HIPAA Tip: What’s Happening in the EMR on the Weekends?
In the ever-evolving technology-driven world we live in, exciting advances are constantly being made from web-/cloud-based EMRs, telehealth software solutions, AI tools, portable medical devices, and so much more.
With these advances comes more opportunities for hackers and threat actors to gain access into healthcare organizations systems and applications containing ePHI.
How, you ask? For starters, many of the systems and applications an organization is using would be web-/cloud-based, allowing user access from any device at any time of the day or week, unless these privileges have been limited, either by the directive of the organization to the software application company (least privileged access/minimum necessary rule), or built-in security measures for limiting user access. What if there are no limitations to access the EMR and ALL staff have unlimited access from outside the business environment and from any device (personal laptop, cell phone)?
A healthcare organization is responsible for the privacy and security of its patients’ data, in all forms. If your organization allows access to systems and applications containing ePHI outside the business environment and from personal devices, then the organization must also have monitoring and auditing solutions in place. User activity has to be reviewed and checked regularly, especially during off-hours when most staff would have no need to be in these systems and applications. Whether this needs to be a manual process (scheduling time to review user activity on weekends and evenings) or an automated tool/solution that runs reports regularly for review, it is the responsibility of the business to check user’s access and look for questionable activity.
HIPAA Compliance Is an Ongoing Journey
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.