input is unalterable, and file recovery procedures.
- Confidentiality protections may also include encryption, detailed user access controls, transaction logs, and use of blinded files.
ALL of the following
- Medical records are not released without a written, signed consent from the patient or the patient’s representative that identifies the specific medical information to be released and specifies to whom records are released, the purpose, and the expiration date of the consent.
Exceptions (ONE of)
- This requirement does not prevent release of statistical or summary data, or exchange of individually identifiable medical information between individuals or institutions providing care, fiscal intermediaries, research entities, and State or local official agencies per 45 CFR §164.524.
ALL of the following
- Records of services rendered under Medi‑Cal or other programs administered by the department or its agents/contractors must be kept confidentially and securely and must include beneficiary, date of service, and any additional information required by regulation.
- Fax cover sheets used for transmittal of records must include a confidentiality statement.
ALL of the following
- Providers must retain required records (including minors under 18 years old) for 10 years from the later of: the final date of the contract between the plan and provider, the date of completion of any audit, or the date the service was rendered.
- Retention requirement is in accordance with 42 CFR 438.3(u) and WIC 14124.1.
Record Release Authorization and Provider Responsibilities
Record release requires written, signed patient/representative consent
Medical records must not be released without a written, signed consent from the patient or the patient's representative that identifies the specific medical information to be released, specifies to whom the records will be released, the purpose, and the consent expiration date. Exceptions permitting release without this consent include disclosure of statistical/summary data and exchanges of identifiable information between care providers, fiscal intermediaries, research entities, and state or local official agencies per 45 CFR §164.524.
- Consent must be written and signed by the patient or patient’s representative.
- Consent must identify specific information to be released.
- Consent must state recipients, purpose, and expiration date.
- Allowed exceptions: statistical/summary data and inter-provider or agency exchanges (including fiscal intermediaries, research entities, and state/local agencies).
Definitions: Electronic Records and Record Release
OpenPayer is powered by Trek Health's payer performance platform. Trek continuously ingests, validates, and normalizes Transparency in Coverage data alongside payer policies and other commercial payer data to create a structured payer intelligence foundation. OpenPayer uses this foundation to deliver personalized search results, dynamically generated policy pages, and tailored policy monitoring based on each user's payers, specialties, billing codes, and areas of interest. The same intelligence powers broader payer performance workflows, including reimbursement benchmarking, contract evaluation, payer negotiations, and financial decision-making.