Read through the CHIMA Professional Practice Brief 0016.
08 on “Privacy &
Security in a Health Information Exchange (HIE)”. Read the scenario below
and answer the following questions using information from the Practice Brief.
You may also research google engine for reliable sources to come up with an answer.
At Halifax Health System, patient care is expedited by computerized real-time reports
generated by the laboratory, pathology, and diagnostic imaging departments. These are then
sent by an HL7 V3 interface to an electronic patient information system. As a result, staff
physicians can retrieve these results on office PCs or at the bedside. This type of patient
information access permits them to make informed treatment decisions for optimal patient
care. The risk is that physicians may forget to log off the system. If this occurs, others working in
the vicinity of the PCs may be able to view patient information.
Questions:
1. Does the failure to log off individual PCs place patient confidentiality in jeopardy?
Explain why or why not.
2. What are the risks of this system?
3. There are three types of safeguards – administrative, technical, and physical. Briefly
describe each type of safeguard and provide two examples of how each type of
safeguard could reduce the risk of inappropriate disclosure of personal health
information.
4. Would regular backups of the computerized patient information system be beneficial in
this case? If so, in what way. If not, why?
5. As part of the HER implementation team, what would you recommend should the
electronic system be unavailable (e.g., eMPI system down, how are record numbers
retrieved to pull paper charts; if electronic health record system is down, what is the
downtime procedure to retrieve information? How will physicians access lab and DI data
when system is down?)?