Protecting Our Patients’ Privacy: Know the Rules for Accessing Information in Epic
Protecting our patients’ health information is everyone’s responsibility. Whether you provide direct care, support clinical operations or assist behind the scenes, we all play a vital role in maintaining privacy and upholding patient trust.
Epic is our electronic medical record (EMR) system, and it contains protected health information (PHI) for all of our patients. Please review the following common scenarios to refresh your understanding of what is—and isn’t—okay when it comes to accessing PHI.
What is PHI?
Protected health information (PHI) is any information about a patient’s past, present or future, physical or mental conditions, the provision of their healthcare or payment of it, and somehow reasonably identified the patient. It includes medical and payment information as well as demographic information that could identify them. Our patients trust us to keep their information private.
Q: Can I access PHI to perform my job duties?
A: Yes. Access to PHI is permitted when it’s necessary to carry out your official job duties, such as providing patient care, coordinating billing or supporting clinical operations. Remember, you must access only the minimum necessary information to complete your task.
Q: I saw a sad story in the news and heard the patient was treated at Carilion. Can I look them up in Epic?
A: No. Unless you are directly involved in the patient’s care or have a legitimate business reason, you may not access their information. Every patient—no matter their story—deserves privacy.
Q: Can I use the ED track board or other unit census list to see what’s going on in the organization?
A: Only if your role requires it. These tools are intended for care teams or leaders with operational oversight. Viewing them out of curiosity or without a valid work-related reason is not allowed.
Q: I created a personal list in Epic of patients I’ve treated for quick reference. Is that okay?
A: While your dedication to patient care is appreciated, maintaining a personal list outside of your current assignment is not appropriate. Patient lists must be updated each shift and should include only those you are actively caring for. It’s acceptable to leave a patient on your list while you complete documentation.
Q: I recently treated a patient and want to check on how they’re doing. Am I allowed to look up their information?
A: No. Accessing a patient’s chart is only allowed if you are actively involved in their care or have a legitimate business need. This includes any searches by name or viewing of demographic information. When you log in to Epic, you’re accessing PHI—so every action taken must serve a clinical or business-related purpose. If you have clinical concerns or believe follow-up is needed, speak with your leader or use the appropriate reporting channels.
Have Questions or Concerns?
The Privacy Office and your leader are here to help. If you’re unsure whether access or use of a tool is appropriate for your role, here are the ways to reach out to the Privacy Office:
- Email: privacy@carilionclinic.org
- Phone: 540-510-4600
- Compliance and Privacy Help Line (anonymous reporting):
- 844-732-6232 or compliance.CarilionClinic.org
- Include as many details as possible when reporting anonymously.
Test Your Knowledge—and Win!
Now that you have refreshed your knowledge about PHI, take our short Privacy Quiz. Everyone who completes the quiz by Saturday, Aug. 30 will be entered for a chance to win a gift card.
You can access patient records if you have a business need to do so.
Access only the minimum amount of information needed to perform your task.
When in doubt, ask! The Privacy Office is here to support you.