YOUR BUSINESS AUTHORITY

Springfield, MO

Log in Subscribe

Derek B. Hunter
Derek B. Hunter

Paperless record storage calls for strong controls

Posted online
Many organizations are moving to paperless document filing and storage systems – systems that may be closer to “less paper” than completely “paperless.” Even so, the bottom line with any information system is to carefully choose the personnel who have access to it.

For health care providers in today’s litigious society, it has become increasingly important to protect both patient and employee personal health information, especially considering the legislative and media emphasis on privacy.

Prioritize privacy, security

The Health Insurance Portability and Accountability Act imposes specific requirements and penalties for noncompliance. Health care providers may encounter privacy-related lawsuits that seek financial awards, making it crucial to protect personal records and discussions by restricting access only to those who need to know.

When it comes to protecting other confidential information, your organization may have additional concerns beyond those of HIPAA.

For example, payroll information must be carefully protected, especially in organizations with wide variations in salaries and benefits. If you are located in a nonmetropolitan area where more members of the community know each other, information and data leaks can be particularly damaging to public perceptions.

Limit access

It’s appropriate and important to regularly review the limits on access to information in your system. Different types of data should have different levels of access, but limiting access comes with trade-offs.

Just as certain members of your management team need access to highly confidential documents, so will members of your information technology personnel because of the system services they provide.

However, in many companies, IT personnel are sometimes more transient than other departmental personnel and may move from one employer to another more often. This makes the access limitation more important.

To address what could potentially threaten your system’s security, regularly remind all employees – especially those with access to highly confidential documents – of their responsibility to protect private information and not disclose it.

Though access must be limited to those who need to know, you don’t want to limit access so much that a technical problem can’t be fixed and information in the system can’t be accessed by those who need it.

Weigh access against risks

Virtually all organizations have certain documents that must be kept very confidential. A traditional paper-based system can contain everything from personnel files, payroll information and medical records to management discussion memos and documents prepared in anticipation of litigation. Access is physically controlled, with documents locked safely away in file cabinets inside offices with restricted access.

Paperless, technological records storage can enhance operational access, but not without the challenge of how to limit access only to those who need to know. You must also allow your IT staff access so it can perform regular system updates and maintenance.

Derek B. Hunter is a partner with BKD LLP’s Health Care Group in the firm’s Springfield office. He may be reached at dhunter@bkd.com.

Comments

No comments on this story |
Please log in to add your comment
Editors' Pick
Fall 2026 Architects & Engineers Project Report

This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.

Most Read
Update cookies preferences