[MCOH-EH] Employee occupational health clinic medical record confidentiality in an EMR

Hartley, Patrick HartleyP at uihealthsystem.org
Mon Nov 19 12:52:25 PST 2018


Is your legal counsel proposing that you not enter the non-employee health side of the firewall within your EMR when ordering tests? Is it a concern with regard to what hat you are wearing when you are in the EMR (in other words, you are either Director of OHS, or you are a medical provider within the hospital).
What is the proposed workaround if you cannot order CXR in your EMR? Can you order tests as if you are an external clinic (unaffiliated with the University) referring a patient to your health facility?


Patrick G. Hartley,  M.B., B.Ch., B.A.O., M.P.H.
Professor (Clinical) of Internal Medicine
Division of Pulmonary Diseases, Critical Care and Occupational Medicine
Medical Director: University Employee Health Clinic & Occupational Medicine Clinic
Carver College of Medicine
University of Iowa
Iowa City, IA 52242-1009
319-353-7072 (Office)
319-356-2115 (Pulmonary / Occ. Med. Clinic)
319-356-3631 (UEHC)
319-353-6406 (Fax)
patrick-hartley at uiowa.edu

From: MCOH-EH [mailto:mcoh-eh-bounces+patrick-hartley=uiowa.edu at mylist.net] On Behalf Of Denece O Kesler
Sent: Monday, November 19, 2018 2:42 PM
To: 'mcoh-eh at mylist.net'
Subject: [MCOH-EH] Employee occupational health clinic medical record confidentiality in an EMR

The topic of employee health medical records/confidentiality is periodically brought to this group-I have a new angle and need your help.  We are within an academic medical center and complete all occupational health clinic functions for the hospital's employee population. We have our own medical record room for some encounter types, but do place our work injury encounters into the hospital's EMR for continuity of care for referral, etc. There is a wall currently in the system so that other employees within the hospital cannot access any of our EMR records without permission.

The problem I have is this--- our IT legal counsel reviewed OSHA requirements and is providing the opinion to our IT department that the occupational health clinic should not have any records viewable to anyone outside of our clinic in the EMR-to the point where she is advising that we can't order x-rays, labs, or anything else under the employees' names. Has anyone experienced this opinion before? I have not and told IT that I would take it to this wise group with a request for comments.

Thank you!

Denece Kesler, MD, MPH
Medical Director, OHS
Professor, DoIM
Director, COEHP
University of New Mexico

Notice: This UI Health Care e-mail (including attachments) is covered by the Electronic Communications Privacy Act, 18 U.S.C. 2510-2521 and is intended only for the use of the individual or entity to which it is addressed, and may contain information that is privileged, confidential, and exempt from disclosure under applicable law. If you are not the intended recipient, any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the sender immediately and delete or destroy all copies of the original message and attachments thereto. Email sent to or from UI Health Care may be retained as required by law or regulation. Thank you.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mylist.net/archives/mcoh-eh/attachments/20181119/8eed8e36/attachment.html>

More information about the MCOH-EH mailing list