Phase 6: Engagement Execution
Applies to: All staff who conduct, record, or document participant engagement activities including interviews, advisory boards, panels, meetings, and surveys
Sequence note: Phases 0-4 sequential; phase 10 anytime; not all phases apply
What you'll learn
- Apply the required activity definition, recording consent, and PHI-minimization controls during every engagement session
- Handle notes, recordings, and file transfers using only approved tools, storage locations, and communication channels
- Recognize and avoid prohibited practices including unapproved AI transcription tools, personal device use, unencrypted PHI email, and PHI in subject lines
Lesson
Step 1 - Define and Approve the Engagement Activity
All engagement activities - interview, advisory board, panel, meeting, or survey - must be defined and approved before they take place. The definition must cover the type of content, purpose, distribution channels, and intended audience.
Source: slide 20 - Patient Content Creation and Media Handling_Final_8-2026
Step 2 - Announce Recording and Re-Confirm Consent
At the start of any recorded session, announce that the session is being recorded and re-confirm the participant's consent to record before proceeding. Do not start the recording until consent is re-confirmed.
Source: slide 20 - Patient Content Creation and Media Handling_Final_8-2026
Minimize PHI Capture During the Session
Do not record or document more health information than is needed for the specific program purpose. If a participant shares clinical details that are not relevant to the engagement, do not include them in notes or records.
Source: slide 20 - PHI Handling and HIPAA Safeguards_Final_8-2026
Step 3 - Secure Notes and Recordings Within 24 Hours
Upload all notes and recordings to the participant's SharePoint folder within 24 hours of the session. Remove all content from local devices as soon as the transfer is complete.
Source: slide 20 - Patient Data Storage and Access Control_Final_8-2026
AI Transcription - Approved Tools Only; Otter.ai Prohibited
Only transcription tools listed on the IT Approved Systems Register may be used. Otter.ai is explicitly prohibited for any workflow. No AI transcription or generative AI tool may be used for PHI processing unless expressly approved by IT, Privacy, and Legal.
Source: slide 20 - IT Approved Systems Register for the Patient Engagement Program_Final_8-2026
Physical Safeguards for Onsite Sessions
All content must be captured and handled on secure, organization-managed workstations only. Access to recording equipment must be controlled and limited to authorized personnel. Editing or handling content on personal devices or unapproved platforms is prohibited.
Source: slide 20 - Patient Content Creation and Media Handling_Final_8-2026
Internal Teams Messages - Use Subject ID, Not Patient Name
Use the participant's subject ID (not their name) in all Teams messages, meeting invites, and internal trackers. Do not share patient details, health information, or identifying information in general or public Teams channels.
Source: slide 21 - PHI Handling and HIPAA Safeguards_Final_8-2026
Encrypting Email That Contains PHI
To encrypt an email containing PHI, add the word 'Encrypt', '[Encrypt]', 'Secure', or '[Secure]' to the subject line. This triggers Microsoft 365 encryption so that only the intended recipient can read the message body and attachments. PHI Handling and HIPAA Safeguards Section 9.1 requires encrypted email for PHI transmission.
Source: slide 21 - Quick Guide - Email_Encryption_User_Guide
Never Place PHI in Email Subject Lines
Never place PHI in email subject lines. Even when the email body is encrypted, the subject line is not encrypted and can be read by email servers and administrators along the delivery path.
Source: slide 21 - Quick Guide - Email_Encryption_User_Guide
File Transfers - Logging and Approved Channels Only
All file downloads and transfers must be logged through DLP (Data Loss Prevention) monitoring. Use SharePoint for all file sharing. Personal cloud storage - including Google Drive, Dropbox, iCloud, or any unapproved platform - is prohibited.
Source: slide 21 - Patient Data Storage and Access Control_Final_8-2026
Scenario
You are a Patient Engagement coordinator running an advisory board session conducted via video call. The session has been defined and approved. You announced the recording at the start, re-confirmed consent, and began recording. Midway through, a participant volunteers detailed information about a recent hospitalization that is not relevant to the advisory board topic. After the session, you need to take notes, store materials, and email a summary to an internal colleague. You draft an email with the subject line: 'Advisory Board Summary - [Participant Name] - Diabetes History'.
The participant volunteers clinical details about a recent hospitalization that are not relevant to the advisory board topic. What should you do?
Incorrect. Voluntary disclosure does not change the minimum-necessary rule. You must not document health information beyond what is needed for the specific program purpose.
Incorrect. The minimum-necessary requirement applies to all records and recordings. Irrelevant clinical details must not be captured in any form.
Correct. The minimum-necessary standard requires that you not record or document more health information than is needed for the program purpose. Irrelevant clinical details must be excluded from all notes and records.
Incorrect. Soliciting or re-capturing irrelevant clinical details compounds the violation. The correct action is to exclude them from all records.
You are about to send the internal email with the subject line: 'Advisory Board Summary - [Participant Name] - Diabetes History'. What is the correct action?
Incorrect. Internal recipients do not remove the PHI email requirement. PHI transmission requires encrypted email per PHI Handling and HIPAA Safeguards Section 9.1, and PHI must never appear in a subject line.
Correct. Two separate rules apply: (1) PHI must never appear in the subject line because subject lines are not encrypted; (2) the email body containing PHI must be encrypted by adding an approved keyword such as 'Secure' or 'Encrypt' to the subject line. The name and diagnosis must be removed from the subject.
Incorrect. Adding '[Encrypt]' triggers encryption of the body, but it does not protect the subject line itself. The participant's name and diagnosis in the subject line remain visible to email servers and administrators along the delivery path - this is a PHI exposure.
Incorrect. Teams does not exempt you from PHI-handling requirements. All internal messages must also use subject IDs rather than participant names, and Teams channels have their own restrictions.
Knowledge Check
Select an answer to see feedback. This is practice - it does not affect your score.
Before an engagement session begins, what must happen regarding the recording?
Incorrect. Recording cannot begin automatically. The announcement and re-confirmation of consent must occur before recording starts.
Correct. At the start of any recorded session, the coordinator must announce that the session is being recorded and re-confirm the participant's consent before proceeding.
Incorrect. A prior written form does not satisfy the in-session requirement. The announcement and re-confirmation must happen at the start of the session.
Incorrect. Prior consent does not eliminate the in-session announcement requirement. Consent must be re-confirmed at the start of every recorded session.
A staff member wants to use Otter.ai to transcribe a recorded advisory board session. What is the correct response?
Correct. Otter.ai is explicitly prohibited for any workflow. Only transcription tools listed on the IT Approved Systems Register may be used.
Incorrect. Recording consent does not authorize the use of prohibited tools. Otter.ai is explicitly prohibited regardless of consent status.
Which of the following correctly describes how to send an email containing PHI to an internal colleague?
Incorrect. Even with '[Encrypt]' in the subject, the subject line itself is not encrypted and any PHI in it is exposed along the delivery path.
Incorrect. A ZIP file attachment does not satisfy the Microsoft 365 encryption requirement, which is triggered by an approved keyword in the subject line.
Correct. PHI must never appear in the subject line. Adding an approved keyword such as 'Secure', '[Secure]', 'Encrypt', or '[Encrypt]' to the subject line triggers Microsoft 365 encryption of the body and attachments.
Incorrect. PHI Handling and HIPAA Safeguards Section 9.1 requires encrypted email for PHI transmission regardless of whether the recipient is internal or external.
Key Controls Recap
- [RULE] Step 2 - Announce Recording and Re-Confirm Consent
- [RULE] Minimize PHI Capture During the Session
- [RULE] Step 3 - Secure Notes and Recordings Within 24 Hours
- [WATCH OUT] AI Transcription - Approved Tools Only; Otter.ai Prohibited
- [WATCH OUT] Physical Safeguards for Onsite Sessions
- [RULE] Internal Teams Messages - Use Subject ID, Not Patient Name
- [WATCH OUT] Never Place PHI in Email Subject Lines
- [WATCH OUT] File Transfers - Logging and Approved Channels Only
You've completed the Phase 6 learning module.
Return to Dayforce and take the Phase 6 quiz.