7.4 Fee Splitting, Kickbacks & Patient Privacy (Texas Medical Records Privacy Act)
Key Takeaways
- A dentist may not pay or receive prohibited remuneration for securing or referring patients; bona fide compensation for real services must not become a disguised referral fee.
- Patient confidentiality permits disclosures authorized by the patient, required by law, or allowed for treatment, payment, oversight, and other applicable purposes.
- Texas covered-entity workforce privacy training occurs within 90 days of hire and after a material change affecting duties, not automatically every two years.
- A Texas breach affecting at least 250 residents triggers Attorney General notice within 30 days under current state law.
- Consumer breach notice generally must occur without unreasonable delay and no later than the applicable 60-day outside limit, while federal and contractual duties may also apply.
7.4 Fair Dealing, Remuneration, and Patient Privacy
Referral remuneration
Texas professional-conduct rules prohibit paying or accepting prohibited remuneration for securing or soliciting patients or referrals. A cash payment for each surgical patient sent by another provider is the classic risk. The rule also reaches disguised value—free staff, inflated “consulting” fees, below-market leases, or marketing payments tied to professional referrals.
Not every payment between healthcare businesses is a referral fee. Compensation for real administrative, laboratory, lease, or professional services may be lawful when commercially reasonable, properly documented, and not payment for clinical steering. Analyze Texas dental rules along with any applicable state or federal anti-kickback law; do not assume a contract label or percentage automatically resolves the issue.
Discounts and gifts must not be deceptive or used to compromise professional judgment. The dentist discloses material financial relationships and recommends care based on the patient, not the payment source.
Confidentiality and permitted disclosures
Dental records contain protected health information. HIPAA and the Texas Medical Records Privacy Act can both apply, with Texas sometimes reaching entities or conduct beyond the federal floor. Use or disclose information only with valid patient authorization or a legal permission, such as treatment, payment, healthcare operations, required reporting, qualifying health oversight, court process, or prevention of a serious threat under the applicable standard.
“HIPAA” is not a reason to refuse every lawful disclosure. A valid TSBDE oversight request, child-abuse report, or treatment communication may be permitted without an ordinary authorization. At the same time, a subpoena, court order, police request, and patient authorization are not interchangeable; verify the required process and disclose only what it supports.
Workforce training and safeguards
Texas law requires covered-entity workforce privacy training within 90 days after hire. If a material change in state or federal privacy law affects the employee’s duties, retraining occurs within a reasonable period and no later than the first anniversary of the change. It is incorrect to describe this as an automatic every-two-years course. The employee signs a completion statement, which the covered entity keeps until the sixth anniversary of signature. HIPAA also requires appropriate training and administrative, physical, and technical safeguards.
Use role-based access, strong authentication, secure backups, device encryption, private conversations, proper disposal, and vendor agreements. Staff should not look up family or celebrity charts out of curiosity. Avoid discussing patient facts in review responses, even when the patient posted first.
Breach analysis and notice
On discovering a possible breach, contain it, preserve evidence, perform the required risk analysis, notify privacy leadership and insurers, and apply federal and Texas notice rules. Under current Texas Business and Commerce Code § 521.053, a breach involving at least 250 Texas residents requires notice to the Texas Attorney General within 30 days after determining the breach occurred. That is not a 60-day Attorney General deadline.
Affected consumers generally receive notice as quickly as possible without unreasonable delay and no later than the applicable 60-day outside limit, subject to law-enforcement delay and the governing law. HIPAA has its own 60-day outer rule and federal reporting mechanics. Use the shortest applicable deadline.
Patient access and communications
Privacy and access coexist. Authenticate the requester and use secure delivery, but do not use privacy as a pretext to withhold the patient’s own record. Obtain appropriate permission before marketing with patient images or testimonials. De-identification must meet the legal method; cropping a face may not de-identify distinctive dental images or context.
Applied examples
A lab charges fair market value for fabrication regardless of referrals: that is ordinary service compensation. A consultant receives $300 for every implant patient steered to one office: analyze prohibited remuneration. A ransomware event exposes 400 Texans: begin individual and federal analysis and make the Texas AG notice within 30 days of determining the breach.
Minimum-necessary and incident response
For a permitted non-treatment disclosure, limit information to what the purpose requires. A billing vendor may need codes and identifiers but not unrestricted access to every clinical photograph. Use business-associate or other required agreements and monitor vendors rather than assuming outsourcing transfers liability.
A lost device is an incident, but breach status depends on encryption, access, mitigation, and the required risk assessment. Begin the analysis promptly; do not wait until the 30th or 60th day to investigate. Document why notice was or was not required.
Sale and collection of accounts
Collections and practice sales still require minimum-necessary disclosure, secure transfer, and contractual safeguards. A collection agency does not need unrestricted treatment photographs to pursue an ordinary balance. A buyer must preserve access and retention obligations for acquired records. Financial ownership of an account never authorizes public disclosure of the patient’s diagnosis or treatment in a demand letter visible to others.
Texas privacy-training clock
- Train a covered entity’s workforce member no later than 90 days after the person is hired.
- After a material change, provide new training within a reasonable period that cannot exceed one year.
- Retain the workforce member’s signed or electronic training statement for six years.
When does Texas covered-entity workforce privacy training occur?
What Texas Attorney General deadline applies when a breach affects at least 250 Texas residents?
Which payment most clearly resembles prohibited referral remuneration?