American Academy of Family Physicians
About UsNews & PublicationsMembersCME CenterClinical & ResearchPractice MgmtPolicy & AdvocacyCareers

Identity Theft Red Flags Rule

NEW May 01, 2009:

The Federal Trade Commission (FTC) announced a delay in the enforcement of the Red Flags rule, giving physicians and other creditors until August 01, 2009, to develop and implement written identity theft programs. This is the second delay in enforcement of the rule due to the wide-ranging impact of the law as written by Congress and resulting confusion regarding who must comply.

The FTC has also published an online template for determining if your practice is at low risk for identity theft and if so, to assist you in developing a program in compliance with the rule. This six-page template allows for creation of a program by filling in the blanks provided for each aspect of your program and then printing the final document for your records.

Most physician practices need to be in compliance with requirements of the final rule entitled, "Identity Theft Red Flags and Address Discrepancies Under the Fair and Accurate Credit Transactions Act of 2003" by the new August 1st deadline. These final rules and guidelines implementing section 114 of the Fair and Accurate Credit Transactions Act of 2003 (FACT Act) and final rules implementing section 315 of the FACT Act were originally posted with a compliance date of November 01, 2008. Due to questions regarding whether physicians met the definition of creditors, this was extended pending a now complete review (9-page PDF file; About PDFs) by the Federal Trade Commission, which determined that many physicians are creditors and subject to the rule.

The following resources are intended to assist members in understanding the purpose of the rule, what is required in the physician practice setting, and to provide some ideas that may make compliance program development, implementation, and training less complex and more integrated with other programs, such as HIPAA privacy and security programs.
AAFP Red Flags Rule Presentation -- To assist members and their staff in learning about and complying with the Red Flags Rule, the AAFP has developed...
What is the purpose of the Red Flags Rule? -- This rule is intended to add protections for consumers and creditors due to ...
What is a Red Flag? -- A “Red Flag” is defined as a pattern, practice, or specific activity that could indicate identity theft...
What is required to comply with the Red Flags Rule? -- Physicians who are creditors as defined by the rule must...
Should I purchase a manual for the Red Flags Rule? -- Perhaps, but your written program must reflect the red flags identified for your practice...
Protecting Yourself & Your Staff From ID Theft -- While considering how to detect red flags of ID theft from outside the practice, consider the risks...
Other Red Flags Resources -- In compiling information on the Red Flags rule, we found some helpful sites...
Regulatory Compliance

Identity Theft Red Flags Rule

FAQ: Anti-kickback/Stark

ADA

HIPAA

OSHA Compliance

Shop Catalog