Setup review · About 20 min
Before using patient records, check whether you need a BAA, which services it covers and how to set up the account.
Bring: The proposed workflow, actual account and vendor agreements.
Make: A list of the account, covered services and approval checks.
Setup review · About 20 min
Give the coding tool a separate practice folder, then check its file, network and app permissions. A folder alone does not limit access.
Bring: A dedicated workspace and fictional sample rows.
Make: A fictional prototype and a permission review.
Setup review · About 15 min
Removing a name is not enough. Use a recognized method and check the whole record, including notes and file details.
Bring: Use fictional records to rehearse; do not upload real records to an unapproved service.
Make: A record of the chosen method and review.
Setup review · About 20 min
Before connecting a tool to your practice, check what it can read, what it can change and where it keeps copies.
Bring: The proposed workflow and actual permission settings.
Make: A map of what the tool can read, do and store.
Setup review · About 20 min
Start with whether HIPAA applies to your practice. Then check the task and the information you plan to share.
Bring: The practice’s status and the information used in the proposed workflow.
Make: Questions for the practice’s privacy or legal lead.
Setup review · About 15 min
“Not used for training” does not mean “not stored.” Check the service’s storage, deletion and retention terms.
Bring: The exact product, feature, account and agreement.
Make: A dated record of training, retention, access and deletion settings.