Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
5
6
8
11
12
13
14
15
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
1
2
3
4
Forbes Healthcare Summit
2014-12-03    
All Day
Forbes Healthcare Summit: Smart Data Transforming Lives How big will the data get? This year we may collect more data about the human body than [...]
Customer Analytics & Engagement in Health Insurance
2014-12-04 - 2014-12-05    
All Day
Using Data Analytics, Product Experience & Innovation to Build a Profitable Customer-Centric Strategy Takeaway business ROI: Drive business value with customer analytics: learn what every business [...]
mHealth Summit
DECEMBER 7-11, 2014 The mHealth Summit, the largest event of its kind, convenes a diverse international delegation to explore the limits of mobile and connected [...]
The 26th Annual IHI National Forum
Overview ​2014 marks the 26th anniversary of an event that has shaped the course of health care quality in profound, enduring ways — the Annual [...]
Why A Risk Assessment is NOT Enough
2014-12-09    
2:00 pm - 3:30 pm
A common misconception is that  “A risk assessment makes me HIPAA compliant” Sadly this thought can cost your practice more than taking no action at [...]
iHT2 Health IT Summit
2014-12-10 - 2014-12-11    
All Day
Each year, the Institute hosts a series of events & programs which promote improvements in the quality, safety, and efficiency of health care through information technology [...]
Design a premium health insurance plan that engages customers, retains subscribers and understands behaviors
2014-12-16    
11:30 am - 12:30 pm
Wed, Dec 17, 2014 1:00 AM - 2:00 AM IST Join our webinar with John Mills - UPMC, Tim Gilchrist - Columbia University HITLAP, and [...]
Events on 2014-12-03
Forbes Healthcare Summit
3 Dec 14
New York City
Events on 2014-12-04
Events on 2014-12-07
mHealth Summit
7 Dec 14
Washington
Events on 2014-12-09
Events on 2014-12-10
iHT2 Health IT Summit
10 Dec 14
Houston
Articles

Aug 08 : EMRs: How to stay HIPAA Compliant

hipaa compliant

Electronic medical records (EMRs) are a hot topic right now. The federal government is making a push towards the usage of digitized healthcare information, and a growing number of organizations are making the switch. But can you remain HIPAA compliant while embracing EMRs? It’s actually easier than you may think. Here’s how to adhere to HIPAA standards while going digital.

Train & Educate Staff

User error is one of the leading causes of security breaches with EMRs. Information stored on mobile devices creates opportunity for private medical records to be accessed by unauthorized individuals and compromised. A workstation that is left unlocked and unprotected can also enable unauthorized users to gain access to data that they are not permitted to see. As a result, staff must be trained to understand the importance of constant diligence in keeping patient information secure at all times. Employees should understand EMR policies, be told to never share their login information with anyone else, and to protect mobile devices storing confidential data at all times.

Establish Clearance Levels

While some departments or individuals may have the professional need to view a patient’s EMR, others may not. Because of this, it’s necessary to assign a user name to all staff members with computer access. The IT department can then give specific users clearance levels to access the information that they are permitted to review. This will work to effectively minimize the risk of an unauthorized staff member from attempting to access confidential records.

Change Things Up

As a rule, most people tend to create passwords for accounts and never change them. Although it can seem inconvenient, it’s actually better for users to change passwords on a regular basis – especially when it comes to accessing EMRs. With so much on the line, it’s of the utmost importance that all measures are taken to ensure that only authorized parties are able to view patient medical records. After an extended period of time, it’s possible that an unauthorized party could figure out the password of another user and abuse their privileges within the system. To prevent this type of problem, users should be required to change their passwords at regular intervals, such as every 3 months or every 6 months, etc.

Utilize Advanced Security Measures

Threats to security are not only internal. Hackers may also be interested in trying to get into your system in order to obtain a patient’s identifying information such as names, addresses, social security numbers, etc. Healthcare facilities that utilize EMRs, then must take security very seriously and do all that they can to protect private and sensitive data. Never set up a digital database without setting up firewalls to keep threats and viruses out. In addition to this, be sure to encrypt all data so that even in the event that your system is hacked or a mobile device is lost or stolen, no one will be able to access your patient’s information.

Inform Patients of Their Rights

Under the HIPAA Final Omnibus Rule that went into place last fall, healthcare professionals are required to provide their patients with electronic versions of their medical records upon requests. In order for you to remain in compliance with this standard, you need to inform your patients of their right to request this type of information. Create a policy that specifies the return-time on issuing these records to patients after the request is made in order to protect yourself. This will need to be a reasonable turn-around time if you wish to avoid any complaints or auditing.
EMRs really are the way of the future. As more and more hospitals, physicians, and other healthcare providers make the switch, discussions surrounding security and HIPAA compliance are becoming increasingly topical. There’s no need to stress, though. When you stick to these best practices, there’s no reason why you can’t keep your patient’s confidential information more secure now than ever before.

Source