AskReference
ApplicationIntermediate

What measures should healthcare organizations take to protect EPHI on mobile devices used offsite?

Healthcare organizations should require data encryption and VPN use for offsite EPHI transmission, keep only essential data on mobile devices, and use tracking or remote deletion tools in case of loss or theft. They should adopt policies covering remote use and device removal, restrict remote access to organization-configured computers, disallow administrator privileges, use sandboxed VPN sessions, and train users in safe remote computing practices.

Organizations must protect EPHI on mobile devices used offsite by combining technical, physical, and policy measures. Encryption should be required whenever EPHI is transmitted over unsecured networks or stored on a mobile device, and virtual private networks (VPNs) must be used to encrypt data sent over unsecured connections. Users should log into the VPN to reach the organization network, and only job-essential data should be kept on a mobile device; nonclinical information such as Social Security numbers should never be carried outside the secure network. Some organizations use thin clients that do not store secure data, though this may be impractical in areas without reliable network access. Agencies are responsible for implementing policies per HIPAA covering appropriate remote use, removal of devices from their usual location, and protection from loss or theft. Physical measures such as covering laptops left in cars and locking car doors can deter theft, and in the event of loss or theft, agencies should have clear procedures plus software for tracking devices and performing remote data deletion. The U.S. Department of Health and Human Services also recommends restricting remote access to organization-owned or configured computers, disallowing administrator privileges, setting restrictions in VPN and remote access policies, configuring the VPN to run in a sandbox or virtual environment, and educating users about safe remote computing. Inappropriate access or theft should be met with swift, public sanctions ranging from warning to termination or prosecution.

Key points

  • Require data encryption and VPN use for transmitting or transporting EPHI on mobile devices.
  • Limit mobile devices to only essential clinical data; avoid carrying nonclinical information such as Social Security numbers.
  • Implement HIPAA-required policies on remote use, device removal, and loss or theft protection.
  • Use physical precautions like covering laptops in cars and locking car doors during transport.
  • Use tracking software and remote data wipe capabilities to recover lost or stolen devices and prevent EPHI release.
  • Apply HHS remote access strategies: restrict to organization-configured devices, disallow administrator privileges, use sandboxed VPN sessions, and educate users.
  • Impose swift, public sanctions for inappropriate EPHI access or device theft.
Source:Nursing Informatics and the Foundation of Knowledge· Electronic Security· p. 623–640

Related questions

Cover of Nursing Informatics and the Foundation of Knowledge

Nursing Informatics and the Foundation of Knowledge

McGonigle, Dee; Mastrian, Kathleen; & Kathleen Mastrian

Fourth edition · Jones & Bartlett Learning

View this ebook