I often get asked about how to positively identify a patient in a consumer or kiosk setting (shared computer environments also). For example, if a patient comes in and you want to hand them a computer to do some data entry with, how would be able to positively identify the patient as a specific person? And, you need to be able to do this without “logging them in” or require them to remember a password.
Basically, for this kind of requirement I’ve been recommending folks use the kind of security that credit bureaus do to identify people who want their credit scores (banks want you to know who they are, credit bureaus need to know who you are). So, if you want to sign me into a kiosk but need to verify my information you could present a screen such as the following:
1. What is your name? _________ (I would type in “Shahid Shah”)
2. If you found my name in the database, you could present another screen with the following types of questions.
Please verify your current address:
* choice A (an address like ‘2313 anywhere street’)
* choice B (an address like ‘4717 another street’)
* choice C (an address like ‘6616 anywhere boulevard’)
Please verify your current employer:
* choice A
* choice B
* choice C
You can ask a set of 3 or 4 questions and provide information from their last visit (submission) instead of or in addition to a password. The types of questions to ask and the choices you want to provide would be determined by how secure you want the system to be and how “Positive” your PPID (positive patient ID) requirements happen to be.
If you’ve used other techniques, please share!