Preference Card Theft in Glaucoma MIGS ASCs: Preventing Exposure of Implant Serials and Patient Names

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Preference Card Theft in Glaucoma MIGS ASCs: Preventing Exposure of Implant Serials and Patient Names

Kevin Henry

Risk Management

September 13, 2026

6 minutes read
Share this article
Preference Card Theft in Glaucoma MIGS ASCs: Preventing Exposure of Implant Serials and Patient Names

Preference cards drive efficiency in minimally invasive glaucoma surgery (MIGS), yet they can also leak protected health information (PHI) and device details if handled carelessly. Theft or photography of cards exposes implant serials and patient names, creating clinical, legal, and reputational risks.

This guide shows you how to harden processes in ambulatory surgery centers (ASCs) so preference card confidentiality is preserved. You will learn practical steps for implant serial number security, patient identifier protection, and surgical safety—without slowing down your glaucoma workflow.

Managing Sensitive Data in Preference Cards

Apply data minimization

Keep preference cards procedural, not patient-specific. List implant categories or models, but never preprint patient names, dates of birth, or full serials. Store unique serial numbers only in the electronic health record (EHR) and inventory system, linked to the case at the point of use.

Segment where identifiers live

Use a scheduling or case ID on pick lists to stage supplies. Keep patient identifiers inside the chart and on wristbands—not on cards that circulate in workrooms. This separation strengthens patient identifier protection while preserving efficiency.

Secure paper cards

  • Issue numbered cards; require sign-out/sign-in and end-of-day reconciliation.
  • Lock storage when unattended; ban personal-device photography in staging areas.
  • Shred outdated cards immediately; never discard in regular trash.

Secure electronic cards

  • Restrict screenshots/printing; watermark exports with user, date, and case ID.
  • Apply document-level permissions and auto-expiration after the case day.
  • Log all views/prints to enable unauthorized access auditing.

Glaucoma MIGS workflow tips

Stage likely implants (e.g., iStent, Hydrus, XEN) by model only. Scan the package at the sterile field to capture the serial into the EHR just-in-time, preserving implant serial number security without exposing it on preference materials.

Implementing Access Controls

Role-based and least-privilege controls

Design ASC data access controls so staff only see what they need. Surgeons view and edit their cards; sterile processing sees supply details; front desk never sees implants. Block export rights for most roles; require justification for temporary elevation.

Strong authentication and session hygiene

  • Enforce unique IDs, multifactor authentication, and short session timeouts.
  • Auto-lock workstations in pre-op/OR; prohibit shared logins and generic badges.
  • Use device encryption and remote wipe on laptops and tablets.

Provisioning discipline

Automate onboarding/offboarding with immediate deprovisioning on role change. Review active accounts monthly and revoke stale access, especially for agency staff and vendor reps.

Vendor and rep safeguards

Give reps escorted, read-only access limited to formulary and inventory—not patient data or preference cards. Prohibit photography in OR cores and supply rooms; require signed confidentiality acknowledgments.

Conducting Regular Security Audits

Build actionable logs

Capture who accessed which preference card, when, from which device, and whether they printed or exported it. Tag each event to a case ID to speed investigation.

Perform unauthorized access auditing

  • Weekly: flag off-hours access, bulk views, and repeated print attempts.
  • Monthly: sample charts to confirm serials exist only in the EHR, not cards.
  • Quarterly: reconcile card inventories; investigate missing numbers immediately.

Measure and improve

  • KPIs: time-to-deprovision, number of export attempts blocked, audit exceptions closed.
  • Run tabletop drills for “lost card” and “photo incident” with clear escalation paths.

Encrypting Electronic Records

Protect data at rest

Encrypt servers, databases, and device storage using HIPAA data encryption standards (e.g., strong AES at rest). Apply encryption to scanned preference cards and any cached files on endpoints.

Protect data in transit

Use modern TLS for EHR and document portals. Disable legacy protocols and restrict access to trusted networks or VPN with MFA.

Key management and backups

Centralize keys with rotation, least-privilege access, and hardware-backed storage. Encrypt backups and test restores regularly to prevent silent data exposure.

Mobile and removable media

Block copying to USB by default; manage phones and tablets with MDM. If clinical photography is permitted, route images directly into the EHR, never to personal galleries.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Ensuring HIPAA Compliance

Map safeguards to operations

Align administrative, physical, and technical safeguards to each workflow: policy, training, facility controls, encryption, and auditing. Document your risk analysis and risk management plan annually.

Minimum necessary and BAAs

Apply the minimum necessary standard to preference cards and pick lists. Execute business associate agreements with any vendor that might handle ePHI, including inventory platforms that store implant details.

Breach readiness

Maintain incident response procedures, decision trees for breach notification, and templates for workforce sanctions. Practice reporting timelines so you act quickly if a theft occurs.

Workforce training

Train teams on spotting social engineering, handling paper cards, and reporting lost materials. Reinforce that “a preference card is not a patient chart.”

Using Two Patient Identifiers

What qualifies as identifiers

Use two independent identifiers—such as full name and date of birth or medical record number. Room number or procedure type never counts as an identifier.

Where to verify

Verify in pre-op, at transfer, and during the surgical time-out with the wristband and EHR. Barcode scanning or RFID strengthens accuracy and creates an auditable trail.

Keep identifiers off cards

Do not place names or DOB on preference cards. Rely on the chart and wristband for identity, and use case IDs on staging materials to preserve privacy while maintaining flow.

Preventing Wrong-Site Surgery

Surgical site verification protocols

Adopt standardized site-marking, consent verification, and a formal time-out that confirms patient, procedure, side, and implant model. Empower anyone to “stop the line” for discrepancies.

Time-out essentials for MIGS

  • Confirm laterality with consent, EHR, and wristband; never rely on preference cards.
  • Match the selected implant model to the planned procedure before opening.
  • If imaging guides selection, display and verify it during the time-out.

Marking and documentation

Use unambiguous eye marking and document confirmations in the EHR. Immediately correct any mismatch and re-run the entire time-out before proceeding.

Summary

By minimizing PHI on cards, enforcing robust access controls, auditing relentlessly, encrypting records, and adhering to HIPAA, you protect privacy and strengthen safety. Coupled with two patient identifiers and disciplined time-outs, these steps reduce exposure and prevent wrong-site errors.

FAQs

How can ASCs prevent theft of preference cards?

Control custody with sign-out logs, locked storage, and end-of-day reconciliation. Restrict photography, watermark any permitted prints, and disable screenshots where possible. Train staff to report missing cards immediately and route all disposals through secure shredding.

What measures ensure implant serial numbers remain confidential?

Keep serials out of preference cards and store them only in the EHR and inventory system. Capture the serial by scanning at the sterile field, limit who can view or export it, and audit all access. Use role-based controls and encryption to maintain implant serial number security end to end.

How does HIPAA regulate patient data in ASCs?

HIPAA requires administrative, physical, and technical safeguards to protect ePHI. In practice, that means documented risk analysis, minimum necessary access, encryption, workforce training, audit controls, breach response, and business associate agreements for vendors handling PHI.

What are the requirements for patient identifiers in surgical procedures?

Verify the correct patient using two independent identifiers—commonly full name plus date of birth or medical record number—during pre-op checks, transfers, and the surgical time-out. Do not use room number or procedure type as identifiers, and avoid printing identifiers on preference cards.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles