{"id":2700,"date":"2019-11-26T10:22:10","date_gmt":"2019-11-26T16:22:10","guid":{"rendered":"http:\/\/blogs.luc.edu\/compliance\/?p=2700"},"modified":"2019-11-26T10:22:10","modified_gmt":"2019-11-26T16:22:10","slug":"training-staff-to-protect-patient-privacy-in-the-era-of-electronic-health-records","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=2700","title":{"rendered":"Training Staff to Protect Patient Privacy in the Era of Electronic Health Records"},"content":{"rendered":"<p><em>Laura Ng<\/em><\/p>\n<p><em>Associate Editor<\/em><\/p>\n<p>Loyola University Chicago School of Law, JD 2021<\/p>\n<p>The rapid evolution of <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC5171496\/\">electronic health records<\/a> has dramatically changed the healthcare system in the past two decades. Healthcare organizations, both large and small, have transitioned from paper records to hybrid records, and then finally, for many organizations, to completely electronic data. In 2009, the American Reinvestment &amp; Recovery Act (ARRA) created the federal \u201c<a href=\"https:\/\/www.cdc.gov\/ehrmeaningfuluse\/introduction.html#:~:targetText=Meaningful%20Use%20was%20defined%20by,improve%20the%20quality%20of%20care.\">Meaningful Use<\/a>\u201d program. This program essentially amounted to a significant government subsidy for practices transitioning to electronic health records and provided funding for organizations to purchase electronic health records subscriptions from health information technology companies in exchange for complete adoption, implementation, and the regular development of quality reporting measures using the new software.<\/p>\n<p><!--more--><\/p>\n<p><strong>Encountering patient data<\/strong><\/p>\n<p>In most healthcare capacities, it is inevitable to encounter patient data. Access is necessary and frequent. Providers and clinical support staff must view patient data while examining a patient\u2019s record; patient service representatives work with demographics information when checking-in patients or scheduling appointments; those who work in the financial arm of the organization would no doubt encounter the financial and\/or insurance information of patients. Furthermore, those who work in health quality and outcomes reporting are likely to access patient data as well from time to time.<\/p>\n<p><strong>Inappropriate usage<\/strong><\/p>\n<p>While it is necessary for those who work at healthcare organizations to view patient data, inappropriate usage or viewing of patient data has been known to <a href=\"https:\/\/www.sandiegouniontribune.com\/news\/health\/sd-no-patient-breach-20180112-story.html\">crop<\/a>up from time to time. To make things more complicated, it can be difficult to discern the difference between looking up a patient\u2019s information for \u201clegitimate\u201d reasons vs. just plain \u201csnooping.\u201d Most electronic health records have an <a href=\"https:\/\/www.ncbi.nlm.nih.gov\/pmc\/articles\/PMC5977720\/\">audit<\/a> function that shows who has viewed a patient\u2019s information, but whether that viewing is \u201clegitimate\u201d can be difficult to prove (or disprove). After all, one could argue that he was attempting to access another patient\u2019s information but made a typo in the search engine, or claim that he was on the record to do something else for the organization. In addition, most staff members go through so many records per day that it can be extremely difficult for compliance staff to keep track of who has viewed each patient record each day, and whether that reason was necessary.<\/p>\n<p><strong>Training staff to respect privacy<\/strong><\/p>\n<p>As with just about everything else in life, it is often easier to prevent behavior than to correct it. Thus, training staff at the employee on-boarding point is critical. New employees ought to be taught <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/index.html\">HIPAA<\/a> rules, specifically the policy of utilizing the least amount of patient information necessary to perform the job. <a href=\"https:\/\/www.hipaajournal.com\/what-happens-if-you-break-hipaa-rules\/\">Consequences<\/a> for violating such rules ought to be reviewed to further drive home the point that the organization takes such violations seriously. After the training, an attestation (signed form) from the employee ought to be collected. It may also be effective to recount stories of \u201csnooping\u201d healthcare employees in the news and to remind the new employees of what would happen in such a situation. Finally, it is wise to remind the employee that the organization does audit for such behavior, and that the electronic health records system is capable of tracking every person who views the record.<\/p>\n<p><strong>Building a culture of privacy<\/strong><\/p>\n<p>Perhaps the most important part of compliance is the building of organizational culture: it is important to build a culture of protecting patient privacy. Thus, audit rules ought to be set up with the electronic health records system, alerting the systems administrator and compliance officer of potential violations. For example, it is possible to set the system to sound an alert every time an employee looks up the record of a co-worker, or set the system to trigger an alert if an employee looks up patients who live within a mile-radius of his\/her home. A regular manual audit of patient privacy ought to be performed at least once a year. It is also important to make the audit public to the organization \u2013 to let employees know that the audit is happening, and that the results will be publicized and taken seriously. In addition, continued, annual training regarding HIPAA and patient privacy is advisable. Finally, senior management ought to be trained to be on the lookout for violations of patient privacy, and to build the culture within their own teams. Hopefully, with a culture of privacy and adequate, continued training at an organization, the risk of patient privacy being violated will be reduced as we advance into a more technological age.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The rapid evolution of electronic health records has dramatically changed the healthcare system in the past two decades. Healthcare organizations, both large and small, have transitioned from paper records to hybrid records, and then finally, for many organizations, to completely electronic data. In 2009, the American Reinvestment &amp; Recovery Act (ARRA) created the federal \u201cMeaningful Use\u201d program. This program essentially amounted to a significant government subsidy for practices transitioning to electronic health records and provided funding for organizations to purchase electronic health records subscriptions from health information technology companies in exchange for complete adoption, implementation, and the regular development of quality reporting measures using the new software.<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2700","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/2700","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2700"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/2700\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2700"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}