Verified Document

Lost Medical Records Are Process Errors That Term Paper

Lost medical records are process errors that can cause significant medical issues affecting patient privacy, care and safety. Furthermore, Federal laws mandate the secure creation, retention and use of medical records to ensure the highest quality of care, security and privacy for patients. Consequently, health care providers, often under severe budgetary limitations, struggle to comply with these legal, medical and ethical mandates. Research appears to show that medical records issues, including but not limited to lost medical records, can best be handled through exclusively electronic medical records, provided certain requirements are met. According to the Bureau of Primary Health Care, lost medical records constitute one of the common "process errors" that could cause medical issues such as incorrect diagnosis, delay in diagnosis and delay in treatment (BPHC Task Force on Patient Safety, January 2001, p. 19). Furthermore, using studies from Colorado, Utah and New York, the report estimates that 44,000 -- 98,000 hospitalized people die in the U.S. annually due to medical errors (BPHC Task Force on Patient Safety, January 2001, p. 5). Consequently, addressing those errors, here reduced to the loss of medical records, is a high priority for the U.S. Health Care System.

b. Medical Records in Summer Practice Setting

The Summer Practice Setting uses a hybrid of paper, electronic and microfiche medical records. Paper records are created and maintained "on the floor." Paper records are kept either readily available for immediate use or kept in a central location at the facility. Access to paper records is restricted and must be requested and signed out at that location. Paper records have reputedly been lost in the past. To compensate for those losses, data from the paper records is entered by medical personnel, including nurses, in coded areas on an electronic system. There is a backup system of electronic records in case the main system crashes; however, possibly due to budget constraints, the backup system appears to be an unreliable patchwork quilt and both the main electronic records system and backup system have reputedly "crashed" in the past, resulting in at least the temporary loss of medical information and, at times, entire medical records. In case the paper and electronic records are lost, microfiche backups of medical records are made and stored in double-locked storage areas in other locations. Access to microfiche records is severely restricted to the director of medical records and/or his/her representatives, and can be obtained upon request. In addition, if a medical record is lost, a new medical record must be created and it must be clearly designated as a replacement medical record. If the original medical record is found, the replacement record must be placed within the original medical record. In sum, the summer practice provider has 3 methods for dealing with lost medical records: if paper records are lost, the provider may rely on the electronic system; if the electronic system crashes, the provider may use the backup system; if all else fails, the provider may rely on microfiche records provided upon request. Full-time health care staff currently working at the facility does not recall a loss of microfiche records at any time. While great effort is obviously made to avoid the loss of medical records, the summer practice provider is obviously struggling with a hybrid system that does not seem well-coordinated and appears to create more administrative work for the health care providers.

c. Medical Records Plan

The proposed medical records plan would use an entirely electronic system brought to full compliance with HIPAA and the HITECH Act, with backups on reputable third party systems, with contractual requirements that the third party provider is bound by HIPAA and the HITECH Act, and with immediate retrieval-upon-electronic-request of lost medical records from the third party's server. Research shows that electronic medical records can provide the optimum system for handling medical records, including avoiding the loss of medical records and/or retrieving lost medical records. Axway, a provider of information technology for medical records systems, cites both HIPAA regulations and the HITECH Act as reasons for adopting electronic records (Axway, 2010, p. 1). Axway specifically cites HIPAA's enhanced mandate for confidential, secure medical information (U.S. Department of Health & Human Services, 2012). In addition, Axway explains the HITECH Act's requirement that health care providers strengthen security for Protected Health Information (PHI), and the Act's encouragement of electronic health/medical records (HER/EMR) (Practice Fusion, 2009), ideally to reduce healthcare costs and improve the quality of patient outcomes (Axway, 2010, p. 1). Consequently, the projected nurse practitioner's office would adopt an electronic medical records plan.

Even electronic medical records plans have proven problematic...

First, there are major potential security problems: Torrey points to the loss of patient records at the Veterans' Administration in 2006 to show that important patient data can be and has been lost (Torrey, Limitations of electronic patient record keeping: Privacy and security issues, 2009). Secondly, electronic medical records are often kept by third party computer servers and the third parties do not have the same HIPAA privacy restrictions that apply to health care providers; consequently, unless the third party is contractually bound to privacy, there are no laws restraining the third party from using the data as they wish (Torrey, Limitations of electronic patient record keeping: Privacy and security issues, 2009). Third, many EMR systems are "local," being tailored for a specific health care provider in a specific area of the country. This local nature of the EMR creates difficulties for patients who are injured or become ill away from their normal health care providers because their medical records cannot be accessed when they are most needed (Torrey, 2008). Fourth, there is a lack of standardization of electronic medical records across the country: EMR systems appear to be typically tailored for specific clients according to varying degrees of sophistication because there are few if any nationwide standards for EMR (Torrey, 2008). Due to all these potential problems, the health care provider must consciously take great care to ensure security, privacy, universality and standardization of its/his/her electronic medical records system.
Experts have suggested 5 steps, in no particular order of importance, which should be taken to ensure security, privacy, universality and standardization of electronic medical records systems, per HIPAA and the HITECH Act. First, the health care provider must secure all Protected Health Information (PHI) "in motion" through e-mail, file transfer, internal electronic data interchanges or external electronic data interchange (Axway, 2010). In order to fulfill this step, the health care provider must define, manage and enforce policies controlling information flow. Some EMI providers are offering "delivery-based policies" that automatically control information flow, including "who can interact with whom," and allowing the health care provider to block/quarantine an interaction; strip sensitive attachments from e-mails; return messages unanswered; notify managers; alter the information; reroute the information so it moves through secure and encrypted channels (Axway, 2010, pp. 1-2). Secondly, the health care provider must ensure the security of PHI "at rest" on the server by encryption technology that meets NIST 800-52 or FIPS 140-2 requirements to ensure the integrity of the data and its delivery. This will ensure that only authorized users may access the information, that the electronic medical record will not be lost, and that PHI is securely destroyed and/or retained (Axway, 2010, p. 2). Third, the electronic medical records system must detect and report breaches in the system, as §13402 of Title XIII HITECH/ARRA requires: "Following a breach of unsecured protected health information covered entities must provide notification of the breach to affected individuals, the Secretary, and, in certain circumstances, to the media. In addition, business associates must notify covered entities that a breach has occurred" (Practice Fusion, 2009). Consequently, electronic medical records must be constantly monitored throughout the system, their movements must be tracked and sufficient compatibility for transfer must be made with the systems of external providers (Axway, 2010, p. 2). Fourth, the electronic medical system must ensure that business associates are in compliance with HIPAA and the HITECH Act so there are no breaches of privacy or losses of medical information. Experts suggest building a "community" of electronic exchange for effective, efficient data exchange without breaches or loss (Axway, 2010, pp. 2-3). Finally, the electronic medical records plan should create a core competence for the exchange of information. The HITECH Act offers incentives for "meaningful use" of electronic data exchange for 90 consecutive days. Meaningful use consists of integrated, automated exchange of EHR/EMR between separate, independent information systems through: Managed File Transfer (MFT) that involves incorporating lab results into EMR/HER and ensuring the exchange of large files such as x-ray films with secure MFT; Electronic Data Interchange (EDI) in secure and efficient systems that can exchange large files quickly and easily so no data is lost; secure e-mail that is "security aware" and allows facilitated messages among health care providers (Axway, 2010) (Axway, 2010, p. 3).

3. Conclusion

The security of medical records is a daily issue with significant impacts on the privacy, security and treatment of patients. Consequently, providers struggle to maintain the security, privacy…

Sources used in this document:
Works Cited

Axway. (2010). The Hitech Act: 5 things you can do right now to pave the road to compliance. Phoenix, AZ: Axway.

BPHC Task Force on Patient Safety. (January 2001). Report of the BPHC Task Force on patient safety. Washington, D.C.: U.S. Department of Health and Human Services.

Practice Fusion. (2009, January 6). HITECH Act. Retrieved on June 16, 2012 from www.hipaasurvivalguide.com Web site: http://www.hipaasurvivalguide.com/hitech-act-text.php

Torrey, T. (2008, February 10). Limitations of elecronic patient record keeping: Lack of standardization. Retrieved on June 16, 2012 from patients.about.com Web site: http://patients.about.com/od/electronicpatientrecords/a/limit-standards.htm
Torrey, T. (2009, February 19). Limitations of electronic patient record keeping: Privacy and security issues. Retrieved on June 16, 2012 from patients.about.com Web site: http://patients.about.com/od/electronicpatientrecords/a/privacysecurity.htm
U.S. Department of Health & Human Services. (2012). Summary of the HIPAA Privacy Rule. Retrieved on June 16, 2012 from www.hhs.gov Web site: http://www.hhs.gov/ocr/privacy/hipaa/understanding/summary/index.html
Cite this Document:
Copy Bibliography Citation

Related Documents

Ruchi Tomar Advantages of Electronic Medical Records
Words: 3264 Length: 12 Document Type: Thesis

The issue of misplaced or lost patient files is also gotten rid of. These advantages aid in producing a marked rise in the health connected security of patients and the welfare of patients (Ayers, 2009). Furthermore, electronic medical records and patient care are identical in that such systems effortlessly permit restrictions to be placed upon end users' admission to specific information of the patient. This personal security feature is

Healthcare Information Technology Electronic Medical Record: User
Words: 1472 Length: 5 Document Type: Research Paper

Healthcare Information Technology Electronic Medical Record: User friendliness is among the significant factors- probably the most essential factor- hampering extensive usage of Electronic Medical Record EMRs in respiratory therapy within my organization. User friendliness features a powerful, usually direct connection with my organization's efficiency, error level, operator exhaustion and operator satisfaction- are all essential elements for EMR usage. Moreover, within my organization, it's been observed that efficient coaching and execution techniques impact

EMR Organizational Change Plan Introducing Electronic Medical
Words: 1595 Length: 5 Document Type: Essay

EMR Organizational change plan Introducing electronic medical records (EMR) Along with expanding health coverage to more Americans, one of the goals of recent federal policy has been the widespread adoption of electronic medical records (EMR) by healthcare providers across the nation. "The federal government began providing billions of dollars in incentives to push hospitals and physicians to use electronic medical and billing records" (Abelson, Creswell, & Palmer 2012). Having EMRs can be used

Legal Aspects of Medical Errors Various Factors
Words: 1275 Length: 4 Document Type: Case Study

Legal Aspects of Medical Errors Various factors in the health care system are reported to be contributors to medication errors. This work reviews a case study discussed in 'Hospital Pharmacy' (Smetzer and Cohen, 1998) which provides a clear example of the complex nature of the health care system and the process of medication use and how this interrelates to medication safety and quality. The nurse made the decision to administer the

Electronic Certificate of Medical Necessity
Words: 1942 Length: 7 Document Type: Term Paper

Electronic Certificates of Medical Necessity: A Proposal Medical billing can now become a relatively painless process for the personal in a medical facility through the electronic filing of certificates of medical necessity (e-CMN). Manually filling out paperwork is very time consuming, and is not very cost effective. However, the technological advancements created in the area of medical billing are very efficient. While many offices now fax the CMN's, the incorporation of

Patient Safety Reduce Medical Errors and Increase Patient Safety...
Words: 3077 Length: 12 Document Type: Term Paper

Patient care and recovery statistics demonstrate that the United States has a medical care system with which Americans are less satisfied than other citizens in developed countries. There are many reasons for this: correlation between health and socioeconomic status; non-universality; federal government is not involved in medical planning although it purchases a large percentage of the 14% health care GNP; lobbying and special interest group interference; and political opposition to

Sign Up for Unlimited Study Help

Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.

Get Started Now