Tech & Innovation in Healthcare

Reader Questions:

Employ HIPAA Security on Your Staff’s Mobile Devices

Question: Do you have some tips on securing our mobile phones while complying with HIPAA requirements, and shielding our patients’ ePHI in our practice?

North Dakota Subscriber

Answer: Certainly! Here are three tips geared toward protecting your patients’ electronic protected health information (ePHI) when using mobile devices.

Tip 1: Instruct your IT or cybersecurity team to outline what mobile devices will be used in your organization, and which person or people will be using them. If multiple people will share devices, like using a tablet to check in patients or confirm appointments, your IT team will need to set up individual logins and passwords.

At the same time, some staff members may choose to use their personal devices for work. If that is the case, your management needs to establish parameters regarding employees using their own devices. The HHS Office of the National Coordinator for Health Information Technology (ONC) suggests establishing “centralized security management” with configuration requirements and “setting policy for individual users or a class of users.”

Tip 2: Master the art of multifactor authentication (MFA). Implementing multifactor authentication with password protocols augments your existing defenses by adding another layer of protection. This extra layer is typically information that only the user could provide, such as a key texted to your mobile phone or a fingerprint.

Tip 3: Encrypt your data and devices. When data and devices are encrypted, your patients’ data and ePHI are protected, as well as any information stored and shared on the mobile device.