No open shelves in a patient or research subject area.
Hipaa storage of paper medical records.
In 2012 there were more breaches involving medical records on paper covered by hipaa than electronic records 45 from mid may to mid june.
Medical records and phi must be stored where there is controlled access we recommend that medical records and phi stored in hallways that are accessible by unauthorized individuals should be in locked cabinets.
The hipaa guidelines for medical records do not exclusively apply to medical records that are created stored or transmitted electronically.
Set up security protections against the risks discovered.
Your emr may not take up the physical office space that your paper records once did but the demand for storage space for these files will only grow.
Assess risks to the data potential results of related attacks and how likely they are to occur.
Physical safeguards are defined in the hipaa security series as physical measures policies and procedures to protect a covered entity s systems and related building and equipment from natural and environmental hazards and unauthorized intrusion.
Here is how you move forward.
Hacking information doesn t just happen to digital information.
Record the security steps that are taken and why they were taken as relevant.
Do you manage your backups internally or is it time to consider looking outside your practice for hipaa compliant backup storage.
In order to maintain hipaa compliance with your paper record storage you need to think about physical safeguards.
All hipaa compliant storage should be assessed for any risks on a regular basis.
What to do about electronic storage.
No open shelves in a hallway that allows access to individuals not authorized to access those medical records and phi.
Paper records and electronic records need to be treated the same don t forget about the paper.
They can physically store your records at a protected location retrieve files for you and scan all or some of your files when you need them.