Skip to content
SCP Health logo with tagline Together, we heal.
  • Clinical Services
    • Emergency Medicine
    • Hospital Medicine
    • Critical Care Medicine
    • SCP Connected Care
    • Hospital at Home
  • Careers
    • Physicians
    • Resident Physicians
    • NP/PAs
    • Nurses
    • Medical Leadership
    • Clinical Education & Training
    • Corporate Careers
  • Company
    • Our Story
    • Leadership Team
    • Advocacy
    • Social Responsibility
  • Resources & Events
    • Case Studies
    • Resources
    • Blog
    • Events
    • Podcast
    • News
SCP Clinician Portal

4 challenges to protecting patient information privacy 

Home » 4 challenges to protecting patient information privacy 

SCP Health logo with tagline Together, we heal.
SCP Clinician Portal
  • Clinical Services
    • Emergency Medicine
    • Hospital Medicine
    • Critical Care Medicine
    • SCP Connected Care
    • Hospital at Home
  • Careers
    • Physicians
    • Resident Physicians
    • NP/PAs
    • Nurses
    • Medical Leadership
    • Clinical Education & Training
    • Corporate Careers
  • Company
    • Our Story
    • Leadership Team
    • Advocacy
    • Social Responsibility
  • Resources & Events
    • Case Studies
    • Resources
    • Blog
    • Events
    • Podcast
    • News

4 challenges to protecting patient information privacy 

Home » 4 challenges to protecting patient information privacy 

  • Clinical Services
    • Emergency Medicine
    • Hospital Medicine
    • Critical Care Medicine
    • SCP Connected Care
    • Hospital at Home
  • Careers
    • Physicians
    • Resident Physicians
    • NP/PAs
    • Nurses
    • Medical Leadership
    • Clinical Education & Training
    • Corporate Careers
  • Company
    • Our Story
    • Leadership Team
    • Advocacy
    • Social Responsibility
  • Resources & Events
    • Case Studies
    • Resources
    • Blog
    • Events
    • Podcast
    • News

4 challenges to protecting patient information privacy 

The rise of telemedicine and ubiquity of electronic medical records has created new concerns regarding patient data privacy. However, whether hospitals store health information electronically or on paper, patients have the right to keep those records private, and physicians and healthcare organizations must make strides to ensure we protect those rights. 

The HIPAA Privacy Rule, a federal law, safeguards a patient’s protected health information (PHI) and sets limits and conditions on who can look at and receive that data. The Privacy Rule applies to all forms of individuals’ protected health information, whether electronic, written, or verbal.  

It also grants patients the right to examine their records, obtain a copy, and request corrections. However, the Privacy Rule does permit the disclosure of personal health information needed for patient care and other essential purposes.  

Another federal law, the HIPAA Security Rule, requires security for health information in electronic form and ensures that only authorized parties have access. 

Common healthcare privacy and security issues

Security barriers

Today’s internet technology tools and platforms are fraught with security hazards, which hospitals must address to remain HIPAA-compliant. These security barriers include:  

Bring your own device policies

The healthcare industry’s bring-your-own-device (BYOD) policies are increasing as familiarity with the comfort of utilizing personal devices in hospitals helps enhance staff productivity, efficiency, and workflow.  

However, security issues stemming from a lack of control over the use of personal mobile devices, which may include sensitive patient PHI, make it one of the most significant healthcare information technology problems for hospital administrations. 

Public WiFi

WiFi in coffee shops, airports, and other public gathering places is a much-appreciated convenience. But healthcare institutions are HIPAA-covered entities, which means they must take precautions to safeguard PHI regardless of the technology used. That includes steps like not connecting to public WiFi from mobile devices used to access PHI, sending PHI over unsecured networks, and encrypting all information. 

Email

Unencrypted email poses another security threat. And although the HIPAA Security Rule does not directly ban the use of email to convey PHI, it does establish a set of standards that hospitals must meet before considering email conversations HIPAA compliant.  

Video conferencing

Video conferencing tools, such as Skype and Zoom, are not necessarily HIPAA-compliant, and issues such as the background of the video and who else can hear the conversation around the office become important. 

Data transmission

Not only does the HIPAA Security Rule require that all electronically transmitted PHI data (ePHI) be encrypted, but the devices and channels utilized to communicate ePHI at a distance must be HIPAA-compliant as well. 

HIPAA telemedicine standards apply to any medical practitioner or healthcare organization providing a remote service to patients in their homes or community centers. Also, only authorized parties can participate. 

Finally, according to the HIPAA guidelines on telemedicine, any system communicating ePHI at a distance must have mechanisms in place to monitor communications and remotely delete if necessary to prevent accidental or malicious breaches. 

Data storage

The alarming uptick in ransomware attacks that have affected several health systems across the country has caused healthcare IT professionals to place particular emphasis on storing patient data securely.  

Ransomware is a form of malware that encrypts a victim’s files. In ransomware attacks, hackers encrypt sensitive information and demand a “ransom” (a monetary fee) to un-encrypt it. Such attacks disrupt systems and patient safety because hospitals can’t access medical records or coordinate care.  

Owing to the increase of these incidents, healthcare organizations must plan proactively to protect patient records. Choosing what data the organization will store and for how long is crucial. Knowing where that data is stored and who has access is also essential. (Access should be permitted only to individuals who have a business need.)  

Additional protective measures include staff training on security best practices, system penetration testing, implementing multi-factor authentication or single sign-on, and system and device monitoring.   

Patient responsibility

HIPAA rules only govern hospitals and health systems, not patients. But that doesn’t mean they don’t share a responsibility to protect their PHI.  

For patients to access PHI electronically, they must also take security measures. It is a good idea to remind patients not to open unknown emails (especially those containing attachments, which may contain malware), encrypt their in-home WiFi routers, and occasionally change their passwords. That’s a good idea not just for their health information but all sensitive data.  And remember, no one will ever ask for your username and password – other than the bad guys!

mySCP

SCP Health does not take protecting patient data lightly. For that reason, a few years ago, we developed mySCP, a HIPAA-compliant communication and security system that keeps patient and clinician information secure and private. Physicians must be credentialed to join, which ensures only authorized individuals have access.  

 mySCP now consists of a suite of apps that include:  

  •  mySCP Connect – a secure messaging solution for SCP Health employees and clinicians;  
  •  mySCP Care – a system that supplies clinicians with patient information in a secure and timely manner. It also helps them record the visit and address quality measures to provide the best care for patients; 
  •  mySCP Practice – a convenient, secure, HIPAA-compliant practice management hub for SCP Health employees and clinicians. 


For more insights on protecting patient information, read the SCP Health blog post, 10 Ways to Protect Your Hospital from Cyber-Attack.

  • Health care technology, Patient Experience

Related Blogs

nurse hugging and smiling with an older female patient

5 innovative and economical ways to improve patient care

physician discussing chart with patient

Clinical decision support: Enhancing expertise without limiting autonomy

The modern care team in a complex health care landscape

Subscribe to our Newsletter

Sign up for our newsletter to receive the latest updates and exclusive content straight to your inbox.

A physician-led team of clinical specialists in emergency, hospital, and critical care medicine, supporting local clinical practices with national resources to deliver high-quality patient care in the communities we serve.

Corporate Phone: (800) 893-9698

Facebook-f Linkedin Youtube

Useful Links

  • SCP Clinician Portal
  • Insurance Request Portal
  • Corporate Compliance
  • Privacy Policy
  • Terms of Use

Contact Interest

  • Billing Questions
  • Clinical Career Opportunities
  • Clinical Services Inquiry
  • Corporate Career Opportunities
  • Employee & Clinician Verification
  • Contact Us

Trending Posts

  • A Clinician's Guide to Evaluating Leadership
  • Four Reasons Why Documentation is Important
  • The Importance of Values in Health Care
  • Social Networks for Doctors
Also of Interest
  • 10 Easy Ways to Improve Patient Satisfaction in the ED
  • 4 Ways to Foster Better Doctor-Patient...
  • 15 Peculiar ICD-10 Codes

Copyright © 2025. All rights reserved.

Insurance Request Portal

Please visit SCP Health’s Insurance Request Portal to submit requests related to medical malpractice liability insurance such as coverage verifications, claims history reports, and certificates of insurance. If you experience issues with the portal submission or have a question about the process, please reach out SCP Health’s Risk Management, Safety and Insurance Department at RM@scphealth.com or 337-609-1250.

Insurance Request Portal Illustrative Instructions

Access Portal

Questions about my bill

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Clinical Career Opportunities Inquiry

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Clinical Services Inquiry

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Corporate Career Opportunities

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Employee & Clinician Verification

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

General Inquiry

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Let's Connect

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Join our Community

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Get this resource

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Let's Connect

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Employment Verification Request

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Request for Medical Records

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Let's Connect

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Let's Connect

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

General Inquiry

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Insurance Request Portal

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Let's Connect

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Let's Connect

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Let's Connect

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Interested in SCP critical care services

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Let's Connect

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Let's Connect

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy

Contact Information

Please provide your contact information. An SCP representative will contact you accordingly.

Apply To Job

Apply to Job

By clicking the “Submit” button, you are agreeing to the SCP Heath Terms of Use and Privacy Policy