Medical professionals improperly share patient info
Ben-Gurion University of the Negev News Oct 04, 2017
Strict regulations for keeping confidential data secure often make it difficult for caregivers to get the information they need. As a result, a majority of medical staff surveyed have accessed an electronic medical record (EMR) system using a password improperly supplied by a fellow medical staffer.
Published in the journal Healthcare Informatics Research, the article titled, ÂPrevalence of Sharing Access Credentials in Electronic Medical Records, is the first study to examine EMR access among medical providers.
In the study, researchers gathered survey responses from 299 medical professionals, including residents, medical students, interns, and nurses. The research team included researchers from Ben-Gurion University of the Negev (BGU), Harvard Medical School, Duke University, Hadassah-Hebrew University Medical Center, and the Interdisciplinary Center in Herzliya, Israel.
Nearly three-quarters (73 percent) of the 299 participants claimed to have used another medical staff memberÂs password to access an EMR at work. More than 57 percent of participants (171 out of 299) estimated they have used someone elseÂs password an average of 4.75 times.
Of the medical residents, all (100 percent) say they had at one time obtained another medical staff memberÂs password with their consent. Within the student and intern groups, 77 percent and 83 percent (respectively) used someone elseÂs access credentials because they said they Âwere not given a user account.Â
Similarly, 56 percent of students and almost 70 percent of interns cited that their user access had inadequate permissions Âto fulfill my duties so they had to ask for someone elseÂs access credentials. Only half of the nurses surveyed (57.5 percent) reported using someone elseÂs password.
ÂThe strength of an information security system is determined by the strength of its weakest link, said researcher Dr. Florina Uzefovsky, an associate professor of developmental psychology at BGU and member of its Zlotowski Center for Neuroscience. ÂEven a single breach may render an information system ineffective.Â
Breaching patient privacy  which is protected under the strict Health Insurance Portability and Accountability Act (HIPAA) rules in the United States and International Standards Organization (ISO) criteria in Israel and other countries  can result in large fines if reported. In addition, an EMR system attack could seriously disrupt healthcare operations and cause direct injury to patients, such as with the manipulation of a prescription or medical device.
Consequently, HIPAA requires healthcare organizations to establish and enforce comprehensive security policies, which include clear definitions of each workerÂs role and access privileges. Organizations must also supply a way to authenticate the identity of each worker, control his or her access to relevant data and audit editing.
ÂMedical staff must provide timely and efficient care while maintaining patient confidentiality, said the primary investigator, Dr. Ayal Hassidim, at Hadassah-Hebrew University Medical Center. ÂThis may sometimes cause conflict between their duty and their obligation to meet security regulations.Â
The researchers offer a number of recommendations. First, attaining access credentials needs to be less difficult and time-consuming. For example, in Israel  where junior staff turnover clinical rotations weekly  medical school students, interns, and other new employees often resort to using another employeeÂs credentials to fulfill their duties while going through the strict, lengthy registration process.
The researchers recommend that understaffed hospitals, especially during on-call hours, may need to delegate administrative tasks and extend EMR system access to para-medical, junior staff, interns, and students. Nurses, who generally carry out more precisely defined duties, are more likely to have the EMR privileges they need. A
Go to Original
Published in the journal Healthcare Informatics Research, the article titled, ÂPrevalence of Sharing Access Credentials in Electronic Medical Records, is the first study to examine EMR access among medical providers.
In the study, researchers gathered survey responses from 299 medical professionals, including residents, medical students, interns, and nurses. The research team included researchers from Ben-Gurion University of the Negev (BGU), Harvard Medical School, Duke University, Hadassah-Hebrew University Medical Center, and the Interdisciplinary Center in Herzliya, Israel.
Nearly three-quarters (73 percent) of the 299 participants claimed to have used another medical staff memberÂs password to access an EMR at work. More than 57 percent of participants (171 out of 299) estimated they have used someone elseÂs password an average of 4.75 times.
Of the medical residents, all (100 percent) say they had at one time obtained another medical staff memberÂs password with their consent. Within the student and intern groups, 77 percent and 83 percent (respectively) used someone elseÂs access credentials because they said they Âwere not given a user account.Â
Similarly, 56 percent of students and almost 70 percent of interns cited that their user access had inadequate permissions Âto fulfill my duties so they had to ask for someone elseÂs access credentials. Only half of the nurses surveyed (57.5 percent) reported using someone elseÂs password.
ÂThe strength of an information security system is determined by the strength of its weakest link, said researcher Dr. Florina Uzefovsky, an associate professor of developmental psychology at BGU and member of its Zlotowski Center for Neuroscience. ÂEven a single breach may render an information system ineffective.Â
Breaching patient privacy  which is protected under the strict Health Insurance Portability and Accountability Act (HIPAA) rules in the United States and International Standards Organization (ISO) criteria in Israel and other countries  can result in large fines if reported. In addition, an EMR system attack could seriously disrupt healthcare operations and cause direct injury to patients, such as with the manipulation of a prescription or medical device.
Consequently, HIPAA requires healthcare organizations to establish and enforce comprehensive security policies, which include clear definitions of each workerÂs role and access privileges. Organizations must also supply a way to authenticate the identity of each worker, control his or her access to relevant data and audit editing.
ÂMedical staff must provide timely and efficient care while maintaining patient confidentiality, said the primary investigator, Dr. Ayal Hassidim, at Hadassah-Hebrew University Medical Center. ÂThis may sometimes cause conflict between their duty and their obligation to meet security regulations.Â
The researchers offer a number of recommendations. First, attaining access credentials needs to be less difficult and time-consuming. For example, in Israel  where junior staff turnover clinical rotations weekly  medical school students, interns, and other new employees often resort to using another employeeÂs credentials to fulfill their duties while going through the strict, lengthy registration process.
The researchers recommend that understaffed hospitals, especially during on-call hours, may need to delegate administrative tasks and extend EMR system access to para-medical, junior staff, interns, and students. Nurses, who generally carry out more precisely defined duties, are more likely to have the EMR privileges they need. A
Only Doctors with an M3 India account can read this article. Sign up for free or login with your existing account.
4 reasons why Doctors love M3 India
-
Exclusive Write-ups & Webinars by KOLs
-
Daily Quiz by specialty
-
Paid Market Research Surveys
-
Case discussions, News & Journals' summaries