HIPAA considerations when using Explore

Plan requirement

Subscription Any plan
Access Admin

Reporting is where protected information leaks by accident: in exports, in scheduled emails, and in free-text fields.

Why reporting is the risk

Everything else keeps data inside the platform. Reporting takes it out: as a file on somebody's laptop, as an email in an inbox, as a dashboard shared with a wider group than the tickets were.

Four things to get right

  1. Report on counts, not content. Volumes and times, not ticket text.
  2. Watch free-text fields. A subject line or a description column can carry exactly what should not leave.
  3. Restrict who may build and export. Viewer access plus a prepared dashboard covers most needs.
  4. Be careful with scheduled email. Once sent, it is in inboxes outside your controls.

Subject lines are the common leak

A ticket list report showing subjects looks harmless and reproduces whatever customers wrote there. People describe their situation in the subject line more often than anybody expects.

Aggregate, do not itemise

Almost every legitimate reporting question is answered by counts, averages and trends. Ticket-level detail is rarely needed, and it is where the exposure is.

Check who a dashboard reaches

Sharing shows everything on it to everybody who can open it. A dashboard built for a clinical team and shared to a wider group is a straightforward disclosure.

Confirm what applies

Whether Explore may be used, and under what conditions, follows from your agreement. Ask pluscloud support before building reporting on an account handling health information.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.