The chart is a legal document —
and your phone is a liability
Nobody plans a privacy violation. They text a colleague from the elevator, photograph a wound “for the chart,” peek at a famous patient’s record, paste a note into a chatbot, or vent on a private account that turns out to be neither. This session covers the digital rules that protect patients, careers, and the record itself — before the habits form.
What interns leave able to do
- Route every patient-related message through approved channels — and state what never goes in a personal text, email, or unapproved app.
- Handle clinical photographs by policy: approved device or workflow, consent where required, never the personal camera roll.
- Use copy-forward as a tool instead of a hazard: what carries, what must be rewritten, and why yesterday’s exam pasted today is a false record.
- State the access rule: the record is opened for care, never curiosity — not family, not colleagues, not the famous admission — and audits are real.
- Apply the AI rule: no patient information into unapproved tools, and anything drafted with approved tools is verified and owned by the clinician who signs it.
- Know the downtime and phishing basics: where the paper process lives, and what a credential-stealing message looks like at 6 a.m.
The case
A single afternoon hands you five moments: a co-resident texts “send me the CT images” from their personal number · a beautiful cellulitis begs to be photographed for the chart · the EHR suggests yesterday’s exam in today’s note · a nurse mentions the local newscaster admitted upstairs · and a chatbot offers to draft your discharge summary if you just paste the chart in.
For each: what is the safe version of the same task — because each has one?
Teaching points
- The message rule: patient care runs on approved channels — the secure-messaging tool, the EHR, the hospital phone. The colleague still gets the images: through the system built for it. Personal channels leak, get subpoenaed, and never die. And the nuance that makes the rule livable: the approved secure app on your own phone is an approved channel — the liability is the unapproved channel, never the device.
- The photograph rule: clinical images are clinical data — approved device or upload workflow, consent per policy, straight into the record. The version in a personal camera roll is a breach with a timestamp.
- The copy-forward rule: carry the stable scaffolding, rewrite everything you claim to have done today — an exam you did not perform, pasted, is a false statement in the record the next clinician treats from, and a false statement in a legal document besides; the chart is a care instrument first, and both of its readers punish the pasted exam.
- The access rule: treatment relationship or no chart — the famous patient, the colleague, your own family member: all audited, all career-relevant, and the curiosity peek is the most common violation in every hospital’s log. If you need to know as family, ask as family.
- The AI rule: nothing identifiable into unapproved tools, ever — and where your institution provides approved ones, the output is a draft the signing clinician verifies line by line, because the signature transfers the accountability, not the tool.
- The self rule: assume everything you post is public and permanent; patient stories are identifiable faster than you think, and “private account” is a setting, not a fact. Downtime has a paper playbook — know where it lives. The 6 a.m. “your password expires” message gets reported, not clicked; an MFA prompt you didn’t start gets denied; a lost phone with hospital access gets reported the hour it’s lost. And remember who else reads the chart: patients read your notes through the portal — write nothing about a patient you would not say to them.
Running the room
| Minutes | Block |
|---|---|
| 0–5 | Frame: “nobody plans a privacy violation — today we install the habits before the shortcuts form” |
| 5–30 | The five scenarios, one at a time: the room commits out loud, then the safe version of the same task is revealed — every scenario has one |
| 30–40 | The local layer on screen: the approved apps demonstrated, the photo workflow, the downtime binder’s location, the reporting path |
| 40–45 | Pocket card |
Watch for, and debrief by name: “everyone texts” normalization — true as description, irrelevant as defense, and the approved app kills the excuse; the intern who quietly realizes a camera-roll photo already exists — the answer is the policy’s deletion-and-report path, handled without shame, because the goal is the habit, not the confession; and curiosity access defended as caring (“I just wanted to see how she was doing”) — the caring version is asking as family, and the room should hear the difference.
Pocket card
- Approved channels only. Personal text/email/apps never carry patient information.
- Photos: approved workflow, consent per policy, never the camera roll.
- Copy-forward: scaffold yes, today’s findings rewritten. Every time.
- Open charts for care, never curiosity. Audits are real.
- No patient data into unapproved AI. Approved AI output: verified, then owned.
- Post nothing you wouldn’t sign. Report the phish. Know the downtime binder.
Notes
Run the five scenarios as commitments — the room says what they would do before the safe version is revealed. Approved tools, photo workflows, downtime procedures, and social-media policy are institutional; show the real documents and the real apps. The scenarios are fictional composites.
This page is a teaching framework for facilitated small-group education, not legal or compliance guidance — your institution’s policies govern. Last reviewed July 2026.