Splinter Hemorrhage Referrals: Records Sharing Rules
It is 9:40 on a Tuesday. A primary care clinician documents a splinter hemorrhage under a patient's fingernail, orders labs, and sends the patient out with two referrals — dermatology and cardiology. By Friday your front desk has fielded a records request from the dermatology group, a phone call from a hospital lab asking you to re-fax an order, a patient portal message asking why the specialist "doesn't have anything," and a photo of the nail sitting in a clinician's phone camera roll.
Nothing about that week is clinically unusual. All of it is administratively unusual, because a single finding just pulled protected health information across three separate covered entities in under 96 hours. This article is about that movement: which disclosures are permitted without authorization, what your staff should actually send, where the images live, and which vendors in the path need a signed agreement.
The Three-Organization Problem a Splinter Hemorrhage Creates
Most encounters generate records that stay put. Referral-heavy findings do not. A splinter hemorrhage is a nail-bed finding that clinicians frequently evaluate with input from another specialty, and that alone determines your administrative exposure: charts move, images move, and lab results route to organizations that never touched your intake paperwork.
Map it once and you will see the pattern in dozens of other encounters. Your practice sends a referral packet out. A specialist sends a consult note back. A hospital or reference lab sends results to both of you. A release-of-information vendor or e-fax service touches the transmission. Possibly a health information exchange sits in the middle. That is four to six information flows per patient, each with its own failure mode.
The failure modes are boring and predictable: the fax goes to a retired number, the packet includes eleven years of unrelated chart, the consult note lands in a scanning queue nobody works on Fridays, and the clinical photo of the nail never leaves a personal device. None of those are clinical problems. They are yours.
Does a Splinter Hemorrhage Referral Need a Signed Authorization?
No. Under the HIPAA Privacy Rule, a covered entity may disclose protected health information to another covered entity for that entity's treatment activities without a patient authorization. Sending a referral packet for a splinter hemorrhage evaluation to a dermatologist, rheumatologist, or cardiologist is a treatment disclosure, permitted under 45 CFR 164.506(c)(2). The same is true when the specialist sends the consult note back to you.
You do need a signed authorization when the disclosure falls outside treatment, payment, or health care operations. Common examples in this exact workflow:
- The patient asks you to send the chart to an attorney, an employer, or a disability insurer.
- A life insurance underwriter requests records.
- Records go to a research registry outside a waiver or limited data set arrangement.
- Psychotherapy notes are involved, which carry their own authorization requirement.
- Marketing or any disclosure that constitutes a sale of PHI.
Train your front desk on the split, because staff routinely over-collect. Chasing a signature you do not need delays a referral, and information blocking rules make unnecessary delay its own problem. HHS's guidance on permitted uses and disclosures for treatment, payment, and health care operations is short enough to hand to a new hire during week one.
Minimum Necessary Does Not Apply to Treatment — But Your Sending Habit Should
The minimum necessary standard does not apply to disclosures to or requests by a health care provider for treatment purposes. That is a genuine exemption, and HHS says so plainly in its minimum necessary guidance.
It is also the most abused sentence in referral operations. "We're allowed to send everything" quietly becomes "we always send everything," and a 340-page PDF crosses the wire because it was easier than curating. Every extra page is extra breach surface if the transmission misfires, and specialists genuinely cannot find the relevant note inside it.
Define the referral packet at the policy level, not the staff level
Write a standing referral packet definition and put it in your Privacy policies so it survives turnover. A workable default for a specialty referral:
- Demographics and current insurance
- The referring encounter note
- Problem list, medication list, allergies
- Relevant labs and imaging from the past 12 months
- Any clinical images tied to the referred finding
- The referral order itself, with the clinical question stated
Anything beyond that requires a clinician to say why. This is not a HIPAA requirement — it is a control that reduces the volume of PHI in motion, which is the only reliable way to reduce the size of an eventual incident.
Photographs, Dermoscopy Images, and the Personal-Phone Problem
Nail and skin findings get photographed. That is the single highest-risk artifact in this whole workflow, because images are the one form of PHI that staff routinely create on hardware you do not control.
A photo of a splinter hemorrhage taken on a clinician's personal phone is PHI the moment it exists. It syncs to a consumer cloud account. It appears in a shared family photo stream. It gets texted to a colleague through a messaging app you never evaluated. When that clinician leaves your practice in eighteen months, the image leaves with them, and you have no mechanism to retrieve or attest to its deletion.
Three controls that cost nothing
- Capture inside the record. If your EHR supports image capture through a managed app, that is the only approved path. Write it down and enforce it.
- Ban personal-device capture explicitly. A general "be careful" policy does not survive an OCR interview. Name the behavior.
- Handle the images you already have. Ask clinically active staff, once, in writing, whether patient images sit on personal devices, and give them a defined path to move and delete them. Do this before it becomes a discovery question.
If you cannot say today where clinical images are captured, stored, and backed up, that gap belongs in your risk analysis — the Security Rule requires an accurate, thorough assessment of risks to all ePHI you create, receive, maintain, or transmit, and images count. Practices that need to move from a stale spreadsheet to a defensible document set often start by generating a current HIPAA risk analysis and the supporting policy set rather than rewriting everything from a blank page. NIST's SP 800-66 Revision 2 is the free companion resource if you want to see how the assessment maps to each Security Rule standard.
The Referral Packet Workflow, With Roles and Clocks
Assign each step to a role, not a person. People leave; roles persist.
Outbound, same business day
Clinician places the referral order and states the clinical question in one line. Referral coordinator verifies the receiving organization's current secure destination — Direct address, portal, or verified fax number — against a list reviewed quarterly. Referral coordinator assembles the standing packet, transmits, and logs the transmission with date, recipient, method, and confirmation.
Verification, within two business days
Confirm receipt. Not "the fax report said OK" — an actual acknowledgment from the receiving practice or a portal receipt. Misdirected faxes remain one of the most durable causes of small-practice breach reports, and a fax confirmation page proves a machine answered, not that the right machine answered.
Inbound, within one business day of arrival
Records staff index the consult note to the correct chart and route it to the ordering clinician's inbox. Referral coordinator closes the loop in the tracking log. An open referral older than 30 days gets worked, because an unclosed referral loop is both a care-continuity problem and, if the patient later requests the complete record, a gap you will have to explain.
Which Vendors in This Path Need a Business Associate Agreement
Walk the splinter hemorrhage referral end to end and count the third parties. In a typical small practice you will find your EHR vendor, an e-fax or secure messaging service, a release-of-information vendor, a transcription service, a document scanning or shredding contractor, an IT managed service provider with remote access, and possibly a patient communication platform sending referral reminders.
Every one of those creates, receives, maintains, or transmits PHI on your behalf. Every one needs a signed business associate agreement, and the agreement needs to be current with the entity you are actually contracting with — not the company that acquired them two years ago under a different name.
The other covered entities in the chain do not need a BAA with you. A dermatology practice receiving a referral is a covered entity acting for its own treatment purposes, not your business associate. Staff confuse this constantly and stall referrals waiting for an agreement that was never required. If your BAA file has gaps, you can produce a signature-ready business associate agreement through a guided wizard and close them the same afternoon.
What You Log, and What You Do Not
Treatment, payment, and health care operations disclosures are excluded from the accounting of disclosures a patient can request under 45 CFR 164.528. So a routine referral packet does not go into the accounting log.
Log it anyway, in your referral tracking system. You are not doing it to satisfy 164.528; you are doing it so that when a patient calls in March asking whether their records ever reached the specialist, someone can answer in ninety seconds instead of interviewing three staff members.
Separately, keep the accounting log that the rule actually requires — disclosures for public health reporting, court orders, law enforcement requests, and similar. Those arrive rarely enough that no one remembers the process, which is precisely why the process needs to be written.
When the Patient Asks for the Chart Themselves
Different rule, different clock. A patient's right of access under 45 CFR 164.524 requires you to act within 30 days, with one 30-day extension available if you notify the patient in writing of the reason and the new date. The response covers the designated record set, which includes the consult notes and images you received from the specialist, not just what your own clinicians authored.
Right-of-access enforcement has been one of OCR's most consistent activity areas, and the settlements published on the OCR portal skew heavily toward small and mid-sized practices, not health systems. Fee limits matter too: you may charge a reasonable, cost-based fee, and "reasonable" does not mean per-page rates copied from a state statute you have not re-read since 2015.
The Next Two Weeks
Pick the referral pathway your practice uses most and trace one real encounter end to end. Note every organization the PHI touched, every vendor in the transmission path, every place an image was stored, and every point where a human had to remember something instead of following a written step. That trace is your gap list.
Then close it in order: verify destinations, define the packet, ban personal-device capture, fix the BAA file, and refresh the risk analysis so the documentation reflects the workflow you actually run. If you want the risk analysis, the policy set, and the supporting documents generated from your real environment rather than assembled by hand, start with a current HIPAA compliance document set and spend your remaining time on the parts only you can do — training the front desk and holding vendors to their agreements.