Welcome to the AMS Team

Welcome to the AMS Team

Before you get access to any system, there's one thing to finish: HIPAA privacy and security training. Read it once, carefully. You'll be tested on it, and everything in it is something you'll use in your first week.

STEP 1
Enter your name
STEP 2
Read the training
STEP 3
Pass the assessment
STEP 4
Sign and get access

Start here

Your name and today's date carry through to the attestation at the end.

Enter your first name, last name, and date before checking your score.


1 Why this training exists

You are being trained because federal law requires it, and because you will handle information that can seriously harm people if it is mishandled.

HIPAA protects patient health information. Two rules matter to you: the Privacy Rule, which governs who may see and share health information, and the Security Rule, which governs how electronic health information is protected. Training is required by 45 C.F.R. § 164.530(b) and § 164.308(a)(5), before you receive access to any system and every year after.

The practical reason matters more than the legal one. A patient whose information is mishandled loses trust in their care. Some stop seeking treatment. Some are harmed by disclosure to an employer, a family member, or an ex-partner. These rules exist because those outcomes are real.

2 Who you are under HIPAA

You are a workforce member of AMS. Under 45 C.F.R. § 160.103, workforce means employees, contractors, volunteers, and anyone else whose work for AMS is under AMS's direct control, whether or not they are paid as employees.

Applies to contractors

If you are paid as a 1099 independent contractor, you are still a workforce member. Your tax classification has nothing to do with your HIPAA obligations. Every rule here applies to you exactly as it applies to a W-2 employee.

3 What AMS does

AMS provides non-clinical management and administrative services to treating medical practices. AMS does not practice medicine. The practices own the patient records and make all clinical decisions.

Because AMS handles patient information on their behalf, AMS is a business associate. AMS has signed agreements with each practice promising to protect their patients' information. When you follow these rules, you are keeping promises AMS made on your behalf.

4 What counts as protected health information

PHI is health information that identifies someone, or could reasonably be used to identify them. Health information includes past, present, or future health conditions, care provided, and payment for care.

Health information combined with any one of these identifiers is PHI:

  1. Name
  2. Address, city, county, ZIP
  3. Any date tied to a person except the year; any age over 89
  4. Phone number
  5. Fax number
  6. Email address
  7. Social Security number
  8. Medical record number
  9. Health plan number
  10. Account number
  11. Certificate or license number
  12. Vehicle or plate number
  13. Device serial number
  14. Web URL
  15. IP address
  16. Biometric identifier
  17. Full-face photograph
  18. Any other unique identifying code
Most important for your role

A phone number in GHL belonging to someone who contacted a medical practice is PHI. The fact that a person is a patient, or is asking about becoming one, is itself health information. You do not need to see a diagnosis for something to be protected.

5 The seven core rules

  1. Access PHI only when your job requires itBeing able to open a record is not permission to open it.
  2. Access only the minimum you needDo not read beyond what the task requires.
  3. Never look up yourself, family, friends, coworkers, or anyone you knowNo exceptions, including when they ask you to.
  4. Keep PHI inside approved systemsNo personal phone, personal email, personal apps, screenshots, or personal storage.
  5. Never share your loginYour credentials identify you in every access log.
  6. Report incidents within 24 hoursOn suspicion. You do not need to be certain.
  7. When unsure, ask before you actAsking is never a violation.

6 Minimum necessary

You may access, use, and share only the smallest amount of PHI needed for the task in front of you.

Correct. A patient asks about their appointment. You open the record, confirm the appointment, close it.

Violation. Same patient, same question. While you are in the record you read their medication list because you were curious. Nothing about that was necessary. That is a violation even though you were authorized to open the record.

The rule also governs sharing. When you escalate to clinical staff, include what they need to act, not the entire history.

7 No snooping

This is the most common cause of HIPAA terminations across the industry, and the fastest way to lose your position at AMS.

Never access

Your own record. A spouse, partner, parent, child, or any family member. A friend, neighbor, or acquaintance. A coworker. A public figure. Anyone you recognize. Anyone whose record you have no assigned reason to open.

This applies even if the person gives you permission. Their consent does not create a business need and does not authorize the access. To get your own records, request them the way any patient would.

Every access is logged with your name, the record, and the timestamp. Snooping is not caught by suspicion. It is caught by log review, and it is unambiguous when found.

8 Approved systems

HealthAide
The clinical portal. Patient charts and clinical documentation live here.
GoHighLevel (GHL)
Communications only. Lead and patient conversation, scheduling, administrative follow-up. Care is not rendered in GHL. Never document clinical information or give clinical advice here.
Google Drive (AMSDoc account)
Approved document storage.
Never use for patient information

Slack is for internal coordination only. Never a patient name, phone number, or detail, in a channel or a DM. Your personal phone or text messages. Personal email. WhatsApp, Messenger, Instagram, or any personal messaging app. Dropbox, iCloud, personal Google Drive. Anything not on the approved list.

9 Never remove PHI from approved systems

Do not forward, copy, screenshot, photograph, print, export, or download PHI to any personal device or account.

The most common mistake

Taking a screenshot to ask a quick question or remember something later puts PHI in your phone's photo roll, which is almost always syncing to a personal cloud account. That is an unauthorized disclosure and may be a reportable breach. If you need to share something internally, share it inside the approved system.

10 AI tools and outside services

Do not enter PHI or patient details into ChatGPT, Claude, Gemini, Copilot, or any AI assistant, chatbot, transcription service, note-taking app, or browser extension that has not been approved in writing by the Privacy Officer.

This applies even when you are only asking for help wording a reply. Once patient information goes into an unapproved tool, AMS has disclosed it to a company with no agreement to protect it. That is a violation regardless of your intent.

You may use AI tools for general work such as drafting non-patient content or learning a process, as long as no patient information goes into them.

11 Device and workspace security

Your device must have full-disk encryption, automatic screen lock, current operating system updates, active security software, and multi-factor authentication on every AMS account.

Never work on a shared or family computer, let anyone else use your login, use AMS systems on open public Wi-Fi, leave your screen visible to others, or leave a device unattended in public or in a car.

Working from home: position your screen so household members cannot read it, use headphones for calls involving patients, and lock your screen every time you step away, even briefly.

Passwords must be unique to AMS, never reused from personal accounts, never shared, never written where others can see. Change immediately if you suspect compromise.

12 Reporting incidents

Report any of the following within 24 hours:

  • A message or document sent to the wrong person
  • Clicking a phishing link, or entering your password on a suspicious page
  • A lost or stolen phone or laptop
  • Discovering you can see records you should not have access to
  • Anyone asking you to share patient information outside normal workflow
  • Malware, ransomware, or unexpected system behavior
  • Anything that makes you think "that probably wasn't right"
Report to

Linda Rhodes, Privacy Officer
[email protected]  ·  941-354-5544

Do not try to fix, delete, undo, or investigate it yourself. Preserve everything and report.

Report your own mistakes. Prompt self-reporting is treated as a mitigating factor. Hiding a mistake is treated as an aggravating factor and is far more likely to end your engagement than the mistake itself.

13 Patient requests and complaints

Patients have legal rights regarding their information: to see it, get a copy, request corrections, request restrictions, and receive an accounting of disclosures. You do not handle these requests.

Forward to the Privacy Officer the same business day: any request to see, copy, or correct records; any privacy complaint; any request from an attorney, law enforcement, a government agency, or the media; any request from a family member for another person's information.

These carry legal deadlines. Delay creates liability.

14 What happens if rules are broken

AMS applies a written Workforce Sanctions Policy with three levels.

Level 1, unintentional. An honest mistake, promptly reported. Counseling and retraining.

Level 2, careless or repeated. Sharing a password, using personal channels for PHI, failing to report on time. Written warning, access restriction, suspension.

Level 3, intentional or reckless. Snooping, disclosing information, using PHI for personal purposes, concealing a violation. Immediate termination and possible referral to authorities.

Beyond AMS sanctions, HIPAA carries civil penalties tiered by culpability, with amounts adjusted annually. Criminal penalties under 42 U.S.C. § 1320d-6 reach up to one year imprisonment for knowing misuse, five years where false pretenses are involved, and ten years where information is used for personal gain or malicious harm.

Protected

You will never be retaliated against for reporting a concern in good faith, or for contacting the HHS Office for Civil Rights.

15 Situations you will actually face

A patient texts your personal cell because they found your number online.

Do not respond from your personal phone. Move the conversation into GHL and reply there. Tell the Privacy Officer.

Your sister mentions she is a patient and asks you to check whether her results are back.

Refuse. Her permission does not authorize your access. Tell her to log into her portal or call the practice.

You send an appointment reminder and immediately realize it went to the wrong contact.

Report within 24 hours. Do not delete anything. This may be a reportable breach and the Privacy Officer decides that.

A caller says they are from a pharmacy and needs a patient's date of birth to complete a fill.

Verify before disclosing. If anything feels off, escalate. Pretexting calls are common.

A patient's message is confusing and you want AI help drafting a reply.

Do not paste it into any AI tool. Ask a colleague inside the approved system.

You notice a coworker's name in the patient list.

Do not open it. Do not mention it to them. If it was assigned to you in error, tell the Privacy Officer.

A patient describes symptoms and asks if they should be worried.

Do not answer. You are non-clinical. Escalate immediately to clinical staff.

Your laptop is stolen from your car with AMS systems open in the browser.

Report immediately so credentials can be revoked and sessions terminated.

Assessment

Twenty questions. You need 16 correct to pass. Answer every question, then check your score.

Training complete

Review the details below, then submit your attestation. Your access is provisioned once it's on file.

Name 
Date completed 
Score 

By submitting, you confirm you completed this training and understood it; that you may access only the minimum information your work requires; that you may never access records of yourself, family, friends, or coworkers; that patient information may exist only in HealthAide, GHL, and the AMSDoc Google Drive, and never in Slack, personal channels, screenshots, or unapproved AI tools; that your access is logged and audited; and that you must report any suspected incident within 24 hours. Violations are subject to the AMS Workforce Sanctions Policy up to immediate termination.