HIPAA Compliance
HIPAA

Is Sharing EHR Passwords a Problem?

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article addresses the importance of Electronic Health Record (EHR) security to help health care organizations, health plans, clearinghouses (Covered Entities) and their business associates avoid HIPAA violations under the Security Rule Standard § 164.312(a)(1). To obtain more information about mitigating the risk of a HIPAA violation, please consult with legal counsel or a HIPAA Security Consultant. 

 

What If . . .

 

What would happen if you shared your login and password to your online bank account? How about sharing the password to access your credit cards? How would you feel if you knew your doctor shared his/her password to your personal medical records with an unauthorized user? What if someone in medical billing shared his/her password to your account (containing your medical and financial identity) with someone not authorized to access your information?


What If EHR Passwords Are Shared . . .


Electronic health records (EHRs) incorporate a vast amount of patient information and diagnostic data, most of which is considered protected health information. With the advancement of technology, the emergence of advanced cyber threats has escalated, which hinders the privacy and security of health information systems such as EHRs.


As defined by the Center of Medicare and Medicaid Services (CMS), “An electronic health record (EHR) is an electronic version of a patient’s medical history, that is maintained by the provider over time, and may include all of the key administrative clinical data relevant to that person’s care under a particular provider, including demographics, progress notes, problems, medications, vital signs, past medical history, immunizations, laboratory data and radiology reports.”


Because this protected information and data can easily get into the wrong hands, individuals should not share passwords with anyone.  


Is This Really a Problem? Doesn’t Everyone Share Passwords?


Due to the sensitive nature of the information stored within EHRs, several security safeguards have been introduced through the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.


Prevalence of Sharing Access Credentials in Electronic Medical Records

To summarize an abstract published by PMC (Public Med Central) of the U.S. National Institutes of Health’s National Library of Medicine, it was found that to prevent data leakage, many countries have created regulations regarding medical data accessibility. These regulations require a unique user ID for each medical staff member, and this must be protected by a password, which should be kept undisclosed by all means. A survey was conducted with the following results:

  • A total of 299 surveys were gathered.
  • The responses showed that 220 (73.6%) participants reported that they had obtained the password of another medical staff member.
  • Only 171 (57.2%) estimated how many times it happened, with an average estimation of 4.75 episodes. All the residents that took part in the study (45, 15%) had obtained the password of another medical staff member, while 57.5% (38/66) of nurses reported this.

Their conclusion from this study: the use of passwords is doomed because medical staff members share their passwords with one another. Strict regulations requiring each staff member to have a unique user ID might lead to password sharing and to a decrease in data safety. Click Here to access the full study.


Remember to Comply With the 3 Pillars of Securing ePHI


The three pillars to securing protected health information outlined by HIPAA are administrative safeguards, physical safeguards, and technical safeguards. These three pillars are also known as the three security safeguard themes for healthcare. These themes range from techniques regarding the location of computers to the usage of firewall software to protect health information. A brief list of the HIPAA Security Safeguards:

  • Access control (technical safeguard) is a technique that prevents or limits access to an electronic resource. The intent behind access control techniques is to limit access to only authorized parties. The healthcare facility collects, stores, and secures patients’ data, which is very sensitive. This safeguard can take the form of role-based access control, attribute-based access control, and identity-based access control. Role-based refers to a person’s role in the healthcare facility. For instance, when a provider begins working at a healthcare facility, he/she has access to patient data, but only the patient data for his/her patients. If this provider also serves on a certain committee in the hospital, then another set of privileges is created to enable access to committee resources. When other data is accessed, a log is created that is periodically audited. When a front-desk clerk begins working in a facility, he/she has no reason to access clinical data, but may need access to the administrative data such as address and phone number, depending on the role that the person plays in the organization. Other names for this are media controls, entity authentication, encryption, firewall, audit trails, virus checking, and packet filtering.
  • Physical access control (physical safeguard) is a technique that prevents or limits physical access to resources. The intent of this control is similar to the technical safeguard: It limits access to only authorized parties. A patient in a facility will not have access to any clinic or ward except the one he/she is seen in. A front-desk clerk in the optometry clinic will not typically need access to the emergency room, so his/her access card will not open those doors. A provider in a facility will not typically need access to the server room, so his/her access card will not unlock those doors. Other names for this are physical security, (some) workstation security, assigned security responsibility, media controls (access cards), and physical access control.
  • Administrative safeguards are techniques that are not entirely technical or physical, but may contain a piece of each. These safeguards typically take the form of policies, practices, and procedures in the facility to regularly check for vulnerabilities and continually improve the security posture of the organization. Other names for this control are risk analysis and management, system security evaluation, personnel chosen for certain roles, contingency, business continuity, and disaster recovery planning.

When Someone Shares a Password – It Is a HIPAA Violation Under the HIPAA Security Rule – Technical Safeguard Related to Access Controls. 

 

The Security Rule defines access in § 164.304 as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subpart E of this part [the HIPAA Privacy Rule]).” Access controls provide users with rights and/or privileges to access and perform functions using information systems, applications, programs, or files. Access controls should enable authorized users to access the minimum necessary information needed to perform job functions. Rights and/or privileges should be granted to authorized users based on a set of access rules that the covered entity is required to implement as part of § 164.308(a)(4), the Information Access Management standard under the Administrative Safeguards section of the Rule.


Unique User Identification Requirement - § 164.312(a)(2)(i)

 

The Unique User Identification implementation specification states that a covered entity must: “Assign a unique name and/or number for identifying and tracking user identity.”


User identification is a way to identify a specific user of an information system, typically by name and/or number. A unique user identifier allows an entity to track specific user activity when that user is logged into an information system. It enables an entity to hold users accountable for functions performed on information systems with ePHI when logged into those systems using audit trails (addressed toward the end of this article).


Regardless of the technology or information system used, access controls should be appropriate for the role and/or function of the workforce member. For example, even workforce members responsible for monitoring and administering information systems with electronic protected health information or ePHI, such as administrators or super users, must only have access to ePHI as appropriate for their role and/or job function.


Sample questions for covered entities to consider:

  • Does each workforce member have a unique user identifier?
  • What is the current format used for unique user identification?
  • Can the unique user identifier be used to track user activity within information systems that contain ePHI?

So, What Can Happen If We Have Insufficient ePHI Access Controls?

Violating HIPAA law 104-191 can be costly. The HIPAA Security Rule requires covered entities and their business associates to limit access to ePHI to authorized individuals. The failure to implement appropriate ePHI access controls is also one of the most common HIPAA violations and one that has caused financial penalties. 


Financial penalties issued to covered entities for ePHI access control failures include:


Anthem Inc. – $16,000,000 penalty for access control failures and other serious HIPAA violations

OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations

OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations

University of California Los Angeles Health System – $865,500 penalty for the failure to restrict access to medical records

Colorado Medical Center – $111,400 penalty for the failure to terminate access to ePHI after an employee termination and a lack of a business associate agreement

Controlling Access to ePHI: For Whose Eyes Only?


The government HIPAA privacy/security enforcement agency is the Office for Civil Rights (OCR). OCR published the Summer 2021 Cybersecurity Newsletter on July 14, 2021, which states:


The rise in data breaches due to hacking as well as threats to ePHI by malicious insiders highlight the importance of establishing and implementing appropriate policies and procedures regarding these Security Rule requirements. Ensuring that workforce members are only authorized to access the ePHI necessary and that technical controls are in place to restrict access to ePHI can help limit potential unauthorized access to ePHI for both threats.


A recent report of security incidents and data breaches found that 61% of analyzed data breaches in the healthcare sector were perpetrated by external threat actors and 39% by insiders.


Without appropriate authorization policies and procedures and access controls, hackers, workforce members, or anyone with an Internet connection may have impermissible access to the health data, including protected health information (PHI), that HIPAA regulated entities hold. News stories and OCR investigations abound of hackers infiltrating information systems, workforce members impermissibly accessing patients’ health information, and electronic PHI (ePHI) being left on unsecured servers.


Information Access Management and Access Control are two HIPAA Security Rule standards that govern access to ePHI.


Download this newsletter:

Monitor Audit Trails


Audit trails automatically register and record where, when and who accessed the system. They also record what users do when they access the system. This tracks every change in patients’ information and documents it.


Since all the data is logged in the EHR system, it enables users to review the data at regular intervals and flag activities that seem suspicious. Regular reviews can also help correct mistakes caused by human error that could be flagged as a HIPAA violation. An audit trail answers the following:

  • Which patients’ data was accessed?
  • What time was it accessed?
  • Who retrieved the data?
  • Where was the data accessed from?

EHR software can also be set to send notifications to patients when their information is accessed. This way patients can report breaches as soon as they happen.


Conclusion


Create strong policies and procedures, then communicate these rules to your workforce. Enforce compliance through auditing and monitoring. Explain that when an individual allows another to use his/her password to access ePHI, that individual can alter and perform unauthorized functions and not be held accountable. The audit trail points back to the person who is assigned that password. 


Conduct on-going training of your workforce, which needs to include your C-Suite executives (who are not exempt from the rules). To gain the BEST results, conduct additional quarterly training with your front-line managers and supervisors.  Give them tools to incorporate HIPAA training at EVERY department meeting. If you think annual HIPAA training is sufficient, then you simply are not doing enough to protect your patient’s ePHI.


Additional Resources


Weekly HIPAA Podcasts (free) at:

OCR “The Security Rule” on the HHS website:

Train Online in HIPAA Privacy & Security:

Read More
General Compliance

Consent and COVID Testing of Employees

Written By: Compliance Blogger




This article addresses COVID testing and consent considerations for:  healthcare organizations, nursing homes and business associates or non-healthcare workplaces. This article is not intended as legal or consulting advice.  Employers are encouraged to collaborate with state, territorial, tribal and local health officials to determine whether and how to implement COVID testing strategies.


SARS-CoV-2 (COVID-19) continues to be a health risk to be mitigated by health care institutions and at the workplace. Employers paying for testing of employees should put procedures in place for rapid notification of results and establish appropriate measures based on testing results, including instructions regarding self-isolation and restrictions on workplace access.


An employer’s testing program (including the implementation of a testing protocol to test employees) may be complex and technical. Certain aspects of the testing program may be more relevant than others to an employee’s decision whether to accept an offered test. Obtain guidance from experts to assist your organization in navigating risk.


Business Associates (non-healthcare organizations)


The Center for Disease Control (CDC) provides guidance for non-healthcare workplaces, which would apply to most business associates who have partnered with a health care institution, such as legal or accounting firms; medical billing companies; IT managed service providers, etc. Workplace-based testing should not be conducted without the employee’s informed consent. Encourage and answer questions during the consent process.


Informed Consent


Informed consent requires disclosure, understanding, and free choice, and is necessary for an employee to act independently and make choices according to their values, goals, and preferences. Consult legal counsel when developing your informed consent form for employees.


To fully support employee decision-making and consent, employers should take the following measures when developing a testing program:

  • Ensure safeguards are in place to protect an employee’s privacy and confidentiality.
  • Provide complete and understandable information about how the employer’s testing program may impact employees’ lives, such as if a positive test result or declination to participate in testing may mean exclusion from work.
  • Explain any parts of the testing program an employee would consider especially important when deciding whether to participate. This involves explaining the key reasons that may guide their decision.
  • Provide information about the testing program in the employee’s preferred language using non-technical terms. Consider obtaining employee input on the readability of the information. Employers can use the CDC tool to create clear messages: https://www.cdc.gov/ccindex/
  • Encourage supervisors and co-workers to avoid pressuring employees to participate in testing.
  • The consent process is active information sharing between an employer or their representative and an employee, in which the employer discloses the information, answers questions to facilitate understanding, and promotes the employee’s free choice.

Disclosures for Non-healthcare Workplace Testing


Individuals tested are required to receive patient fact sheets as part of the test’s emergency use authorization (EUA):

A basic disclosure for COVID-19 should include the following elements to provide information to employees so they understand what is involved when consenting to the test, such as clear information on the manufacturer and name of the test, the type of test, the purpose of the test, the performance specifications of the test, any limitations associated with the test, who will pay for the test, how the test will be performed, how and when they will receive test results, and; how to understand what the results mean, actions associated with negative or positive results, the difference between testing for workplace screening versus for medical diagnosis, who will receive the results, how the results may be used, and any consequences for declining to be tested.


According to the Americans with Disabilities Act (ADA), when employers implement any mandatory testing of employees, it must be “job related and consistent with business necessity.” In the context of the COVID-19 pandemic, the U.S. EEOC notes that testing to determine if an employee has SARS-CoV-2 infection with an “accurate and reliable test” is permissible as a condition to enter the workplace because an employee with the virus will “pose a direct threat to the health of others.” EEOC notes that tests administered by employers which are consistent with current CDC guidance will meet the ADA’s business necessity standard. However, workplace-based testing should not be conducted without the employee’s consent.


Infection Control for Healthcare Facilities


The CDC has made recent changes to infection control guidance for all U.S. settings where healthcare is delivered, including home health. The updated healthcare infection prevention and control (IPC) recommendations as of September 10, 2021 are in response to the COVID-19 vaccination. Consult with legal counsel regarding disclosures and consents appropriate for your organization.


Healthcare Personnel (HCP): HCP refers to all paid and unpaid persons serving in healthcare settings who have the potential for direct or indirect exposure to patients or infectious materials, including body substances (e.g., blood, tissue, and specific body fluids); contaminated medical supplies, devices, and equipment; contaminated environmental surfaces; or contaminated air. HCP include, but are not limited to, emergency medical service personnel, nurses, nursing assistants, home healthcare personnel, physicians, technicians, therapists, phlebotomists, pharmacists, dental healthcare personnel, students and trainees, contractual staff not employed by the healthcare facility, and persons not directly involved in patient care, but who could be exposed to infectious agents that can be transmitted in the healthcare setting (e.g., clerical, dietary, environmental services, laundry, security, engineering and facilities management, administrative, billing, and volunteer personnel).


Healthcare settings refers to places where healthcare is delivered and includes, but is not limited to, acute care facilities, long-term acute-care facilities, inpatient rehabilitation facilities, nursing homes, home healthcare, vehicles where healthcare is delivered (e.g., mobile clinics), and outpatient facilities, such as dialysis centers, physician offices, dental offices, and others.


Source control is the use of respirators, well-fitting facemasks, or well-fitting cloth masks to cover a person’s mouth and nose to prevent spread of respiratory secretions when they are breathing, talking, sneezing, or coughing. Source control devices should not be placed on children under age 2, anyone who cannot wear one safely, such as someone who has a disability or an underlying medical condition that precludes wearing one safely, or anyone who is unconscious, incapacitated, or otherwise unable to remove their source control device without assistance. Face shields alone are not recommended for source control.


IPC Measures


Several of the IPC measures (e.g., use of source control, screening testing) are influenced by levels of SARS-CoV-2 transmission in the community. There are two different indicators in CDC’s COVID-19 Data Tracker which are used to determine the level of SARS-CoV-2 transmission for the county where the healthcare facility is located – Access the COVID Data Tracker:

If the two indicators suggest different transmission levels, the higher level is selected.


Source control and physical distancing (when physical distancing is feasible and will not interfere with provision of care) are recommended for everyone in a healthcare setting. This is particularly important for individuals, regardless of their vaccination status, who live or work in counties with substantial to high community transmission or who have:

  • Not been fully vaccinated; or
  • Suspected or confirmed SARS-CoV-2 infection or other respiratory infection (e.g., those with runny nose, cough, sneeze); or
  • Had close contact (patients and visitors) or a higher-risk exposure (HCP) with someone with SARS-CoV-2 infection for 14 days after their exposure, including those residing or working in areas of a healthcare facility experiencing SARS-CoV-2 transmission (i.e., outbreak); or
  • Moderate to severe immunocompromised; or
  • Otherwise had source control and physical distancing recommended by public health authorities.

Perform SARS-CoV-2 Testing


Anyone with even mild symptoms of COVID-19, regardless of vaccination status, should receive a viral test as soon as possible, according to the CDC recommendation.


Asymptomatic HCP with a higher-risk exposure and patients with close contact with someone with SARS-CoV-2 infection, regardless of vaccination status, should have a series of two viral tests for SARS-CoV-2 infection.

  • In these situations, testing is recommended immediately (but not earlier than 2 days after the exposure) and, if negative, again 5–7 days after the exposure.
  • Note - testing is not recommended for people who have had SARS-CoV-2 infection in the last 90 days if they remain asymptomatic; this is because some people may have detectable virus from their prior infection during this period (additional information is available here). Criteria for use of post-exposure prophylaxis are described elsewhere.

Expanded screening testing of asymptomatic HCP without known exposures was required in nursing homes and could be considered in other settings. It should be conducted as follows:

  • Fully vaccinated HCP may be exempt from expanded screening testing.
  • Guidance for expanded screening testing for nursing homes was described in the Interim Infection Prevention and Control Recommendations to Prevent SARS-CoV-2 Spread in Nursing Homes | CDC but is no longer available.

Performance of pre-procedure or pre-admission viral testing is at the discretion of the facility. The yield of this testing for identifying asymptomatic infection is likely low when performed on vaccinated individuals or those in counties with low or moderate transmission. However, these results might continue to be useful in some situations (e.g., when performing higher risk procedures on unvaccinated people) to inform the type of infection control precautions used (e.g., room assignment/cohorting, or PPE used).


Click Here for more detailed information about infection control guidance.

Read More