I apologize for sending out another "scary" email, but I wanted to update you on the Red Flag Rules that went into effect November 2008. The Federal Trade Commission is requiring that those businesses that handle sensitive personal information implement safeguards to protect against identity theft. As physician practices handle sensitive and personally identifiable information all day long, most practices fall under the auspices of the new law and are required to put in place a written plan designed to pick up on "Red Flags" of potential identity theft.
The AMA has sent a strong letter to the FTC urging them state that the Red Flag Rules do not apply to physicians, however, the FTC has not responded yet.
I've attached a brief article on the topic. Please let me know if you have any questions or comments.
The information contained in and attached to this email are for educational purposes only and does not constitute legal advice.