Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
29
30
31
2
3
4
5
6
7
8
9
10
8:30 AM - HIMSS Europe
11
12
13
14
15
16
17
18
19
20
21
22
26
27
28
29
1
2
3
4
5
6
e-Health 2025 Conference and Tradeshow
2025-06-01 - 2025-06-03    
10:00 am - 5:00 pm
The 2025 e-Health Conference provides an exciting opportunity to hear from your peers and engage with MEDITECH.
HIMSS Europe
2025-06-10 - 2025-06-12    
8:30 am - 5:00 pm
Transforming Healthcare in Paris From June 10-12, 2025, the HIMSS European Health Conference & Exhibition will convene in Paris to bring together Europe’s foremost health [...]
38th World Congress on  Pharmacology
2025-06-23 - 2025-06-24    
11:00 am - 4:00 pm
About the Conference Conference Series cordially invites participants from around the world to attend the 38th World Congress on Pharmacology, scheduled for June 23-24, 2025 [...]
2025 Clinical Informatics Symposium
2025-06-24 - 2025-06-25    
11:00 am - 4:00 pm
Virtual Event June 24th - 25th Explore the agenda for MEDITECH's 2025 Clinical Informatics Symposium. Embrace the future of healthcare at MEDITECH’s 2025 Clinical Informatics [...]
International Healthcare Medical Device Exhibition
2025-06-25 - 2025-06-27    
8:30 am - 5:00 pm
Japan Health will gather over 400 innovative healthcare companies from Japan and overseas, offering a unique opportunity to experience cutting-edge solutions and connect directly with [...]
Electronic Medical Records Boot Camp
2025-06-30 - 2025-07-01    
10:30 am - 5:30 pm
The Electronic Medical Records Boot Camp is a two-day intensive boot camp of seminars and hands-on analytical sessions to provide an overview of electronic health [...]
Events on 2025-06-01
Events on 2025-06-10
HIMSS Europe
10 Jun 25
France
Events on 2025-06-23
38th World Congress on  Pharmacology
23 Jun 25
Paris, France
Events on 2025-06-24
Events on 2025-06-25
International Healthcare Medical Device Exhibition
25 Jun 25
Suminoe-Ku, Osaka 559-0034
Events on 2025-06-30

Events

Articles

Keeping Confidential Information Secure in the Healthcare Environment

confidential information

Keeping Confidential Information Secure in the Healthcare Environment

Federal and state laws govern the handling of confidential information in the healthcare industry. Most providers must follow the Health Insurance Portability and Accountability Act (HIPAA) and Privacy, Security, and Breach notification rules. Businesses must comply with these regulations to avoid costly fines and lawsuits. Data breaches of any size can destroy the public’s trust in the business. These privacy and security laws govern confidential and protected information and how it is used, shared, and accessed. The regulations cover all forms of information, written, verbal and electronic. In addition to the federal laws, states may impose additional restrictions. All these laws work together to protect individuals. The rules clearly state how the protected information can be shared, who has the right to view it, how to secure it, how to store it, and what steps to take if a data breach occurs. Businesses need to take the handling of confidential information seriously and establish a clear company policy. Here are the basic areas to consider when developing a policy.

Employee Training

To keep information secure, companies must provide training to employees. New employees need to be taught what exactly qualifies as confidential information, why it is important to protect it, and its policy on protecting the information. Employees need to know when and what information can be shared and when a signed release or Power of Attorney (POA) is needed. Employees should be made aware that they can be personally liable for breaches where they are found negligent. The best companies provide ongoing data privacy courses at least annually.

Sharing Information

Strong company protocols on releasing information need to be put in writing, and all employees must know how to handle the sharing of data. There are legitimate reasons to share data within the organization in healthcare settings, such as treatment collaboration and billing. Company policy should provide procedures to handle telephone requests for data. Employees need to be aware of caller ID spoofing, technology that impersonates numbers to make them appear as if they are a legitimate partner. These spoofing calls can be attempts to steal confidential information. Provide company policy and guidance on how to verify a caller’s identity. At a minimum healthcare, agencies need strong software to block unwanted calls.

Strong Passwords

For employees accessing computer systems that house confidential data, company policy needs to mandate strong password requirements. The best passwords require a set minimum number of characters and a combination of upper- and lower-case alpha characters, numbers, and special characters. Passwords should be set to expire at regular intervals where the employees need to change them. Never allow employees to share passwords with anyone.

Information Storage

Employees need to know the company policy on the storage of confidential information. Company policy should discuss accessing data on personal devices and under what circumstances equipment can be taken home. Computer screens should be locked anytime an employee steps away from the desk. Confidential paperwork must be secured at the end of the day to prevent unauthorized access.

Patient Access

In healthcare settings such as intake and waiting rooms, a private area where clients can provide information is necessary. Other patients should not overhear confidential information in the waiting areas.

Employee Badges

All employees should have ID badges with a clear, updated photo. Ideally, security systems should be configured to allow access into restricted areas by badge type. Unauthorized individuals should never be allowed into restricted areas where confidential information could be overheard or seen.

Healthcare companies are legally required to protect confidential information. Data privacy goes beyond the legal requirements. In today’s world, data breaches have become common. When this happens, patients can feel violated and take legal action against the company. If a data breach has occurred due to company negligence, the negative publicity could destroy the public’s trust in the business and, eventually, the practice. Companies must do everything they can to protect patient’s confidential information.