HIPAA Q&A: You’ve got questions. We’ve got answers!
HIM-HIPAA Insider, November 30, 2015
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Submit your HIPAA questions to Associate Editor Nicole Votta at nvotta@hcpro.com and we will work with our experts to provide you with the information you need.
Q: What activity must be audited to comply with the requirement to audit EMR activity? Every action a user takes within a record? Length of time in a record? Or only that the record was accessed and by whom?
A: EMR or EHR audit logs should record who accessed the record, when they accessed the record, and what they did (e.g., add, change, delete, view). It's also a good idea to make sure the amount of time spent looking at the record is recorded. For example, if there is a question why an employee looked at a medical record in the EMR because it appears access wasn't related to the employee's job, recording the time spent looking at the record can differentiate between someone snooping in the record versus someone who accessed the record inadvertently. If the employee spent five or 10 minutes viewing the record versus less than a minute, it could be determined that the employee did more than access the record inadvertently.
Editor’s note: Chris Apgar, CISSP, president of Apgar & Associates, LLC, in Portland, Ore., answered this question for HCPro’s Briefings on HIPAA newsletter. This information does not constitute legal advice. Consult legal counsel for answers to specific privacy and security questions.
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Related Products
Most Popular
- Articles
-
- Don't forget the three checks in medication administration
- Note similarities and differences between HCPCS, CPT® codes
- Q&A: Primary, principal, and secondary diagnoses
- The consequences of an incomplete medical record
- OB services: Coding inside and outside of the package
- Complications from immobility by body system
- Practice the six rights of medication administration
- Nursing responsibilities for managing pain
- Differentiate between types of wound debridement
- Skills of effective case managers
- E-mailed
-
- Correctly bill ancillary bedside procedures in addition to the room rate
- Q/A: Coding infusions to correct low potassium levels
- Q&A: Utilization Review Committee Membership
- Q&A: Bill blood administration the same way for inpatient and outpatient accounts
- Q&A: A second look at encephalopathy as integral to seizures/CVA
- OB services: Coding inside and outside of the package
- Know the medical gas cylinder storage requirements
- Intravenous therapy guidelines
- Coding, billing, and documentation tips for teaching physicians, interns, residents, and students
- Coding tip: Watch for different codes for SI joint injections
- Searched