Information gathered and recorded in association with the care of a patient is confidential, regardless of the form in which it is collected or stored.

Physicians who collect or store patient information electronically, whether on stand-alone systems in their own practice or through contracts with service providers, must:

  1. Choose a system that conforms to acceptable industry practices and standards with respect to:
    1. restriction of data entry and access to authorized personnel;
    2. capacity to routinely monitor/audit access to records;
    3. measures to ensure data security and integrity;
    4. policies and practices to address record retrieval, data sharing, third-party access and release of information, and disposition of records (when outdated or on termination of the service relationship) in keeping with ethics guidance.
  2. Describe how the confidentiality and integrity of information is protected if the patient requests.
  3. Release patient information only in keeping with ethics guidance for confidentiality.
AMA Principles of Medical Ethics: V
