Privacy Options in Profile
4 min
privacy options in profile keep track of a user’s permissions based on the configuration settings and any additional settings applied via macro this means that system administrators have a high level of control over what gets displayed to which user available options are 1\ role actions is the first line of defense in profile for privacy and should be the basis of your access model set roles to allow users to see the toolbars, views, actions and the parts of the medical record they should see configure different settings for users at different places of service (pos) 2\ notable person let's you 'flag' the patients who are notable figures e g actors, vips, etc available as a preference on a patient’s record usable in conjunction with other privacy settings; used on its own it will not trigger any actions ensures that users of the emr are not viewing the patient’s information without a valid reason 3\ privacy alert lets the user who is opening the medical record know that there is data that they cannot see helps keep duplicate information from being created use with caution because even the flag indicating there is information the clinician cannot see may be a privacy problem, depending on the type of data 4\ grants and exclusions blocks access to a specific patient record by a specific individual – for instance, a relative or friend of the patient protect the record of a staff member from other staff working at a particular clinic using access macro and a supplementary role also lets you set up grants and exclusions; base decisions on “works at” roles or place of service (pos) membership 5\ anonymized lists allows anonymization of patient information in medical condition lists (incidence, prevalence, clinical quality indicators, care plan analysis) note if you are an enterprise customer, these lists are not fully pos aware; these lists will not work effectively for you 6\ break glass is a fast way to access restricted emr information by someone who does not regularly have access to the information useful when an emergency situation or when there's a need to access patient information from a different place of service (pos) use of break glass must be monitored as it as enables extra audit attributes in addition to the standard auditing of all access and changes 7\ cases let users manage one part of the clinical record separately from the longitudinal health record use explicit privacy settings to manage the case's privacy settings entirely independently of the rest of the patient’s health record apply privacy settings via configuration options in the user interface, and macros for more sophisticated rules watch out for any clinical risk or additional administrative overhead from using cases 8\ access rights allow organizations to set access rights to data for a specific clinic e g a clinic can see, but not edit / delete existing records, or create new records assign based upon the user roles or by membership in an access provider group extension of the data types that may have create / read / write / delete access rights assigned is being considered 9\ access provider groups provide a more nuanced and ad hoc management of user rights that can be achieved by roles profile has several provider group types including for data access rights 10\ problem/patient privacy is the second privacy field in the problem window patients can indicate how their information is to be used and shared use with patient access via accession to manage information in the problems view; diagnosis, procedure, social/risk, adverse reaction, administrative using this feature without the patient who sees the problem can result in a loss of information when the patient is transferred to another provider note we recommend creating a comprehensive emr privacy strategy before enabling any of these options