HIPAA Audit Checklist for Glaucoma MIGS Implant Serial Number Documentation on Preference Cards

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Audit Checklist for Glaucoma MIGS Implant Serial Number Documentation on Preference Cards

Kevin Henry

HIPAA

September 15, 2026

7 minutes read
Share this article
HIPAA Audit Checklist for Glaucoma MIGS Implant Serial Number Documentation on Preference Cards

Review HIPAA Privacy Rule Requirements

Objective

Confirm HIPAA Privacy Rule Compliance for how your surgical team captures and stores glaucoma MIGS implant details—especially serial numbers—on preference cards and in supporting systems.

Key points to verify

  • Define what constitutes PHI in your environment and ensure workforce understanding that device identifiers and serial numbers can be PHI when linked to a patient or encounter.
  • Apply the minimum necessary standard for all uses and disclosures tied to MIGS implant documentation and auditing.
  • Map where implant data flows: preference cards, EHR implant logs, inventory systems, billing, sterilization, and vendor portals.
  • Confirm Business Associate Agreements cover any external platforms that ingest Unique Device Identifier (UDI) data.
  • Ensure workforce training explicitly addresses Device Identifier Exclusion from external reports and research extracts unless permissible under HIPAA.

Evidence to collect

  • Policies describing PHI handling, designated record set scope, and implant documentation rules.
  • Work instructions for MIGS case setup, UDI scanning, and preference card completion.
  • Access control matrices and audit logs for systems storing serial numbers.

Verify Device Identifier Classifications

Understand UDI components

Break down the UDI into Device Identifier (DI) and Production Identifier (PI). The DI points to the labeler and model; the PI may include the serial number, lot/batch, manufacturing and expiration dates—collectively a Production Identifier.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Classify privacy risk

  • PI elements, especially the serial number, are direct identifiers when associated with a specific patient or case.
  • DI by itself describes a product model. However, when coupled with encounter details, dates, or rare device models, it can still elevate re-identification risk.
  • For Limited Data Set creation, both DI and PI must be removed. For a De-Identified Data Set via the Safe Harbor method, remove all UDI elements. Under the Expert Determination Method, retention of certain device details requires a documented, statistical risk finding.

Control measures

  • Maintain a clear data dictionary labeling DI and each PI field as “restricted.”
  • Implement field-level masking in exports and dashboards to enforce Device Identifier Exclusion by default.

Assess Serial Number Documentation Practices

Workflow review

  • Observe MIGS case setup to confirm UDI barcode scanning captures the serial number directly into the EHR implant log rather than only onto a preference card.
  • If a preference card is used intraoperatively, verify that serial numbers are transcribed only to systems within the designated record set and not retained on reusable template cards.
  • Validate reconciliation steps: the serial number on packaging labels matches the scanned record and the implant log entry.

Controls and safeguards

  • Restrict who can view or edit serial numbers on any printed or electronic preference card artifacts.
  • Ensure physical chain-of-custody for packaging labels and stickers; dispose securely after EHR capture unless required for the medical record.
  • Document exceptions handling (downtime, unreadable barcodes) with secure manual entry and post-case verification.

Acceptance criteria

  • 100% of MIGS implants have a captured PI serial number in the EHR implant log.
  • No serial numbers persist on reusable preference card templates; case-specific notes route to secured record locations.
  • All third-party tools that store UDI elements are covered by BAAs and access controls.

Evaluate Compliance of Preference Cards

Design principles

  • Treat preference cards as non-patient-specific templates; list device categories and DI-level product options, not serial numbers.
  • For case-specific inserts, ensure they are filed to the medical record or implant log, not saved as part of the reusable card.
  • Configure EHR and OR systems so UDI scanning populates the implant log automatically, making manual serial number entry on the card unnecessary.

Documentation and retention

  • Version-control preference card templates with change justification and approver signatures.
  • Set retention rules so printed cards or notes containing PI data are not stored outside approved repositories.

Quality checks

  • Quarterly sample of MIGS cases: verify preference cards exclude serial numbers while implant logs contain them.
  • Spot-check for orphaned artifacts (photos, texts, emails) that include serial numbers and migrate or purge per policy.

Implement Data De-Identification Procedures

Choose the correct pathway

  • De-Identified Data Set (Safe Harbor): remove names, dates (except year as applicable), and all direct identifiers, including all UDI elements (both DI and PI).
  • De-Identified Data Set (Expert Determination Method): a qualified expert documents that re-identification risk is very small; any retained device fields must pass formal risk testing and documented controls.
  • Limited Data Set: may include certain dates and limited geography but must exclude direct identifiers such as device identifiers and serial numbers.

Operationalize de-identification

  • Build ETL rules to drop or tokenize DI and PI fields before data leaves the clinical system.
  • Apply k-anonymity thresholds to small-volume MIGS cohorts; aggregate or suppress rare device models and dates.
  • Log each extract with method used (Safe Harbor, Expert Determination Method, or Limited Data Set) and approvals obtained.

Validation

  • Run pre-release scanners to flag residual UDI patterns in free text and images.
  • Maintain a change log whenever data schemas or device catalogs update.

Conduct Risk Assessment for Data Sets

Scope and context

Assess who will access MIGS implant data, for what purpose, and under what controls. Low case volumes and niche implant models can heighten uniqueness and re-identification risk.

Risk factors to score

  • Uniqueness: rare device models or serial ranges that map to single cases or dates.
  • Replicability: details visible outside the covered entity (e.g., public presentations or recalls).
  • Availability: data elements that could be obtained from other sources and linked.
  • Environmental controls: access logs, contractual limits, and secure enclaves.

Mitigations

  • Replace specific implant models with category-level labels in shared datasets.
  • Generalize dates (e.g., month or quarter) when sharing beyond treatment, payment, or operations.
  • Use data use agreements with explicit Device Identifier Exclusion and redisclosure prohibitions.

Maintain Audit and Reporting Records

Audit artifacts

  • Annual policy attestations for teams handling MIGS preference cards and UDI data.
  • System audit logs showing who viewed, edited, or exported implant serial numbers.
  • Sample reports demonstrating compliance with HIPAA Privacy Rule Compliance requirements and minimum necessary access.

Metrics and follow-up

  • Key indicators: capture rate of UDI scans, exception rate, time-to-correction, and number of datasets released with confirmed Device Identifier Exclusion.
  • Issue tracking with CAPA plans, owner assignment, and closure evidence.
  • Periodic management reviews summarizing trends and residual risks.

FAQs

What are the HIPAA requirements for device identifier documentation?

Under the HIPAA Privacy Rule, device identifiers and serial numbers are treated as direct identifiers when tied to an individual or encounter. You may use them for treatment, payment, and health care operations, but disclosures and secondary uses must follow the minimum necessary standard and applicable agreements. For Limited Data Set and de-identified sharing, apply Device Identifier Exclusion unless an Expert Determination Method explicitly justifies retention within a De-Identified Data Set.

How should serial numbers of glaucoma implants be handled under HIPAA?

Capture the serial number via UDI scanning into the EHR implant log and restrict access to roles that need it. Do not store serial numbers on reusable preference card templates. Secure any printed labels or notes in the designated record set or dispose of them per policy after verification.

Can device identifiers be included in preference cards?

Include device categories or DI-level product options on reusable preference cards, but exclude serial numbers and other PI elements. If case-specific documentation is necessary on the card, file that content to the medical record and ensure it is not retained on the reusable template.

What steps ensure compliance in implant serial number documentation?

Standardize UDI scanning, enforce field-level masking in exports, keep BAAs current for any systems with UDI data, perform periodic audits of MIGS cases, and use Safe Harbor or the Expert Determination Method to produce compliant De-Identified Data Sets. For Limited Data Sets, remove all device identifiers and serial numbers before release.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles