It's 7:50 on a Monday and your front desk is holding three pieces of paper: a skilled nursing facility's pre-hire health form, a school district's clearance letter, and a fax from a county health department. All three concern the same category of encounter — a latent TB screening — and all three want something different from your records system. One wants a result. One wants a signed attestation. One wants a report you may be legally required to send whether or not the patient agrees.

This post is about that workflow: what your staff must capture at the point of service, where the record lives, who is entitled to a copy, how long you keep it, and which outside parties on the path need a Business Associate Agreement. It is not clinical guidance. The clinical facts appear only because they explain why the paperwork moves the way it does.

Why a Latent TB Encounter Touches More Organizations Than a Typical Visit

Screening is usually initiated by someone other than the patient. An employer requires it. A school requires it. A licensing board, a residency program, a long-term care facility, or an immigration process requires it. That means a third party is waiting on an output from the start, which is different from a routine sick visit.

The workup also tends to be distributed. A blood-based test typically goes to a reference laboratory. Imaging is frequently performed elsewhere. Positive findings often route to an infectious disease specialist or a public health clinic. Your practice may be the ordering provider, the interpreting provider, the recipient of outside results, or all three at different points in the same case.

Every one of those handoffs is a disclosure that has to be authorized, logged, or both. Your records staff are the only people in the building who see the whole chain.

Map the chain before you build the workflow

Sit down with your practice manager and draw the actual path for a single case. A typical map looks like this:

  • Requesting party (employer, school, agency) → patient → your front desk
  • Your practice → reference lab → your practice
  • Your practice → imaging center → your practice
  • Your practice → specialist or public health clinic (referral)
  • Your practice → requesting party (release, with authorization)
  • Your practice → state or local health authority (reportable-condition disclosure, where required)

Six arrows. Each one needs an owner, a form, and a retention rule. Most practices have documented two of them.

This is the single most common structural error I see, and it costs practices real money in remediation.

When your clinic performs a screening on a member of the public, the resulting record is protected health information held by you as a provider. Standard HIPAA rules apply: right of access, accounting of disclosures, minimum necessary, the works.

When your organization screens its own staff as a condition of employment, the copy that lands in your HR file is an employment record, which HIPAA's definition of protected health information specifically excludes. HHS explains the boundary plainly in its guidance on employers and health information in the workplace. That does not mean the record is unprotected — the ADA requires employee medical information to be kept in files separate from personnel files, and state law often adds more. It means a different rulebook governs it.

The trap is the practice that screens its own medical assistants in its own clinic and drops the result into the EHR under a patient chart. Now you have one document that is simultaneously a clinical record subject to HIPAA and the source of an employment decision. Untangling that during an audit is unpleasant.

The fix is a documented intake question

Train the front desk to ask one thing before registration: who is paying for and requiring this visit? If the answer is "we are, as the employer," the encounter routes to your occupational health workflow, uses a separate consent, and the result goes to a designated HR custodian — not to the general chart-release queue. If the answer is anything else, it is a standard patient encounter.

What Records Must a Practice Keep for a Latent TB Encounter?

At minimum, your file for a screening encounter should contain:

  1. The order and its source — who requested the screening and under what requirement.
  2. The result document as received, including the performing lab or facility identifier and the date read or resulted.
  3. Any outside records you received (imaging reports, prior results from another provider) and the date received.
  4. The signed authorization for any release to a non-treatment third party, with its expiration date.
  5. A disclosure log entry for every release, including required disclosures made without authorization.
  6. The referral record, if the encounter moved to a specialist or public health clinic.
  7. Interpreter or language-assistance documentation, where applicable.

HIPAA itself requires you to retain required documentation — policies, authorizations, disclosure logs, notices — for six years from creation or last effective date. The underlying medical record retention period is set by state law and payer contract, not by HIPAA, and it is frequently longer. Check both.

Public Health Reporting Without an Authorization

Active tuberculosis is a reportable condition in every U.S. jurisdiction. Whether latent TB infection is separately reportable varies by state and sometimes by county, and several jurisdictions have added or expanded reporting requirements in recent years. Your compliance officer should have a current, dated citation to your state's reportable-condition list on file — not a memory of what it said in 2019.

The privacy question is easier than people fear. HIPAA permits disclosure to a public health authority authorized by law to receive the report, without patient authorization. The Privacy Rule's permitted-disclosure provisions cover it. The operational question is harder: who in your practice actually sends it, on what deadline, and how do you prove you sent it?

Document the required disclosure anyway

Required-by-law disclosures still belong in your accounting of disclosures, which patients can request. Log the date, the receiving authority, the specific data elements sent, and the statutory basis. A one-line entry per report is enough. Missing entries are what turn a routine access request into a complaint.

If your jurisdiction uses an electronic reporting portal or an interface from your EHR, confirm in writing whether the intermediary is acting as a public health authority, as your business associate, or as a conduit. Those are three different contractual outcomes and your vendor should be able to state which applies.

The 30-Day Clock and the Employer Attestation Form

A patient who asks for their own screening record gets it under the right of access: within 30 days, with one 30-day extension available if you provide written notice of the delay and the reason. Fees must be reasonable and cost-based, and you cannot condition access on payment of an unrelated balance. OCR's right of access guidance is the authority, and the agency has pursued a long series of enforcement actions on exactly this point. Delayed records are the most reliably penalized failure in the entire rule.

The employer form is a different animal. When a third party asks you to send results directly to them, you need a valid authorization identifying the recipient, the specific information, the purpose, and an expiration. A vague form signed 18 months ago at a staffing agency is not that.

Minimum necessary when the requester asks for "the file"

Employers and schools routinely request the whole chart when what they need is a single line: screened on this date, cleared or referred, signed by the provider. Send the attestation, not the record.

Build a one-page release template with the four fields the requester actually needs and use it every time. This is faster for your staff, reduces your breach surface, and satisfies minimum necessary without a debate. Keep a copy of what you sent, not just a note that you sent something.

Which Vendors on the Latent TB Path Need a Business Associate Agreement

Walk the six-arrow map again and ask, for each outside party: are they receiving PHI to perform a function on your behalf?

  • Reference laboratory — usually a covered entity in its own right, treating the exchange as treatment. Confirm the relationship in writing rather than assuming.
  • Imaging center — same analysis.
  • Release-of-information vendor — business associate, always. They handle your access requests.
  • Occupational health portal or pre-hire clearance platform — business associate when it processes PHI for you. This one is missed constantly.
  • Interpretation and translation service — business associate.
  • Fax-to-email or secure messaging service — business associate.
  • Document scanning or offsite storage — business associate.
  • Courier moving specimens with identifiers — evaluate; often yes.

If that list produced two or three names you cannot immediately match to a signed, current agreement, fix it this week. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is faster than routing a redline through counsel for a low-risk courier contract. Save the legal review for the vendors holding volume.

Note the direction of the agreement, too. If another practice sends you records because you are the specialist, you are not their business associate — that's a treatment disclosure. Vendors who invoice for "BAA services" they do not need are a recurring waste line in practice budgets.

Amendments, Stale Documents, and the Requester Who Comes Back in Three Years

Screening documentation has a long tail. A patient cleared for one employer will need the same document for the next one, sometimes years later. Two administrative consequences follow.

First, amendment requests. If a date, a name, or a facility identifier is wrong on a document an employer already received, the patient can request an amendment under HIPAA — and you must respond within 60 days, with one 30-day extension. You must also forward the amendment to parties you previously disclosed to, when the patient identifies them. That is why your disclosure log matters more than it feels like it does.

Second, authorization expiry. An authorization signed for a 2023 employer does not cover a 2026 request from a different employer. Your release staff need a hard rule: verify the authorization matches the current requester and has not expired, every single time, no exceptions for repeat requesters.

Access Logging When the Patient Is Also on Your Payroll

Screening results carry stigma. In practices that also employ people from the communities they serve, internal snooping is a live risk, and it is one of the categories that reliably shows up on the OCR breach portal as an unauthorized access incident rather than a hacking event.

Two controls, both cheap. Run a monthly report of chart access by staff who are also registered patients at your practice, and review any access outside a documented care relationship. Second, put a named individual — not "the office" — on the review, and log that the review happened. An unreviewed audit log is worse than no log, because it proves you had the data and did nothing with it.

The 90-Day Version of This Project

  • Week 1: Draw the six-arrow map for your own practice. Name an owner per arrow.
  • Week 2: Pull your state's current reportable-condition list. Date it and file it.
  • Week 3: Separate employee screening from patient screening in your intake script and your record locations.
  • Weeks 4–6: Build the one-page attestation release template. Retire the "send the whole chart" habit.
  • Weeks 7–9: Reconcile the vendor list against signed BAAs. Close the gaps.
  • Weeks 10–12: Turn on the monthly access review and document the first one.

None of this requires new software. It requires deciding who owns each handoff and writing it down.

If the vendor reconciliation turns up gaps, start with the BAA generator for the straightforward agreements, and if your broader documentation set — risk analysis, policies, workforce training records — has not been refreshed since your last screening workflow changed, automated compliance documentation will get you a defensible baseline faster than rebuilding templates by hand. Either way, the goal is the same: when the next fax arrives asking for a latent TB clearance, your staff already know which bucket it lands in, who signs it, and what leaves the building.