Privacy >> TUSDM Policy on Visitors and Non-Workforce Members

TUSDM Policy on Visitors and Non-Workforce Members

I. Purpose and Scope: 
  1. This policy provides guidelines for visitors and other non-workforce members entering the Tufts University School of Dental Medicine (TUSDM) campus to engage in educational or research collaboration, observation, and study. 
II. Policy Statement: 
  1. TUSDM welcomes visiting colleagues for research and educational collaboration, observation, and study. The observation of a procedure or other type of provision of care by a visitor, student, or other observer falls under the TUSDM mission of education and thus becomes a function of TUSDM healthcare operations. Visitors who participate in patient care activities must do so in accordance with Commonwealth of Massachusetts laws related to the practice of dentistry, dental assisting, medicine, and dental hygiene and while participating in the treatment of patients become members of TUSDM’s workforce. Visitors must adhere to all policies of TUSDM and Tufts University.
III. Definitions: 
IV. General Rules: 
  1. All visitors to TUSDM are not allowed into clinical areas under any circumstances or as otherwise provided under this policy. 
  2. Faculty and staff are not permitted to host visitors on an ad hoc basis. “Shadowing” or short-term observation activity is prohibited in the predoctoral clinics, though shadowing is allowed in the postgraduate clinical areas. In these cases, it is TUSDM’s policy that a patient will be informed that: 
    1. a visitor/student/observer is not a TUSDM Workforce member, 
    2. that the patient has no obligation to share their protected health information (“PHI”) in the presence of the visitor/student/observer, and
    3. that the patient will not be treated differently if they refuse to share such information.
  3. The following safeguards are put in place to protect the health and privacy of all TUSDM patients and to fulfill TUSDM’s duties and responsibilities in allowing visitors access to the TUSDM campus, facilities, and patient population.
    1. All visitors who observe clinical activities must fully comply with TUSDM’s HIPAA Privacy and Security, Immunization, OSHA, and Infection Control policies and training requirements before they will be permitted access to the TUSDM clinic areas. 
    2. Visitors must also comply with the policies and procedures of the Departments of Student Affairs and Continuing Education where applicable. 
    3. Any visitor observing clinical activities should review and sign the "TUSDM Confidentiality and Information Security Agreement" (Appendix A: Confidentiality and Information Security Agreement).
    4. This Agreement must be reviewed and signed before the visitor will be allowed access to TUSDM Clinic areas or view patient PHI stored within TUSDM’s Electronic Health Record (EHR) system. 
    5. Visitors are prohibited from photographing/videotaping any procedure or patient care service performed during their educational, research, or observation activities at TUSDM. 
    6. The TUSDM sponsoring/hosting clinic or department should review and discuss the contents of this document with the visitor to ensure full understanding of same. 
  4. The visitor may comply with TUSDM HIPAA Training requirements by performing one of the following:
    1. Producing documentation reflecting participation and completion of an appropriate HIPAA training program or training comparable to that offered by TUSDM.
    2. Reviewing and signing the Confidentiality and Information Security Agreement. 
  5. Visitors must always remain under the supervision of the TUSDM host/sponsor or an appropriate designee. Prior to allowing the visitor access to the TUSDM campus/facility, the TUSDM sponsoring/hosting clinic or department must:
    1. Ensure that all visitors observing clinical activities have complied with all HIPAA Privacy and Security, Immunization, OSHA, and Infection Control requirements.
    2. Ensure that all visitors are provided with a temporary visitor ID that identifies the name of the sponsoring/hosting clinic or department.
    3. Within clinical areas, explain to patients that the visitor is not a member of the TUSDM Workforce and receive the patient’s verbal consent for the visitor to be present when PHI is discussed.
    4. Document/memorialize within the patient’s record the patient’s verbal consent for the visitor to be present when PHI is discussed/exchanged.
  6. PHI may be NOT be discussed/exchanged with the visitor without a patient’s verbal consent.
  7. In accordance with University policy, all visitors who may have direct and unmonitored contact with children in the course of their educational or research activities must be given thorough reference and background checks, including review of criminal and sexual offender records.
  8. The clinics or departments are responsible for maintaining all documentation associated with those visitors that they sponsor or host. All documentation must be maintained for a minimum of six years and is subject to routine audit by the TUSDM Compliance Department and/or the TUSDM Security and Privacy Officer.
V. Policy Compliance Monitoring and Enforcement: 
  1. The Compliance Officer and TUSDM Security and Privacy Officer shall monitor policy compliance and recommend revisions to standard operating procedures or workforce training, as appropriate. However, directors and managers are also responsible for monitoring compliance with procedures specific to their areas. 
VI. Potential Disciplinary Actions and Sanctions: 
  1. Failure to follow standard operating procedures may trigger review for potential disciplinary action under the TUSDM Sanctions for HIPAA and MGL c. 93H Violations Policy.
VIII. Approval and Review Cycle: 
  1. This policy shall be subject to annual review, revision, and approval by the TUSDM Compliance Committee.
Attachments: 

Appendix A: Confidentiality and Information Security Agreement

TUSDM Confidentiality and Information Security Agreement

All Tufts University School of Dental Medicine ("TUSDM") Workforce Members which include faculty, staff, students, volunteers, and interns (regardless of whether they are TUSDM trainees or rotating through TUSDM from another institution) as well as TUSDM sponsored Visitors observing within the clinic areas and other individuals who perform work for TUSDM, are personally responsible for ensuring the privacy and security of all confidential patient, employee, and business information.

I understand and acknowledge the following:

Policies and Regulations:

  • I will comply with all Tufts University and TUSDM policies governing protected information.
  • I will timely complete all privacy and security training required of my position within the TUSDM workforce.
  • I will report all concerns about inappropriate access, use or disclosure of protected information, and suspected policy violations to the TUSDM confidential hotline 1 (866) 384-4277, or via email at Dental-Compliance@tufts.edu
  • I will report all suspected information security incidents and information security policy violations to the TUSDM HIPAA Information Security or Privacy Officers or the Tufts Information Security team at (617) 627-6070 or Information_Security@tufts.edu.

Patient Health Information (“PHI”) includes: Information that relates to the past, present or future health of an individual, including the provision of health care to an individual and payment for the provision of health care, which identifies, or reasonably could be used to identify, the individual, and which is transmitted or maintained in any other form or medium (electronic, paper, verbal etc.). Examples include, but are not limited to:

  • any information about the patient’s physical or psychological condition/health status,
  • verbal information overheard or provided by or about a patient, and
  • visual observations of patients receiving medical care or accessing services at TUSDM.

Confidential Personal Information (“PI”) includes, but is not limited to the following:

A person’s first name and the last name or first initial and last name in combination with any one or more of the following data elements that relate to the individual:

  • Social Security Number, driver’s license number or state-issued identification card number;
  • financial account number or credit or debit card number with or without any required security code, access code, personal identification number or password that would permit access to an individual’s financial account; and
  • other such information obtained from Tufts University or TUSDM records which, if disclosed, would constitute an unwarranted invasion of privacy.

Confidentiality of Information

  • I will access, use, and disclose PI and PHI, including paper or electronic records, only to perform my assigned duties or educational activities and in a manner consistent with the policies and procedures of Tufts University and TUSDM. I will limit my access, use and disclosure of PI and PHI to the minimum amount necessary to perform my authorized duties or educational obligations. I understand that my access will be monitored to assure appropriate access, use or disclosure.
  • I will maintain the confidentiality of all PI and PHI to which I have access.
  • I will not discuss confidential information with any unauthorized persons. When required as part of my work or education-related duties or activities, I will make every effort to discuss confidential information in non-public areas.
  • I will take all reasonable steps to keep patient information out of view of patients, visitors, and individuals who are not involved in the patient’s care.
  • I will use Tufts University and TUSDM resources, including computers, email, photography, video, audio, or other recording equipment only for job-related duties or for duties/actions expressly permitted by applicable Tufts University or TUSDM policy. https://it.tufts.edu/ispol.
  • I will not take PI or PHI off the TUSDM campus, for any reason, unless expressly permitted by the TUSDM Privacy Officer. Should I be given permission to take PI or PHI off site, I will keep the PI or PHI fully secured and in my physical possession during transit, never leaving it unattended or in any mode of transport (even if the mode of transport is locked).

Computer, Systems, and Electronic Health Record Access Privileges

  • I will only access the records of patients for job or education-related duties or activities.
  • I will not electronically access the records of my family members, including minor children, except for assigned job or education-related duties.
  • I will protect access to patient and other job and education-related accounts, privileges, and associated passwords:
    • I will use a strong password on my computer, laptop, and smartphone.
    • I will commit my password to memory or store it in a secure place.
    • I will not share my password.
    • I will not log on for others or allow others to log on for me.
    • I will not use my password to provide access or look up information for others without proper authority.
  • I am accountable for all accesses made under my login and password, and any activities associated with the use of my access privileges.
  • I will only use my own credentials in accessing patient accounts and/or systems as provided to me for my job or education-related duties and activities. 

Computer Security

  • I will store all PI or PHI on secured systems, encrypted mobile devices, or other secure media.
  • I will not change my TUSDM computer configuration unless specifically approved to do so. 
  • I will not disable or alter the anti-virus and/or firewall software on my TUSDM computer.
  • I will log out or lock computer sessions prior to leaving a computer.
  • I will not download, install, or run unlicensed or unauthorized software on University-issued media.
  • I will use administrative permissions only when I am approved to do so and when required by job function.
  • If I use a personally owned computing device for TUSDM functions, I will not connect it to a TUSDM network unless it meets the same security requirements as a TUSDM-issued or owned device.

My obligation to safeguard patient confidentiality and protected information continues even after I am no longer a TUSDM workforce member or my work performed on behalf of TUSDM has concluded.

I acknowledge that I have read and understand the foregoing information and that my signature below signifies my agreement to comply with the conditions imposed above. I further understand that failure to comply with this agreement may result in disciplinary action up to and including termination of my status as a TUSDM Workforce Member or TUSDM-sponsored Visitor. Additionally, there may be criminal or civil penalties for inappropriate uses or disclosures of certain protected information.

Print Name:______________________________________________________________________________________________________________

Department:_____________________________________________ Position/Student Title:__________________________________________

Signature:________________________________________________________________ Date:__________________________________________

Copy Provided on:__________________________________________ by __________________________________________________________

                                                                            (Date)                                                               Print: Name, Title, Signature

Provide copy of this Agreement to the TUSDM Workforce Member, Consultant, or Visitor.