If you were to imagine how to access a patient’s personal health information (PHI) illegally, what would the operation look like? You may think of a Watergate-esque operation, sneaking into a doctor’s office or hospital ward under cover of night, wearing all black and ski masks, frantically flipping through charts while trying to get by undetected, and afterwards slinking back into the darkness.
Nowadays, it’s as easy as just waiting for someone to get up from their shared workstation and accessing thousands of patient charts instantly.
Or maybe wait until a doc puts their phone down to grab a coffee, and if it’s not PIN locked give it a quick swipe-through.
Delivering care is complex and hectic, and we need to be as efficient as possible to meet the rising demand and patient volumes. Communication is one of the biggest determinants in delivering high quality care. But if clinicians are only given ineffective and unencrypted tools such as pagers and fax machines, they will find more efficient workarounds.
Studies have shown that clinicians text each other all sorts of patient information on their own (often non-secure) mobile devices with alarming regularity. They don’t do this out of malice or laziness, they are truly trying to provide the best care for their patients, and this just happens to be the most effective and convenient way.
Unfortunately, the majority of hospitals in Canada do not offer secure ways of communicating patient information in a convenient way that reflects modern care pathways and workflows. The default option is to have a policy to tell everyone not to send any PHI on mobile devices, and throw the book at those who get caught.
As the old adage goes: an ounce of prevention is worth a pound of cure. Why not take up tools that already exist to make the lives of clinicians and patients better, to improve efficiency, to reduce the risk of a privacy breach, and to improve patient care?
Secure messaging is widely available now, and it is offered at a price that is cheaper than a pager subscription or a switchboard operator. Messaging has been extensively shown to improve user satisfaction and improve hospital operations (references below). This will also give clinicians who already rely on non-secure messaging a safer and more efficacious alternative. We’ve tried policies and regulations, but that has failed. It is time for real options, real tools, and real alternatives if we’re going to take safeguarding patient privacy seriously.