HIPAA Summit West: 1 in 4 Organizations Report Data Breaches
In many organizations, the compliance officers have been given the role of privacy officer, but Patrick maintains that they're different roles with different regulations.
"I don't advocate that the compliance officer also be the privacy officer," Patrick told the audience, though she does recognize many smaller facilities must do so.
What suffers when privacy and security officers are doing too many things? Policies and procedures that don't get updated or delivered and staff members who are not properly educated on them.
In some cases, such as the case of the Pittsburgh Pirates and social media, they were never written.
Angel Hoffman, RN, MSN, corporate quality/compliance officer, Kane Regional Medical Centers and principal, Advanced Partners in Health Care Compliance in Pittsburgh, told the audience about Major League Baseball's Pittsburgh Pirates, which fired an employee for inappropriate Facebook posts about the organization.
But since the Pirates did not have a policy for social media use, it had to rehire the employee.
Hoffman said organizations must have a sanctions policy for enforcement.
Remind employees that when something's written, it never goes away, Hoffman said. Organizations cannot ban social media use among its employees, but they must have a policy for it and educate employees on the consequences of inappropriate posts.
- Ebola: Health Officials Try to Quell Front Line Fears
- Reducing Readmissions Starts with Better Collaboration
- Ebola: A New Normal in Dallas
- Partners HealthCare M&A Deal Under Scrutiny
- Readmissions: No Quick Fix to Costly Hospital Challenge
- How Educated Nurses Save Money
- 'Overtreatment' Debate Circles Back to Lung Cancer Screening
- As virus spreads, insurers exclude Ebola from new policies
- Defensive Medicine Still Prevalent Despite Tort Reform
- How Top-Ranked MA Plans Earn Their Stars