In last week’s column, Anne Roberts, CPMSM, CPCS wrote that her hospital was looking into encrypted flash drives.
To clarify, the reason for the encrypted flash drives is so that no additional information can be added onto the drive. For example, if the hospital provides a practitioner with a flash drive containing policies and procedures, the hospital wants to ensure the practitioner can not use the flash drive to download confidential patient health information (PHI) and risk violating HIPAA regulations. Although the practitioner could potentially download documents containing PHI onto a personal flash drive not provided by the hospital, the hospital wants to take extra precautions and not provide a mechanism that would allow for this potential HIPAA violation.