One of the most common privacy problems in care facilities is not a hacker. It is a coworker looking at a record they had no reason to open. A curious staff member checks on a neighbor who was admitted, a former employee still has a working login, or a role is granted broad access because it is easier than setting up the right permissions.
HIPAA addresses this in two connected ways. The Privacy Rule includes the minimum necessary standard, and the Security Rule requires access controls and audit controls. Together they say, in effect, that people should be able to see only the information they need for their job, and that you should be able to show who looked at what.
Under the Privacy Rule, when a covered entity uses or discloses protected health information, or requests it from another entity, it must make reasonable efforts to limit the information to the minimum necessary to accomplish the intended purpose. There are important exceptions. The standard does not apply to disclosures to a provider for treatment purposes, disclosures to the individual, or those required by law, among others.
For internal use, organizations must identify which workforce members need access to which categories of information, and make reasonable efforts to limit access accordingly. Reasonable is the key word. The standard is flexible, and it does not require a perfect system, but it does require thought and documentation.
The Security Rule's technical safeguards include, among others:
Unique user identification: every person has their own login.
Access control: technical policies allow access only to authorized people or software.
Audit controls: mechanisms record and examine activity in systems that contain electronic protected health information.
Automatic logoff: sessions end after inactivity, as an addressable specification.
Authentication: verifying that a person is who they claim to be.
The administrative safeguards also call for procedures covering authorization and supervision, workforce clearance, and termination of access when employment ends.
Start by listing the job roles in your organization and the information each truly needs. For example, a dietary aide may need to see allergies and diet orders but not diagnoses or billing details. A business office employee may need demographic and insurance data but not clinical notes. A nurse needs clinical details for the residents they care for.
Most EHR systems, including long-term care platforms, allow permission sets tied to roles. Build a small set of standard roles instead of customizing each person. When someone changes jobs, update their role rather than adding more permissions on top.
Employees who are also residents, family members of residents or neighbors may need extra monitoring or restrictions
Contract and agency staff should receive limited and time-bound accounts
Highly sensitive categories may deserve additional protections, depending on your policies and state law
Approve access in writing at hire, based on role
Review access when roles change
Disable accounts immediately at termination
Review all accounts, including vendor and service accounts, at least quarterly
Logging is only useful if someone looks at it. Decide what to review:
Access to records of residents not assigned to the user
Access outside normal working hours
Access by terminated or inactive accounts
High-volume record viewing
Access to records of employees or public figures
Many EHRs provide audit reports. Schedule time monthly or quarterly to review a sample, and investigate anything suspicious.
Staff should know that looking at a record without a work reason is a violation, even if they do not share what they see. Include it in training, have employees sign confidentiality acknowledgments and state the consequences clearly. Apply sanctions consistently, since the Security Rule requires a sanction policy.
Keep your role definitions, access request forms, review records and sanction policy. If a regulator or resident asks how you limit access, you will be able to show the process.
Broad default access for all clinical staff
Shared accounts at nursing stations
No periodic review of who has access
Delay in disabling former employees
Audit logs enabled but never examined
UnityCare IT can help you map roles, review EHR and network permissions, clean up stale accounts and set up a recurring access review so minimum necessary becomes a routine rather than a slogan.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034