preview

HIPAA Compliance Case Study

Decent Essays

A.1. There would be multilevel of HIPAA training with presentations, online training material, and a frequently asked questions page. The live presentation will be mandatory for all current medical staff and new hires. The online training would be a refresher course given out every year, with a quiz at the end. A frequently asked question page would be available all year long on the intranet and updated as needed. A.1.a. Three appropriate types of PHI that can be shared among staff include patients name, patients date of birth and lab results. A.1.a.i. Information sharing can take place over the phone with approved family members or hospital employees. Another location is in the departments when transferring the patient. A.1.a.ii. Three individuals …show more content…

Patients orders and medications will be recorded on the electronic health record, EHR, before the end of each shift. This is to ensure the next shift will have all the information that is needed for the continuation of care. The computers will time out when not active for the specified amount of time and employees would be required to lock the computer before walking away. Any monitors in patient care areas would have screen shields that block the view of PHI. A.2.a. A.2.b. The audit would review who has access to the patient’s EHR and set limits per employee’s job title. Health records archive would need to be updated. Any film would need to be digitized if still within the timeline of mandatory record obtainment or destroyed. There is a mandatory backup of the records that must be maintained. The EHR with updated firewalls and password protection would high priority to ensure no hackers can penetrate the system. A.2.c. Each employees job would allow them to access the EHR but limit access or what modifications can be added. Health records would be digitized or destroyed in accordance with the law. Records would be protected by a password, that must be changed every two months, and the lasted

Get Access