HIPAA Summit West: 1 in 4 Organizations Report Data Breaches
In many organizations, the compliance officers have been given the role of privacy officer, but Patrick maintains that they're different roles with different regulations.
"I don't advocate that the compliance officer also be the privacy officer," Patrick told the audience, though she does recognize many smaller facilities must do so.
What suffers when privacy and security officers are doing too many things? Policies and procedures that don't get updated or delivered and staff members who are not properly educated on them.
In some cases, such as the case of the Pittsburgh Pirates and social media, they were never written.
Angel Hoffman, RN, MSN, corporate quality/compliance officer, Kane Regional Medical Centers and principal, Advanced Partners in Health Care Compliance in Pittsburgh, told the audience about Major League Baseball's Pittsburgh Pirates, which fired an employee for inappropriate Facebook posts about the organization.
But since the Pirates did not have a policy for social media use, it had to rehire the employee.
Hoffman said organizations must have a sanctions policy for enforcement.
Remind employees that when something's written, it never goes away, Hoffman said. Organizations cannot ban social media use among its employees, but they must have a policy for it and educate employees on the consequences of inappropriate posts.
- Don't Underestimate Emotional Intelligence
- Two-Midnight Rule Must be Fixed or Replaced, Say Providers
- The Secret to Physician Engagement? It's Not Better Pay
- Yale New Haven Health Partners with Tenet Healthcare in CT
- Care Coordination Tough to Define, Measure
- Size Matters in Antibiotic Overuse
- CDC Warns of Antibiotic Overuse in Hospitals
- 4 Reasons PCMH Principles Aren't Going Away
- Physicians Take SGR Repeal Message to Washington
- SCOTUS Review of NC Board Case 'A Very Big Deal' to Providers