Wow, this is actually something I consider when sending letters to my clients. I don't ever want to "leak" their info, even if it's not really considered sensitive.
I always assume the top third to be "compromised", only putting the private contents in the lower two thirds or on the back.
I wonder why they don't have the mailing rule of the top third as a written policy.
> A cost/benefit analysis of "put all HIPAA-relevant information inside an opaque envelope" probably comes out ahead if it prevents one issue like this.
To be pedantic, the patient's name and address are both considered PHI under HIPAA.
The way that most insurers deal with this is by mailing an envelope that has no obvious information on the outside about the sender (it has a return address that's usually a PO box somewhere in the midwest, but not the company's name). So without opening it, you can't tell that the piece of mail relates to medical information.
Banks do this as well when mailing things like credit cards, to make it less obvious to a would-be interceptor of the mail that there's something valuable inside. (Of course, the deliberate inconspicuousness of it is itself conspicuous, but that's another problem).
Also there is something called a security envelope, which is printed on the inside with a pattern of lines that makes it difficult to read the contents of an unopened letter by holding it up to the light.
Back when mailing checks to pay bills was a thing, everyone had a box of them and that's what you used. I imagine companies today should still use them.
I always assume the top third to be "compromised", only putting the private contents in the lower two thirds or on the back.
I wonder why they don't have the mailing rule of the top third as a written policy.