The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
#161 Cell Phones & HIPAA Violations in Dentistry
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Is using your personal cell phone for work-related tasks possibly a HIPAA violation? This week the Divas discuss the pros and cons of using a personal device for work and what you should do to be compliant.
- HealthIt: Managing Mobile Devices in Your Healthcare Organization: https://www.healthit.gov/sites/default/files/fact-sheet-managing-mobile-devices-in-your-health-care-organization.pdf
- HHS Mobile Device Checklist: https://www.hhs.gov/sites/default/files/hph-mobile-device-security-checklist-tlpclear.pdf
- OCR Cybersecurity Newsletter: https://www.hhs.gov/sites/default/files/october-2017-ocr-cybersecurity-newsletter.pdf
Welcome!
SPEAKER_02I'm Leslie Cannon. I'm Mary Gavoni.
SPEAKER_03I'm Linda Harvey. I'm Olivia Juan, and together we are the Compliance Divas. Welcome to the Compliance Divas podcast. My name is Olivia Juan, and I'll be your moderator today. In today's episode, we're talking about cell phones and HIPAA compliance in dentistry and how this may result in HIPAA violations. We've noticed increased use of cell phones in dentistry, and there's definitely a potential for HIPAA violations. As the Compliance Divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please subscribe to the Compliance Divas podcast through your favorite podcast channel or visit our website at the ComplianceDivas.com. Any resources that we mentioned during the episode can be found on the website. You can also submit your questions to support at the ComplianceDivas.com. Please also give us a like. So the use of cell phones in dentistry can be very convenient and even productive, but dental offices must be aware that there is risk associated with increased usage of cell phones, especially when mobile devices are used to create, receive, maintain, or transmit protected health information. We have to keep in mind that we are regulated by HIPAA and must comply with HIPAA's privacy, security, and breach notification rules. And that even includes assessing our mobile devices, including cell phone usage. So we'd like to get the divas involved in some conversation about usage of cell phones in dental practices. And I'd love to start with our diva, Mary. Mary, can you talk to us a bit about why are dental offices even using cell phones in the first place in the dental office?
SPEAKER_02Mary. Thanks, Olivia. I think the number one reason that they're using them is convenience. It's quick, it's easy to scan a photo of a patient and send it to the dental lab. It's quick to send a text, perhaps, to another provider or to the patient. There are so many uses of texting and emailing and so forth on these mobile devices that it again just saves a lot of time and they may not have the capability to do some of those things from their workstation in the office, or they may not even be in the office. It may be from home. Someone calls the doctor in the evening and they maybe have a toothache. And in some cases, uh the doctors may ask the patient to take a picture of their tooth andor area of swelling or something and send it to the doctor. And that is not a HIPAA violation, but if the doctor saves that um image, which they most likely would on their cell phone, they now have protected and protected health information on their mobile device. So these are the kinds of issues that, as you said, if they're creating, um, sending, receiving, and um storing that information, then we have to make sure that those devices are secure. So the first thing that a practice needs to do is decide whether they're going to use mobile devices to access, receive, transmit, or store patients' health information. And if they do, they need to develop a policy for what kind of situations those will be used for, and understand what the risks are to the organization. Because if that cell phone or that mobile device was stolen or lost, and that information was accessible to someone who got was able to get into that phone, then that is a HIPAA violation that can have some pretty serious consequences to um to a practice. Most people use some type of security login to their mobile phone, uh face recognition or a password. But what we're finding more and more is that those can be broken in some cases. They can be hacked. Um, someone can get at that information that's stored. So I think a practice needs to really sit down and consider what all the risks are and decide if this is worth the convenience or do they need to use another method of communication.
SPEAKER_03That's great info, Mary. And obviously, this needs to be part of our HIPAA security risk assessment. So people are using cell phones. I know we're not comfortable with that. Anytime we see team members using their personal cell phones to communicate with patients, to us, it puts up that flag and there's risk. Because why is that not done through a practiced-owned device? Now, in our legal software, we can text right from within our practice management program, and it works beautifully because it's encrypted, it's part of the case notes, it's all together. But my understanding is with a lot of the practice management programs in dentistry, we don't have that as an option. So we really need to figure out, as you mentioned, will team members be using it and are they using their own devices? Because that certainly can elevate risk. Would you agree, Mary?
SPEAKER_02I would totally agree. Um, I cringe just as you said, every time I see the individual team members using their own devices, I always recommend that the practice have a dedicated device for using that if that's what they're going to do. And you're you're so right. And I think we may see that in the future, um, that the practice management software platforms will include the ability to send secure messages, um, texting, and so forth. But some of the other communication programs that people use for practices use for confirming appointments and so forth, do allow texting right from the computer, just like you described for your law practice. But because it involves another subscription, many times people are hesitant to use it. But there is that capability.
SPEAKER_03Right. But Mary, I like to remind people that the subscription fee is always cheaper than the violation and penalty in having to deal with it or having to pay a lawyer. Uh, so this last year I've represented several dentists in actions that involved HIPAA violations over uh cell phone use because of photos. So there's a lot of picture taking going on in dental offices, whether you know they're taking a shade, they're taking a picture of the before and after. Uh, but I want to remind people that full face photos are actually one of the 18 core identifiers. And so if we're compiling that information, it would have to be protected. So this is definitely an area that is wide open for potential HIPAA violations. So I'd love to interview Linda Harvey at this point and inquire of you about, you know, what kind of risk management strategy can we have in place? Whether people are using personal devices or they're prohibited to use personal devices and they have a practice-issued cell phone. But what are some things that dental offices can keep in mind, Linda?
SPEAKER_01Olivia, that's a good question. As I begin to address that, I first want to say that I agree with you and Mary. I think dental practices, the team members and the doctors are using their personal phones more than any of us are comfortable with. And they seem to be comfortable sitting in that gray zone, you know, kind of thinking they're not quite violating HIPAA, but not sure where they really sit. And they're quite comfortable in that gray zone. And that makes me uncomfortable because you never know what issue could arise. As you said, it's much cheaper to pay the cost of a subscription, it is a fine. And in addition to thinking about the full-faced photographs being an element of protected health information and covered under the federal law, there's another section in that same list of identifiers that addresses other comparable images, numbers, and codes, anything that we can assign to the patient. Even if we assign instead of Linda Harvey, now I'm now I'm code patient number 2795, that 2795 is a piece of protected information. So we're, and it seems vague, and I think the law is written so broadly to begin to address all the different areas that are evolved in technology. I don't know about you all, but I have some offices that have told me that some of the companies that they're working with have advised the office to take pictures with those new Apple phones because they have a better camera than the office camera does. So you're having folks advise them to be non-compliant in one sense. So, how do we address this? Well, you conduct the security risk analysis, as Mary mentioned, you determine how many phones are involved, what are the phones being used for, and then we have to determine what kind of strategies we can implement to keep the information private and secure. And we do that by following three specific safeguards, and these are part of the security role: the administrative safeguards, the physical safeguards, and the technical safeguards. The administrative safeguards are the policies and procedures that the doctor puts in place for the mobile devices and who can do what with their devices. And the physical safeguards, or what's the office going to require then if you're going to use your own device for work reasons? How do you keep that device secure? Is it got more than password protection? Is it simply got biometric identifiers? Does it have encrypted email? You know, does it have remote wipe? What are the software features that and hardware features that you want to have on this phone to manage the security? And you just think about it from everybody's personal perspective. What would you want to have on your personal cell phone if it was stolen or lost? So similar thought process in the practice. And then the technical safeguards are the encryptions and so forth that Mary and I have been mentioning. So once you identify the safeguards that you're going to use to mitigate the specific risk that are identified, then you develop the policy or document or protocol that puts in place what your organization's mobile device policies are going to be in order to safeguard the protected health information of all your patients. Do you have your patients, do you have your team members sign off on a mobile device management policy agreement? What kind of restrictions are you going to have them? And then how do you want the phones configured? Do you want your IT company to help them to manage the security on their phone, to take a look at the individual phones and find out what other devices, pardon me, what other software programs could be added for more security? So it's it's a comprehensive approach to security with HIPAA and trying to stay not so close to the gray zone or right close to the edge. And it always reminds me, like when you go to the Grand Canyon, you don't want to stand right at the edge. You know, you want to be back just a little bit to take in that view because the edge just leaves you too close to you know uh to something dangerous happening. And I'd much rather save all of our clients and listeners from the headaches of having a hip investigation with the Office of Civil Rights andor any fines. And Olivia, I'm aware of at least several medical professionals that have already been under the radar for texting. It just doesn't make big news headlines when you see things compared to a breach with ATT or change health care, for example. So back to you, Olivia.
SPEAKER_03And I know that we're so tired of hearing change healthcare, but this is a big to-do. So uh great valid points. And what folks may not realize is that a text could be sent to the wrong number, or maybe it's the wrong, a different family member that we're texting, not the correct patient. So there's so many things that could go wrong in using mobile devices. And you're right, Linda. In the medical world, doctors are texting so much because it's easy and convenient to communicate with their staff while they're at the hospital. Is that true, Linda?
SPEAKER_01It is entirely true. Working in the medical world myself, especially with ambulatory surgery centers, one of the benefits of quick communication is having your phone on you in the OR, the operating room of all places. Now, typically you don't find the surgeon texting, but you'll find that the um charge nurse might be the one who's got time to text us. She's checking on the cases or giving somebody up front an update on the cases. Um, so it's interesting to see, you know, how it's all playing out. And it's just important that we all take the safe road. And I want to tell you that oftentimes I'm asked by a doctor how they can successfully use a free app like WhatsApp, because WhatsApp is supposedly encrypted or secure, but it's not HIPAA compliant. And so they want me to show them how to be in the gray zone. I just I'm chuckling because it's not a comfortable place to be. You know, I don't want somebody to come back later and say, I got this breach or I got in trouble with the patient, and you told me how to do this. So there's an attachment there, but to be careful because um while those programs are great, have lots of value to them for certain things, there's no real good way to communicate with our team members about patients and us for using a HIPAA secure encrypted app with a HIPAA compliant program where you can get a business associate agreement with that group.
SPEAKER_03And we'll provide a list of potential vendors. And I think the big thing to look for is the words HIPAA compliant, where that is a built-in feature of the service. And Linda, you reminded me while you were talking about wearable technology. There have been several dentists that I've built HR policies for that wanted to address the issue of wearable technology that it's very distracting when an employee is looking at their wrist to read a text, could even send a text. Uh, there's so many options on uh Apple Watches and wearable technology that there's been a need to have to address it in the employer's handbook. And as uh Mary and Linda have already pointed out, people don't know this until they join our practices. So we need to educate them. And that leads us to our next diva, Leslie Cannon. Can you talk to us about conducting privacy and security awareness? Because how would people know when they join a practice that this is maybe not acceptable or permitted?
SPEAKER_00That's right, Olivia. Sometimes we don't know what we don't know until something arises, a breach or some other kind of infraction. So obviously, team member training and uh ongoing training for existing team, but new team members should be trained immediately, just like with bloodborne pathogens. They should have that HIPAA awareness for security and privacy. Uh, they should also be looking at the policies and procedures, which it dovetails into what Linda was saying about technical, physical, and administrative uh measures that we take to comply with HIPAA. And part of the administrative part is that important team training. There's a lot of threats that are posed to stored uh information on mobile devices, and sometimes they're lost or stolen. I know my own son had his uh cell phone stolen when he was at a dental meeting, not a dental meeting, but another type of convention similar to a dental meeting, he set his phone down for just a minute and it didn't take long for someone to walk off with that nice expensive Apple phone. So if something like that happens, is there a way if information is stored on a mobile device for it to be wiped remotely? And if there's policies in place that allow a team member to bring their own device, that's B Y O D, somewhere to BYOB, bring your own bottle, bring your own device, uh, then there's a chance that staff members could actually unleash some pretty nasty uh ransomware or other types of HIPAA type of software into their own cell phones that might compromise patient data. So employees should always be trained on the risk of viruses and malware that could affect and infect mobile devices. So just like any other computer type of software, they need to make sure that they are cautious and have always have awareness up. Um I know that many times we've heard in the past with other HIPAA consultants that we've talked to on a podcast with the company divas that you don't want to have data mining of your cell phones. And so if you're on your social media, you're uh playing a game or otherwise, sometimes that information allows that data to be mined for you, but also may even create a portal for information to be uh attacked so an external entity can get into your cell phone without knowledge, without your knowledge. So implementing policies and procedures regarding the use of mobile phones in the workplace, especially like Olivia said, when used to create, receive, or maintain or transmit electronic protected health information. So with that in mind, we also want to make sure that we look at other areas that we might be using cell phones if we are using personal cell phones and not an enterprise uh controlled cell phone, it's not a cell phone that the doctor has set up specifically for communication. Then there needs to be other uh security measures to reduce the risk of something happening. And the security measures might have to do with secure Wi-Fi connections and making sure that we uh keep what's on that cell phone out of view of other people. Uh again, uh reduce the risk posed by third-party apps and and then also securely storing that data on a mobile device. So, training includes how to securely use mobile devices when you talk about workforce training.
SPEAKER_03Great, great points, and so needed in a dental office so that new hires understand what the policies are that are in place and that there's ongoing training to issue these very important reminders. I was thinking about you know the facial recognition. I use that on my personal cell phone, and I was reviewing an article that face matching technology can be inaccurate, particularly with respect to women and minorities. And it made me chuckle because I remember my nieces, their sisters, and even though they're several years apart, one could open the other's cell phone because their faces look so similar. And so that might be what some people are relying on for some of the security. But I really want to emphasize how critical it is that if you are texting, you need to look at some of these apps for encryption to make sure that the messaging is secure and does not result in a violation. And all of the materials that we have referred to will be available in the show notes. Uh, is there anything else that the Divas want to share? Mary.
SPEAKER_02Thanks, Olivia. I have worked with several practices recently that use their cell phones to take um photographs, especially full face, because as you said, I think that they've been told that that, and we know that the cell phone cameras have such high quality. Um and they say, well, we as soon as we take them, we text them to the office email, and then we um delete them off our phone. But just doing one step of deleting a file off of a cell phone doesn't really delete it. You still have to then go in to um the deleted items folder, kind of like the recycle bin on your computer, and delete it off. So you can delete it from your photos, but it's not deleted off your phone. And that's a big deal if your phone is lost or stolen and that information is still there.
SPEAKER_03That's interesting. Leslie.
SPEAKER_00Well, I would like to share a couple of stories of what happens when uh workers have. A cell phone that is on and it may be inadvertently on when you're providing patient care. Now, for myself, I know that I accidentally butt dial and I do it frequently, and I don't know the rhyme or reason as to who it's calling. It seems at random, it just picks a phone number and it calls, and and I I my phone is calling someone and I'm totally unaware. So I'm talking and that other person is hearing my conversation. What happened in April of 2015? There was a patient in Ruston, Virginia who was had actually had her cell phone on, or pardon me, his cell phone on to record post-operative instructions given to him before he was put to sleep. And he forgot to turn his phone off during the procedure. And of his materials, his his uh clothes and everything else was in a bag under the gurney that he was on, where he was rolled from the pre-surgery to the surgery room to the recovery room. And when he played back his cell phone, he found that the gastroenterologist, the anesthesiologist, and the medical assistant had made very rude and derogatory comments about him. They were mocking him while he was on under general anesthesia. So the the um the uh anesthesiologist took the biggest hit. She made the most derogatory uh remarks, and there was a $500,000 lawsuit that the patient won as a result of that. And in Houston, Texas, there was a woman who recorded comments uh from hospital staff about her attitude as well as her weight when they worked on her during a 2015 operation. And the reason she had her cell phone or she had a device, it was probably not a cell phone because in this case it was uh woven into her hair extension. So it's some kind of an audio recording device. And uh after the surgery, sure enough, there was all these uh comments about her. Now, uh in playing that back to how that uh how that works with a cell phone, not only do cell phones have magnificent cameras, but they have extraordinary recording devices and they have microphones that can pick up conversations that you wouldn't think they would be able to hear. So I'd like dental offices to also keep in mind uh from a HIPAA and privacy and security standpoint, that if your team is wearing their cell phone on their body, that could possibly dial, like a butt dial, they don't know it, and that information is being sent out, uh, whatever conversations they're having with the patient.
SPEAKER_02Mary. That is such great information, Leslie. And the other thing to remember, especially with respect to like images, there's also all kinds of metadata that's linked to those images. So someone may say, Oh, you can't identify who that person is, but that metadata actually can be traced back to that healthcare provider or to that employee. So it's not as simple as we think it is.
SPEAKER_03So true, Mary. Linda, what are your thoughts?
SPEAKER_01Beautifully said, Mary. It's not as simple as we think it is. So I would just like to remind our listeners that we have need to have apps that are not only HIPAA compliant and state they're HIPAA compliant, as you mentioned, Olivia, but to be able to get that business associate agreement in place. Security, being secure and being HIPAA compliant are two entirely different things under the federal law with the comes with respect to following HIPAA privacy and security rules. And my favorite program right now is ORL, A-W-R-E-L. It's pronounced like Oral. It's a great little program, it's not very expensive. You can upload documents, you can invite other doctors there, other team members. So when you are sending encrypted information from one provider to another, which is required, it's mandatory, it's not optional, that you are able to invite them to this portal, if you like, and they don't see each other's patients' information, only what you send them, and that's one secure thread. And I like that in the fact that sometimes my clients will say, We try to send it encrypted to other offices and they complain. They say they can't open it, they have trouble, they just want to regulate us to send a regular email. And I tell them that we're not allowed to do that. So this is going to be a great um work. I'm gonna call it a workaround, but it's not. It's a compliant workaround because it's easier than some of the um email encryption programs. And I think it's safer than using Gmail. And Olivia, talking about safety, I want to share a story that I was made aware of several years ago. And Diva's you may have heard of it too. Just speaking of having your cell phone on you in a dental practice, there was a hygienist that had her cell phone in her scrub jacket pocket and it was on vibrate. So when it went off, somebody was calling her, it startled her and she lacerated her patient. I don't think it uh ended up into the kind of settlement that Leslie talked about, but still not a good place to be with patient safety overall. Great topic, Olivia. Thanks for bringing it up today. Sure.
SPEAKER_03And and I've been concerned about the geo mapping. So if a patient takes a picture, you know, trying to take a picture because they have a toothache and they send it over to the dental office, the geo mapping will show their address in that metadata that Mary was talking about. And then if that photo gets shared once they have it, and then the photo is shared beyond their office, now isn't this person's address, their their image of their face. So so many things can go wrong. So I agree, Linda. This was a great topic to share with our followers, and we hope that the information and research that we put together will save them time. You know, as the compliance divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please submit your questions to support at thecompliancedevas.com, and please look at the show notes for the resources that we discussed during this episode. Thanks again for tuning in.