In addressing the visitor/vendor policy, there are certain vendors that we have that are here on a regularly scheduled basis and are not in areas where there is ePHI, such as the laundry delivery, food delivery, and such ones as FedEx and UPS. The business of these particular vendors are confined to the hallways. Do we need to treat these the same as others that may be here on an extended basis (repair personnel, on site trainers, students shadowing personnel, etc.) where we have these sign a confidentiality/non-disclosure form and must log-in? What are the recommendations for writing this into policy? Can I differentiate between the 2 types?
October 16, 2017

The vendors who do not come in any possible contact with PHI, may just have a confidentiality agreement but, you need that in place. If they have a key to access any room(s) after hours, or unattended in which PHI is possibly in their path, you should consider that contact with PHI. Some hospitals have confidentiality/non-disclosure agreements, so I imagine Home office can supply you one. But at any rate, they must sign-in and out and be identified while on the premises and you must have an auditable log of their presence.
However, the vendors, teaching facilities and students, contactors, etc. who may come in contact with PHI or ePHI must have a BA in place. No exceptions (and must sign-in and out, accordingly, with the same audit log(s) in place).
And yes, I would differentiate the two on the procedure you are writing, you can make sub-lines (like a1, a2, etc., if needed) to explain your circumstances.

Share Us on: