HSP Disease Coding and Claims: Who Actually Sees PHI
A referral fax lands at your front desk: "eval for HSP, please expedite." No code, no laterality, no clarifying note. Your referral coordinator has to route it, your coder eventually has to bill it, and somewhere between those two steps the chart will be copied into a prior authorization packet, a lab portal, and a clearinghouse queue. That is four organizations touching one patient's record before anyone has confirmed what the abbreviation meant.
This post is about the administrative machinery around hsp disease encounters — coding documentation, claims attachments, vendor access, and records requests. It is not clinical guidance. It is the paperwork map you need so that the PHI generated by a rare-disease workup does not end up in six places you never inventoried.
The Abbreviation Problem: "HSP" Is Not One Code
In everyday clinical shorthand, "HSP" gets used for at least two unrelated conditions. One is Henoch-Schönlein purpura, now more commonly called IgA vasculitis, which lands in the allergic purpura family of ICD-10-CM (D69.0). The other is hereditary spastic paraplegia, a genetic neurological condition coded in the G11 hereditary ataxia and related family (G11.4). Different specialty, different documentation trail, different payer rules.
You do not need to resolve that ambiguity clinically — that is the provider's job. You need a documentation rule that prevents the ambiguity from reaching the claim. In practice that means your intake and coding staff never expand an abbreviation on the patient's behalf. If a referral or a note says only "HSP," it goes back to the ordering or rendering provider for a spelled-out diagnostic statement before the encounter is coded.
Why does this belong in a privacy article? Because guessing wrong generates a downstream mess with real PHI consequences: a claim denied on medical necessity, an appeal packet assembled in a hurry, and a records dump sent to a payer that includes far more of the chart than the appeal required. Sloppy coding is the most common upstream cause of over-disclosure I see in small practices.
Verify the code set you are using against the current official files rather than a cheat sheet in a shared drive. CMS publishes the annual ICD-10-CM code files and updates, and code descriptions do change between fiscal years.
Who Touches the Chart in a Single HSP Disease Claim
Take one patient, one specialist evaluation, one claim. Here is the realistic list of entities that see identifiable information, in the order they usually see it:
- Front desk / intake. Demographics, insurance card image, the referral document with the abbreviation on it.
- Referral coordinator. Chart summary sent to the receiving specialist's office, often by fax or a portal upload.
- Rendering provider and scribe. If you use a documentation assistant or an ambient transcription tool, that tool is a business associate handling the full narrative.
- Reference or genetic lab. Requisition with diagnosis, demographics, and sometimes family history.
- Coder or coding vendor. Full encounter note, plus any pathology or imaging report used to support code selection.
- Practice management system and clearinghouse. The 837 claim: patient identifiers, diagnosis codes, procedure codes, rendering provider.
- Payer and its utilization management subcontractor. Prior authorization packet, medical records attachments, appeal documentation.
- Statement and collections vendor. Patient balance, service dates, sometimes a service description.
- Specialty pharmacy or infusion coordinator, where applicable, receiving a benefits investigation with diagnosis attached.
That is nine touchpoints for one encounter. Count how many of them are covered by a signed, current business associate agreement in your files. In most practices I review, the answer is "most of them," and the gaps are always the same three: the coding contractor hired last year, the transcription or scribe tool a physician started using independently, and the statement printer inherited from a prior practice management migration.
The Vendor Gap You Will Find If You Look Today
Run this exercise: pull your last ten claims involving a rare or specialist-managed diagnosis. For each, list every organization that received any part of the record. Then match that list against your BAA binder. Any name without a matching agreement is an unpapered disclosure, and it is the kind of finding that turns a small incident into a lengthy investigation.
If you find a gap, close it the same week. You can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is faster than waiting for a vendor to send you their template and then negotiating their terms line by line.
Does a Diagnosis Code on a Claim Count as PHI?
Yes. A diagnosis code transmitted with a patient identifier is protected health information. The code itself, sitting alone in a codebook, is not. The moment it is paired with a name, member ID, date of birth, account number, or any other identifier, the whole record is PHI and every HIPAA rule applies to it.
That has three practical consequences for billing operations:
- Claim submission is a permitted disclosure for payment — you do not need an authorization to bill the payer, and you do not need one to send supporting documentation the payer legitimately requires to adjudicate.
- Minimum necessary still applies to those payment disclosures. "They asked for records" is not authority to send the entire chart. HHS guidance on the minimum necessary requirement expects you to have criteria limiting routine disclosures to what is reasonably needed.
- Internal access should be role-limited. Your statement clerk does not need the neurology narrative. Your scheduler does not need the genetic test report. If your practice management system cannot enforce that, document the compensating control and audit access logs on a set schedule.
Prior Authorization Packets: The Most Common Over-Disclosure
Conditions in the HSP disease category frequently involve specialist management, imaging, and sometimes genetic or laboratory confirmation. That means prior authorization and medical-necessity review are routine, and each review request is an invitation to send too much.
Build a packet standard before the next request arrives. For each recurring authorization type, define the exact document set: the order, the relevant office note, the specific report supporting the request, and nothing else. Put that standard in writing, name an owner, and require a second set of eyes when someone deviates from it.
A Worked Example of Packet Discipline
A payer requests "records supporting the requested consultation." Your billing coordinator's instinct is to print the last twelve months. Your standard says: the referral, the most recent relevant encounter note, and the one report cited in the order. Three documents, not forty pages of unrelated history, behavioral health notes, and a family member's contact log.
Log the disclosure regardless. Payment disclosures do not have to appear in a patient's accounting of disclosures, but a simple internal log — date, recipient, purpose, documents sent, staff member — is what lets you answer a complaint in an afternoon rather than a month.
Genetic Test Results Have Extra Handling Rules
Where a workup involves genetic testing, the resulting information is PHI and genetic information under the HIPAA Privacy Rule as amended following GINA. Health plans are prohibited from using or disclosing genetic information for underwriting purposes, and that prohibition shapes what you should be comfortable pushing into a claims or benefits-investigation channel.
Two operational rules keep you clean. First, do not attach genetic reports to a claim unless the payer's published policy specifically requires them for adjudication; if it does, send the report page, not the full lab file. Second, treat genetic results as a distinct document class in your record system so that a broad records request does not sweep them up by default.
Family history is the quiet risk here. A hereditary condition workup often documents relatives' health information inside your patient's chart. When you respond to a records request, that relative's information travels with it. Flag those sections during review rather than after.
The 30-Day Clock When the Patient Asks for the Billing Record
Patients with a long specialist trail request records more often than average, and they frequently want the billing record — claims, EOB copies, itemized statements — not just clinical notes. Both live in your designated record set.
You generally have 30 days to act on a request, with one 30-day extension available if you notify the patient in writing with a reason. Fees must be limited to the reasonable cost-based amount HHS describes in its right of access guidance. Per-page schedules borrowed from state subpoena rules are one of the most reliably enforced-against practices in this space, and access complaints have been a persistent driver of OCR resolutions, which you can browse in the HHS breach portal and enforcement listings.
Where Requests Stall in Practice
Almost always at the seam between clinical and billing systems. Clinical staff pull the notes, assume someone else handles claims data, and the request sits. Assign one owner per request who is accountable for both halves, and give that owner authority to pull from the billing system without a second approval chain.
Denials, Audits, and the Records Requests That Are Not Really Requests
Rare-diagnosis claims draw scrutiny. You will see additional documentation requests, retrospective reviews, and sometimes contact from a third party claiming to audit on a payer's behalf. Before anyone sends a page, verify two things: that the requester is who they say they are, and that the request falls within payment or health care operations rather than something requiring authorization.
Give your billing staff a scripted escalation. Any records request that arrives from an unfamiliar entity, by an unusual channel, or with unusual urgency goes to the privacy officer before a single document leaves the building. Pretexted records requests aimed at billing departments are not exotic; they work because billing staff are trained to be responsive.
What to Fix Before the Next Quarter Closes
- Write the abbreviation rule. Ambiguous shorthand like "HSP" never gets expanded by non-clinical staff. It goes back to the provider.
- Reconcile your vendor list against actual claim and referral traffic, not against last year's binder.
- Define packet standards for your five most common prior authorization and appeal types.
- Separate genetic and family-history documents into a flagged class in your record system.
- Name a single owner for each records request, spanning clinical and billing systems.
- Audit access logs quarterly for the roles that should never see specialist narratives.
None of these require new software. They require a decision, a written procedure, and someone whose name is on it.
Start With the Paper You Can Fix Today
The coding and claims trail behind an hsp disease encounter is long, crosses organizational boundaries, and generates PHI in systems you do not control. You cannot shorten the trail much. You can make sure every stop on it is papered, scoped, and logged.
If your vendor reconciliation turns up missing agreements, build the BAA you need in a few minutes and export it for signature. If the deeper problem is that your risk analysis and policy set have not been refreshed since your last system change, the full compliance document set can be generated and updated rather than rebuilt from scratch each year. Either way, start with the gap you can close this week.