HIPAA Tip: 13 Best Practices to Keep Your Staff HIPAA Compliant
HIPAA Compliant Practices
- Practices must provide an up-to-date training program on the handling of PHI, patients and their confidentiality and all security aspects as it pertains to patient data.
- Do not share sensitive PHI with others who should not have access (co-workers or personal acquaintances).
- Never access a patient’s health record unless needed to complete work or with written permission from the patient.
- Minimize occurrences of others overhearing patient information.
- Secure all paperwork containing PHI by placing in drawers or cabinets when not in use. Cover charts, secure papers at front desk. Never leave records and other PHI unattended: fax machines; clean desk policy after hours.
- Always close out of computer programs containing ePHI when not in use. Enable automatic time out settings for these programs.
- Never email patient information unless an email encryption software solution is being used.
- Ensure that all patient data and important business information is being backed up securely onsite and offsite.
- Assign different levels of security clearance to specific staff for the office and the network. Set up role-based access for systems containing PHI.
- Never share passwords between staff members. Assign individual IDs and passwords to all employees who are allowed access to ePHI.
- Properly dispose of paper PHI by shredding with either a cross-cut or diamond shredder.
- Make sure computers, laptops, servers have updated antivirus software installed.
- Be sure all staff understand the “CIA” triad for Protected Health Information: confidentiality is a set of rules that limits access to information, integrity is the assurance that the information is trustworthy and accurate, and availability is a guarantee of reliable access to the information by authorized people.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author:
Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP