Mobile EHR Access: Policy Points for Phones and Tablets

Mobile devices are increasingly part of care. A nurse can document at the bedside, a therapist can review a plan in a resident's room, and an on-call provider can look at a chart from home. The benefits are real. So are the risks: devices get lost, shared, left unlocked or loaded with unapproved apps. A clear mobile policy lets you gain the convenience without losing control.

Decide who owns the device

Organization-owned devices

Easiest to secure. You choose the settings, install what is needed and can wipe the device if it is lost. They cost more and need to be tracked.

Personal devices

Lower cost, but harder to control. If you allow them, you need a clear agreement about what the organization can do on the device and what staff must do to keep it secure. Many organizations restrict personal devices to limited access, such as using a browser or a managed app, rather than allowing local storage of clinical data.

Whatever you choose, state it in writing.

Policy points to cover

Access and authentication

Require a passcode or biometric lock and an automatic lock after a short idle period

Require multi-factor authentication for access to clinical systems

Prohibit sharing devices or credentials, and use individual accounts

Device security

Keep the operating system and apps updated

Prohibit jailbroken or rooted devices

Enable device encryption, which is typically on by default on current phones and tablets

Install only approved apps for clinical work

Management tools

Use mobile device management or a similar tool to enforce settings, separate work data from personal data and remotely wipe or lock a device. For personal devices, a managed work profile can limit the organization's reach to work data only, which also makes staff more comfortable.

Data storage

Do not store resident information locally on the device if the system can be accessed through an app or secure browser session

Prohibit saving or forwarding clinical information to personal email, cloud accounts or messaging apps

Address screenshots and photos. Taking photos of residents or screens with a personal phone is a frequent cause of privacy incidents. State what is allowed, if anything, and where images must go.

Messaging and communication

If clinicians text each other, specify which approved secure messaging tool to use. Ordinary text messages and consumer chat apps are generally not appropriate for protected health information.

Network use

Staff should use the organization's secured wireless on site and avoid public wifi for clinical access unless protected by an approved secure connection.

Lost or stolen devices

Staff must report a lost device immediately, at any hour, to a named contact. Provide the phone number. The organization should be able to lock or wipe the device quickly, and the incident should be documented and reviewed under your breach procedures.

Leaving the organization

Define how access ends and how work data is removed from a personal device when employment ends.

Physical handling

Staff should not leave devices unattended on carts, in hallways or in cars. Screens should not be visible to residents' visitors.

Make the policy usable

A policy that is too restrictive will be bypassed. Involve nurses and therapists when drafting it, and test the login and documentation flow on actual devices during a shift. Keep it to a few pages written in plain language, and have staff acknowledge it at hire and annually.

Train and audit

Walk through the rules in a short session, with examples such as what to do if a family member asks to see a screen. Periodically check which devices are enrolled, which are out of date and who has access.

HIPAA considerations

The HIPAA Security Rule expects safeguards for electronic protected health information on all devices, including mobile ones. Your risk analysis should cover mobile use, and your policy and training help show that you addressed it.

How UnityCare IT can help

UnityCare IT can help you choose a device approach, set up management and multi-factor authentication, and draft a mobile policy that your clinical staff will actually follow.

Related service

Keeping PointClickCare and other EHR systems fast, connected and available.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172