Showing posts with label EHR. Show all posts
Showing posts with label EHR. Show all posts

Wednesday, June 17, 2015

5 Tips for HIPAA Compliant Technology

 HIPAA (The Health Information Portability and Accountability Act) was designed to protect the privacy of individually identifiable health information.  The complexity of protecting that information is growing as government mandated moves to increase Meaningful Use of Electronic Health Records (EHR) enter Stage 2 in 2015. 

Regularly updating your security protocols will help to protect your practice from break-ins or accidental breaches.  Below are some ways to help your Electronic Health Records stay HIPAA compliant and secure.
  1. Initial Risk Assessment.  An initial risk assessment can help you determine where the sensitive EHR is being stored and how it is accessed.  This allows you to find potential areas of weakness and take steps to reduce existing risks.
  2. Encrypt Electronic Protected Health Information (ePHI).  Properly encrypted date is protected even if other safeguards fail. Data encryption is necessary to prevent improper disclosures of ePHI. 
  3.  Utilize Secure Servers.  Only authorized staff should have access to servers and they should be password-protected or secured with public key authentication.  Encryption is the first line of defense, but ensuring that servers where ePHI is stored are both physically and virtually secured is also crucial. 
  4.  Do Not Allow the use Portable Drives for ePHI.  A portable drive can be easily misplaced or stolen. 
  5. Limit Access.  Staff should only be able to access ePHI that is critical to their ability to perform their job and they must be properly trained on HIPAA compliance. Employee access to workstations and software must be limited with authorizations, passwords, and clearance levels. 


Securing electronic personal health information is a must to maintain HIPAA compliance.  Start byconducting a risk assessment today!

Tuesday, February 17, 2015

Electronic Medical Records and Medical Malpractice Suits: Six Common Issues

Many physicians currently employ some kind of Electronic Medical Record (EMRs) and although many issues related to paper charts have been resolved, the EMR isn't foolproof. Some common ways physicians might get burned or even sued while using EMRs include: security breaches, password difficulties, meeting the standard of care, input errors, ignoring clinical decision-making support, and communication with the patient.
Passwords must be protected and secret to safeguard confidential patient data. Independent passwords for every employee will help determine someone that could be breaking workplace policies. Clear, well-defined guidelines regarding internet use and password defenses can minimize the chance for security breaches. If a security breach does occur, there is a legal and moral duty  to inform the individuals affected. HIPAA has created specific processes for notice to patients who have been potentially affected by a security violation of their confidential health information.
EMR alerts are created to assist the physician’s decision making process, but ignoring or over-looking these warnings could put the doctor and patients at risk. EMRs often report the total amount of time spent reading alerts thus speeding through them could be a major factor in a lawsuit. Standard of care concerns are also impacted by the usage of EMRs. Some EMRs have devices to inform about certain criteria or issues and not using the various tools provided within the EMR may result in lawsuits.
Input errors and sloppy records can be a road map for or, in the least, can raise concerns about competence in a medical malpractice situation, even if the mistakes or omissions had nothing to do with the results. Communication is another potential pitfall in that some patients feel the doctor is not listening or focusing on their issues, but instead on a computer.  Patients feeling too little connection to their doctor are more likely to sue.
There are lots of issues that could lead to litigation, although EMRs have tremendous potential to boost quality and continuity of care. Accurate and appropriate use of the EMR is essential to prevent litigation risks.

We are at the crossroads of medicine and the law, contact us today!