I worked with a gentlemen who passed away. He was very open about his illness. My only knowledge of his illness is through him disclosing it to myself & another coworker in a personal conversation. I wrote a farewell message, briefly mentioning cancer on my personal social networking page. Some coworkers have gone to my boss & stated that I violated HIPAA because at my job, I help verify that members (not coworkers, as was he) are eligible for health insurance.
I do not work with medical claims. I have never seen any of this person's private health records, nor worked on his insurance eligibility. My database does not even contain diagnosis info or medically specific info. I deleted the post and my whole page. Can I lose my job or face legal trouble for this? What can I do?
I should also say that he told us this info in casual conversation, outside of work, in no way related to anything regarding work.