Full transcript
0:05Okay, let's discuss a real scenario.
0:08Imagine you're finishing up a busy
0:10morning and quickly attach lab results
0:12to an email for a specialist.
0:15You hit send and immediately realize
0:18autocomplete sent them to the wrong
0:20provider.
0:22You just sent PHI somewhere it shouldn't
0:23be. If this ever happens, don't panic.
0:27Instead of trying to recall the email or
0:29delete evidence, take a deep breath,
0:33notify your supervisor, and document
0:35exactly what happened.
0:38Fast reporting ensures the privacy team
0:40can act quickly and correctly every day.
0:43As a medical assistant, you handle
0:45patient information, names, birthdays,
0:48diagnosis, insurance details. HIPPA
0:51calls this protected health information
0:53or PHI. A breach is when PHI is
0:56accessed, used, or disclosed in any way
0:59that isn't allowed by HIPPA and risks
1:02patient privacy. Let's look at a few
1:04examples. Opening a patient file out of
1:07curiosity. Emailing records to the wrong
1:09provider. Leaving a chart visible where
1:12unauthorized people can see it. Losing a
1:15USB drive or phone that contains PHI. As
1:18we've discussed previously, these
1:20breaches can have severe consequences
1:23both for medical professionals and the
1:25patients impacted.
1:27And we'll dig into these details even
1:29more in future videos.
1:32If someone who does not have permission
1:34can view or use patient information,
1:36even by accident, that's potentially a
1:39breach. Your role isn't to decide if
1:41it's officially a breach. Your role is
1:44to recognize when something feels wrong
1:46and speak up immediately.
1:49Acting quickly protects patients and
1:51protects you. So, you should always
1:54report an incident right away. When you
1:56start working at a new clinic, they will
1:58inform you if there are any specific
2:00steps you need to take. Step one, stop
2:03the exposure, close the chart, retrieve
2:06the paperwork, secure the screen.
2:09Whatever you can do immediately to limit
2:11access, do it.
2:13Step two, notify your supervisor or
2:16privacy officer. This is urgent. Do not
2:19wait until the end of day. Inform them
2:21that you think there may have been a
2:22breach, and provide them with all the
2:24details.
2:26Step three, document what you know.
2:28Include what happened, when it happened,
2:31whose information was involved, and who
2:33may have viewed it. Be honest and
2:36accurate. Step four, do not try to fix
2:40or hide anything on your own. Deleting
2:42emails, altering notes, or contacting
2:45the patient yourself is not allowed. The
2:48privacy team handles the investigation.
2:51Reporting isn't about blame. It's about
2:53protection. When you report fast, you
2:55maintain patient trust and keep your
2:57clinic compliant.