What PHI Looks Like in a Clinical Setting
Protected Health Information is any individually identifiable health information held or transmitted by a covered entity or its business associate. In a hospital or surgical setting, a sales rep encounters PHI in forms that are easy to overlook.
Signs of a Privacy Risk in Clinical Settings
What Medical Device Sales Reps Must and Must Not Do
Emergency Response: If You Inadvertently Encounter or Disclose PHI
Supervisor Tips
Worker Checklist: Before and During Each Clinical Visit
Key Takeaways
Frequently Asked Questions
Am I personally liable for a HIPAA violation as a sales representative?
Potentially yes. Criminal penalties under 42 U.S.C. 1320d-6 apply to individuals who knowingly obtain, use, or disclose PHI in violation of HIPAA. Civil liability falls primarily on the covered entity and the business associate (your employer), but individual employees have faced enforcement consequences in cases involving intentional or reckless disclosure. The safer framing: treat your HIPAA obligations as personal obligations, not just your company’s problem.
Can I take photos of a device I implanted or installed for sales records or case documentation?
Not without explicit authorisation. A photo of a device in use during a procedure almost always captures patient identifiers, either directly (the patient is visible) or indirectly (device serial number linked to a patient, procedure type, date). Facilities have specific policies on clinical photography. Check those policies before the case, not during it. Many facilities require a separate patient consent form for any photography involving a device in situ.
What if a surgeon or nurse gives me permission to photograph during a case?
Clinical staff cannot authorise a HIPAA waiver on behalf of the facility or the patient. Only the facility’s privacy officer or an authorised administrator can grant that permission, and the patient’s own authorisation may also be required depending on whether they are identifiable in the image. A surgeon saying “go ahead” is not compliant authorisation. This is one of the most common misunderstandings in clinical sales settings.
What is the minimum necessary standard and how does it apply to me?
The minimum necessary standard requires that access to PHI be limited to the least amount needed to accomplish the legitimate purpose. As a device sales rep, your legitimate purpose is typically supporting the use or maintenance of a specific device. You should not access patient records, scheduling systems, or clinical documentation beyond what that purpose requires. If your BAA authorises access to device tracking records, that authorisation does not extend to viewing a patient’s full medical history even if the system allows it technically.
Government and Regulatory Sources
- HHS – HIPAA Privacy Rule
- HHS – HIPAA Security Rule
- HHS OCR – HIPAA Enforcement
- HHS – Business Associate Agreement Guidance
Related VelSafe Articles
- HIPAA: The Impact on Clinical Research
- Hearing Conservation: What Every Worker Needs to Know
- Heat Stress Law: OSHA Requirements and Employer Compliance
Staying Compliant in the Field
HIPAA compliance for medical device sales representatives is practical, not theoretical. The rules reduce to a few operational habits: confirm the BAA, do not photograph, keep case information within the clinical team, report incidents the same day, and access only what your authorised purpose requires. A rep who follows those habits consistently will not generate a HIPAA incident, regardless of how often they work in clinical environments. Find more compliance resources at velsafe.com.


