E/M Coding Alert - 2013 Issue 8
Privacy: Would A HIPAA 'Kiosk' Help With Patient Record Requests?
Subscribe or sign in to view the full article.
Article Overview
This article discusses whether a dedicated computer or kiosk for patient record access could fit into a healthcare workflow. It focuses on HIPAA privacy and security considerations, including access control, physical safeguards, logoff practices, auditing, staff training, and legal compliance. The piece is aimed at practices evaluating patient-facing access to protected health information and the operational risks involved.
Why This Topic Matters
Healthcare organizations increasingly balance patient access expectations with privacy and security obligations. Understanding the operational issues around patient-access stations can help practices evaluate workflow changes without compromising protected health information.
Article Sections
-
Who’s Entitled To What?
Discusses the general scope of patient access to records and the decision points a practice must consider before making information available through a kiosk or portal.
-
Password Protection
Covers identity authentication and the importance of secure sign-in practices for patient-facing access to health information.
-
Physical Protection
Reviews environmental and workstation safeguards intended to limit unauthorized viewing or handling of patient information.
-
Logging Off
Addresses session-ending controls and user training to reduce the risk of unattended access to protected information.
-
The Bottom Line
Summarizes the operational oversight, auditing, training, and policy considerations involved in evaluating a patient-access information station.
What You Will Learn
- How a patient-access computer or kiosk may affect practice workflow
- What privacy and security concerns arise with patient-facing access to records
- Why authentication, screen privacy, and automatic logoff are important topics
- How auditing and staff training factor into patient access operations
- What broad compliance issues practices should review before implementation
Who Should Read This
- Medical practice administrators
- Compliance officers
- Health information management professionals
- Privacy and security staff
- Office managers
- Healthcare providers considering patient access tools
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com