I. Purpose and Scope:
- The Tufts University School of Dental Medicine (TUSDM) is committed to maintaining formal practices to control the communication of electronic Protected Health Information (ePHI) and Protected Personal Information (ePPI). This policy establishes safeguards and rules for appropriate communication of ePHI and ePPI using electronic means; and supports TUSDM compliance with HIPAA and Massachusetts regulations governing patient privacy.
- This policy applies to any technology that transmits ePHI and/or ePPI electronically, including but not limited to email, instant messaging, voice mail, and file transfer. This policy specifically governs all email messages and electronic systems carrying the name or abbreviation of Tufts University that originate within TUSDM. It also governs use of clinical messaging systems (i.e., axiUm Messenger module) and use of texting to share patient-related information.
- This policy supplements the Tufts University Information Stewardship Policy, the Use of University Systems Policy, the Information Classification and Handling Policy, the Information Roles and Responsibilities Policy and the Tufts University Information Security Program to specifically address TUSDM’s status as a covered entity under the Health Insurance Portability and Accountability Act Omnibus Rule.
- This policy applies to all TUSDM Workforce Members.
II. Policy Statement:
- TUSDM requires all Workforce Members to take measures to ensure any ePHI/ePPI that may be transmitted electronically is transmitted in a manner that protects it against unauthorized access and ensures its integrity. ePHI/ePPI may be sent electronically only when the use or disclosure is permitted under TUSDM policy and federal and state regulations governing patient privacy.
III. Definitions:
IV. General Rules:
- The TUSDM default mode for patient communication is the primary telephone number provided by the patient. The patient may designate a home, work, or cell number as primary contact number.
- The patient has the right to determine his/her electronic communication preferences. Unless otherwise prohibited under this policy, TUSDM Workforce Members must respect patient preferences. All non-default modes of provider to patient communication (e.g., email, text, etc.) must be previously authorized by the patient and documented in contact notes section of the patient’s electronic health record.
- If the patient has an authorization to receive information by text on file, such information must be limited to: appointment confirmations, reminders, and/or cancellations.
- ePHI may only be sent to a patient or a patient’s authorized personal representative after the recipient’s contact information has been carefully verified and entered correctly into the patients electronic health record.
- All messages originating in or received by the Tufts University email system and the TUSDM clinical messaging system (i.e., axiUm Messenger) are the property of Tufts University. TUSDM mandates that all Workforce Members include a standard confidentiality notice in their Tufts email account signatures:
Confidentiality Notice: The information contained in this e-mail message, including any attachments, is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure or distribution is prohibited. If you are not the intended recipient and have received this message in error, please contact the sender by reply e-mail and destroy all copies of the original message.
- TUSDM is a clinical setting and all electronic messages that pertain to a patient should be linked to the patient’s electronic record both for care purposes and legal purposes. Encrypted clinical messaging (i.e., axiUm Messenger module) is the preferred and most appropriate vehicle for such communications.
- TUSDM requires email encryption if it is necessary to send electronic messages that contain ePHI or ePPI to email addresses outside Tufts University’s email system. Senders must follow Tufts University’s Proofpoint instructions and place the word “secure” in brackets in the subject line of your email as follows: Subject: [secure]. Secure is not case sensitive. Do not put any PHI in the subject line of the email. One may also use the Microsoft Outlook Encryption Function (Appendix A: Secure Email Instructions)
- Certain ePHI is classified as highly sensitive and confidential and should never be communicated to patient, authorized patient representative, other provider, or unauthorized parties by electronic message (i.e., email, text, axiUm Messenger, voicemail). Highly sensitive and confidential health information includes patient- identifiable information about alcohol and substance abuse; sexually transmitted disease; HIV and AIDS, sexual assault, domestic violence, and mental health.
- ePHI and ePPI that may be shared under this policy should be limited to the “minimum necessary.” Although disclosures for treatment purposes between health care providers and disclosures to the patient who is the subject of the information are generally exempted from the HIPAA minimum necessary standard, TUSDM strongly encourages all workforce members to exercise judgement and limit the amount of information shared.
- TUSDM requires discussions of potential dental diagnosis and treatment be conducted in person. If a patient initiates discussion using electronic means, the patient should be advised to make an appointment. Do not respond to the patient’s requests or questions, instead one may send a [secure] email so that the patient’s communication is secure. Electronic requests for information of potential dental diagnosis, treatment, treatment plans, treatment in process or fees should be brought to the attention of supervising faculty. Other HIPAA compliant alternatives to communicate with a patient are Zoom for Healthcare and Doximity.
- TUSDM strictly prohibits certain activities and modes of communication:
- Workforce Members may not, under any circumstances, take photographs, film video, or record audio in the clinical areas, including the patient reception areas, during clinic hours of operation. During clinic closed periods, Workforce Members must ensure any photography, film, video, or recorded audio does not capture any ePHI or ePPI (e.g., huddle boards, white boards, rosters, etc.).
- Workforce Members may not disclose any information (e.g., descriptive details, audio, photo, or video including names, physical or demographic descriptions, details of medical/dental diagnosis, clinical procedures and activities, etc.) about past or current patients at TUSDM on personal social media (e.g., Facebook, LinkedIn, Twitter, or similar platforms). (See Appendix B: Best Practice for Social Media Use at TUSDM).
- Workforce Members may not use or auto forward their official Tufts email accounts to non-Tufts email accounts (e.g. Google, Yahoo, AOL, Comcast, Verizon, etc.). This ban prevents intentional or accidental unsecure communication of ePHI/ePPI. (Appendix C: Email Forwarding Warning).
- Individual email messages may be forwarded to non-Tufts accounts as long as the email message does not contain ePHI or ePPI.
- Workforce Members may not leave voicemail messages containing ePHI/ePPI. If a workforce member wants to use their personal cell phones to communicate with patients or leave voicemails regarding appointment scheduling, TUSDM strongly recommends installation of the Cisco Jabber application with activation of the single number reach feature.
- Workforce Members may not use non-Tufts voice to text systems (e.g., GoogleVoice, etc.) to communicate with patients, patient authorized representatives, or other providers engaged in the patient’s care.
- Workforce Members may not use instant messaging services (e.g., AOL instant Messenger, G-Chat, Facebook Instant Messenger, etc.) to communicate with patients, patient authorized representatives, or other providers engaged in the patient’s care.
- Workforce Members may not use any other calendars such as Google Calendar for patient appointments. This ban prevents intentional or accidental unsecure communication of ePHI/ePPI. Appointment information should only be in axiUm or in one’s Tufts Outlook calendar.
- Workforce Members may not text diagnosis, treatment, prescription, or payment information to patients; use of texting is strictly limited to patient appointment logistics.
- Workforce Members may not copy, download, or store ePHI/ePPI to any personal and/or shared device. This includes, but is not limited to, radiographs, Dolphin images, and patient rosters.
- Workforce Members may not use commercial cloud-based data storage services (e.g., Dropbox, OneDrive Live, GoogleDrive, etc.) The only cloud-based storage workforce members may use for ePHI/ePPI is TuftsBox (tufts.box.com or Tufts-issued SharePoint site) and other applications that have been expressly authorized by the TTS Office of Information Security for use with ePHI/ePPI. Workforce Members may store ePHI using their University sponsored TuftsBox account with certain restrictions:
- Workforce Members may not use the Box sync function to store ePHI/ePPI on any personal device.
- Workforce Members may not grant access to TuftsBox folders containing ePHI/ePPI to non-TUSDM workforce members, unless the external party has submitted a signed TUSDM Confidentiality and Information Security Agreement to the TUSDM Privacy Officer.
V. Policy Compliance Monitoring and Enforcement:
- The Privacy Officer & Information Security Officer are jointly responsible for monitoring and enforcing this policy with the assistance of technical staff.
- Each individual who has been granted an email account, network access, and access to patient information is responsible for following this policy and adhering to these security and privacy protections.
- In accordance with its Use of University Systems policy, Tufts University reserves the right to monitor use of its computer systems, networks and other institutional systems, including electronic communications (e.g., email, social media, web browsing) of all faculty, staff and students who use or access those systems. Tufts Information Technology staff members are prohibited from using their broad access to systems containing ePHI for any purpose other than strictly in the course of (1) debugging, testing or maintaining hardware or software systems, responding to an incident, or compliance monitoring, or (2) investigations, as directed by the Office of University Counsel or otherwise in accordance with the Tufts University Use of University Systems Policy. While Information technology staff may inadvertently view TUSDM Workforce Member messages while performing their job descriptions, they are prohibited from re-disclosing message contents other than as required by their job responsibilities in accordance with University policies. Reading confidential information not directly required for job performance, such as an employee, student, or patient record, even if with good intentions, and even if that information is not further disclosed, is strictly prohibited.
VI. Potential Disciplinary Actions and Sanctions:
- Failure to adhere to the safeguards and rules established in this policy will trigger review for potential disciplinary action. Workforce Members who do not comply with this policy may be required to participate in additional training or be referred to the appropriate Ethics, Professionalism, and Citizenship Committee for potential disciplinary action.
VIII. Approval and Review Cycle:
- This policy is subject to annual review, revision, and approval by the TUSDM Compliance Committee and, in the event of material changes, official adoption by the TUSDM Dean.