Privacy Management
21 min
privacy management has been implemented in profile, which includes new audit reports to record privacy and access actions on a medical record preferences must be enabled, and role actions must be granted in order to make these reports available preferences in order to populate the necessary information in privacy management and the privacy audit reports, the extended logging preferences must be enabled in organization/preferences/global security preferences/emr & case audit panel note extended logging may affect system performance this should be monitored please see ‘set global security preferences’ in the profile helpfile for more information in organization/preferences/patient/alerts , a secrecy warning alert can be set upon the event of opening a medical record this secrecy warning alert will display a message that there is data on the patient which cannot be viewed or that the patient record cannot be viewed when a patient encounter or record has been made private through the privacy management view note the apply to all users checkbox must be checked in order for everyone in the practice to see the secrecy warning and all other checked alerts role actions to grant the required role actions, go to organization/roles select the appropriate user role in the left panel of the roles window in the find field, enter the following role actions one at a time and press go at the end of the field\ privacy role actions role action description privacy\security monitor informs user by profile email message of each break glass session the message will show the initiator of the session, the time the session occurred, the patient involved, and the reason privacy management\allow break glass allows access to break glass in privacy management view privacy management\allow make private allows access to add, add record, update and revoke in the privacy management view privacy management\manage privacy allows access to set and view privacy rights which the user does not possess report role actions report\audit reports\current user status report report\audit reports\medical record audit report report\audit reports\private data access report\audit reports\same last name report\audit reports\user emr activity report\audit reports\user security audit to grant each role action, press grant in the actions toolbar press ok to save the changes and close the roles window reports go to report/audit reports to see available reports user security audit report this report is to view the item the specified user acted upon in people & places it allows searching by user and/or time frame the information displayed includes the date/time of the action, the user, and details, with extended details where necessary, such as whether a role was granted or revoked same last name accessed report this report generates the list of patients accessed by users who share the last name of the patient it allows searching by user and/or time frame the information displayed includes the date/time of the access, the user full name and the patient information id, full name, dob, and gender user emr activity report this report allows searching by date range, pos, user and patient the columns that are checked will display that information the user who accessed the data, the patient whose data was accessed, the patient filenum, the type of privacy record which was recorded against the patient (ex break glass, private encounter, private record, etc ), the action taken, and the date/time private data access report this report allows searching by date range, user, patient and privacy types the columns that are checked will display that information the user who accessed the data, the patient whose data was accessed, the patient filenum, the type of privacy record which was recorded against the patient (ex break glass, private encounter, private record, etc ), the date/time, the transaction id and the reason the user entered for break glass current user roles report this report generates a list of all current users who do not have inactive status, all the role groups which have been applied to those users and the last log in date of that user the role groups are listed in descending order, with the topmost role first medical record audit report this report displays the user who accessed the medical record, the point from which it was accessed, encounter records and their versions and letter records and their versions the report also displays whether any printing or exporting of the medical record was done and by whom and any changes to the encounter or medical record privacy and by whom privacy management view privacy in profile can now be managed through the control centre/manage/privacy management view the three required role actions are from the same list necessary to see the privacy audit reports privacy management\allow break glass privacy management\allow make private actions privacy management\manage privacy the toolbar contains the following icons icon description add encounter privacy for a patient add record privacy for a patient updates the privacy setting for the selected privacy record removes the selected privacy record grants access to the selected privacy record refreshes the list view of privacy records the list view contains the following columns item/column description icon single encounter entire record breakglass patient the patient whose encounter or record has been made private private to the user to whom the private encounter or record belongs private date the date the privacy record was added encounter date the date of the encounter that was made private breakglass the user who performed the break glass breakglass date the date the break glass was performed add encounter privacy press add on the privacy management toolbar this opens a select patient window once you search for and select a patient, press ok this opens the set as private window this shows the list of the patient’s contacts with their dates select a contact and select the appropriate private to role option from the dropdown menu and press ok to save the selections and close the window note the private to dropdown menu contains the list of all the privacy rights to which the user currently belongs ( people & places/roles/privacy rights panel) and the private to me option note encounters can still be made private in medical record/encounters and medical record/new encounter these will not be shown to users without access add record privacy press add record on the privacy management toolbar this opens a select patient window once you search for and select a patient, press ok this opens the set record as private window select the appropriate private to role option from the dropdown menu and press ok to save the selection and close the window this will set the patient’s record as private note the private to dropdown menu contains the list of all the privacy rights to which the user currently belongs ( people & places/roles/privacy rights panel) and the private to me option update a privacy record select a privacy record for a patient (encounter or record) and press update on the privacy management toolbar this opens the update \[patient] privacy window select the appropriate private to role option from the dropdown menu and press ok to save the selection and close the window note the private to dropdown menu contains the list of all the privacy rights to which the user currently belongs ( people & places/roles/privacy rights panel) and the private to me option revoke a privacy record select a privacy record for a patient (encounter or record) and press revoke on the privacy management toolbar this opens a dialog window press yes to remove the private to value from the selected privacy record the private to value will be blank break glass a privacy record select a privacy record for a patient (encounter or record) and press breakglass on the privacy management toolbar this opens a dialog window enter a reason for the break glass in the free text reason field, which is mandatory, and enter your profile password press ok to save the information and close the window the break glass will be performed on the selected privacy record privacy management filter the privacy management view can be filtered