Showing posts with label HIPAA Violation. Show all posts
Showing posts with label HIPAA Violation. Show all posts

Tuesday, April 25, 2017

Walking the Social Media Tightrope

Much like walking on a tightrope, participating on social media is a science as well as an art.


People post on social media all the time. They like to post pictures, tag their location when they are somewhere cool and they even like to write about what they are eating. Unfortunately, many people do not see any harm in what they post. For example, below is an example of somebody posting something that they perceived as innocent and, in their eyes, thoughtful:

In an assisted living center, a housekeeper posted a picture of a vision and hearing impaired resident on her social networking webpage, with the caption "This is my friend," along with the resident's first name.

By posting the picture of the resident without their consent, the employee violated HIPAA Privacy regulations. After the violation was brought to the employees’ attention, the employee apologized and immediately removed the photo. She said she was not aware that a person could not do such a thing without the resident's consent. While the employee did not have malicious intent, the action was still a violation of the resident’s privacy.

Social media is a double edged sword. If used properly, social media can be an amazing tool that can be used in many beneficial ways. However, if used improperly, social media can do extensive damage to the user and the organization they work for.

Dangers of Social Media

Use of social media by healthcare professionals can present some challenges and possibly open the door to HIPAA Privacy violation and future liability. Here are some examples of social media privacy violations that have lead to a HIPAA Privacy audit:

  • Posting pictures of patients/residents without their consent
  • Posting a video of a patient
  • Posting a video describing a patient or a patients situation
  • Posting a “selfie” in a restricted area where Protected Health Information (PHI) is visible
  • Writing a post or comment about a patients situation

These social media posts can severely damaging to an organization and to the individual who’s privacy had been compromised. In addition to these actions leading to a HIPAA Privacy audit, these type of social media posts also have a negative effect on the reputation of the healthcare organization. Privacy violations do not go unnoticed by other patients and these privacy violations do cause patients to rethink their trust in their healthcare provider.

As with walking a tightrope, it is very easy to slip and fall into unwanted territory with social media posts.

Beauty of Social Media

While social media can have many negative effects on an organization and patients, it can also be used for some great things. These are some examples where social media can have a positive impact in the healthcare world:

  • Educate followers with various health tips
  • Maximize exposure of an organizations community contribution
  • Give patients a platform for them to write positive reviews
  • Celebrate the accomplishments of your employees (post with their permission)
  • Announce specials, discounts, or new product

There is so much an organization can do with social media that will have a positive effect. However, social media posting in the healthcare industry is like walking a very fine line. When posting on social media, it is important to have established guidelines and policies in writing. This will enable a healthcare provider to safely post on social media without fear of slipping and falling into unwanted territory.

Be sure to take to have documented training on social media for your employees. They need to know the impact their social media posting can have on patients and on the organization itself. In addition, having documented training will help protect the organization against liability if the need arises to discipline an employee for not following social media policies and procedures.

If done right, having a positive social media presence will be very beneficial to an organization. However, it is important to stay on that narrow rope when posting. It can be very easy to move slightly to one side or the other and fall into unwanted post territory.


For more information about safely posting on social media, please watch the following webinar:




To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, April 8, 2016

Being Clear on Healthcare Social Media Policies

 Healthcare Compliance Solutions INC.
Define Your Social Media Policies Now To Reduce Future Issues

Love it or hate it, social media is a fact of life. It can be a great means for medical practices to raise awareness, educate, and engage patients.
However, it's also easy to find stories about social media gone wrong in healthcare. Many of these involve HIPAA violations by staff who don't understand the inherent lack of privacy in social media posts. ProPublica, an investigative news organization, recently reported on more than 30 incidents where staff inappropriately shared images and other patient information over social media networks.

In light of the horror stories, there is a temptation for practices to construct a "defensive" policy focused solely on restricting staff use of social media; essentially "What you don't say can't hurt us." Instead, you should seek a balance that not only protects patient privacy and discourages public relations gaffes, but also allows those who know your practice best — its staff — to show pride in their work and promote it. Designing a good social media policy for your practice can tip that balance to the positive.

Here are some ways to help you get there:

1. Keep it simple. Staff will view a policy that is too long and tries to cover everything negatively — if it's read at all. Further, because social media is constantly evolving, too much specificity will virtually guarantee your policy will quickly become obsolete.

2. Be clear about your goals. To provide context for your social media policy, put the focus on what you are trying to accomplish. These goals may be things such as maintaining patient confidentiality, compliance with applicable laws and regulations, protecting the practice from negative outcomes, enhancing the practice's professional image, and ensuring a productive and focused workplace.

3. Don't reinvent the wheel. There are many easily adaptable, great policies available online. You can find many examples here and can even view policies by professional sector, including healthcare of course.

4. Get beyond the "thou shalt not." See the positive as well as the negative. Don't be so afraid of the worst-case disaster that you stop staff from telling your practice's story. The average adult Facebook user has about 300 friends, meaning that even in a small practice you could easily reach thousands of people with a positive message. Imagine someone saying, "I'd love to tell my Facebook friends about the money we raised at the local charity event, but our social media policy won't allow us to post on work-related topics."

5. Don't just dictate, educate. Beyond the policy itself, staff may need help in thinking through how this all works "in real life." Again, there already are some great resources to give you a running start on this. One example is "A Nurse's Guide to the Use of Social Media." You can offer real examples and scenarios that help your staff understand the repercussions on using social media to represent your practice.
6. Listen and respond to feedback. This allows you to not only hear concerns staff may have, but also get a sense whether they understand your social media policy. Initial staff reaction to a social media policy may not be warm and fuzzy. Most staff will easily understand rules on using practice equipment and network connections for personal use during the workday. However, you may get pushback on "restrictions" outside of work time. Point out that HIPAA violations hurt patients — and they can have negative legal consequences for not only the practice, but also the individual staff member. Be upfront and explain that your policy covers both staff social media activity at work and off the clock. Respond to any concerns by communicating the practice's expectations of staff professionalism, both on and off the clock.

7. Back it up. Enforcement and sanctions may be unpleasant, but they are an absolute necessity. Having a policy but not enforcing it may be worse than no policy at all, since this sends staff the message that you're not serious. It also can create liability for the practice if you have a policy in place and make no effort to ensure that it is followed. Your medical practice's sanctions for policy violations — especially those involving HIPAA — should be documented and consistently applied to all staff.

If you are successful, your social media policy and staff education efforts will offer bright-line guidance prohibiting illegal or unethical activity, while also encouraging staff to share their successes at your practice. That is a win-win for patients, the practice, and staff.

Source(s): Stephen McCallisterhttp://www.physicianspractice.com, www.hcsiinc.com

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, December 29, 2015

The Importance Of Yearly HR/Compliance Training

HR Training Can Save Your Practice in the New Year

As we prepare for 2016, I remind our clients to think about annual HR and compliance training for all practice employees.  Not surprisingly, clients often complain that it’s unnecessary because “nothing has changed” or employees still remember their training from last year. In my experience, employees forget most of their training (almost immediately) and those who do remember are complacent about applying their knowledge or are unable to practically apply training to real-life situations.  For example, last year, just weeks after training a client’s practice, the following occurred:
A nurse in the practice (“Sue”) complained she had been sexually harassed by a male supervisor nurse (“Tim”).  Sue and Tim are immediately put on different schedules so they could no longer interact and statements were taken from both parties (which tell opposite stories).  There is no video evidence and no direct witness to the events, although statements are taken from other staff members.

Sue appears at work the next day apparently distressed and under the influence.  Another nurse “friend” (let’s call her "Jane") provides prescription medication to calm Sue and drives her to the hospital.  Later, Jane is “so concerned” about Sue’s condition that she accesses the hospital’s EHR system (to which the practice is connected) to check on Sue’s status.

Sue calls the practice manager the next morning to inform him that she considers herself on family and medical leave (FMLA) and further insists the practice should have to pay for her leave (due to her complaints) since she has no accrued paid time off (PTO) left.  The practice’s policy does not call for any paid FMLA leave (if Sue was to qualify).

This may seem like a crazy scenario, but it’s really not that surprising at all! What is unfortunate is that every one of the employees in the above scenario had been completely trained numerous times on the practice’s policies and yet various violations still occurred. 

First, with regard to the alleged sexual harassment, there could be no conclusions made after the investigation was complete.  The results of the investigation were still distressing since numerous witnesses, in addition to Sue and Tim, admitted there was a pattern of lewd, vulgar  and inappropriate discussions going on throughout the workday and numerous employees complained (during the investigation) that they had asked Sue, who seemed to be the main source, to cease such behavior.  It appeared that various staff and physicians were aware and participated in such sexual discussions, which clearly violated the practice’s sexual harassment policy.  Specific scenarios during training had covered the exact violations that occurred and yet no employee recognized there was a violation of the policy.  To address the matter, the practice issued warnings to all involved and hired an expert to bring in more training, which will now be repeated twice annually.  Every employee will acknowledge and sign a new policy as well. 
Another issue in the scenario that occurred was Jane’s violation of HIPAA by accessing another employee’s EHR at the hospital. She also went against practice policy by prescribing medications to an employee of the practice (who already appeared impaired).  This was not Jane’s first HIPAA violation and per practice policy, she was terminated.  Action is still being considered on the prescription issue and Sue’s appearance at work under the influence.

Finally, like other practices, this client has a policy for FMLA and paid time off. Our advice is that the practice should always try to follow its policies consistently and without exception. When a practice opts to reach a unique arrangement with an employee (such as letting them dip into future PTO), this should be documented.  Certainly, a practice should never pay an employee who has made threats against the practice without talking to counsel, as such payment could be deemed an admission of wrongdoing.

No matter how much training a practice provides, there are always going to be violations of a practice’s policies that occur.  The expense and hassle of dealing with the repercussion of such event is far greater than scheduling and/or paying for annual training.  If you think your staff remembers everything they have been trained on in the past — try asking a few random questions and see whether you are surprised by the results! 

By  from http://www.physicianspractice.com

For more information on this and other healthcare compliance topics related to HIPAA, OSHA, Medicare and HR, simply email your questions to support@hcsiinc.com
visit our website at http://www.hcsiinc.com or post a question on our LinkedIn group at: http://bit.ly/1FWmtq6
To subscribe to this blog, enter your email address:


Delivered by FeedBurner