HIPAA Compliance for Glaucoma MIGS ASCs: Is It OK to Record Implant Serial Numbers on Paper Preference Cards?
HIPAA Privacy Rule Overview
For ambulatory surgical centers that perform glaucoma MIGS procedures, the HIPAA Privacy Rule safeguards protected health information, which is any individually identifiable health information that relates to a patient’s health, care, or payment. If a data element can identify a patient on its own or when combined with other data, it is PHI and must be protected.
HIPAA permits the use and disclosure of PHI for treatment, payment, and health care operations. The “minimum necessary” standard applies to payment and operations, while treatment activities allow broader access to what you reasonably need to care for the patient. Paper records must be handled with reasonable safeguards, such as controlling access, preventing casual viewing, and disposing of documents securely.
Device Identifiers and Serial Numbers
Under HIPAA’s de-identification framework, device identifiers and serial numbers are treated as direct identifiers. When these numbers appear in a record tied to a specific patient or encounter, they are PHI and must be handled accordingly.
In glaucoma MIGS, implants carry a Unique Device Identifier (UDI) that may include a device identifier (model) and production identifiers (such as lot, batch, and serial numbers). If you document UDIs alongside a patient name, medical record number, or other identifiers, the combined record is protected health information.
By contrast, a stand-alone inventory list of device identifiers and serial numbers with no patient link is not PHI. However, because crosswalks often exist inside ASCs, you should still treat these numbers cautiously and prevent unintended linkage back to an individual.
Limited Data Sets and De-Identification
HIPAA recognizes two primary paths to remove identifiability: the Safe Harbor method and Expert Determination. Safe Harbor requires removing specific identifiers, which expressly include device identifiers and serial numbers. Expert Determination allows a qualified expert to certify a very low risk of re-identification using statistical and technical controls.
A limited data set (LDS) is PHI stripped of most direct identifiers for use in operations, research, or public health with a data use agreement. Importantly, an LDS still cannot include device identifiers or serial numbers. Dates (such as surgery date) and certain geographic details may appear in an LDS, but device IDs must be excluded.
- You may include in an LDS: surgery dates, age in years, city, state, or ZIP (with limitations).
- You must exclude from an LDS: names, MRNs, full addresses, contact numbers, biometric identifiers, and device identifiers and serial numbers.
Recording Serial Numbers on Paper Preference Cards
The short answer
Yes, you may record implant serial numbers on paper during a MIGS case when it is necessary for treatment or operations—provided the document is controlled, secured, and managed under your HIPAA policies. If the preference card or case document includes or can be readily linked to the patient, treat the serial number as PHI and safeguard it accordingly.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
When it is acceptable
- Case-specific use: Writing the UDI or serial number on a case card or checklist used during the procedure is permissible for treatment and documentation.
- Workflow capture: Transcribe or scan the serial number into the electronic record or implant log promptly, then file the paper into the chart or dispose of it securely if it is only a working note.
What to avoid
- Permanent entries on generic surgeon preference cards reused across patients. These cards are not patient-specific and should not store PHI.
- Uncontrolled documents that pair patient identifiers with serial numbers and are left in open areas, placed in regular trash, or copied unnecessarily.
Operational safeguards
- Use patient labels or barcodes on case documents only when those documents will become part of the designated medical record or will be securely collected and destroyed after transcription.
- Lock paper records when unattended, limit who can view them, and use secure shredding bins after use.
- Reconcile each recorded serial number against the EHR implant log before the patient leaves recovery.
De-Identification Requirements for ASCs
When you analyze MIGS outcomes or share data for quality improvement, remove direct identifiers and any data that can reasonably point back to a patient. Under Safe Harbor, do not include device identifiers and serial numbers in de-identified data. If those elements are essential for analysis, use an Expert Determination approach and maintain robust controls that prevent re-linkage.
Practical steps include separating key files (the crosswalk between study IDs and patients), limiting access to re-identification keys, and documenting a data governance workflow. For routine benchmarking, most ASCs can de-identify by keeping only year of surgery, procedure type, device model (without serial), laterality, and aggregate outcomes.
Patient Implant Cards Standards
Providing a patient implant card at discharge is a best practice for glaucoma MIGS. The card helps patients and downstream providers identify the device quickly and supports recalls or adverse event investigations.
Core elements to include
- Device name, model, and the UDI (device identifier and applicable production identifiers such as lot or serial).
- Implant date, facility name, surgeon, and eye laterality.
- Manufacturer information and any critical device notes relevant to future care.
Process recommendations
- Capture the UDI by scanning the label in the OR, verify it during the surgical time-out, and place a copy in the medical record.
- Hand the patient card to the patient or caregiver at discharge, and document that delivery in the chart.
- Maintain an internal implant log to support tracking, quality review, and any needed notifications.
HIPAA Compliance Best Practices for ASCs
Governance and policies
- Designate a privacy lead, conduct a risk analysis, and maintain written policies addressing paper and electronic PHI handling.
- Define when paper case notes become part of the record versus temporary working documents and how each is stored or destroyed.
Workforce training and access
- Train staff on protected health information, including why device identifiers and serial numbers can be PHI.
- Apply role-based access and the minimum necessary standard for payment and operations tasks.
Documentation and retention
- Standardize an implant log that captures the UDI in the patient record and supports recalls and audits.
- Follow applicable retention rules for medical records and ensure timely, documented destruction of transitory notes.
Physical and technical safeguards
- Secure paper documents in locked areas, use clean-desk practices, and place shred bins near ORs and PACU.
- Prefer barcode scanning into the EHR to reduce transcription errors and stray paper.
Vendor and data governance
- Execute business associate agreements where appropriate and verify vendors’ safeguards for any PHI they handle.
- For analytics, use de-identified data or limited data sets with a data use agreement, excluding device identifiers and serial numbers.
Bottom line
It is acceptable to record implant serial numbers on paper during glaucoma MIGS cases when necessary, but treat those numbers as PHI whenever they can be linked to a patient. Prefer capturing the UDI directly into the medical record, limit what appears on reusable preference cards, secure any paper you do use, and follow de-identification rules for analytics.
FAQs.
What constitutes protected health information under HIPAA?
Protected health information is individually identifiable health information related to a patient’s health, care, or payment. If a data point identifies a person directly or in combination with other data—such as a name, MRN, or a device serial number linked to that person—it is PHI and must be safeguarded.
Can implant serial numbers be recorded on paper without violating HIPAA?
Yes. You may write serial numbers on case documents used for treatment or operations, as long as you secure the paper, restrict access, and promptly capture the information in the medical record or implant log. If the document contains patient identifiers, treat it as PHI and store or destroy it according to policy.
What are the de-identification requirements for device data?
Under Safe Harbor, you must remove specific identifiers, including device identifiers and serial numbers, to create de-identified data. If you need to retain device-level detail, use Expert Determination with strong controls, or rely on a limited data set that still excludes device identifiers and serial numbers.
How should ASCs handle device identifiers to remain HIPAA compliant?
Capture the UDI in the patient’s record for clinical accuracy and tracking, restrict who can access documents pairing device data with patient identifiers, and avoid storing PHI on reusable preference cards. For analytics, exclude serial numbers or de-identify data, and maintain clear policies for storage, access, and destruction of paper records.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.