What special measures should we take to reduce the likelihood of inappropriate access to PHI of VIPs?
HIPAA Weekly Advisor, May 9, 2005
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Whether you regularly treat VIPs (e.g., movie stars, athletes, politicians) at your facility or do so only occasionally, consider performing special audits to see which employees in your organization access VIPs' PHI.
If your organization only occasionally treats a VIP, run a special audit on each one. If your organization treats these patients often, you probably won't have time for such extensive research. Instead, schedule access audits regularly for a few of those VIPs.
Both the HIPAA privacy and security regulations require healthcare organizations to control access to PHI. The security regulations specifically require organizations employ to audit controls. So running regularly scheduled audits (i.e., monthly or quarterly) of all patients' PHI (including VIP patients) should be part of your normal compliance procedures.
Additional access audits focused on VIPs' PHI may be a good idea because VIP audits will most likely reveal more incidents of inappropriate access than other regularly scheduled audits and performing VIP audits could bolster your defense if a patient sues you for breach of privacy.
Editor's Note: Attorney Todd Brower of Wolf Block Brach Eichler answered this question. This is not legal advice. Please consult your attorney for legal matters.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- QA:Coding multiple initial infusions
- News and briefs: Oklahoma Osteopathic Association against residency bill change
- HIPAA Q&A: Level of encryption needed for email
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- ED-to-inpatient transfers are flawed with safety gaps
- Joint Commission Center announces handoff communication solutions
- Inside best practice: Reduce patient falls with a stoplight
- Identify modifiable risk factors to prevent patient falls
- Searched