Facility Security: Difference between revisions
Nirichardson (talk | contribs) (Created page with "POLICY NO : 6067<br /> EFFECTIVE DATE: 03/17/03<br /> <big>'''Facility Security Policy'''</big> NOTE: These guidelines are provided to assist UNMC workforce, including t...") |
No edit summary |
||
Line 1: | Line 1: | ||
POLICY NO : 6067<br /> | <table style="background:#F8FCFF; text-align:center" width="100%" cellspacing="0" cellpadding="0" border="0"> | ||
<tr> | |||
<td style="padding:0.5em; background-color:#e5e5e5; font-size:90%; line-height:0.95em; border:1px solid #A3B1BF; border-bottom:solid 2px #A3B1BF" | |||
width="20">[[Human Resources]]</td> | |||
<td style="border-bottom:2px solid #A3B1BF" width="3"> </td> | |||
<td style="padding:0.5em; background-color:#e5e5e5; font-size:90%; line-height:0.95em; border:1px solid #A3B1BF; border-bottom:solid 2px #A3B1BF" | |||
width="20">[[Safety/Security]] </td> | |||
<td style="border-bottom:2px solid #A3B1BF" width="3"> </td> | |||
<td style="padding:0.5em; background-color:#e5e5e5; font-size:90%; line-height:0.95em; border:1px solid #A3B1BF; border-bottom:solid 2px #A3B1BF" | |||
width="20">[[Research Compliance]] </td> | |||
<td style="border-bottom:2px solid #A3B1BF" width="3"> </td> | |||
<td style="padding:0.5em; background-color:#e5e5e5; font-size:90%; line-height:0.95em; border:1px solid #A3B1BF; border-bottom:solid 2px #A3B1BF" | |||
width="20">[[Compliance]]</td> | |||
<td style="border-bottom:2px solid #A3B1BF" width="3"> </td> | |||
<td style="padding:0.5em; background-color:white; line-height:0.95em; border:solid 2px #A3B1BF; border-bottom:0; font-weight:bold;" width="20">[[Privacy/Information Security]]</td> | |||
<td style="border-bottom:2px solid #A3B1BF" width="3"> </td> | |||
<td style="padding:0.5em; background-color:#e5e5e5; font-size:90%; line-height:0.95em; border:1px solid #A3B1BF; border-bottom:solid 2px #A3B1BF" | |||
width="20">[[Business Operations]]</td> | |||
<td style="border-bottom:2px solid #A3B1BF" width="3"> </td> | |||
<td style="padding:0.5em; background-color:#e5e5e5; font-size:90%; line-height:0.95em; border:1px solid #A3B1BF; border-bottom:solid 2px #A3B1BF" | |||
width="20">[[Intellectual Property]]</td> | |||
</tr> | |||
</table> | |||
<br /> | |||
[[Identification Card]] | [[Secure Area Card Access]] | [[Privacy/Confidentiality]] | [[Computer Use/Electronic Information]] | [[Confidential Information]] | [[Protected Health Information (PHI)]] | [[Notice of Privacy Practices]] | [[Access to Designated Record Set]] | [[Accounting of PHI Disclosures]] | [[Patient/Consumer Complaints]] | [[Vendors]] | [[Fax Transmissions]] | [[Psychotherapy Notes]] | [[Facility Security]] | [[Conditions of Treatment Form]] | [[Informed Consent for UNMC Media]] | [[Transporting Protected Health Information]] | |||
<br /><br /> | |||
POLICY NO: '''6067'''<br /> | |||
EFFECTIVE DATE: 03/17/03<br /> | EFFECTIVE DATE: 03/17/03<br /> | ||
<big>'''Facility Security Policy'''</big> | <big>'''Facility Security Policy'''</big> | ||
NOTE: These guidelines are provided to assist UNMC workforce, including those in the patient treatment areas of the Munroe-Meyer Institute, the College of Medicine Optical Shop, the Lions Eye Bank and the College of Dentistry, as applicable, comply with HIPAA regulations. Those departments and clinics which fall under the jurisdiction of The Nebraska Medical Center and/or University Medical Associates should consult the policies and procedures of those entities for authoritative guidance.<br /> | |||
=== Basis for Policy === | === Basis for Policy === | ||
<br /> | <br /> | ||
It is the policy of the University of Nebraska Medical Center (UNMC) to comply with authoritative guidelines, to ensure a safe and secure workplace for faculty, students, staff, patients and visitors, and to protect the University. Further, it is the policy of UNMC to protect confidentiality and privacy through appropriate use of information gathered in the course of employment or other affiliation with UNMC or entrusted to UNMC for academic, research, patient care, or administrative purposes.<br /> | It is the policy of the University of Nebraska Medical Center (UNMC) to comply with authoritative guidelines, to ensure a safe and secure workplace for faculty, students, staff, patients and visitors, and to protect the University. Further, it is the policy of UNMC to protect confidentiality and privacy through appropriate use of information gathered in the course of employment or other affiliation with UNMC or entrusted to UNMC for academic, research, patient care, or administrative purposes.<br /> | ||
=== Policy === | === Policy === | ||
<br /> | <br /> | ||
All exterior doors to buildings and interior doors to clinics and offices housing protected health information (PHI) or confidential proprietary information will be locked after normal business hours, including weekends and holidays. | All exterior doors to buildings and interior doors to clinics and offices housing protected health information (PHI) or confidential proprietary information will be locked after normal business hours, including weekends and holidays. | ||
Exterior and interior doors are secured by means of mechanical and/or electronic locking mechanisms. | Exterior and interior doors are secured by means of mechanical and/or electronic locking mechanisms. | ||
'''Department Personnel Responsibilities''' | '''Department Personnel Responsibilities''' | ||
* Knowing who should legitimately be in their work area | * Knowing who should legitimately be in their work area | ||
Line 41: | Line 51: | ||
# Contact 911 for occurrences off main campus | # Contact 911 for occurrences off main campus | ||
* Securing offices and other areas containing PHI or confidential proprietary information when not in use<br /> | * Securing offices and other areas containing PHI or confidential proprietary information when not in use<br /> | ||
'''Securing Campus Buildings After Normal Business Hours''' | '''Securing Campus Buildings After Normal Business Hours''' | ||
* Campus buildings which include, but are not limited to, Clarkson Tower, University Tower, Durham Outpatient Center, University Medical Associates, and UNMC Recycling Center which house confidential information are protected by a variety of physical security measures to prevent unauthorized individuals from gaining access. A Facility Plan (under construction) has been developed for the University of Nebraska Medical (UNMC) campus to safeguard the premises and buildings (exterior and interior) from unauthorized physical access, tampering, or theft. | * Campus buildings which include, but are not limited to, Clarkson Tower, University Tower, Durham Outpatient Center, University Medical Associates, and UNMC Recycling Center which house confidential information are protected by a variety of physical security measures to prevent unauthorized individuals from gaining access. A Facility Plan (under construction) has been developed for the University of Nebraska Medical (UNMC) campus to safeguard the premises and buildings (exterior and interior) from unauthorized physical access, tampering, or theft. | ||
Line 50: | Line 58: | ||
* Campus Security will conduct routine patrols of all buildings (both interior and exterior) after normal business hours to assure buildings and departments remain secure | * Campus Security will conduct routine patrols of all buildings (both interior and exterior) after normal business hours to assure buildings and departments remain secure | ||
* Campus Security will check any individual found in a secured area after hours to assure they are authorized<br /> | * Campus Security will check any individual found in a secured area after hours to assure they are authorized<br /> | ||
'''After Hours Access to Campus Buildings/Departments''' | '''After Hours Access to Campus Buildings/Departments''' | ||
* Workforce authorized to access specific buildings and/or departments within a building may have a key issued to them in accordance with Key Control Procedures | * Workforce authorized to access specific buildings and/or departments within a building may have a key issued to them in accordance with Key Control Procedures | ||
* If card access is available to a building or department, workforce authorized access to the building/department may be granted access via card access in accordance with UNMC Policy No. 6009, Secure Area Card Access Control Policy and Secure Card Access Control Procedures<br /> | * If card access is available to a building or department, workforce authorized access to the building/department may be granted access via card access in accordance with UNMC Policy No. 6009, Secure Area Card Access Control Policy and Secure Card Access Control Procedures<br /> | ||
'''Securing Clinics and Health Care Centers Located Off Main Campus''' | '''Securing Clinics and Health Care Centers Located Off Main Campus''' | ||
:Managers of locations off the main campus are responsible for: | :Managers of locations off the main campus are responsible for: | ||
Line 67: | Line 71: | ||
# Training and instructing staff members on how to properly secure patient related information | # Training and instructing staff members on how to properly secure patient related information | ||
# Securing buildings after hours<br /> | # Securing buildings after hours<br /> | ||
Securing Department Areas During Cleaning | Securing Department Areas During Cleaning | ||
* Department management in conjunction with Environmental Services (EVS) management is responsible for performing a risk assessment of the physical security of the area when cleaning of the area takes place | * Department management in conjunction with Environmental Services (EVS) management is responsible for performing a risk assessment of the physical security of the area when cleaning of the area takes place | ||
* It is department management responsibility to know the cleaning schedule and to inform EVS of any changes which might impact the physical security of the area during the cleaning hours | * It is department management responsibility to know the cleaning schedule and to inform EVS of any changes which might impact the physical security of the area during the cleaning hours | ||
* If after normal business hours, EVS will ensure that the main door to the area remains locked where possible. If it is not possible to lock off the area, EVS and department management will evaluate options to mitigate the risk<br /> | * If after normal business hours, EVS will ensure that the main door to the area remains locked where possible. If it is not possible to lock off the area, EVS and department management will evaluate options to mitigate the risk<br /> | ||
=== Definitions === | === Definitions === | ||
<br /> | <br /> | ||
'''Privacy''' is defined as the right of individuals to keep information about themselves from being disclosed. | |||
'''Proprietary information''' refers to information regarding business practices, including but not limited to, financial statements, contracts, business plans, research data, employee records and student records as defined in UNMC Policy No. 6045, Privacy, Confidentiality and Information Security. | '''Proprietary information''' refers to information regarding business practices, including but not limited to, financial statements, contracts, business plans, research data, employee records and student records as defined in UNMC Policy No. 6045, Privacy, Confidentiality and Information Security. | ||
'''Protected Health Information (PHI)''' is individually identifiable health information. Health information means any information, whether oral or recorded in any medium, that: | '''Protected Health Information (PHI)''' is individually identifiable health information. Health information means any information, whether oral or recorded in any medium, that: | ||
* is created or received by UNMC; and | * is created or received by UNMC; and | ||
* relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual.<br /> | * relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual.<br /> | ||
Records containing PHI, in any form, are the property of UNMC. The PHI contained in the record is the property of the individual who is the subject of the record. | |||
Workforce refers to faculty, staff, volunteers, trainees, students, independent contractors and other persons whose conduct, in the performance of work for UNMC, is under the direct control of UNMC, whether or not they are paid by UNMC. | |||
Workforce refers to faculty, staff, volunteers, trainees, students, independent contractors and other persons whose conduct, in the performance of work for UNMC, is under the direct control of UNMC, whether or not they are paid by UNMC. | |||
For more information on facility security, contact Gary Svanda, Campus Security. | |||
Key Control Procedures / Secure Card Access Control Procedures | |||
Key Control Procedures / Secure Card Access Control Procedures | |||
This is a new UNMC Policy.<br /> | This is a new UNMC Policy.<br /> | ||
This page updated on Friday, March 03, 2006, by dkp.Reviewed with minor changes on February 17, 2006. | This page updated on Friday, March 03, 2006, by dkp.Reviewed with minor changes on February 17, 2006. |
Revision as of 14:22, October 9, 2012
Human Resources | Safety/Security | Research Compliance | Compliance | Privacy/Information Security | Business Operations | Intellectual Property |
Identification Card | Secure Area Card Access | Privacy/Confidentiality | Computer Use/Electronic Information | Confidential Information | Protected Health Information (PHI) | Notice of Privacy Practices | Access to Designated Record Set | Accounting of PHI Disclosures | Patient/Consumer Complaints | Vendors | Fax Transmissions | Psychotherapy Notes | Facility Security | Conditions of Treatment Form | Informed Consent for UNMC Media | Transporting Protected Health Information
POLICY NO: 6067
EFFECTIVE DATE: 03/17/03
Facility Security Policy
NOTE: These guidelines are provided to assist UNMC workforce, including those in the patient treatment areas of the Munroe-Meyer Institute, the College of Medicine Optical Shop, the Lions Eye Bank and the College of Dentistry, as applicable, comply with HIPAA regulations. Those departments and clinics which fall under the jurisdiction of The Nebraska Medical Center and/or University Medical Associates should consult the policies and procedures of those entities for authoritative guidance.
Basis for Policy
It is the policy of the University of Nebraska Medical Center (UNMC) to comply with authoritative guidelines, to ensure a safe and secure workplace for faculty, students, staff, patients and visitors, and to protect the University. Further, it is the policy of UNMC to protect confidentiality and privacy through appropriate use of information gathered in the course of employment or other affiliation with UNMC or entrusted to UNMC for academic, research, patient care, or administrative purposes.
Policy
All exterior doors to buildings and interior doors to clinics and offices housing protected health information (PHI) or confidential proprietary information will be locked after normal business hours, including weekends and holidays.
Exterior and interior doors are secured by means of mechanical and/or electronic locking mechanisms.
Department Personnel Responsibilities
- Knowing who should legitimately be in their work area
- Observing and reporting immediately any suspicious activities and/or individuals acting in a suspicious manner:
- Contact Campus Security, Ext. 9-5111 for occurrences on main campus
- Contact 911 for occurrences off main campus
- Securing offices and other areas containing PHI or confidential proprietary information when not in use
Securing Campus Buildings After Normal Business Hours
- Campus buildings which include, but are not limited to, Clarkson Tower, University Tower, Durham Outpatient Center, University Medical Associates, and UNMC Recycling Center which house confidential information are protected by a variety of physical security measures to prevent unauthorized individuals from gaining access. A Facility Plan (under construction) has been developed for the University of Nebraska Medical (UNMC) campus to safeguard the premises and buildings (exterior and interior) from unauthorized physical access, tampering, or theft.
- Campus Security will control facility access, including locking, unlocking, and restricting access during designated hours
- Campus Security will conduct routine patrols of all buildings (both interior and exterior) after normal business hours to assure buildings and departments remain secure
- Campus Security will check any individual found in a secured area after hours to assure they are authorized
After Hours Access to Campus Buildings/Departments
- Workforce authorized to access specific buildings and/or departments within a building may have a key issued to them in accordance with Key Control Procedures
- If card access is available to a building or department, workforce authorized access to the building/department may be granted access via card access in accordance with UNMC Policy No. 6009, Secure Area Card Access Control Policy and Secure Card Access Control Procedures
Securing Clinics and Health Care Centers Located Off Main Campus
- Managers of locations off the main campus are responsible for:
- Evaluating and performing a risk assessment for their Clinic/Healthcare Center
- Working with Facilities Management and Campus Security to develop appropriate polices and procedures for securing their work areas
- Training and instructing staff members on how to properly secure patient related information
- Securing buildings after hours
Securing Department Areas During Cleaning
- Department management in conjunction with Environmental Services (EVS) management is responsible for performing a risk assessment of the physical security of the area when cleaning of the area takes place
- It is department management responsibility to know the cleaning schedule and to inform EVS of any changes which might impact the physical security of the area during the cleaning hours
- If after normal business hours, EVS will ensure that the main door to the area remains locked where possible. If it is not possible to lock off the area, EVS and department management will evaluate options to mitigate the risk
Definitions
Privacy is defined as the right of individuals to keep information about themselves from being disclosed.
Proprietary information refers to information regarding business practices, including but not limited to, financial statements, contracts, business plans, research data, employee records and student records as defined in UNMC Policy No. 6045, Privacy, Confidentiality and Information Security.
Protected Health Information (PHI) is individually identifiable health information. Health information means any information, whether oral or recorded in any medium, that:
- is created or received by UNMC; and
- relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual.
Records containing PHI, in any form, are the property of UNMC. The PHI contained in the record is the property of the individual who is the subject of the record.
Workforce refers to faculty, staff, volunteers, trainees, students, independent contractors and other persons whose conduct, in the performance of work for UNMC, is under the direct control of UNMC, whether or not they are paid by UNMC.
For more information on facility security, contact Gary Svanda, Campus Security.
Key Control Procedures / Secure Card Access Control Procedures
This is a new UNMC Policy.
This page updated on Friday, March 03, 2006, by dkp.Reviewed with minor changes on February 17, 2006.