Tip of the week: Conduct regular physical security checks to ensure the safety of your PHI.
HIM Connection, May 15, 2007
Want to receive articles like this one in your inbox? Subscribe to HIM Connection!
The security rule has led many healthcare providers to upgrade antivirus software, properly set up servers and firewalls, and conduct audits of access to ePHI. However, although taking these security measures is important, don't neglect basic physical security requirements in the process. Physical vulnerabilities can pose just as much-or perhaps more-of a threat to your organization.
"[Health information management (HIM)] departments have a good understanding of how important it is to protect their records," says Tom Walsh, CHS, CISSP, president of Tom Walsh Consulting, LLC, in Overland Park, KS. "Very few have weak physical security. But there can be [problems] out on the floors."
Common problems include the following:
- Failing to promptly shred confidential documents
- Leaving PHI out in the open
- Failing to secure laptops, other portable devices, and paper charts when working remotely
- Failing to scrutinize visitors closely enough
Conduct regular physical security checks
Include physical security in your organization's regular risk assessments so you can devise a plan to address these vulnerabilities. Also conduct regular walk-throughs in which you assess the physical security of all departments, Walsh recommends. The checks should include everything from making sure medical charts are not visible on desks to ensuring that computer passwords aren't in public view. (See the sample checklist on p. 8 for more information.)
Try to do walk-throughs during day and night shifts to make sure that everyone is following the rules; the smaller night staffs often do things differently, Walsh says. "Sometimes, the night shift tends to bend the rules."
It's also a good idea to perform a walk-through before conducting awareness training in a particular department so you can tailor your training to present problems, Walsh says. Then do another walk-through to confirm your training's effectiveness. You might also want to create a rewards program to motivate staff members to take physical security issues seriously, he suggests.
One common physical security problem is that staff members collect confidential information under their desks because they don't think to shred it frequently. Or worse, they might simply put confidential information in the regular trash where anyone could find it. Sometimes it can pile up for a week or more in an unsecured bin that anyone can access, Walsh says.
Tom Walsh, CHS, CISSP, president of Tom Walsh Consulting, LLC, in Overland Park, KS, provided this tip in the May 2007 issue of Briefings on HIPPA. To read more tips, visit http://www.hcpro.com/content/69735.cfm.
Want to receive articles like this one in your inbox? Subscribe to HIM Connection!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- QA:Coding multiple initial infusions
- News and briefs: Oklahoma Osteopathic Association against residency bill change
- HIPAA Q&A: Level of encryption needed for email
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- Q&A tackles coding questions about injections and infusions
- Joint Commission Center announces handoff communication solutions
- Inside best practice: Reduce patient falls with a stoplight
- Identify modifiable risk factors to prevent patient falls
- Searched