Security of Health Information in Pennsylvania
In Pennsylvania, different types of medical facilities have special requirements for maintaining the security of patient medical records. For most facilities, including hospitals1, ambulatory surgical facilities2, birthing centers3, and home health care centers4, Pennsylvania requires simply that medical records be stored in an area that will protect against loss, damage and unauthorized access. For adult daily living centers, the state requires that all client records be kept locked when unattended.5
Under certain circumstances, entities around the state can gain access to medical record data housed by the health care cost containment council through the Right-to-Know-Law. The council can provide access to special reports derived from raw data to entities that purchase health benefits for their employees, collective bargaining representatives of those employees, and any other entities it deems appropriate.6