Q. A large specialty medical group with a nonprofit research foundation allows the foundation to use its patient database for its annual giving campaign mailing. Does this practice violate HIPAA?
A. This is acceptable provided that the medical group informs individuals about this use of their information in their Notice of Privacy Practices and gives them the opportunity to opt-out if they do not wish to receive further fundraising communication.
In addition, covered entities may only use patients' basic demographic data for fundraising purposes; they may not use any type of clinical information for targeted fundraising.