HIPAA mainly protects a patient's protected health information (PHI), which drug testing can often fall under. Drug test results are treated like any PHI where consent is needed for disclosure, except when individuals agree to release the information to certain individuals, like their employer.
The Privacy Rule generally restricts the sharing of PHI without patient consent. The limited instances where consent is not necessary, such as a response to a court order, during a legal investigation, or for worker's compensation claims. To release drug test results to other individuals or entities, the patient will need to provide authorization.
A study published in The Journal of Urgent Care Medicine states, “An employer should have restrictions on how (and if) such information can be shared with others. As part of this process, employees who undergo a drug test will typically sign a release at the time of the test to permit the employer to receive the results.”
Although HIPAA can apply to patient information collected by providers, it does not protect employment records. In short, if drug tests are not handled by healthcare practitioners, HIPAA does not apply.
As mentioned, drug testing is treated like any other PHI when handled by providers or covered entities. It can therefore only be shared without consent in the following instances:
When disclosure is requested, make sure that the reason for the request aligns with the exceptions mentioned above, such as a court order.
HIPAA uses the minimum necessary standard to ensure only the necessary information is shared. It means that:
Maintain a detailed record of the steps followed from the disclosure request. The information documented includes:
Make use of secure methods of sharing any PHI including drug test results. One of the best possible methods of doing so is HIPAA compliant email like Paubox which allows for the inclusion of features like encrypted messaging as well as convenient, consistent communication.
Yes, but only as required by law or to prevent serious threats to the health and safety of persons or populations.
A few specific instances include proceedings and enforcement purposes.