Describe concepts of privacy and security as applied to the EHR.

Description should include discussion of

  • user passwords
  • physical security of systems (e.g., encryption)
  • risk management
  • authentication and authorization
  • regulatory frameworks
    • Office of the General Counsel (OGC)
    • Office for Civil Rights (OCR)
    • Office of the National Coordinator for Health Information Technology (ONC)

  • biometrics.

Teacher Resource: Security Risk Assessment Videos (https://www.healthit.gov/topic/privacy-security-and-hipaa/security-risk-assessment-videos Links to an external site.), HealthIT.gov

Process/Skill Questions:

  • What are some of the privacy concerns for the EHR?
  • What are some of the mechanisms used to determine identification of individuals?
  • Which regulatory bodies (federal and/or state) are responsible for the privacy and security of the EHR?
  • What is biometrics, and how is it used?