Electronic Medical Records, HIPAA, and Patient Privacy

نویسندگان

  • Jingquan Li
  • Michael J. Shaw
چکیده

The continued growth of healthcare information systems (HCIS) promises to improve quality of care, lower costs, and streamline the entire healthcare system. But the resulting dependence on electronic medical records (EMRs) has also kindled patient concern about who has access to sensitive medical records. Healthcare organizations are obliged to protect patient records under HIPAA. The purpose of this study is to develop a formal privacy policy to protect the privacy and security of EMRs. This article describes the impact of EMRs and HIPAA on patient privacy in healthcare. It proposes access control and audit log policies to safeguard patient privacy. To illustrate the best practices in the healthcare industry, this article presents the case of the University of Texas M. D. Anderson Cancer Center. The case demonstrates that it is critical for a healthcare organization to have a privacy policy. IntroductIon The strategic utilization of information systems/ information technologies (IS/IT) has played a central role in enabling organizations across many industry segments to address many business challenges and achieve a level of sustainable competitive advantage (Croasdell, 2001; Hammond, 2001; Holt, Love, & Li, 2000). Healthcare is noted for embracing new scientific discoveries and using leading edge technologies to enable better cures for diseases and better means to enable early detection of most life threatening diseases. Ironically, the healthcare industry in the United States, which has a greater need for more accurate and timely information, has experienced less development of IS/IT than other industries such as banks or airlines. The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is the largest governmental law in healthcare since Medicare. HIPAA mandates new federal standards for elec1795 Copyright © 2010, IGI Global. Copying or distributing in print or electronic forms without written permission of IGI Global is prohibited. 1796 Electronic Medical Records, HIPAA, and Patient Privacy tronic transactions, such as payment processing, patient’s medical information privacy, and security procedures that secure the privacy protections. Currently healthcare organizations are contending with relentless pressures not only to implement IS/IT technologies but also to become compliant with HIPAA. The growing use of healthcare information systems (HCIS) has provided healthcare organizations with tremendous benefits, including significantly reduced costs, reduced harmful medical errors, and improved quality of care. But the resulting dependence on electronic medical records (EMRs) has also kindled patient concern about patient data privacy and security. EMRs often contain some of the most sensitive information about who and what we are, such as mental and physical illness. Perhaps more than any other type of data, the confidentiality of EMRs is absolutely essential. When doctors’ file cabinets held the bulk of medical records, the employees working in those practices had access to them. As hospitals and clinics switch to electronic record keeping, however, many more people might have access to private medical records. Under HIPAA, new healthcare privacy provisions designed to protect data transmitted and stored electronically went into effect April 14, 2003. The requirements of HIPAA and compliance issues are getting the attention of top executives in the healthcare industry. Having a formal privacy policy is a key step in implementing any HIPAA compliance program. It should expressly cover how a health organization is protecting EMRs; the rules and limits on who can access and use EMRs; and the capability to track who has disclosed sensitive data and the circumstances of disclosure. A positive, formal, and continually practiced privacy policy by all employees can establish rules and limits on who can access and disclose EMRs and thus minimize the possibilities of privacy breaches. On the other hand, a poorly defined and improperly implemented and managed privacy policy can make EMRs ripe for privacy abuse. The HIPAA privacy rule puts an emphasis on access control and audit trails to protect patient data. This study investigates the use of access control and audit log policies to safeguard patient privacy. The objective of this study is to develop formal access control and audit policies to protect the privacy of EMRs. The development of HIPAA compliance program and security policies has been addressed by several studies (Kieke, 2003; Messmer, 2003; DeMuro & Grant, 2001; Li & Shaw, 2004; Patient privacy, 2001). There are also several papers addressing the issue of protection of EMRs (Ateniese & Medeiros, 2002; Swartz, 2004). The closely related works to this study include the following. Zunkel (2005) studied how to use biometric technology to protect personal information and found that biometric technology does not endanger personal information; it protects it. Borrowing the principles of reporting and auditing from the accounting sector, Stevens (2002) found that through comprehensive reports of network activity logs and regular auditing of security measures and devices, healthcare organizations can generate the proof of HIPAA compliance. While these studies are devoted to technical aspects and particular access control and audit log technologies, this study takes a management-oriented approach to develop access control and audit log policies to protect EMRs strategically. The rest of the article is organized as follows. In the second section, we discuss the issue of patient privacy in healthcare. In the third section, we describe the HIPAA privacy rule and its privacy implications. In the fourth section, we investigate access control and audit log policies to protect patient privacy. To illustrate the impact of EMRs on patient privacy and the importance of having a privacy policy in the healthcare system, we present a case example of the University of Texas M. D. Anderson Cancer Center in the fifth section. We conclude with a summary in the final section. 8 more pages are available in the full version of this document, which may be purchased using the "Add to Cart" button on the product's webpage: www.igi-global.com/chapter/electronic-medical-records-hipaapatient/49966?camid=4v1 This title is available in InfoSci-Books, Business-Technology-Solution, InfoSci-Medical, Healthcare, and Life Science and Technology, Communications, Social Science, and Healthcare. Recommend this product

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Taiwan's perspective on electronic medical records' security and privacy protection: Lessons learned from HIPAA

The protection of patients' health information is a very important concern in the information age. The purpose of this study is to ascertain what constitutes an effective legal framework in protecting both the security and privacy of health information, especially electronic medical records. All sorts of bills regarding electronic medical data protection have been proposed around the world incl...

متن کامل

Privacy and security of patient data in the pathology laboratory

Data protection and security are critical components of routine pathology practice because laboratories are legally required to securely store and transmit electronic patient data. With increasing connectivity of information systems, laboratory work-stations, and instruments themselves to the Internet, the demand to continuously protect and secure laboratory information can become a daunting ta...

متن کامل

Safeguarding patient privacy in electronic healthcare in the USA: the legal view

The conflict between the sweeping power of technology to access and assemble personal information and the ongoing concern about our privacy and security is ever increasing. While we gradually need higher electronic access to medical information, issues relating to patient privacy and reducing vulnerability to security breaches surmount. In this paper, we take a legal perspective and examine the...

متن کامل

HIPAA regulations - a new era of medical-record privacy?

Although the regulations under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) regarding the privacy of medical records are new, 1 the concept of using federal law to protect the privacy of medical records is not. The substance of the new regulations can be traced back to work done in the 1970s, especially the report of the Privacy Protection Study Commission, which help...

متن کامل

Assessing the effects of the HIPAA privacy rule on release of patient information by healthcare facilities.

The HIPAA privacy rule (HIPAA) has had both positive and negative effects on the release of patient information by healthcare facilities. Although the intention of HIPAA was to protect patient privacy and to promote security and confidentiality of patient information, it has had unintended consequences for facilities. To identify some of these unintended effects, two expert panels of health inf...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IJISP

دوره 2  شماره 

صفحات  -

تاریخ انتشار 2008