On a typical Tuesday, a busy occupational health practice may run thirty telehealth intakes that end the same way: an order sent to a lab, a patient told where to get blood drawn, and a form somebody's employer wants back by Friday. A quantiferon gold screening visit is one of those. Clinically it is short. Administratively it touches your telehealth platform, your e-signature vendor, your lab interface, your public health reporting obligation, and — most dangerously — a third party who wants the result and has no treatment relationship with the patient.

This article is for the person who owns that workflow. Not the clinician. You. It maps the consent artifacts, the vendor agreements, the disclosure rules, and the timelines that surround a telehealth-initiated screening order.

Why quantiferon gold visits generate more paperwork than clinical complexity

Tuberculosis screening blood tests are ordered overwhelmingly for administrative reasons: pre-employment clearance, hospital credentialing, school or clinical-rotation requirements, immigration paperwork, long-term care staff onboarding. That means a third party is almost always waiting on the result.

Two structural facts follow. First, a non-patient — an employer, a school, a staffing agency — has a stake in the outcome and will call your front desk about it. Second, tuberculosis is a reportable condition in every state, so results may travel to a public health authority regardless of what the patient wants. Both facts are administrative, not clinical, and both are yours to manage.

Add telehealth as the intake channel and you have introduced a software vendor, a scheduling vendor, an identity-verification step, and often a separate e-signature tool. Each one is a place where protected health information moves before a single tube of blood is drawn.

Most practices capture one and assume it covers everything. It does not. These are four distinct documents doing four distinct jobs, and an auditor or a plaintiff's attorney will read them separately.

State law drives this one, not HIPAA. Many states require documented informed consent for telehealth specifically, sometimes with prescribed language about the limits of the modality and the patient's right to request an in-person encounter. Your intake form should record the consent text version, the timestamp, and the state the patient was physically located in at the time of the encounter.

That last field matters more than administrators expect. If your practice serves patients across state lines, the applicable telehealth consent rule and the applicable state privacy statute both key off patient location, not your office address.

2. Notice of Privacy Practices acknowledgment

You must make a good-faith effort to obtain written acknowledgment of receipt of your NPP for direct treatment relationships. In a telehealth flow this is usually a checkbox plus a downloadable PDF. Two failure modes recur: the NPP link 404s after a website redesign, and the acknowledgment is captured but never written back to the chart. Test both quarterly.

3. Authorization for disclosure to a third party

This is the document that keeps practices out of trouble. If the patient wants the result sent to an employer, a school, or a staffing agency, you need a HIPAA-compliant authorization under 45 CFR 164.508 unless a specific exception applies. It must name the recipient, describe the information with specificity, state an expiration date or event, and carry the revocation language.

Do not accept a blanket "release all records to my employer" form drafted by the employer's HR department. Scope the authorization to the screening result and the specific date of service. Minimum necessary does not technically apply to disclosures made pursuant to an authorization, but sending an entire chart when a one-page result was requested is how practices end up in an OCR complaint file.

4. Financial responsibility and who the customer is

Employer-paid screening changes the billing path and sometimes the legal posture of the encounter. Record whether the patient, an employer, or a payer is responsible. If the employer pays, that fact does not by itself entitle the employer to the result — a distinction your front desk needs scripted, because employers ask.

Does an employer need authorization to receive quantiferon gold results?

Usually yes. If your practice has a treatment relationship with the patient and the employer is simply an interested party, you need a signed HIPAA authorization naming that employer before you release a quantiferon gold result.

There is one narrow exception at 45 CFR 164.512(b)(1)(v). A covered entity that provides health care to an individual at the request of the employer may disclose findings to that employer when the care relates to a work-related illness or injury or to medical surveillance of the workplace, the information is limited to findings about whether the individual meets workplace medical surveillance requirements, and the individual receives written notice that the information will be disclosed. The notice must be given at the time care is delivered, or posted prominently where care is provided.

Read the conditions narrowly. If any of them fails, get an authorization. The practical rule for your staff: an authorization is always defensible; the occupational surveillance exception is only defensible when you can produce the written notice and show the visit was employer-requested surveillance. Build the exception path as a deliberate, documented intake branch — not as something the front desk decides on a phone call.

Your vendor map for a single screening encounter

Walk one quantiferon gold telehealth visit end to end and list every organization that touches identifiable data. A typical list runs longer than administrators expect:

  • Telehealth video platform
  • Online scheduling and intake form vendor
  • E-signature provider handling the authorization
  • Patient portal or secure messaging tool
  • Clearinghouse or billing service
  • Transcription or ambient documentation tool, if used
  • Cloud storage or backup provider
  • IT managed services provider with administrative access
  • Answering service or after-hours triage line
  • Release-of-information contractor, if you outsource records

Every one of those needs a business associate agreement. The reference lab performing the assay generally does not — a lab is a covered entity in its own right and receives the order for treatment purposes, which is a permitted disclosure. Interfaces and middleware sitting between you and the lab, however, frequently do need one. So does a courier company that handles specimens with identifiers, depending on the arrangement.

If your BAA binder has gaps — and after two years of adding telehealth tools it probably does — you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, as a one-time purchase rather than another subscription. Close the gaps vendor by vendor before your next risk analysis, not after. HHS publishes sample business associate agreement provisions if you want to compare required clauses line by line.

One caution on the telehealth platform specifically: the OCR enforcement discretion that applied during the public health emergency ended in 2023. Consumer video tools used without a BAA are no longer covered by any grace period. If a clinician is still taking screening intakes on a personal video account, that is a finding waiting to happen.

Public health reporting runs on a separate track

Reportable-condition disclosures to a state or local public health authority are permitted under 45 CFR 164.512(b) without patient authorization. Your obligation is to know your state's reporting mechanism, timeline, and designated reporter — and to log the disclosure.

Two administrative points. First, these disclosures are not treatment, payment, or operations, so they belong in your accounting of disclosures. Under the right of access rules a patient can request an accounting covering the six years prior to the request; if your system cannot produce one, that is a gap to fix now. Second, the reporting duty often sits with the ordering practice and the performing lab simultaneously. Duplicate reports are a nuisance; zero reports are a violation. Confirm in writing which party files.

Results routing, patient access, and information blocking

Patients have a right under HIPAA to access their records, and under the 2014 CLIA amendment they may also request completed test reports directly from the performing laboratory. Both paths exist. Your workflow should assume the patient may see the result before your clinician calls.

Delaying release to the patient portal purely to allow a clinician to "call first" can implicate the information blocking rules. Practices that maintain a blanket delay on all results should document the specific exception they are relying on and review it with counsel. The information blocking resources at HealthIT.gov lay out the exception framework.

The 30-day clock

When a patient — or a personal representative, or a third party under a valid patient-directed request — asks for records, you have 30 calendar days, extendable once by 30 days with written notice of the reason and the new date. Fees must be reasonable and cost-based. OCR's Right of Access Initiative has produced a long line of settlements against small practices, most of them over requests that simply sat in someone's inbox. The HHS right of access guidance is worth putting in front of every staff member who opens the mail.

A ten-step workflow you can hand to the front desk

  1. Patient books online; scheduling vendor is under BAA and collects the minimum necessary fields.
  2. Intake form captures patient's physical location at time of visit, employer or school requiring the screening, and who is paying.
  3. Telehealth consent presented with version number; timestamp written to chart.
  4. NPP delivered and acknowledgment recorded.
  5. If a third party will receive results, present a scoped authorization naming that recipient and expiring on a defined date.
  6. If the visit is employer-requested workplace surveillance, deliver the 164.512(b)(1)(v) written notice and store proof of delivery.
  7. Order routed to lab; interface vendor confirmed under BAA.
  8. Result returns; released to patient per your standard portal policy, exceptions documented.
  9. Third-party disclosure executed strictly within the authorization's scope; logged with date, recipient, and content sent.
  10. Reportable-condition disclosure, if triggered, filed by the designated reporter and entered in the accounting of disclosures.

Six things to audit before your next quarter closes

  • Pull ten screening charts. Confirm all four consent artifacts exist and are legible.
  • Check authorization scope. Any that say "all records" get rewritten.
  • Reconcile the vendor list against signed BAAs, including anything added in the last twelve months.
  • Test the front desk script by having someone call and pose as an HR manager asking for a result.
  • Verify your accounting of disclosures can produce a six-year report on demand.
  • Confirm the public health reporting owner in writing with your reference lab.

Screening encounters look like the lowest-risk thing on your schedule, which is exactly why they get the least governance attention. Review the HHS breach portal and you will find plenty of incidents that began with a routine disclosure to a party who should not have received it.

Where to start this week

Start with the vendor list, because it is the one item you can close completely in a single afternoon. Enumerate every organization that touches a telehealth screening encounter, mark which ones have a current signed agreement, and build the missing Business Associate Agreements in one sitting. If the exercise turns up more structural gaps than paperwork gaps, an automated risk analysis and policy set will give you a documented baseline to work from — and something concrete to hand OCR if they ever ask what your practice actually does.