HIPAA in a "Nutshell" - Guidelines for EMR and Paper Medical Records Compliance

HIPAA in a “nutshell”The criminal penalties are for
There are two HIPAA rules requirements; privacy“misuse” and for obtaining or using
(2003) and security (2005). Both rules require:health information by “false
-Identifying possible threats,pretenses” or with the intent to sell,
-Assessing specific vulnerabilities,transfer or use it for commercial advantage,
-Determining appropriate and reasonablepersonal gain or malicious harm. These penalties
safeguards andare up to $250,000 and five years in jail.
-Implementing the necessary defenseCurrently there is no real effective enforcement
mechanisms and policies.body.
Using an EMR (electronic medical record) has noHIPAA compliance "thumb rules"
absolute right and wrongs in either computerWith an EMR most of the requirements are
equipment or software for HIPAA compliance.common sense and providers do not need to be
Usually there are four areas to examine:overly concerned but do require some basic steps
-Physical Security – can your computerslike:
with patient data be stolen?-Put your computer server in a secure room,
-User Security - can anybody log on to thelocked,
patient database?-Use an EMR with user management and
-System Security – what happens on apermissions,
hard drive crash?-Make regular back-ups and store them in a
-Network Security – can unauthorizedsecure place and
persons outside your facility access patient data?-Employ a computer specialist.
Using paper medical records begs similar questions:Most medical practices and clinics using paper
-Physical Security – how secure are therecords need to make physical changes to be
files from fire and theft?HIPPA compliant. If you continue to use paper
-User Security - what access controls and loggingthen there are a myriad of physical complexities
is there?to consider:
-System Security – what happens in a fire-How to monitor staff access,
or flood?-Fire and flood protection (insurance is not enough)
-Storage Access – are the files in a locked,-A disaster plan (that has been documented and
secure area?practiced.)
There are HIPAA penaltiesFinally, if there is a legal case brought forward a
The civil monetary penalty is up to $100 perprovider to protect themselves should have a trail
person record per violation and up to $25,000 perof how the patient's individual information was
year total for the same type of violation. There isaccessed. For paper records this means at a
30 days to correct the problem if it is not throughminimum a monitored sign out sheet and for an
willful neglect.EMR user logging of patient file access.