HIPAA Audit Checklist for Anticoagulation Clinics: How to Handle SMS INR Disclosures and Patient Portal Preferences
Designating a HIPAA Privacy Officer
Scope of responsibility
- Oversee policies governing Protected Health Information (PHI) across anticoagulation workflows, including SMS disclosures of INR results and portal messaging.
- Coordinate risk analysis and risk management with the Security Officer to address texting, device, and portal threats.
- Maintain and periodically update Notices of Privacy Practices to describe how the clinic uses SMS and patient portals.
- Manage Business Associate Agreements with texting, EHR, and portal vendors that create, receive, maintain, or transmit PHI.
- Respond to patient rights requests, including access, amendments, restrictions, and Accounting of Disclosures where applicable.
- Lead incident and breach response, root-cause analysis, and corrective actions related to misdirected or exposed messages.
Documentation to maintain
- Written designation of the Privacy Officer and backup designee.
- Current policies on SMS use, portal security, minimum necessary, and role-based access controls.
- Vendor BAAs, risk assessments, and training attestations retained for six years.
Obtaining Patient Consent for SMS Communication
Core consent elements
- Plain-language disclosure that SMS is not a secure channel and may expose PHI (for example, INR values) if seen by others.
- The specific phone number, message types (alerts vs. results vs. care instructions), and whether numeric INR values may be sent.
- Minimum necessary commitment (e.g., default to portal notifications; use SMS with PHI only when the patient opts in).
- Revocation method (reply STOP, call, or portal toggle) and the effective date of changes.
- Attestation that the number is personal or that the patient accepts risks if shared (family, employer, caregiver).
How to document consent
- Capture e-signature or written consent; store the signed record, date/time, staff witness, and scope of disclosures.
- Record consent status and preferences in the EHR and the texting platform; reconcile any discrepancies daily.
- Reconfirm at each visit or medication management touchpoint; maintain version history for audits.
Operational tips
- Verify identity before enabling SMS (e.g., two-factor phone verification) and confirm the number at every INR encounter.
- Segment content: appointment reminders via SMS by default; INR values via portal unless explicit SMS opt-in exists.
- Include opt-out language in operational messages where feasible without revealing PHI.
Message templates (examples)
- No-PHI alert (default): “You have a new test result from the clinic. Please check your patient portal or call us.”
- With consent, minimal PHI: “INR 2.4 today. Continue current dose. Recheck in 1 week. Questions? Call the clinic.”
Implementing Secure Patient Portals
Security controls to expect
- Strong authentication (Multi-Factor Authentication), unique user IDs, and automatic logoff.
- Encryption in transit and at rest, with keys managed by the portal or hosting provider under a signed BAA.
- Role-Based Access Controls to restrict staff functions and proxy access to only what is necessary.
- Comprehensive audit controls: logins, message views, result downloads, preference changes, and disclosures.
- Session safeguards: device recognition, throttling, and anomaly detection for suspicious access.
Operational safeguards
- Enable a preferences center so patients choose SMS alerts, portal-only delivery, or both.
- Display INR values and dosing plans in the portal; use SMS primarily to nudge patients to log in.
- Document the portal’s security posture, backup/restore, and change management within your HIPAA risk management program.
Managing SMS INR Disclosure Risks
Key risks to address
- Misdirected messages due to wrong numbers, reassigned numbers, or contact entry errors.
- Lock-screen previews exposing PHI on shared or lost devices.
- Unsecured staff devices or ad hoc texting outside the approved platform.
- Over-disclosure (full clinical context) when the minimum necessary would suffice.
Controls and compensating safeguards
- Default to portal delivery for results; use SMS with PHI only when patients explicitly opt in.
- Use templates that avoid diagnosis, medication names, or dosing unless consented and clinically necessary.
- Send a verification code to confirm ownership before first SMS with PHI; re-verify after number changes.
- Deploy an approved texting platform under a BAA; disable personal/BYOD texting for PHI unless governed by policy and MDM.
- Establish thresholds: critical INR values require a phone call with identity verification, not SMS.
Response to errors
- Stop further messages, notify the Privacy Officer, investigate scope, and determine breach obligations.
- Document the incident, corrective actions, and patient notifications as required.
Enforcing Workforce Training on HIPAA Policies
Curriculum essentials
- Definition of PHI and minimum necessary in the context of anticoagulation and INR workflows.
- Approved message templates, identity verification steps, and when to escalate to calls or portal-only delivery.
- Use of sanctioned systems only; prohibition of personal texting apps for PHI.
- Handling opt-outs, revocations, and patient restrictions on communications.
- Recognizing and reporting misdirected messages, suspected breaches, and social engineering attempts.
Program structure
- Role-based onboarding and annual refreshers with attestations.
- Spot audits of message content and number verification steps; coaching and remediation documented.
Maintaining Audit Trails and Documentation
What to log
- SMS metadata: recipient, sender, date/time, template used, and minimal content or a redacted/hashed reference.
- Portal events: logins, result views, message reads, downloads, and preference changes.
- Consent lifecycle: versions, timestamps, revocations, and staff actions.
Make logs tamper-resistant
- Implement Tamper-Evident Audit Logging (e.g., write-once or hash-chained logs) with time synchronization.
- Restrict log access via Role-Based Access Controls and monitor for privilege abuse.
Retention and reporting
- Retain HIPAA-required documentation and logs for at least six years or longer if state law dictates.
- Maintain an Accounting of Disclosures where required (e.g., certain public health, legal, or non-routine disclosures).
- Produce audit-ready reports that tie each INR communication to consent status and the rationale for disclosure.
Handling Patient Portal Preferences
Preference center design
- Allow granular choices: alerts only vs. full results by SMS; portal-only vs. combined notifications.
- Support proxies and caregivers with scoped access and independent notification settings.
- Surface risks for SMS with PHI and require explicit acknowledgment before enabling.
Operationalizing preferences
- Sync preferences across EHR, portal, and texting systems; reconcile nightly and after each clinic encounter.
- Reconfirm preferences at check-in and when anticoagulation plans change.
- Honor patient restrictions and document exceptions (e.g., emergencies) per policy.
Conclusion
Build your audit program around clear governance, explicit SMS consent, a secure portal with MFA and RBAC, and tamper-evident logging. By defaulting to portal delivery and tightly managing exceptions, you protect PHI while giving patients control over how they receive INR information.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk AssessmentFAQs
What constitutes a HIPAA-compliant SMS message?
A compliant message follows the minimum necessary standard, aligns with the patient’s documented consent and preferences, avoids unnecessary clinical detail, and is sent through an approved system under a Business Associate Agreement. Prefer portal nudges (“You have a result”) over sending INR values. If the patient opts in to receive INR by SMS, use concise templates, verify the number, include an opt-out method, and log the disclosure.
How should patient consent be documented for SMS disclosures?
Obtain written or electronic consent that specifies the phone number, message types, whether INR values may be sent, and the risks of SMS. Record the date/time, staff witness, and version of the consent text. Store it in the EHR and texting platform, link it to the patient record, and maintain a full history of updates and revocations for at least six years.
What security measures are required for patient portals?
Implement administrative, physical, and technical safeguards that include strong authentication (preferably Multi-Factor Authentication), encryption in transit and at rest, Role-Based Access Controls, automatic logoff, and comprehensive audit logging. Manage vendor risk under a Business Associate Agreement, validate backups and incident response, and enforce least privilege across staff and proxy accounts.
How can clinics audit communications involving INR results?
Maintain tamper-evident logs that tie each INR communication to patient identity, consent status at the time of sending, message channel (SMS vs. portal), content template, sender, and timestamps. Reconcile logs across the EHR, portal, and texting vendor; run exception reports for messages sent without active consent; and retain artifacts—policies, BAAs, training attestations, and Accounting of Disclosures where applicable—for audit readiness.
Table of Contents
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk Assessment