Electronic Medical Record (EMR) Data Conversion and HIPAA Security

Data conversion and data migration are householdrequirements for HIPAA controlled PHI data.
words among clinics that are changing PracticeThere are fiduciary and identity theft laws which
Management/Billing Systems. Many choose togovern patient demographic and financial
convert patient information and other relevantinformation but they do not adequately cover PHI
data from their Legacy system into their newdata.
system. Some do not. And that is an acceptableThe EMR conversion will require the exchange of
choice primarily because the data left behind arePHI data.
available from patients when they next visit theHIPAA requires secure transmission of patient
clinic. The relevant financial data will usuallydata. It is essential that your data conversion
become obsolete in about 90 days.provider implement a policy to use an encryption
However, Clinical data (Electronic Medical Recordsmethod which meets or exceeds HIPAA
including image files) are not so easily dismissed.requirements. One option is to use the 256 bit
Leaving EMR data in the Legacy system may beencryption provided by WinZip (there are others,
a short term option but maintaining two EMRWinZip is used here as an example and for a
systems will soon become a financial burden, willreference point). It does meet the HIPAA
decrease efficiency and increase opportunity forrequirements for secure transmission. After data
error. Not keeping electronic Chart records is, infiles are zipped they are encrypted with a 256 bit
most cases, not a viable option.encryption key and then password protected. It is
Contrary to some opinions, Clinical data andrecommended that passwords of 10-20
images can be converted into a new EMRcharacters be randomly created each time a file is
System. The issues to effect an accuratetransferred. Passwords should include upper and
conversion are not trivial. Different from a Billinglower case letters, numbers and special
System conversion, accurate EMR conversionscharacters.
cannot be completed without significantRegardless of the size of the file to be
involvement of skilled users from the clinic, peopletransferred, when PHI data are included HIPAA
who know the data from having used it over asecurity is required. Failing that puts all parties
period of time.involved in the transaction at risk for
More about EMR conversions at another time. Thenon-compliance.
point of this article is to discuss the security