Language Selection

Get healthy now with MedBeds!
Click here to book your session

Protect your whole family with Orgo-Life® Quantum MedBed Energy Technology® devices.

Advertising by Adpathway

         

 Advertising by Adpathway

How Penn Medicine Investigates Improper Patient Record Access

10 hours ago 1

PROTECT YOUR DNA WITH QUANTUM TECHNOLOGY

Orgo-Life the new way to the future

  Advertising by Adpathway

Philadelphia-based Penn Medicine is a complex health system with seven hospitals and hundreds of clinics, yet its privacy investigation team is actually pretty small — a team of three, including Privacy Officer John Nocito. During a recent summit meeting, Nocito described his team’s process for investigating potential inappropriate access of patient records. 

Nocito was speaking at a summit meeting put on by Bluesight, a company whose PrivacyPro solution is an automated patient-privacy monitoring platform designed for healthcare organizations to track and investigate EHR access. 

He said his team has an interesting mix of background. One has a nursing and clinical background, another has a medical records background, and Nocito has a legal background. “That combination has worked well for us because the cases we deal with obviously can involve clinical workflows, medical records, and employment issues,” he said. “So in a lot of ways, we're bringing three different professional lenses to the same cases, and it helps that collectively we have over 15 years of experience in handling these cases.”

With a team of only three, he said they have to be thoughtful about how they allocate their resources. “We're increasingly spending more and more time on improper disclosures and responding to data security incidents,” he said.  

Nocito said they have found they can learn from their cases and use that experience to make their monitoring better. “Even after we've decided that a case warrants our attention, we don't necessarily handle every case the same way,” he said. “We have a standard investigative process for what we deem as the higher-risk cases — cases where clinical information was viewed, maybe multiple patients were involved, or there were unusual circumstances. We’ve also developed what we call a streamlined process for certain lower-risk cases.”

Some cases involving only demographic information may not always require the same level of investigative resources as a case where someone has entered the clinical portions of a chart, he explained. One example is a coworker case where the employee spent about three seconds in the patient identity report and didn't view clinical information. 

“We've had numerous cases where employees were working on multiple screens and thought they typed a coworker's name into Teams or e-mail, but the cursor is actually still in Epic,” he said. “So the employee inadvertently searched the coworker in Epic, and PrivacyPro did exactly what it's supposed to do — it identified the access, generated an alert, oftentimes with a high suspicion score. But time and experience have told us that a three-second demographic-only access like that doesn't necessarily require us to bring in HR business partners or schedule a formal employee meeting and go through our entire process. In those situations, we may handle the matter with a phone call and re-educate the employee on the spot. We have found that approach can still be very impactful. We do something similar with certain family member cases because, based on our experience, we've found that many of those accesses were authorized by the patient.”

When circumstances are appropriate, the team can handle those cases more efficiently and that helps them move faster and get to the next case, while also being thoughtful about how they use the time of their HR partners, medical leaders and other supervisors. 

“But if there's anything about a case that raises our suspicion, even in a patient identity report only or family member case, we will definitely err on the side of using our standard process and bring the full set of resources to that investigation,” Nocito said. 

Owning the investigation

One of the most important decisions they’ve made is that the privacy office owns the investigation from beginning to end, he stressed. “We don't simply send the privacy report out to the employee supervisor and ask them to investigate for us. That's not to say we don't involve our supervisors or operational leaders. We absolutely do. In fact, they're often essential to the investigation because they understand more about the employee's job and workflow better than we do,” he said. “We're asking the supervisor to help us understand the workflow, but we’re not asking the supervisor to conduct the investigation.”

Maintaining ownership also gives the team experience and consistency. “We have the same team applying the same process across the seven hospitals and hundreds of practices, rather than potentially having hundreds of different supervisors conducting the investigations in different ways,” Nocito said, “and we found that consistency served us very well, including situations where we've had to defend our process after the fact, whether it be in an employee grievance setting, or in one case where I ultimately had to testify at an arbitration hearing.”

Here is how Nocito described the process: When they can't establish a work-related reason for the access, the next step is meeting with the employee. When an alert comes in, they know what happened in the record. They can see what the employee viewed but don't necessarily know the why. An alert is a reason to investigate, he said. It’s not a determination of wrongdoing. The employee may have intentionally snooped. They may have a misguided or maybe a well-intentioned reason for looking, or they made a mistake. 

"One case that comes to mind involved a nurse who hadn't seen her elderly neighbor in quite some time. She became concerned about her and looked in the medical record to see whether she was in the hospital,” he said. “Now, to be clear, that doesn't necessarily answer the question of whether the access was appropriate, but it told us something important about the situation that we wouldn't have gotten from the audit trail alone. We knew what she did, but we didn't know why she did it, and that's one of the reasons we think it's important to actually meet with the employees, hear the explanation before we make any on-the-record disciplinary recommendation.”

Nocino added that the way they conduct that meeting is also very deliberate. Once they’ve decided that they need to meet with the employee, they are intentional about how they conduct that meeting. First, they have standard questions that they use in all of the meetings. They tailor them to the circumstances that require it, but they don't reinvent the interview every time they sit down with somebody. That helps them make sure they’re still covering the same basic ground with every employee, and gives them greater consistency and fairness from one case to the next. 

“We also show the employee the evidence,” he said. “We don't hide the ball at all. We'll show them the PrivacyPro report, the relevant audit trail, and walk through the access we're asking them about. I think that's important for a couple reasons because it gives the the employee a clear understanding of exactly what we're asking about, and second, it gives them a meaningful opportunity to explain what happened, and that's really the whole point of the meeting.”

Nocito said they are there to listen and understand what happened, not to conduct some kind of “gotcha” interview. “While we have a a set of questions we need to cover, we want the employee to have the opportunity to tell us their side of the story. At the end of every meeting we conduct, we ask the same question every time: Is there anything additional you'd like to say before we end the meeting? I like that question at the end because sometimes the employee has something else they want to tell us that didn't necessarily fit neatly into the questions we asked, but it also closes them off from later claiming that they didn't get a chance to talk during our meeting, which which we don't want.”

Once they’ve completed the meeting and heard the employee's story and version of events, they have to make a disciplinary recommendation. He said they make sure to apply a consistent decision-making framework to the facts of each case, and they start with their disciplinary guidelines that have three starting buckets: a lower-level accidental conduct, more serious or intentional conduct, and the most serious involving personal gain or maybe malicious intent or serious disregard for patient privacy. 

“They help promote consistency, but they don't dictate the outcome of a particular case,” he said. “We also have to look at precedent, how we've handled similar cases in the past, and then we consider the specific circumstances of the case in front of us. That is really important because two cases can look similar on the surface, but when you learn more about what actually happened, there can be different wrinkles or factual nuances that could affect our recommendation.”

Then they share their recommendations with HR, which implements the final action. 

Nocito noted that throughout the process, they have to remember the people involved — the patient, the employee, and all their colleagues who help them get it right. “That's really what this is about: using the technology well, having a disciplined process, and treating the people involved with respect.”

Read Entire Article

         

        

Start the new Vibrations with a Medbed Franchise today!  

Protect your whole family with Quantum Orgo-Life® devices

  Advertising by Adpathway