HIPPA violation or not? Need opinions

This forum made possible through the generous support of SDN members, donors, and sponsors. Thank you.
Get help with your application

Use all the free resources available to you from SDN: articles, guides, expert advising, forums discussions, and school research.

Spurrierliveson

New Member
7+ Year Member
Advertisement - Members don't see this ad
Hi guys. This situation is basically about a grey-area HIPPA violation I supposedly committed at my recent acute care rotation. The situation got me into some hot water, so I am petitioning some of the details about my performance to a committee soon. I want to know if this situation can be classified as HIPPA violation.

I was having a lot of trouble working up patient cases by hand at the hospital the first few days because i write pretty slow and my notes are very unorganized. I type much faster than I write and organize faster and more efficiently, making follow up visits and workups a lot easier. One afternoon I decided to type up my patient reports on my laptop for the first time. I was planning on putting the file on a flash drive to use to print the patient case on paper with the hospitals printer after finishing the initial case workup. Afterwards, I would destroy the patients file off my laptop, flash drive and the hospital computer to avoid exposing HIPPA. And of course, I was going to leave the hardcopy printed at the hospital, with no PHI, to use when I did workups the next day, but with pencil from then on because the follow up information needed in each daily review requires much less information (no complete baseline vitals, labs, meds, disease states, DDR, HX, etc.) I included PHI originally in the laptop document to help identify which patients went with which documents, with the intention to remove the PHI before transferring to the other computer to print. My preceptor came in one afternoon and saw me working up the patient and saw the PHI on the file and immediately scolded me for breaching HIPPA law and that i was never to have any patient medical record information saved on my computer, and to start again on paper. She didnt give me a chance to explain what my intentions were after finishing each workup that day. Her statement in my post rotation report basically states that she walked in and saw me typing a patient workup on my laptop with PHI involved, an obvious HIPPA violation.

So in the petition I want to know if my intentions stated above about my laptop workup process actually violated any HIPPA laws. I believe she assumed I was typing ALL of my workups on my laptop, with the PHI that wasn't going to be removed, including daily follow up notes; and that I was saving the information and taking it home with me (which I am aware IS a HIPPA violation, and of course not what I was doing).

Am I at fault?
Is it her word versus mine?
 
Did you type anything in the report that can be use to identify the patient like his full name, dob, address, social security number?
 
Advertisement - Members don't see this ad
Anyway, I highly doubt you were using an HHS guidance compliant encrypted set-up, and you do know simply dragging a file to the trash can does not actually render the file unsearchable/unusable, right?

This is dumb. You should have NEVER keyed in identifying information into your personal computer, much less MENTION the word "copy to flash drive" and "PHI" in the same sentence. Dumb dumb DUMB.

This is a nightmare scenario for any preceptor because of the extensive liability involved. I nearly failed a student for doing the exact same thing you did, not because I wanted to be an dingus, but because our department chairs (a physician + their student) FOUND the damn flash drive in the medical library, opened it up, and found SCREENSHOTS of patient charts...then took it to me.

You're definitely at fault. Doesn't matter what your intentions were - thank your preceptor for not letting you continue being a walking lawsuit, fine, and piss poor liability for your school and hospital waiting to happen.

Pretty sure these people didn't intend for these laptops to even leave the hospital.
 
HIPAA isn't violated until PHI is exposed to someone who is not involved in that patient's care. You probably violated some policies, but not HIPAA. You need to know more about what is being alleged.
 
For this very reason all our students are provided access to our shared drive and each has their own personal private files that meet encryption requirements. They can only use personal computers to work on presentations that do not contain identifiable information. After they leave for the month - their drive is wiped clean. 1. You should never put patient identifiable info on a flash drive - dumb dumb dumb. 2. Always ask the sites policies on IT use. It would save you a lot of time and hassle.
 
I included PHI originally in the laptop document to help identify which patients went with which documents, with the intention to remove the PHI before transferring to the other computer to print.

Typical copy-paste mentality and probably using the "Guest" wi-fi too.

Lucky your preceptor passed you and didn't slide your laptop through the PHI disintegration bin slot.
 
I usually don't defend students when they do stupid things, but I wonder if the school and/or hospital gave him the proper education on things such as this? All new employees have to take exams that show they understand?
 
I usually don't defend students when they do stupid things, but I wonder if the school and/or hospital gave him the proper education on things such as this? All new employees have to take exams that show they understand?

You can't teach common sense
 
It's a big no-no to have patient information on any unsecured device. It's also usually a breech of a hospital's policy regarding PHI. Did they orient you on their HIPAA policies or use of PHI? Most places I've been at have had me take online orientation courses or sign documents regarding PHI policies, with nearly all forbidding the use of personal electronics to store PHI. I'd have to use the computers at their facility and not bring printed documents home to work on.

When it comes to anything with a patient's name or data on it I'd always ask first if it's ok to do something innovative with your work-style or using your personal electronics to work. I think the preceptor was right to scold you, but I also think as a practice site taking students they should have discussed how they handle PHI. I'd say you're both in the wrong, but common sense should also say to not store such things on a personal computer. The issue isn't whether or not you delete it afterwards, it's that it's on an unsecured device outside of the hospital network and they have liability with that.
 
It sounds like what you did is a HIPAA violation. But I think if you would have FULLY de-identified the patient by NEVER keying in their name, room number, or anything that could possibly be used to identify them into your computer, you would have an argument. I thought having labs, med list, notes etc copied down without ever mentioning any identifying information was completely fine. Can someone please correct me if I am wrong?
 
Advertisement - Members don't see this ad
It's a policy violation, with the potential for a HIPAA breach, but most likely that didn't occur. It's an easy mistake to make, since you are using the computers on rotation, you assume that it's okay to use any computer. I don't think I was ever explicitly told not to do that, and I will admit that while on rotation I emailed myself some of my SOAP notes to finish up at home. Thankfully I never put anything identifiable, but I can see the argument that even doing that could be an issue.

Case reports that are fully de-identified are okay, you see them published in journals and the like all the time. It gets a little tougher when you're in a specific institution, on a specific unit, dealing with a specific case. Now it's not just an anonymous patient, because when you do a report about a "patient with double lung transplant and atypical mycobacterial pneumonia" everybody knows exactly who that patient is.
 
I agree with you that documents containing PHI should generally never be brought home (though my hospital policies during rotations allowed it as long as they were contained within locked containers). But I don't know what you mean by "secured devices"...The majority of hospitals that I know of allow pharmacists and residents to access the hospital system from home, particularly during overnight on-call, to accomplish most things. Hell, all the doctors and residents were using personal ipads/devices to check on their patients. Granted, it's usually by remote desktop access that requires login. Personally, I don't see a problem with using a personal computer as many of the other posters do if used in this scenario, but it seems like you didn't.
 
I agree with you that documents containing PHI should generally never be brought home (though my hospital policies during rotations allowed it as long as they were contained within locked containers). But I don't know what you mean by "secured devices"...The majority of hospitals that I know of allow pharmacists and residents to access the hospital system from home, particularly during overnight on-call, to accomplish most things. Hell, all the doctors and residents were using personal ipads/devices to check on their patients. Granted, it's usually by remote desktop access that requires login. Personally, I don't see a problem with using a personal computer as many of the other posters do if used in this scenario, but it seems like you didn't.

My remote access is secured by VPN and all my mobile devices are tied to IT with remote wipe capability and minimum security requirements in place.

It might look like I'm casually just looking at a chart but there's some very very powerful encryption behind all of it.
 
OP, yes, what you did is completely wrong. I agree with the others who question if you were properly trained. Obviously, you weren't intending to violate Hipaa and you aren't a computer major, so you can't be expected to already know what is considered secure and what isn't. Your preceptor and or the orientation teacher should have made it clear that flash drives and personal computers can not be used to store patient information. As Confetti pointed out, if you did see someone else using a personal computer, it would be because they are going through VPN and/or have other encrypted security systems in place on their computer. Your best bet it to plead ignorance, because you were clearly wrong, but it sounds like your preceptor/orientation teacher failed you by not teaching you this (now if you did know this, but ignored it thinking it didn't matter, then you deserve the bad report.)
 
... thousands of dollars of secure tech which can easily be circumvented by hitting "prnt scrn". That's what cracks me up against encryption technology XD

Why not take a picture of the computer screen?

All tech can be defeated because the eventual output is analog. The primary security in place defends against mass data theft and decryption, not the actual end user creating an analog version.

I can hit print anytime I want, mass produce the results, and drop them from an airplane. I can call you and gossip about patient X. Encryption doesn't prevent that, the legal and financial penalties dissuade me from doing that.
 
Anyway, I highly doubt you were using an HHS guidance compliant encrypted set-up, and you do know simply dragging a file to the trash can does not actually render the file unsearchable/unusable, right?

This is dumb. You should have NEVER keyed in identifying information into your personal computer, much less MENTION the word "copy to flash drive" and "PHI" in the same sentence. Dumb dumb DUMB.

This is a nightmare scenario for any preceptor because of the extensive liability involved. I nearly failed a student for doing the exact same thing you did, not because I wanted to be an dingus, but because our department chairs (a physician + their student) FOUND the damn flash drive in the medical library, opened it up, and found SCREENSHOTS of patient charts...then took it to me.

You're definitely at fault. Doesn't matter what your intentions were - thank your preceptor for not letting you continue being a walking lawsuit, fine, and piss poor liability for your school and hospital waiting to happen.

Pretty sure these people didn't intend for these laptops to even leave the hospital.

What happened to your student???
 
What happened to your student???

I chewed them out in a back room/office for about 10 minutes and made them almost cry, and sent them home early.

I reviewed our student training manuals and presentations and our only line addressing HIPAA was a blurb about privacy and did not address electronic storage specifically.

We found a way to hook students into the corporate/systemwide HIPAA modules required of medical staff and we added more specific instruction in our material.

Student passed rotation, partly because the USB drive never left the premises (still a problem), but mostly it was unintentional and our training wasn't crystal clear.
 
This would be a violation of my hospital's policy which would potentially lead to termination if you were an employee. We train our students about what is right and wrong with regards to PHI during their computer training.
 
We train our students about what is right and wrong with regards to PHI during their computer training.

We consciously do this now in our face-to-face + online module w/ test...I missed this in my other reply, but the part about electronic storage was buried deep in a multipage document about HIPAA that was further buried in another stack of orientation documents. Technically the students got notice, but it was not very effective.
 
We consciously do this now in our face-to-face + online module w/ test...I missed this in my other reply, but the part about electronic storage was buried deep in a multipage document about HIPAA that was further buried in another stack of orientation documents. Technically the students got notice, but it was not very effective.

My hospital basically has a zero tolerance policy with these things. We were able to take some of the online training materials for employees and use them for students. This is one we always include. It seems to work as one of my recent students was telling me he was coming in early to work on his case presentation, since he wasn't allowed to save any of the information and work on it at home.

To the OP, I don't think what you did had any malicious intentions, but you were in the wrong. It also seems like you knew you were not supposed to save any materials on your computer or flash drive while you were doing it. Despite what your intentions were, if you were an employee, you could have been fired. Take this as a lesson learned as it looks like the preceptor gave you a break. An employer may not be so nice in the future. These rules get more and more strict.