If a nursing home is converting to an electronic paperless health information management system:
policies and procedures must be established and maintained that require password protection of the clinical database;
any outside contract for health information management services must include a provision that the company providing the services assumes responsibility for maintaining the confidentiality of all health information within its control;
audit trails must be developed for computer applications to determine the source and date of all entries and deletions;
there must be a plan for preparing, securing, and retaining archived copies of computerized clinical databases;
procedures must be implemented for preparing and securing daily, weekly, and monthly archived copies of computerized clinical databases; and
there must be confidentiality and protection from unauthorized use of active and archived computerized clinical databases.
20 SR 303
October 11, 2007
Official Publication of the State of Minnesota
Revisor of Statutes