Patient Safety in Virtual Care
In telehealth, patient safety applies not only to physical safety but also to keeping medical records secure in a digital environment. Introducing new technologies, or any technology for that matter, in a healthcare setting requires applications with the highest levels of security for this very reason. Medical records and personal health information (PHI) must always remain protected, and Third Eye Health takes that responsibility seriously.
Our partners and their patients trust that our services and technology always have their best interests at heart. Keeping patient medical records and passwords secure from attackers is our highest priority. They only need to get it right once, so we must get it right every time. To do this, we reduce the number of attack surfaces, or ways they can penetrate our system. From our applications to our hardware, we safeguard everything.
There are two primary criteria for ensuring secure data:
It must be encrypted in transit (HTTPS)
It must be encrypted at rest
Oftentimes, a company will claim to “whole-disk encrypt” the database, claiming encryption at rest. The problem with this method is that the database may still be accessible directly, virtually, or physically. If that's possible, it really isn’t encrypted at rest. We eliminate this threat by encrypting each record individually with its own initialization vector, eliminating a single key that could decrypt all the data. We also don’t store our data on internal servers or internal hard drives. We keep everything in highly secure cloud-based data centers.
For the iPads used for our telehealth consults with Third Eye Health clinicians, similar measures apply. Nothing is stored on the iPads; photos are sent to the device as a transmitted image file called a byte array and displayed directly on the screen, so no files are saved. Texts or medical records viewed during the patient consult are gone as soon as it is complete.
The best way to understand how we keep patient records and related data secure is to follow the data through the workflow of one of our consultations. Third Eye Health works with leading post-acute care EHR providers, PointClickCare and MatrixCare, creating secure integrations with SNF EHRs. When a nurse requests a consult, the integration lets the nurse select the patient, which loads encrypted data from the EHR directly into our application. During the consultation, any details shared (photos, text conversations) and consult-related metrics are securely transferred to our cloud-based storage, where the data points are encrypted as well.
Of course, our workflow doesn't stop at the end of the consultation. We’ve found that patients experience better outcomes when there are no gaps in care, and so every encounter is reviewed by a Care Coordination Manager in Third Eye Health’s dashboard. Once again, the dashboard connects with each facility’s EHR in the same way it accesses and connects the patient’s name through the iPad by encrypting the data. Third Eye Health physicians use it to make notes and submit orders, sending them directly to the EHR. Care Coordination Managers can review this documentation in our system for quality assurance and provide care summaries to the SNF through our secure care coordination messaging platform, even providing links directly to the medical record.
Not all telehealth is created equal when it comes to security. During the pandemic, some physicians were using Zoom and other insecure video conferencing platforms to conduct virtual patient visits. Consulting with patients in a secure digital environment helps ensure HIPAA compliance with The Security Rule and prevents unauthorized individuals from accessing health records. By partnering with Third Eye Health for your telehealth needs, you can be certain your patients and their records are safe.
