Skip to Main Content
Dream Factory by TruBridge Ideas Portal
Categories Security
Created by Aaron Mitcham
Created on Aug 10, 2023

Customized security audit reports or more granular controls for aduits

For Hipaa auditing it would be nice to be able to create custom audit reports to make sure no one is accessing data for whom they're not responsible or for a patient that is not in facility.
An example idea would be to have a report where could specify by date range and then see every user that has accessed patients who are not physically in the facility or for a patient they're not currently reasonably responsible for.
Being able to filter by roles would also be nice so you could filter out false positives from places like billing, or admissions which would likely need to access old records.

  • Attach files
  • Grady Warner
    Reply
    |
    Sep 6, 2024

    I have asked for YEARS to add patient names to the audit logs. It is so frustrating when you pull a report with 20-30 accounts (or more), and then have to go enter every account to find and type the name in the report. Many of the other systems we use list patient names in the audit reports. Why has CPSI/Evident/Trubridge refused to add this? Create another report that shows who pulled a security audit report and all of the patients that were listed if you want to track who looked at patient names. You could create a switch that you can choose: Include Patient Name (Yes or No) if someone doesn't need the patient name. Not sure why they wouldn't...you're going to go enter every single account number to find the patient name as soon as you run the audit report anyway. PLEASE ADD THIS!

  • Susan Stevens
    Reply
    |
    Sep 13, 2023

    To expound upon this further, I feel the "descriptors" of the path users are taking which could also then be clicked on to take you directly to the specific patient and document or area accessed. It is very difficult to complete a comprehensive review of an audit trail when the naming conventions don't really tell you anything. Example, and I apologize for the comparison to Centriq: Ability to have a drop down that not only covers a specific date range, but also additional dropdowns for search of specified user (both actual name and username), drop down with search for patient names, drop down with search for specific area of chart such as Notes, Lab, Documents and ability to search from dropdown for service type (IP, ER, OP, etc.). After that point, the ability to click on the "Note" and it will bring up the exact note a user had accessed.