Privacy Flashcards
§164.530(c)(2)(i) PRIVACY Personnel:
How is access to PII, PHI or ePHI safeguarded from unauthorized access in your area.
1) Keys
2) Card swipes
3) Other
4) Permissions
§164.530(c)(2)(i) PRIVACY Personnel:
How is your staff trained on privacy and security?
1) Are there any checklists for in-department on-boarding.
2) Are there any policies or procedures documented.
Terminations:
Please describe your termination process for both voluntary (resignation) or involuntary termination’s.
1) Are there any special processes such as the requirement to take office keys or building keys.
Terminations:
How are people terminated from your ________ department/special applications.
Please describe the process.
1) Who notifies IT?
Collection of Fees / PCI. DSS:
Are you required to collect any fees for services such as: medical records fees, parking fees, etc.
Please describe the process.
Collection of Fees / PCI DSS:
What form of payment do you accept?
How are the credit cards processed?
How are checks processed?
How is cash processed?
Collection of Fees / PCI DSS:
If they use a card swipe terminal is that device connected to the network, phone line or is it a stand-alone (cell service) device.
When was the last PCI audit performed on the terminal.
General:
Is information ever taken via the phone and or written down?
What happens to that paperwork once you’re completed with it?
§164.530(c)(2)(i) PRIVACY Personnel:
Please describe your staff, their roles and responsibilities as well as any third parties you may work with.
(a) Inquire of management as to whether administrative, technical,
and physical safeguards are in place to protect all PHI.
(b) Obtain and review procedures and policies and evaluate the
content to determine if administrative, technical, and physical
safeguards are in place to protect all PHI (e.g., electronic PHI,
written PHI, rules about speaking about PHI).
(d) Observe and verify whether the safeguards in place are
appropriate.
General:
Is information ever taken via the phone and or written down?
What happens to that paperwork once you’re completed with it?
General:
Do you utilize a departmental drive?
What information is stored on your departmental drive?
How would someone gain access to that share?
Contingency planning:
Do you have a documented emergency disaster recovery plan.
Where is the plan kept.
How was the plan updated.
When was the last time the plan was updated.
How is the plan tested.
When was the last time you tested the plan.
Medical records:
Where is the legal medical record kept? system / paper / other locations?
Please describe the process for a record that has been placed on the legal hold.
Medical records:
Are any medical records left out during the night?
Please describe the process for safeguarding the medical record.
Medical records:
Do you send ePHI to other facilities?
How do you send the ePHI?