| A | B |
| Electronic Medical Record (EMR) | An electronic record used within a physician's office, clinic, or practice that contains health information created and maintained by that provider or clinic. |
| Electronic Patient Record (EPR) | An electronic record containing information about a patient's health encounters within a specific organization or institution. |
| Electronic Health Record (EHR) | A more complete electronic record that brings together health information from different healthcare providers and organizations. |
| Personal Health Record (PHR) | A patient-controlled record that allows patients to access, store, and manage some of their own health information. |
| Patient Portal | An online tool that may allow patients to access their own health information and become more involved in their healthcare. |
| Longitudinal Record | A lifelong health record that connects information from different healthcare providers and organizations over time.- often EHR |
| Continuity of Care | Ongoing coordinated care supported by access to accurate and complete patient information. |
| Practice Management Software | A digital platform used to manage daily practice operations and often combine EMR functions with administrative tools. |
| Patient Registration | An EMR or practice management function used to collect and manage identifying patient information. |
| Health Record Management | The use of systems and procedures to organize, store, update, retrieve, and protect patient records. |
| Referral Tracking | A practice management function used to monitor referrals and related documentation. |
| Document Scanning and Storage | The process of scanning documents and storing them electronically in the patient record. |
| Remote Access | Access to patient information or care systems from another location when appropriate and secure. |
| Shared System | An electronic system that allows authorized users or providers to access shared health information. |
| Preventative Care Reminder | An EMR alert or reminder that a patient is due for screening, immunization, or follow-up care. |
| Duplicate Testing | Repeating tests unnecessarily, which electronic records may help reduce by making prior results easier to locate. |
| Unauthorized Access | Access to patient information by someone who does not have permission. |
| Accidental Disclosure | Unintentional sharing or exposure of patient information. |
| Cybersecurity Risk | A risk involving computers, networks, digital systems, or electronic health information. |
| Cybercrime | Crimes involving computers, networks, or digital systems. |
| Malware | Harmful software designed to damage systems, steal information, or allow unauthorized access. |
| Ransomware | A cyberattack that blocks access to systems or data until payment is demanded. |
| Hacking | Unauthorized access to digital systems to steal information, disrupt services, or damage systems. |
| Malicious Insider | A person with authorized access who intentionally misuses that access to harm, share, or damage information inappropriately. |
| Software Glitch | A software problem that may make information difficult to access or use. |
| Corrupted Data | Data that is difficult or impossible to access or read because the system or storage has failed. |
| Copy-and-Paste Documentation Error | A documentation problem caused when copied information is inaccurate, outdated, placed in the wrong chart, or not specific to the patient. |
| Audit Trail | A record of user activity that shows who accessed information and what actions were taken. |
| System Downtime | A period when electronic systems are unavailable due to power outages, internet problems, software issues, computer problems, or cybersecurity incidents. |
| Downtime Procedure | A procedure used to continue essential work when electronic systems are temporarily unavailable. |
| Safeguard | A protective measure that helps keep information secure, accurate, and available when needed. |
| Physical Safeguard | A safeguard that protects the physical environment, equipment, documents, and records used in healthcare settings. |
| Identification Badge | A physical safeguard used to help identify authorized people in a healthcare setting. |
| Visitor Registration | A physical safeguard that tracks visitors entering a healthcare setting. |
| Locked Computer Screen | A physical safeguard used when leaving a workstation to prevent unauthorized viewing or access. |
| Locked Cabinet | A physical safeguard used to secure place to store paper records or documents. |
| Locked Server Room | A physical safeguard used to protect hardware and systems. |
| Alarm System | A physical safeguard used to protect facilities, equipment, or information. |
| Fire Suppression | A physical safeguard used to help protect equipment and records from fire damage. |
| Flood Mitigation | A physical safeguard used to reduce the risk of damage from flooding. |
| Offsite Backup | A copy of data stored away from the main location to support recovery after disruptions. |
| Disaster Recovery Safeguard | Planning and procedures used to restore access to systems or information after disruptions. |
| Disaster Recovery Planning | Preparing for events such as natural disasters, power outages, cyberattacks, or equipment failures. |
| Emergency Procedure | A planned response used during emergencies or system disruptions. |
| System Restoration Plan | A plan for restoring electronic systems after downtime or disruption. |
| Communication Procedure During Outages | A procedure that explains how staff should communicate when electronic systems are unavailable. |
| Administrative Safeguard | Policies, procedures, and training that guide how healthcare workers access, use, and disclose information. |
| Privacy Policy | An administrative safeguard that explains how personal health information should be protected. |
| Confidentiality Agreement | An agreement requiring staff to protect confidential patient information. |
| Access Control Procedure | A procedure that determines who may access information and what they may access. |
| Privacy Awareness Training | Training that helps staff understand privacy responsibilities and secure information practices. |
| Privacy Breach Reporting Procedure | A procedure that explains how staff should report a suspected or confirmed privacy breach. |
| Technical Safeguard | Technology-based tools and policies used to protect electronic information. |
| Password Protection | A technical safeguard that restricts system access to authorized users. |
| Encryption | A technical safeguard that protects information by making it unreadable without proper authorization. |
| Firewall | A technical safeguard that helps prevent unauthorized access to networks or systems. |
| Intrusion Detection System | A technical safeguard that helps detect unauthorized or suspicious system activity. |
| Secure Network | A network protected by security controls to help prevent unauthorized access. |
| Antivirus Software | Software that helps detect, prevent, or remove harmful software. |
| Application Safeguard | A protection built into specific software to control access and user actions. |
| Role-Based Access | Limiting software access based on a user's job role. |
| User Access Review | A regular review of who has system access and whether that access is still needed. |
| Anonymized Data | Data with identifying information removed when possible to protect privacy. |
| Restricted Software Access | Limiting access to unnecessary sections or functions of software. |
| MOA Role in EMR Security | Maintaining accurate, secure, and professional electronic records by following policies, protecting work areas, and logging out when away. |