Privacy and Security — Protecting Patients’ Health Information

Privacy and Security — Protecting Patients’ Health Information
复制标题

隐私和安全 — 保护患者 — 健康信息

DOI:
10.1056/nejmp2201676
复制
发表时间:
2022
影响因子:
158.5
通讯作者:
Hoffman, Sharona
Hoffman, Sharona
中科院分区:
医学1区
文献类型:
--
作者:
Hoffman, Sharona

文献摘要

相似文献

保护患者的健康信息[j];21 nejm。,并要求修改其记录或限制其使用。例如,患者可能会要求医疗服务提供者不要向他们的保险公司提交索赔信息,因为他们更愿意自掏腰包支付治疗费用。一般来说,如果患者的记录是正确的,并且不需要遵守将妨碍治疗、付款或医疗保健操作的使用限制请求,则受保实体可以拒绝修改请求。涉及未加密数据的隐私泄露事件(如黑客获得未加密记录的事件)的受保护实体必须通知受影响的患者、卫生与公众服务部,以及当泄露事件涉及州或辖区内超过500人的记录时,必须通知媒体。HIPAA安全规则为保护电子健康信息免受隐私泄露建立了管理、物理和技术保障措施。管理保障涉及安全管理流程、劳动力安全、信息访问管理、安全意识和培训、安全事件过程和应急计划。例如,员工应接受培训,避免在候诊室与病人讨论医疗信息,避免出于与工作无关的目的(如满足自己的好奇心)查看记录。受保实体必须指定HIPAA安全官员并进行安全风险评估。卫生与公众服务部发布了关于风险分析的有用指南。物理防护包括控制进入设施和设备以及保护工作站的工具。例如,受保实体必须确保未经授权的人员无法进入服务器机房,也无法看到计算机显示器上显示的健康信息。技术保障措施涉及
Protecting Patients’ Health Information n engl j med 387; 21 nejm. org November 24, 2022 health records and request modifications to their records or restrictions on their use. For example, patients may request that providers not submit claims information to their insurer because they would prefer to pay for treatments out of pocket. In general, covered entities may deny requests for modification if the patient’s record is correct and are not required to comply with requests for usage restrictions that will hinder treatment, payment, or health care operations. Covered entities that experience privacy breaches involving unsecured data, such as incidents in which hackers gain access to unencrypted records, must notify affected patients, HHS, and—when breaches involve the records of more than 500 people in a state or jurisdiction—media outlets. The HIPAA Security Rule establishes administrative, physical, and technical safeguards for protecting electronic health information against privacy breaches. Administrative safeguards address security-management processes, workforce security, informationaccess management, security awareness and training, securityincident procedures, and contingency plans. For example, employees should be trained to refrain from discussing medical information with patients in waiting rooms and from looking at records for non–work-related purposes, such as for satisfying one’s curiosity. Covered entities must appoint HIPAA security officers and conduct security risk assessments. HHS has issued useful guidance regarding risk analysis. 2 Physical safeguards include tools for controlling access to facilities and devices and securing workstations. For instance, covered entities must ensure that unauthorized people do not have access to server rooms and cannot see health information displayed on computer monitors. Technical safeguards relate to