When HelpDesk Solutions performs services that require us to create, receive, maintain, or transmit PHI on behalf of a healthcare organization, the appropriate Business Associate Agreement (BAA) is established.
Our team accesses PHI only as required to perform the administrative responsibilities assigned to us.
Team members are provided access only to the systems and information required for their assigned role.
We do not believe external team members should receive unrestricted access simply because they support the practice.
Technology alone does not protect patient information. Team members with access to healthcare information are trained on their responsibilities for privacy, security, appropriate information handling, and escalation of potential concerns.
Security responsibilities remain part of the operating relationship after onboarding.
Our teams are expected to work within the systems and communication methods approved for the client engagement. Depending on the workflow, that may include:
We establish where information should be accessed, documented, communicated, and escalated before responsibilities transition to our team. The objective is to prevent informal workarounds from becoming part of normal operations.
Administrative responsibilities do not require unrestricted access to every part of a patient's record. Where appropriate, access and workflows are limited to the information reasonably required to complete the assigned function.
For example, a team member handling scheduling should not need broader access simply because additional information exists within the system.
Potential privacy or security concerns require clear escalation. Our operating procedures are designed so suspected incidents can be:
Any applicable notification responsibilities are handled according to the relevant agreements and legal requirements.
Where a third party or subcontractor is permitted to handle PHI in connection with services provided by HelpDesk Solutions, appropriate privacy, security, and contractual requirements must apply to that relationship.
We do not treat outsourcing a function as outsourcing responsibility for protecting the information involved.
HelpDesk Solutions works within the access and operating structure established for the engagement.
HelpDesk Solutions is responsible for following the agreed administrative, privacy, and security requirements within the work assigned to our team.
Our approach to protecting healthcare information is built around a few straightforward principles:
Only appropriate team members should have access to the information required for their work.
Privacy and security responsibilities must be understood before access begins.
Sensitive information should not move through improvised channels.
Access, workflow boundaries, and escalation requirements should be clear.
Potential privacy or security issues should be surfaced rather than ignored.
Access and procedures should change when roles, systems, or responsibilities change.
Before a workflow involving PHI transitions to HelpDesk Solutions, we establish the relevant requirements with the practice. This may include: