EHR, Meaningful use, ICD-10, Electronic Health Records
EHR Adoption > Has Practice Fusion’s review site violated patient privacy?

Has Practice Fusion’s review site violated patient privacy?

Author | Date October 23, 2013

Up until now, the criticism received by Practice Fusion about its free EHR solution appears unwarranted considering the number of ambulatory care providers who have adopted the certified EHR technology. However, a new wave of criticism could be merited if a recent report about the company’s handling of user privacy is in fact true.

According to Kashmir Hill of Forbes, San Francisco-based EHR developer may be in hot water over its handling of patient reviews which became public, potentially exposing sensitive patient data as well as personally identifiable information (PII).*

Editor’s note: Practice Fusion has responded to the article in Forbes. See the response in the comments section below.

The source of the problem is a doctor review site launched by Practice Fusion in April:

The site came as a surprise to some doctors — who knew the start-up emailed their patients appointment and prescription reminders but didn’t realize it had been reaching out to their patients after visits asking for reviews. And it is likely a surprise to some of the patients whose reviews are available publicly on the site. There are candid reviews with sensitive medical data and “anonymous reviews” that contain patients’ full names and/or contact details, suggesting they didn’t realize that what they were writing was going to be made public.

Around March, Practice Fusion informed physicians of their intentions with the review site and even game them a glimpse of what patients would receive, but the problem appears to be a lack of any mention that the reviews would be made public, reports Hill.

A representative from the company told Forbes that its practices are reviewed by HIPAA experts and that the emails themselves were HIPAA compliant. However, Hill has pointed to the possibility that the company could be motivated by a more business-oriented end. “While Practice Fusion says contacting patients for reviews is a service done on behalf of doctors — as is required by HIPAA — the cynical take is that they used their access to patient records for business purposes — to build a review site to compete with ZocDoc and Yelp,” she writes.

Health data privacy and security watchdog published the company’s “lengthy privacy policy” and surmised that the company is likely to have a health data breach on its hand:

If patients weren’t properly informed about the public nature of their feedback and didn’t provide informed consent, I’d say that Practice Fusion has a whopping HIPAA privacy disclosure breach on its hands. Hopefully, HHS is looking into this whole thing. And if healthcare providers didn’t fully understand how Practice Fusion would be using the information provide, then that’s a second round of complaints/matter to be investigated.

With Stage 2 Meaningful Use staring down eligible professionals and Stage 1 still a focus on some providers late to the game, Practice Fusion’s handling of the situation could end up costing them in one form or another.

Related Resources:

  • Practice Fusion

    The accusations outlined in Kashmir Hill’s article are false. The patient review program does not violate HIPAA and follows all regulations. The content below outlines the relevant facts:

    1. Practitioners have complete control
    a. They can elect to not send patient surveys at all
    b. They can elect to send patient surveys and keep their reviews private
    c. They can elect to send patient surveys and post their reviews to their profiles
    2. Patients explicitly consent to sharing their survey responses online
    3. The terms of this program are clearly outlined in our Business Associate Agreement
    a. As with all our features, we have publicized this program to our customers and have acknowledgements from each customer that they saw the notifications
    b. Our offering is free and the doctor has complete freedom in deciding to use the product and can choose to leave Practice Fusion at any time

    More information can be found here:

    Our mission at Practice Fusion is connecting doctors, patients and data to drive better health and save lives. We take this seriously and have an ethical obligation to make sure patients are aware of the quality of their provider, and that practitioners have visibility into the feedback from their patients; this is why we make this functionality available to our physician-patient community.

    Ryan Howard, CEO & Founder, Practice Fusion


Sign up for our free newsletter and join

40,000 of your peers to stay up to date with tips and advice on:
  • Meaningful Use
  • ICD-10
  • EHR Replacement

no, thanks

Our privacy policy