Privacy and Security — Protecting Patients’ Health Information
Privacy and Security — Protecting Patients’ Health Information
复制标题
隐私和安全 — 保护患者 — 健康信息
DOI:
10.1056/nejmp2201676
复制
发表时间:
2022
影响因子:
158.5
通讯作者:
Hoffman, Sharona
中科院分区:
文献类型:
--
作者:
Hoffman, Sharona
Protecting Patients’ Health Information n engl j med 387; 21 nejm. org November 24, 2022 health records and request modifications to their records or restrictions on their use. For example, patients may request that providers not submit claims information to their insurer because they would prefer to pay for treatments out of pocket. In general, covered entities may deny requests for modification if the patient’s record is correct and are not required to comply with requests for usage restrictions that will hinder treatment, payment, or health care operations. Covered entities that experience privacy breaches involving unsecured data, such as incidents in which hackers gain access to unencrypted records, must notify affected patients, HHS, and—when breaches involve the records of more than 500 people in a state or jurisdiction—media outlets. The HIPAA Security Rule establishes administrative, physical, and technical safeguards for protecting electronic health information against privacy breaches. Administrative safeguards address security-management processes, workforce security, informationaccess management, security awareness and training, securityincident procedures, and contingency plans. For example, employees should be trained to refrain from discussing medical information with patients in waiting rooms and from looking at records for non–work-related purposes, such as for satisfying one’s curiosity. Covered entities must appoint HIPAA security officers and conduct security risk assessments. HHS has issued useful guidance regarding risk analysis. 2 Physical safeguards include tools for controlling access to facilities and devices and securing workstations. For instance, covered entities must ensure that unauthorized people do not have access to server rooms and cannot see health information displayed on computer monitors. Technical safeguards relate to