Validating profile... 0% complete

What is your current level of experience in freelance work?

 

 

HIPAA and GDPR Expert for Healthcare systems

Healthcare Data Compliance Consultant Needed - Patient Data Deletion Policy Review Project Overview We are seeking a healthcare compliance consultant with expertise in California privacy laws and HIPAA regulations to review and provide recommendations on our patient data deletion practices. About Us We operate an Electronic Health Record (EHR) system based in California. We need professional legal guidance regarding our patient data deletion policies, specifically when patients request removal of their information from our system. Current Challenge We understand that healthcare providers are legally required to retain patient health information for specific periods. However, we're seeking clarity on our obligations as an EHR software provider when patients explicitly request data deletion. Current Data Deletion Process Our system currently handles patient deletion requests as follows: Creates a comprehensive backup (ZIP file) of all patient data, including demographics, clinical notes, and invoices Removes identifiable patient data from our live system, replacing names with numeric identifiers and wiping associated data Automatically deletes the backup ZIP file after 7 days Patient data can be deleted through: Patient-initiated requests via our patient portal Staff members with appropriate permissions via the patient dashboard Deliverables Required Comprehensive legal assessment of our current data deletion practices Identification of potential compliance gaps under California law, HIPAA, and relevant federal regulations Specific recommendations for policy modifications to ensure legal compliance Guidance on appropriate data retention periods and documentation requirements Recommendations for patient notification and consent processes.