I. Purpose and Scope:
- Tufts University School of Dental Medicine (TUSDM) is committed to protecting patients’ electronic protected health information (ePHI) by maintaining formal practices specifying the proper use of email within a healthcare organization.
- Electronic email is pervasively used in almost all industries and is often the primary communication method within an organization. At the same time, misuse of email can pose many legal, privacy, and security risks, therefore, it is important to understand the appropriate use of electronic communications.
II. Policy Statement:
- This policy identifies the proper use of TUSDM’s email system and makes users aware of what is deemed as acceptable and unacceptable use of its email system. This policy outlines the minimum requirements for use of email within the TUSDM organization.
- This policy covers the appropriate use of email sent from TUSDM workforce members’ email address and applies to all TUSDM Workforce Members and agents working on behalf of TUSDM.
III. Definitions:
IV. General Rules:
- As a medical/dental professional your duties are to treat your patient in a timely manner and to protect the privacy of your patients’ protected health information. Therefore, to protect TUSDM and the individual workforce member from a HIPAA data breach caused by an inadvertent transmission of unsecured ePHI, TUSDM has implemented the following restrictions regarding the use of Tufts email within TUSDM.
- Only Tufts accounts may be used to transmit or receive PHI/ePHI.
- Workforce Members may not use or auto forward their official Tufts email accounts to non-Tufts email accounts (e.g. Google, Yahoo, AOL, Comcast, Verizon, etc.). This ban prevents intentional or accidental unsecure communication of ePHI/ePPI.
- If Tufts email account is forwarded to a non-Tufts account, the owner of the email will receive a warning via email and their account forwarding will be disabled (Attachment A: Email Forwarding Warning).
- Individual email messages may be forwarded to non-Tufts accounts if the email message does not contain ePHI or ePPI.
- The patient has the right to determine his/her electronic communication preferences. Unless otherwise prohibited under this policy, TUSDM workforce must respect patient preferences. All non-default modes of provider to patient communication (e.g., email, text) must be previously authorized by the patient and documented in the contact notes section of the patient’s electronic health record.
- ePHI may only be sent to a patient or a patient’s authorized personal representative after the recipient’s contact information has been carefully verified and entered correctly into the patient's electronic health record.
- All messages originating in or received by the Tufts University email system are the property of Tufts University. TUSDM mandates that all workforce members include a standard confidentiality notice in their Tufts email account signatures. "Confidentiality Notice: The information contained in this e-mail message, including any attachments, is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure or distribution is prohibited. If you are not the intended recipient and have received this message in error, please contact the sender by reply e-mail and destroy all copies of the original message."
- TUSDM is a clinical setting and all electronic messages that pertain to a patient should be documented in the patient’s electronic health record both for care purposes and legal purposes.
- TUSDM requires email encryption if it is necessary to send electronic messages that contain ePHI or ePPI to email addresses outside Tufts University’s email system. Senders must follow Tufts University’s Proofpoint instructions and place the word “secure” in brackets in the subject line of your email as follows: Subject: [secure]. Secure is not case sensitive (Attachment B: Secure Email Instructions).
- ePHI and ePPI that may be shared under this policy should be limited to the “minimum necessary.” TUSDM strongly encourages all workforce members to exercise judgement and limit the amount of information shared.
- TUSDM requires discussions of potential dental diagnosis and treatment be conducted in person. If a patient initiates discussion using electronic means, the patient should be advised to make an appointment. Email requests for information of potential dental diagnosis, treatment, treatment plans, treatment in process or fees should be brought to the attention of supervising faculty.
- TUSDM reserves the right to refuse to allow access to particular devices or software where it considers that there is a security or other risk to its information or facilities.
V. Policy Compliance Monitoring and Enforcement:
- The TUSDM Security and Privacy Officer and/designated person/s are responsible for the monitoring and enforcement of this policy. However, directors and managers are also responsible for monitoring compliance with procedures specific to their areas.
VI. Potential Disciplinary Actions and Sanctions:
- Failure to follow standard operating procedures may trigger review for potential disciplinary action under the TUSDM HIPAA Sanctions Policy.
VIII. Approval and Review Cycle:
- This policy shall be subject to annual review, revision, and approval by the TUSDM Compliance Committee