Showing posts with label patient privacy. Show all posts
Showing posts with label patient privacy. Show all posts

Saturday, February 23, 2013

How Medical Professionals Use Texting and Still Comply with PHI

by Holly Shoemaker

In a previous blog I recapped how text messaging had become a preferred method of communication for those working in the emergency room (ER). Now, some medical professionals have looked at texting as a means of sending information regarding patient follow ups.

Study at a Glance and HIPAA

A recent study published in the American Journal of Public Health (AJPH) looked at using text messaging to follow up with lower-income parents whose children had received a flu shot and needed follow-up visits.

The participants determined they wanted to send targeted messages, which were to include the child’s name and a reference to a “second flu shot.”

That seemed like an easy and effective way to remind parents about a follow-up visit, and texting provides an easy way to communicate with a majority of patients. However, there were problems with the language. The message contained Patient Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA). Under HIPAA, all communication must protect patient information. In this case, the message had the patient’s name and implied he/she had already received a flu shot. Those two pieces of information violated patient privacy.

Text messaging is also not considered a secure form of electronic communication. Even when sent by secured means, there is no way to guarantee the intended recipient receives the message.

The study team found away to protect PHI. It eliminated names and made the language generic. Instead of saying that a child needed a second flu shot, the team send a reminder that some children may need a second one. The message ended by prompting the recipient to call for an appointment.

Concluding Thoughts

The study serves as a good reminder for those medical professionals who prefer texting. It is a feasible means to communicate as long as the messages keep patient information private. The study also sets a standard on how to comply with HIPAA and PHI.

Friday, July 20, 2012

Protecting Patient Privacy Remains at the Forefront of Medical Mobile Apps

by Holly Shoemaker

Patient privacy continues to remain a top priority and focus of concern regarding medical mobile applications. As the Federal Drug Administration (FDA), other government agencies and a medical app store drafted guidelines pertaining to aspects of eHealth applications, the Future of Privacy Forum (FPF) has provided its own input regarding how to best protect data collection and has also released best practices for app developers.

Overview of Best Practices

The FPF stresses that developers should embed privacy measures throughout the development lifecycle. The guidelines also stress the importance of using clear and simple language to ensure all users understand how data is collected and shared. Along with that, the FPF discusses the importance of securing data and having someone accountable for ensuring privacy measures are followed.

Concluding Thoughts

As mentioned before, guidelines will help developers streamline the development lifecycle and provide consumers with information on how to best protect their information. The challenge comes in when integrating all the feedback gathered from all sources to ensure all parties get what they need from regulatory measures - no developer wants to prolong an already long lifecycle for medical applications.