There are many good reasons to do logging.
There are also many good reasons to drive a Mercedes S500.
My objection to logging is only its cost.
While a large organizations with a well trained ( and paid) IT staff can do all
the necessary infra structure for logging the reality is that a lot of
organizations just don't have the resources. Neither in personnel nor in
funds. And I think it is important to point out that a covered entity can
forego the access logging if its privacy and security policies are well
written. Those rules have to assign a specific role to everyone that
comes in contact with PMI , defining the level of access and also training the
personnel in their obligations regarding the privacy and
security. Any tightly run healthcare enterprise should be close to
compliance by adhering to common sense guidelines.
For example: your customer service
representatives have access to the complete member or patient records.
You have to put in place a strict code of conduct
and enforce it too. Even fire employees who are caught browsing for their
neighbor's records. But beyond that you don't have to change your system,
you don't have to create a log of anybody who accessed the records. The key word
is "reasonable". A covered entity has to undertake every resonable step to
insure the PMI. We don't have to do an access log that rivals those for
national security documents.
If you can afford logging, great. If you can't,
don't sweat it.
Lastly I think healthcare professionals have an
obligation to keep the costs under control. 40 million uninsured
Americans mean also millions of premature deaths every year. ( BTW, this
article has good statistical info http://www.washingtonpost.com/wp-dyn/articles/A41642-2002Jul8.html )
Martin Scholl
Scholl Consulting Group, Inc. 301-924-5537 Tel 301-570-0139 Fax [EMAIL PROTECTED] www.SchollConsulting.com
********************************************************************** To be removed from this list, send a message to: [EMAIL PROTECTED] Please note that it may take up to 72 hours to process your request. ====================================================== The WEDI SNIP listserv to which you are subscribed is not moderated. The discussions on this listserv therefore represent the views of the individual participants, and do not necessarily represent the views of the WEDI Board of Directors nor WEDI SNIP. If you wish to receive an official opinion, post your question to the WEDI SNIP Issues Database at http://snip.wedi.org/tracking/. Posting of advertisements or other commercial use of this listserv is specifically prohibited. |
Title: Logging Record Access in Transaction Systems
- Logging Record Access in Transaction Systems Owens, Kris
- Re: Logging Record Access in Transaction Systems Martin Scholl
- Re: Logging Record Access in Transaction Systems James Kelly
- Re: Logging Record Access in Transaction Systems Dave_Hays
- RE: Logging Record Access in Transaction Systems Owens, Kris
- RE: Logging Record Access in Transaction Systems Lee, Gary
- RE: Logging Record Access in Transaction Systems Martin Scholl
- RE: Logging Record Access in Transaction Systems Lee, Gary
