Showing posts with label access. Show all posts
Showing posts with label access. Show all posts

Thursday, November 5, 2015

HIPAA Workforce Security

HIPAA policies and procedures ensure all employees have appropriate ePHI access


Security Rule Language: Implement policies and procedures to ensure all members of its workforce have appropriate access to electronic protected health information (ePHI), as provided under paragraph (a) (4) of this section, and to prevent those workforce members who do not have access under paragraph (a) (4) of this section from obtaining access to electronic protected health information.”
45 CFR 164.308 (a)(3)(i)

The Workforce Security standard requires that you implement policies and procedures to ensure that all members of your workforce have appropriate access to ePHI and to prevent those workforce members who do not have access from obtaining access to ePHI. The type and extent of access to your information systems containing ePHI must be based on your Risk Analysis. Your Risk Analysis must consider the following factors:

• The importance of the applications running on the information system
• The value or sensitivity of the ePHI on the information system
• The extent to which the information system is connected to other information systems

Access to your information systems containing ePHI must be authorized only for your properly trained workforce members having a legitimate need for specific information in order to accomplish job responsibilities. All such access must be defined and documented. Such access must be regularly reviewed and revised as necessary.

Access to your information systems containing ePHI must be established through a formal, documented process. This process must include:

• Identification and definition of permitted access methods
• Identification and definition of how long access will be granted to user
• Procedure for granting a workforce member an access method (e.g. password or token) or changing an existing access method
• Procedure for managing access rights in networked environment
• Appropriate tracking and logging of actions of authorized workforce members on our information systems containing ePHI.

Your workforce members must not attempt to gain access to your information systems containing ePHI for which they have not been given proper authorization.

Following these policies and procedures will help prevent unauthorized access to ePHI while giving appropriate access to designated employees so that they can do their job.

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Friday, October 16, 2015

Access to Records for Investigation

When a investigation occurs, can they access our patients records?



Q: When is Adult Protective Services (APS) entitled to copies of a patient’s medical record without a signed authorization?

An adult patient was transferred from a hospital to our skilled nursing facility for long-term care. Prior to transfer, the hospital social worker called APS with a concern that family members were neglecting the patient and using the patient’s money for their own benefit. APS then came to our facility asking to review the patient’s medical record.

A: APS and Child Protective Services have authority under state law to obtain the information they need to investigate cases under their jurisdiction.


Because APS has an open investigation in this case, the caseworker has legal authority to review the patient’s medical record or obtain copies without authorization from the patient or the patient’s legal representative.


For more information on this and other topics related to HIPAA, HR, OSHA, and Medicare, please emailsupport@hcsiinc.com or visit our website at http://www.hcsiinc.com

 

Be sure to become a member of our Linkedin group by visiting; http://bit.ly/1FWmtq6

Wednesday, October 7, 2015

Emergency Access Procedures

Your practice must establish procedures so your employees know how to obtain electronic protected health information (ePHI) during an emergency.


Access controls will still be necessary under emergency conditions, although they may be very different from those used in normal operational circumstances. For example, in a situation when normal environmental systems, including electrical power, have been severely damaged or rendered inoperative due to a natural or man-made disaster, procedures should be established beforehand to provide guidance on possible ways to gain access to needed electronic protected health information. 

Follow these tips on how your practice can meet emergency access requirements:

·         Review your contingency plan to determine what processes you have in place to provide rapid access to ePHI in an emergency
·         Have backup copies of any ePHI that you deem critical
·         Have plans to restore the system and data inside your facility and at an alternative site

·         Document the names and roles of individuals with administrative privileges who can grant access in a crisis.

For more information on this and other topics related to HIPAA, HR, OSHA, and Medicare, please email support@hcsiinc.com or visit our web site at http://www.hcsiinc.com