
Burn Navigator® User’s Manual
Page 35
Security and Privacy Safeguards & Best Practices
The Burn Navigator should be used and handled in a manner that protects the privacy of
patients. You may have an obligation to do so by law. Burn Navigator implements various
technical and operational safeguards to assist in keeping data secure and reduce the
likelihood and severity of any breach; however, these are not foolproof and must be coupled
with other best practices.
Following is a non-exhaustive list of security features implemented by the Burn Navigator.
1.
Patient data is stored on the device in an encrypted format.
2.
Access to potentially insecure functions of the operating system is restricted.
3.
The app does not transmit or receive any patient information over a network, except
during a user-initiated handoff procedure, and only to the extent necessary to support
such functions.
4.
When a patient record is transferred to Burn Nav Web, it is sent over a secure HTTPS
connection.
5.
Burn Navigator does not require entry of any identifying patient information. The
“Patient ID” label can be changed to “Cite ID” to emphasize this. The software will
automatically record the dates and times of various events during resuscitation;
however, dates are kept for internal purposes only and are not displayed to the user.
6.
It is possible to permanently delete patient records after resuscitation has ended.
7.
The device can optionally be configured to require a PIN or password to access the
software.
We believe that Burn Navigator patient records, as stored on the device and displayed to
users, can be treated as de-identified data, provided that no personally identifying
information is entered into the Burn Navigator during resuscitation.
Bluetooth handoff communications are unencrypted and should be considered insecure. You
should not use Bluetooth handoff with records containing secret or sensitive information,
unless you are certain that the communications will not be intercepted.
It is assumed that organizations will have appropriate physical access controls in place to
protect the device against theft or access by unauthorized persons.
Arcos
does not
enter into a business associate agreement with you or your organization
solely by virtue of your purchase and/or use of the Burn Navigator tablet.
If you have security or privacy questions, please contact us at