YOUR BUSINESS AUTHORITY
Springfield, MO
For health care providers in today’s litigious society, it has become increasingly important to protect both patient and employee personal health information, especially considering the legislative and media emphasis on privacy.
Prioritize privacy, security
The Health Insurance Portability and Accountability Act imposes specific requirements and penalties for noncompliance. Health care providers may encounter privacy-related lawsuits that seek financial awards, making it crucial to protect personal records and discussions by restricting access only to those who need to know.
When it comes to protecting other confidential information, your organization may have additional concerns beyond those of HIPAA.
For example, payroll information must be carefully protected, especially in organizations with wide variations in salaries and benefits. If you are located in a nonmetropolitan area where more members of the community know each other, information and data leaks can be particularly damaging to public perceptions.
Limit access
It’s appropriate and important to regularly review the limits on access to information in your system. Different types of data should have different levels of access, but limiting access comes with trade-offs.
Just as certain members of your management team need access to highly confidential documents, so will members of your information technology personnel because of the system services they provide.
However, in many companies, IT personnel are sometimes more transient than other departmental personnel and may move from one employer to another more often. This makes the access limitation more important.
To address what could potentially threaten your system’s security, regularly remind all employees – especially those with access to highly confidential documents – of their responsibility to protect private information and not disclose it.
Though access must be limited to those who need to know, you don’t want to limit access so much that a technical problem can’t be fixed and information in the system can’t be accessed by those who need it.
Weigh access against risks
Virtually all organizations have certain documents that must be kept very confidential. A traditional paper-based system can contain everything from personnel files, payroll information and medical records to management discussion memos and documents prepared in anticipation of litigation. Access is physically controlled, with documents locked safely away in file cabinets inside offices with restricted access.
Paperless, technological records storage can enhance operational access, but not without the challenge of how to limit access only to those who need to know. You must also allow your IT staff access so it can perform regular system updates and maintenance.
Derek B. Hunter is a partner with BKD LLP’s Health Care Group in the firm’s Springfield office. He may be reached at dhunter@bkd.com.
This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.
Longtime employee sues Ozarks Tech, alleges retaliation
Cavender’s opens hat shop in southeast Springfield
Eric Schmitt introduces Modern Skies Act
Caterpillar to acquire John Fabick Tractor Co.
Springfield airport to cut the ribbon on $35M in construction projects
Legacy Bank accused in lawsuit of failing to protect customers in data breach