Privacy >> TUSDM Policy on Personal Mobile Device Use

TUSDM Policy on Personal Mobile Device Use

I. Purpose and Scope: 
  1. Tufts University School of Dental Medicine (TUSDM) is committed to protecting patients’ protected health information (ePHI) by maintaining formal practices specifying the proper mobile device functions to be performed, the manner in which those functions are to be performed, and the physical attributes of any mobile device or class of devices that can access ePHI. As such, TUSDM will continually assess potential risks and vulnerabilities to individual health data in its possession, and develop, implement, and maintain appropriate administrative, physical, and technical security measures.
II. Policy Statement: 
  1. TUSDM seeks to protect its mobile devices, and the data stored on such devices, from unauthorized access, use, disclosure, alteration, modification, deletion, destruction and/or removal. Using non-company owned/controlled mobile devices to access, use, or store sensitive company-related information, including sensitive or confidential personal information, is strictly prohibited unless previously approved.
  2. The policies and procedures stated herein apply to all ePHI created, maintained or transmitted by Tufts University School of Dental Medicine (TUSDM).
  3. Workforce Members shall use mobile devices (e.g., laptops, tablets, cell phones, digital cameras, flash drives, portable hard drives) in the appropriate manner as to consider the sensitivity of ePHI contained therein and minimize the possibility of unauthorized access to such information.
  4. Physical safeguards will be implemented for all mobile devices to minimize unauthorized access to ePHI.
III. Definitions: 
IV. General Rules: 
  1. The use of any Mobile Device to access, transmit or store TUSDM ePHI creates risks including those relating to data protection, virus infection, copyright infringement, unintentional or unlawful compromise of data and even loss or theft of device and/or data. The risks are increased, and are also more difficult to manage, when using Personally Owned Mobile Devices (laptops, tablets, cell phones, digital cameras, flash drives, and any other storage media).
  2. TUSDM is the owner of all TUSDM ePHI and the contents of TUSDM systems together with everything which is created on, transmitted to, received on or printed from, or stored or recorded on each Mobile Device, in each case during the course of the TUSDM’s business or otherwise on TUSDM’s behalf—irrespective of who owns that Mobile Device.
  3. The physical security of these devices is the sole responsibility of the owner of the device. Mobile devices shall be kept with the owner/user whenever possible. Whenever a device is being stored, it shall be stored in a secure place, preferably out of sight.
    1. No phone calls may be made or received during a patient appointment and need to be muted.
  4. Workforce Members may not copy, download, or store ePHI/ePPI to any personal and/or shared device. This includes, but is not limited to radiographs, Dolphin images, and patient rosters.
    1. Cellphone cameras may NEVER be used at any time 24 /7 in any patient clinic or used to capture any part of a patient’s electronic health record or identifiable information.
  5. All communication with patients must be with the Cisco Jabber App, with no exception.
  6. As a medical/dental professional your duties are to treat your patient in a timely manner and to protect the privacy of your patients’ protected health information. Therefore, to protect TUSDM and the individual workforce member from a HIPAA data breach caused by an inadvertent download of patient information, TUSDM requires all Personal Mobile Devices to be encrypted.
    1. Whole disk encryption is the only 100% protection against a data breach. Therefore, enabling vendor encryption (e.g., Windows BitLocker) is highly recommended.
    2. Any TUSDM workforce member wishing to access TUSDM electronic patient records remotely, must enable device encryption and register their device(s) with the TUSDM Security and Privacy Officer before virtual desktop infrastructure (VDI) access will be enabled. (Attachment A: Personal Mobile Device Use Agreement.)
      1. NOTE: At this time texting patients is not allowed since this is not a secure link.
  7. Additional Security features are highly recommended: 
    1. Create a different password for your Tufts account.
    2. Do not save your Tufts account credentials in any web browser.
    3. If you think your password has been compromised, change it immediately.
    4. Enroll and Use 2FA (Two-Factor Authentication).
    5. If possible, enable PIN, locate device, and remote wipe options.
    6. Activate automatic screen savers and set for 10 minutes or less.
    7. Only use the Tufts_Secure network for Wi-Fi access.
    8. Use Tufts VPN for secure off campus access.
    9. Install anti-virus software and enable automatic scans.
    10. Set operating system, web browsers and key applications to auto-update.
    11. Restart your device daily.
    12. Back up your data to a location other than your device. You can use Tufts Box (https://tufts.box.com).
  8. Workforce Members may not use commercial cloud-based data storage services (e.g., Dropbox, One Drive.Live, Google Drive, etc.) The only cloud-based storage Workforce Members may use for ePHI/ePPI is TuftsBox (tufts.box.com) and other applications that have been expressly authorized by the TTS Office of Information Security for use with ePHI/ePPI. Workforce Members may store ePHI using their University sponsored TuftsBox account with certain restrictions:
    1. Workforce Members may not use the Box sync function to store ePHI/ePPI on any personal device.
    2. Workforce Members may not grant access to Tufts Box folders containing ePHI/ePPI to non-TUSDM Workforce Members unless the external party has submitted a signed TUSDM Confidentiality and Information Security Agreement to the TUSDM Privacy Officer.
  9. If a mobile device is lost or stolen, promptly report the incident to the TUSDM Security and Privacy Officer.
  10. TUSDM reserves the right to request access to inspect or delete TUSDM information held on a Personally Owned Mobile Device to the extent permitted by law and for legitimate business purposes. Every effort will be made to ensure that the University does not access the private information of the individual.
  11. TUSDM reserves the right to refuse access to particular devices or software when it considers that there is a security or other risk to its information or facilities.
  12. TDF Clinics operate as an office clinic and therefore interacts with their patient base in ways different from the Dental School. The customary workflow varies as the need to contact responsible third parties occurs on a regular basis. Therefore, this office setting needs to utilize a different standard of mobile communication usage.
V. Policy Compliance Monitoring and Enforcement: 
  1. The Security & Privacy Officer is responsible for the monitoring and enforcement of this policy; however, directors and managers are also responsible for monitoring compliance with procedures specific to their areas.
VI. Potential Disciplinary Actions and Sanctions: 
  1. Failure to follow standard operating procedures may trigger review for potential disciplinary action under the TUSDM HIPAA Sanctions Policy.
VIII. Approval and Review Cycle: 
  1. This policy shall be subject to annual review, revision, and approval by the TUSDM Compliance Committee.
Attachments: 

Attachment A: Personal Mobile Device Use Agreement

I request permission to use my Personal Mobile Device (PMD) to access TUSDM’s clinic information systems and data for work-related purposes. 
I agree to use my PMD described below in accordance with TUSDM’s HIPAA Security and Privacy policies and procedures, and I understand that all policies and procedures will apply to this device just like they apply to equipment owned by TUSDM. I understand that permission to use my PMD to access TUSDM’s systems may be revoked at any time.

I agree to the additional limitations and requirements specific to PMDs described below:

  1. I will protect the device with strong password, inactivity time out/log off setting of no more than five minutes and best encryption practices possible for my PMD (e.g., whole device, application, or file encryption). I will use separate password for encryption and applications accessing ePHI.
  2. I agree to surrender my device immediately to TUSDM Security Official upon request for review in course of scheduled or unscheduled device monitoring activities, review or investigation. 
  3. I agree for TUSDM to install specific software on my PMD, enabling TUSDM:
    1. To manage mobile devices (e.g., track network access, monitor for malicious software or implementation of security policies).
    2. To remotely wipeout any ePHI or other data belonging to TUSDM in case device is determined to be compromised (e.g., stolen, lost, not with authorized user).
    3. I agree to remove, specific from my PMD, all applications deemed to be unsecure by TUSDM Security Official.

EMPLOYEE NAME:

 


Name Signature Date

Personal Mobile Device Use

Workforce Member Name:

 

Workforce Member Signature:

 

Today’s Date:

 

Device Information

Device 1

Device 2

Device Type:

 

 

Device Model:

 

 

Device Tag Number or Serial Number:

 

 

Is the Device Encrypted?

Yes ☐

No ☐

Yes ☐

No ☐

Systems to Access:

 

 

 

 

 

 

Access Granted by (Signature):

 

 

Date Access Granted:

 

 

Access Revoked by (Signature):

 

 

Date Access Revoked: