Healthcare Must Stop Treating Phone Numbers as Proof of Patient Identity

Healthcare organizations routinely use phone numbers as if they're a reliable link to a patient's identity.

Here's how it typically plays out.

A patient provides a number during registration. The practice stores it in the electronic health record (EHR). Months later, staff use the same number to send appointment details, billing information, test results, or follow-up instructions.

However, a phone number is technically a routing address.

It doesn't prove who currently controls the number, who can access the device, or whether the person receiving the message is still the patient associated with that record.

It is possible, therefore, for clinicians to select the correct patient record, use the exact phone number listed in the system, and still send protected health information (PHI) to the wrong person.

The underlying issue is not always human error.

It is the assumption that a stored phone number remains a dependable representation of patient identity over time.

Let’s expound on the last point.

‍

‍

Table of Contents

‍

1. The correct phone number can still reach the wrong person

2. Personal address books create patient identity problems

3. A matching phone number is not enough to authenticate a patient

4. Secure patient communication needs its own separate channel

5. How healthcare organizations should handle caregivers and other authorized recipients

6. Message archives become critical when identity checks fail

7. Patient communication systems need more than a stored phone number before sending PHI

8. The bigger lesson

‍

‍

The correct phone number can still reach the wrong person

Consider a hypothetical patient who registers a mobile number during a healthcare facility visit. 

A receptionist confirms the number, and the practice copies it from the EHR into its messaging platform. 

Several months later, the patient stops using that number. Eventually, the carrier assigns it to another subscriber. But the patient hasn't notified the practice, so both the EHR and messaging platform retain the number..

During a subsequent follow-up, a clinician selects the correct patient and sends treatment instructions. The messaging platform reports successful delivery.

From an operational perspective, the systems appear to have worked. The records match, the employee followed the usual procedure, and the message reached its destination. However, the patient no longer uses the number. And there’s in lies the possibility of a HIPAA breach. 

Shared phones create a related problem. 

A number can remain active and associated with the patient. However, a spouse, caregiver, or another household member could read incoming messages, creating a privacy breach. Connected tablets and computers can also make those conversations accessible elsewhere. 

The problem here is the assumption that a number remains a dependable connection to one patient indefinitely. 

‍

‍

Personal address books create patient identity problems

Healthcare organizations create another privacy problem when staff communicate with patients from devices that also contain personal contacts.

Indeed, personal address books are convenient to use. However, healthcare communication requires stricter separation.

Staff need a controlled patient address book that distinguishes verified patient contacts from friends, relatives, personal service providers, and unrelated entries.

Besides, mixed contact lists increase the chance of selection errors.

For instance:

  • Similar names can appear next to each other
  • Autocomplete can suggest a personal contact after an employee types only a few characters
  • Old patient entries can remain beside current ones
  • Employees can also save patients under informal names that colleagues may not recognize

A healthcare-managed address book reduces those problems by separating patient contacts from personal entries.

It can also associate each phone number with additional context, such as:

  • Patient name
  • Internal patient identifier
  • Verification status
  • Authorized caregiver
  • Communication preference
  • Account ownership

The point is, a personal phonebook simply stores names and numbers. A business address book, in comparison, connects patient identities, approved recipients, communication destinations, and authorization details.

‍

‍

A matching phone number is not enough to authenticate a patient

Healthcare organizations need to distinguish identification from authentication.

On one hand, identification tells the system who a person claims to be. Authentication, on the other, checks the evidence for that claim. 

A stored phone number can help with identification. On its own, however, it provides weak authentication.

If a patient sends a message from a number already listed in the EHR, the system can recognize the number. However, that doesn't prove who is currently typing the message.

The same problem applies when the practice starts the conversation.

When staff sends PHI to the number stored in the patient record, they confirm the destination they selected but can't determine who ultimately reads the message.

Two internal systems can also contain matching information and still point to the wrong person.

Suppose the EHR and messaging platform both list the same mobile number for a patient. While the match confirms that systems contain the same data, that's not enough to prove the patient still accesses or uses the number.

‍

‍

Secure patient communication needs its own separate channel

Healthcare organizations create privacy problems when staff use the same messaging apps for patient conversations and personal chats.

For sensitive patient information, healthcare organizations need a separate communication channel, distinct from regular SMS, and one that links the conversation to a verified patient or an approved recipient.

A separate channel makes it easier to separate:

  • Patient messages from personal texts
  • Verified patient contacts from regular phone contacts
  • Healthcare conversations from unrelated chats
  • Approved recipients from anyone who happens to have access to the phone number

Encryption also plays an essential role in protecting patient privacy.

But while it protects the message in transit, it cannot fix the recipient's mistake.

If a staff member sends an encrypted message to the wrong person, the healthcare provider can still expose private patient information.

Thus, healthcare facilities need encryption and identity checks. They require encryption to protect the message, and identity checks to confirm who should receive it.

‍

‍

How healthcare organizations should handle caregivers and other authorized recipients

Patient communication gets more complicated when another person communicates on the patient's behalf.

For example:

  • A caregiver may use their own number to manage appointments
  • A parent may communicate for a child
  • A child may assist an older parent
  • A spouse may be listed as an emergency contact

A healthcare provider should, therefore, know two things:

  • Who uses the phone number?
  • What information can that person receive?

A caregiver, for example, may be allowed to receive appointment updates but not detailed medical information. An emergency contact may also be listed in the patient record, but has no permission to receive routine PHI.

Healthcare facilities should record the relationship between the patient, the other person, the phone number, and the type of information that person can receive from the get-go.

Owning or using the phone number alone does not answer those questions.

‍

‍

Message archives become critical when identity checks fail

When a privacy incident occurs, the healthcare facilities need to determine exactly what happened. And, in most cases, staff memory is not enough.

A solid message record should answer questions such as:

  • Which employee sent the message?
  • Which patient contact did they select?
  • Which number received the message?
  • When did they send it?
  • What information did the message contain?
  • Did it contain any attachments?
  • Did the system confirm delivery?
  • Did the recipient reply?
  • Has anyone recently changed the contact details?
  • Who accessed the conversation afterward?

Centralized message archiving and activity records provide healthcare providers and privacy officers with concrete evidence to review during an investigation.

Archiving also means the organization doesn't have to rely solely on the employee's phone to determine what happened. 

And that’s crucial if an employee deletes a message, replaces a device, leaves the organization, or simply cannot remember exactly what happened.

It is worth noting, though, that while message archiving will not prevent a wrong-recipient error, it provides the organization with a reliable record for investigating the incident and documenting what happened.

‍

‍

Patient communication systems need more than a stored phone number before sending PHI

Before sending PHI, a healthcare provider should determine more than whether they have a phone number for this patient.

It should also ask:

  • Who does the number belong to?
  • When did the practice last verify it?
  • Does the patient still use or control the number?
  • Does another person have permission to use it?
  • What information can that person receive?
  • Does the message contain sensitive information that needs another identity check?
  • Do other systems contain a different number for the same patient?
  • Is the conversation happening through a business-managed communication channel?
  • Can the organization review the message later if something goes wrong?

These questions give the facility more context before it sends sensitive information.

‍

‍

The bigger lesson

Indeed, a phone number can tell a healthcare system where to send a message, but it cannot prove who will receive it.

The difference is easy to overlook because the number appears next to the patient's name inside the EHR. Over time, however, the patient may stop using the number, share the device, hand communication over to a caregiver, or lose access to the account.

Healthcare providers should treat phone numbers as contact information, not permanent proof of identity.

They should also build patient communication around verified contacts, separate patient directories, secure messaging channels, appropriate permissions, and reliable message records.

The lesson here is straightforward. 

Sending a message to the number listed in the patient record does not automatically mean the right person received it. 

Healthcare organizations need to consider who controls the number, who can access the conversation, and how confidently their communication setup links that line to the intended patient.

‍

‍

Tags
No items found.
Download Our APP Now!