Top Priorities for Internal Auditors in U.S. Healthcare Provider Organizations

Size: px
Start display at page:

Download "Top Priorities for Internal Auditors in U.S. Healthcare Provider Organizations"

Transcription

1 Top Priorities for Internal Auditors in U.S. Healthcare Provider Organizations Key Areas for Improvement Include Compliance, Information Security, Social Media and Quality Assurance

2 INTRODUCTION Historic disruption. Risk-based contracting. Value-based purchasing. Population health management. Continuum of care. New operating models. Acquiring physician practices. Securing PHI. Connectivity and integration. Improving the patient experience. Fundamental transformation The U.S. healthcare industry is facing a number of critical and transformational questions: How do we maintain and increase profit margins in the face of declining reimbursements? How do we keep pace with new regulatory compliance requirements and new risks? How do we improve IT system integration and connectivity inside and outside the company? How do we identify acquisition targets that augment our capabilities and support our strategic objectives? The answers inevitably create new questions, and big challenges, for internal audit functions in healthcare organizations, which must ensure that new structures, processes, partners, data and IT systems are harmonious with organizational risk appetites. Not surprisingly, a 014 survey conducted by North Carolina State University s ERM Initiative and Protiviti concludes that healthcare organizations perceive themselves to be facing the greatest amount of risk relative to all other industries. 1 The results of the 014 Internal Audit Capabilities and Needs Survey of Healthcare Provider Organizations from AHIA and Protiviti underscore this point. They present a portrait of a healthcare internal audit function that is intent on delivering assurance across multiple risk realms while simultaneously enhancing the efficiency and quality of their heavy workloads. Our results indicate that healthcare internal audit functions are concentrating their attention and resources in four key areas of priority, which we discuss further in our report: 1. Mastering regulatory risk and cost containment. Strengthening information security and risk management. Introducing more auditing automation and greater effectiveness 4. Partnering and persuading 1 Executive Perspectives on Top Risks for 014, North Carolina State University s ERM Initiative and Protiviti, 1

3 About the Survey Protiviti conducts its Internal Audit Capabilities and Needs Survey annually to assess current skill levels of internal audit executives and professionals, identify areas in need of improvement and help stimulate the sharing of leading practices throughout the profession. This year, survey respondents answered close to 150 questions in the study s three standard categories: General Technical Knowledge, Audit Process Knowledge, and Personal Skills and Capabilities. In each category, respondents were asked to assess, on a scale of one to five, their competency in the different skills and areas of knowledge, with 1 being the lowest level of competency and 5 being the highest. They were then asked to indicate whether they believe they possess an adequate level of competency or if there is need for improvement, taking into account the circumstances of their organization and the nature of the healthcare industry. Respondents also answered a separate set of questions in a special section, Social Media Risk and the Audit Process. The overall results, which are based on information provided by all respondents (who numbered more than 600), are contained within the master report (available at Respondents from healthcare providers who comprise 14 percent (n=85) of the survey participants also answered questions in a unique section featuring internal audit areas specific to the healthcare industry. AHIA and Protiviti partnered to analyze these results and produce this report in order to equip internal audit executives and professionals in the healthcare industry with more targeted insights about the unique challenges within their domains.

4 MASTERING REGULATORY RISK AND COST CONTAINMENT Addressing regulatory risk is a challenging, yet important and necessary, objective. CAEs and their staffs appear to recognize the need to gain an in-depth understanding of new regulatory compliance requirements to assist their organizations effectively in managing this risk. The introduction of many new regulatory compliance requirements makes plain that mastery requires, first and foremost, keeping informed of them. Healthcare information exchanges (HIE), ediscovery and Meaningful Use compliance, respectively, represent three of the most important need to improve areas within the healthcare-specific technical knowledge category (see Tables 1 and ). Need to Improve Rank Table 1: Healthcare Industry-Specific Technical Knowledge Overall Results Areas Evaluated by Respondents Competency (5-pt. scale) 1 Health information exchanges.8 4 ediscovery. Meaningful Use compliance.8 Coding knowledge (ICD-9, ICD-10, HCC, HCPCS, CPT).5 Healthcare joint ventures.8 Physician compensation methodologies (e.g., wrvu).7 Risk pool/capitation accounting.4 Cost containment labor and non-labor.8 Delivery System Reform Incentive Payment (DSRIP) program.1 Hospital value-based purchasing.9 ICD-10 impact, readiness and implementation.9 Medicare Modernization Act.4 State-specific prompt payment laws.5 State-specific privacy/security laws.7 Of note, while respondents to our 01 survey did not identify Meaningful Use compliance among their top priorities for improvement, it returns as a top priority this year (as it was in 01 see Table ).

5 Need to Improve Rank Table : Healthcare Industry-Specific Technical Knowledge CAE Results Areas Evaluated by Respondents Competency (5-pt. scale) 1 Health information exchanges.8 IRB and clinical trials. Meaningful Use compliance.1 Physician compensation methodologies (e.g., wrvu).0 Case management.0 Coding knowledge (ICD-9, ICD-10, HCC, HCPCS, CPT).8 Delivery System Reform Incentive Payment (DSRIP) program. ediscovery.6 Healthcare joint ventures. Pandemic planning/business continuity.8 Physician organizations. Risk pool/capitation accounting.8 Many, but not all, of the compliance-related priorities identified by this year s survey respondents stem from the Patient Protection and Affordable Care Act (ACA), a primary catalyst driving the proliferation of risks throughout the industry and, by extension, internal audit workloads that include auditing, monitoring and consulting activities related to the strategic challenges healthcare provider organizations are facing. Other compliance requirements that qualify as internal audit priorities include ICD-10, state-specific prompt-payment laws and state-specific privacy/security laws. Additionally, our respondents revealed that their healthcare-specific general technical knowledge objectives extend beyond compliance into strategic and operational issues, such as healthcare joint ventures, cost containment and hospital value-based purchasing. 4

6 Table : Healthcare Industry-Specific Technical Knowledge Overall Results, Three-Year Comparison Health information exchanges Health information exchanges Meaningful Use compliance ediscovery Value-based purchasing Health information exchanges Meaningful Use compliance ICD-10 implementation Accountable care organizations Coding knowledge (ICD-9, ICD-10, HCC, HCPCS, CPT) Payment bundling Electronic health records Healthcare joint ventures Accountable care organizations ICD-10 readiness Physician compensation methodologies (e.g., wrvu) Risk pool/capitation accounting Cost containment labor and non-labor Delivery System Reform Incentive Payment (DSRIP) Program Hospital value-based purchasing ICD-10 impact, readiness and implementation Medicare Modernization Act State-specific prompt payment laws State-specific privacy/security laws Clinical documentation ICD-10 impact and readiness Pay-for-performance quality standards (CMS core measures and HCAHPS) State-specific privacy/security laws Coding (CPT, ICD-9) Patient Protection and Affordable Care Act provisions Clinical systems = Three-year trend Table 4: Healthcare Industry-Specific Technical Knowledge CAE Results, Three-Year Comparison Health information exchanges Health information exchanges Accountable care organizations IRB and clinical trials Payment bundling Health information exchanges Meaningful Use compliance ICD-10 implementation Electronic health records Physician compensation methodologies (e.g., wrvu) Pay-for-performance quality standards (CMS core measures and HCAHPS) Meaningful Use compliance Case management Physician credentialing ICD-10 readiness Coding knowledge (ICD-9, ICD-10, HCC, HCPCS, CPT) Delivery System Reform Incentive Payment (DSRIP) program ediscovery Value-based purchasing Durable medical equipment ediscovery Healthcare joint ventures HIPAA 5010 Pandemic planning/business continuity Physician organizations Risk pool/capitation accounting Physician alignment and employment strategies Physician organizations Professional fee billing Quality of care Hospital billing IRB and clinical trials Managed care contracting = Three-year trend 5

7 STRENGTHENING INFORMATION SECURITY AND RISK MANAGEMENT Technology primarily in the form of data and the applications in which the data resides represents an increasingly crucial component of an effective organizational risk management capability. Healthcare data and information must be kept secure and private amid growing cybersecurity risks as well as the growing need to exchange patient data with external partners (e.g., insurers and pharmacies) and other entities (e.g., HIEs). The strength of information security and the quality of enterprise risk management in healthcare organizations are complicated by the emergence of new and disruptive technologies first and foremost, social media and mobile applications as well as new forms of guidance related to managing and communicating these risks. Both the risks internal auditors are addressing and the way they are addressing them are changing. Need to Improve Rank 1 Table 5: General Technical Knowledge Overall Healthcare Industry Results Areas Evaluated by Respondents Competency (5-pt. scale) Recently enacted IIA Standard: Overall Opinions (Standard 450).9 Social media applications.8 Mobile applications Recently enacted IIA Standard: Audit Opinions and Conclusions (Standards 010.A and 410.A1) GTAG 16 Data Analysis Technologies.0 NIST Cybersecurity Framework. GTAG 6 Managing and Auditing IT Vulnerabilities.7 GTAG 15 Information Security Governance.9 Recently enacted IIA Standard Functional Reporting Interpretation (Standard 1110) GTAG 10 Business Continuity Management.9 ISO 7000 (information security).4 Reporting on Controls at a Service Organization SSAE 16/AU 4 (replaces SAS 70) Several recently enacted standards from The Institute of Internal Auditors (The IIA) such as Standards 450, 010.A, 410.A1, and 1110 figure as top priorities (see Table 5). Most of these standards provide guidance as to how internal auditors communicate and present their work, including unfavorable findings, to their business partners. The updated Standard 1110 outlines the functional reporting structures and activities that should be in place (e.g., having the CAE report functionally to the board of directors, having the board review and approve the risk-based audit plan, etc.) to achieve organizational independence while enabling the function to fulfill its growing list of risk-related responsibilities. Of note, a majority of the top priority areas survey respondents cited in the General Technical Knowledge category relate to technology. The same holds true to an even greater extent, in fact for CAE respondents (see Table 6). 6

8 Table 6: General Technical Knowledge Healthcare Industry CAE Results Need to Improve Rank 1 4 Areas Evaluated by Respondents Competency (5-pt. scale) Mobile applications.7 NIST Cybersecurity Framework.5 Social media applications.7 Cloud computing.7 ISO 7000 (information security).6 GTAG 6 Managing and Auditing IT Vulnerabilities.9 GTAG 15 Information Security Governance.8 GTAG Continuous Auditing.1 GTAG 4 Management of IT Auditing.1 GTAG 9 Identity and Access Management.1 GTAG 10 Business Continuity Management.1 GTAG 14 Auditing User-developed Applications.8 GTAG 16 Data Analysis Technologies. GTAG 17 Auditing IT Governance.0 IT governance.8 The Guide to the Assessment of IT Risk (GAIT).8 Social media, in particular, bears close monitoring as a growing risk. In a separate section of the survey ( Social Media Risk and the Audit Process ), specific types of social media concerns CAEs and their staffs identified include brand/reputational damage, regulatory or compliance violations, employee defamation, data security (company information), data leakage (employee personal information), and viruses and malware, respectively (see Figure 1). Figure 1: Top Social Media Risks (10-point scale) Overall Healthcare Industry Results Brand/reputational damage 7. Regulatory and compliance violations 6.8 Employee defamation 6.4 Data security (company information) 5.5 Data leakage (employee personal information) Viruses and malware.9 Interrupted business continuity.6 Loss of employee productivity.8 Loss of intellectual property.4 Financial loss

9 Table 7: General Technical Knowledge Overall Results, Three-Year Comparison Recently enacted IIA Standard: Overall Opinions (Standard 450) Cloud computing Social media applications Social media applications GTAG 16 Data Analysis Technologies Cloud computing Mobile applications ISO 7000 (information security) GTAG 16 Data Analysis Technologies Recently enacted IIA Standard: Audit Opinions and Conclusions (Standards 010.A and 410.A1) GTAG 16 Data Analysis Technologies GTAG 17 Auditing IT Governance Social media applications Fraud risk management GTAG 1 Fraud Prevention and Detection in an Automated World NIST Cybersecurity Framework Fraud risk management GTAG Continuous Auditing GTAG 6 Managing and Auditing IT Vulnerabilities GTAG 15 Information Security Governance Recently enacted IIA Standard Functional Reporting Interpretation (Standard 1110) Recently enacted IIA Standard Functional Reporting Interpretation (Standard 1110) GTAG 10 Business Continuity Management ISO 7000 (information security) Reporting on Controls at a Service Organization SSAE 16/AU 4 (replaces SAS 70) IT governance GTAG 1 Auditing IT Projects = Three-year trend 8

10 INTRODUCING MORE AUDITING AUTOMATION AND GREATER EFFECTIVENESS The growing importance of information security and privacy in determining overall risk management effectiveness is evident in the realm of Audit Process Knowledge in our survey, which covers the insights, techniques and technology internal auditors deploy to improve their work continuously. In this area, various types of IT audits feature as prominent priorities, including auditing new technologies, program development, security, computer operations and continuity (see Tables 8 and 9). Need to Improve Rank 1 Table 8: Audit Process Knowledge Overall Healthcare Industry Results Areas Evaluated by Respondents Quality Assurance and Improvement Program (IIA Standard 100) Periodic Reviews (IIA Standard 111) Competency (5-pt. scale) Statistically based sampling.7 Auditing IT new technologies.9 Marketing internal audit internally. Auditing IT program development.0 Auditing IT security.0 Computer-assisted audit tools (CAATs).4 Quality Assurance and Improvement Program (IIA Standard 100) External Assessment (Standard 11) 4 Assessing risk emerging issues In addition to focusing closely on the IT function, internal auditors are concentrating on improving the quality of their work. Survey respondents identified as priorities components of the update to The IIA s International Standards for the Professional Practice of Internal Auditing that took effect in early 01. The update consists of 18 revisions that are designed to strengthen internal audit s effectiveness. Our respondents cited a desire to learn more about the updated Standards, particularly by increasing their focus on the Quality Assurance and Improvement Program and its guidance regarding external assessments as well as ongoing and periodic reviews. Our respondents also expressed a desire to enhance their fraud-prevention efforts, along with all of their other work, by introducing more automation to their endeavors, in the form of practices like statistically based sampling and computer-assisted audit tools (CAATs). 9

11 Table 9: Audit Process Knowledge Healthcare Industry CAE Results Need to Improve Rank 1 Areas Evaluated by Respondents Competency (5-pt. scale) Auditing IT new technologies. Auditing IT security. Marketing internal audit internally.8 Assessing risk emerging issues.8 Quality Assurance and Improvement Program (IIA Standard 100) External Assessment (Standard 11) Quality Assurance and Improvement Program (IIA Standard 100) Periodic Reviews (IIA Standard 111) Statistically based sampling.6 Auditing IT change control.6 Auditing IT computer operations.6 Auditing IT continuity.5 Auditing IT program development.4 Data analysis tools data manipulation.6 Data analysis tools statistical analysis Table 10: Audit Process Knowledge Overall Results, Three-Year Comparison Quality Assurance and Improvement Program (IIA Standard 100) Periodic Reviews (IIA Standard 111) Statistically based sampling Auditing IT new technologies Marketing internal audit internally Data analysis tools data manipulation Quality Assurance and Improvement Program (IIA Standard 100) External Assessment (IIA Standard 11) Quality Assurance and Improvement Program (IIA Standard 100) Ongoing Reviews (IIA Standard 111) Quality Assurance and Improvement Program (IIA Standard 100) Periodic Reviews (IIA Standard 111) CAATs Continuous auditing Continuous monitoring Data analysis tools data manipulation Auditing IT program development Fraud fraud risk assessment Data analysis tools sampling Auditing IT security Enterprisewide risk management Data analysis tools statistical analysis CAATs Fraud monitoring Marketing internal audit internally Quality Assurance and Improvement Program (IIA Standard 100) External Assessment (Standard 11) Assessing risk emerging issues Assessing risk emerging issues Fraud auditing Fraud fraud detection/investigation Fraud fraud risk assessment 10

12 PARTNERING AND PERSUADING During periods of significant change and disruption, it is critical for internal auditors to develop, sustain and strengthen effective relationships at all levels of the organization and beyond the company, as well. Within rapidly changing organizational environments, internal auditors must persuade their colleagues throughout the business to operate in a risk-savvy manner. The desire for this type of partnership and persuasion is evident in our survey results (see Tables 11 and 1). As discussed in a recent issue of The Bulletin from Protiviti, internal auditors must collaborate effectively with other independent functions focused on managing risk and compliance. Collaboration is a vital skill on many fronts in any discipline, and especially for internal audit. Of necessity, auditors should undertake a collaborative approach with independent risk management and compliance functions to coordinate roles, responsibilities and assurance plans, as well as share risk information and available resources. Further, in Protiviti s recent editions of Internal Auditing Around the World (specifically, Volumes 9 and 10), internal audit leaders in numerous companies cite the critical importance of collaboration and partnerships in their organizations, which serve to enhance the effectiveness of their internal audit functions and processes. Need to Improve Rank Table 11: Personal Skills and Capabilities Overall Healthcare Industry Results Areas Evaluated by Respondents Competency (5-pt. scale) 1 Presenting (public speaking).5 Developing other board committee relationships.4 Developing outside contacts/networking.8 Leadership (within your organization).6 Persuasion.6 Time management.7 Using/mastering new technology and applications.7 Dealing with confrontation.6 Developing audit committee relationships.5 Negotiation.6 For all respondents as well as CAEs, the lists of priorities in this category are dominated by skills such as developing relationships, negotiation, persuasion and presenting. Clearly, effective collaboration and partnerships are viewed as critical components for internal auditors in healthcare organizations as they address the many other priorities identified and discussed earlier in our report. The Bulletin, Volume 5, Issue 6, The Future Auditor: The Chief Audit Executive s Endgame, available at For more information about Protiviti s Internal Auditing Around the World series, visit World.aspx. 11

13 Need to Improve Rank Table 1: Personal Skills and Capabilities Healthcare Industry CAE Results Areas Evaluated by Respondents Competency (5-pt. scale) 1 Using/mastering new technology and applications.7 4 Developing audit committee relationships 4. Developing other board committee relationships 4.0 Developing outside contacts/networking 4. Negotiation.8 Presenting (public speaking) 4.1 High-pressure meetings.8 Persuasion 4.0 Creating a learning internal audit function 4. Dealing with confrontation 4.0 Developing rapport with senior executives 4. Leadership (within your organization) 4. Strategic thinking 4. Time management.9 Table 1: Personal Skills and Capabilities Overall Results, Three-Year Comparison Presenting (public speaking) Presenting (public speaking) Developing outside contacts/networking Developing other board committee relationships High-pressure meetings Leadership (within your organization) Developing outside contacts/networking Dealing with confrontation Negotiation Leadership (within your organization) Persuasion Dealing with confrontation Persuasion Time management Using/mastering new technology and applications Dealing with confrontation Developing audit committee relationships Negotiation Using/mastering new technology and applications Persuasion High-pressure meetings = Three-year trend 1

14 IN CLOSING While the burden of the healthcare industry s ACA compliance remains, a weighty collection of interconnected technology and strategy concerns are adding to these already significant burdens. As the very strategy and structure of healthcare provider organizations undergo major changes in the coming year, it will be increasingly important for CAEs and their internal auditing functions to keep their eyes on their priority lists, regardless of how long those lists become. 1

15 ABOUT AHIA Founded in 1981, the Association of Healthcare Internal Auditors (AHIA) is a network of experienced healthcare internal auditing professionals who come together to share tools, knowledge and insight on how to assess and evaluate risk within a complex and dynamic healthcare environment. AHIA is an advocate for the profession, continuing to elevate and champion the strategic importance of healthcare internal auditors with executive management and the board. If you have a stake in healthcare governance, risk management and internal controls, AHIA is your one-stop resource. Explore our website ( for more information. If you are not a member, please join our network. Contact Heidi Crosby AHIA Board Chair ABOUT PROTIVITI Protiviti ( is a global consulting firm that helps companies solve problems in finance, technology, operations, governance, risk and internal audit, and has served more than 40 percent of FORTUNE 1000 and FORTUNE Global 500 companies. Protiviti and its independently owned Member Firms serve clients through a network of more than 70 locations in over 0 countries. The firm also works with smaller, growing companies, including those looking to go public, as well as with government agencies. Protiviti is a wholly owned subsidiary of Robert Half (NYSE: RHI). Founded in 1948, Robert Half is a member of the S&P 500 index. Contacts Brian Christensen Executive Vice President Global Internal Audit brian.christensen@protiviti.com Susan Haseley Managing Director Healthcare Industry Leader susan.haseley@protiviti.com 14

16 Education Networking Resources Protiviti is not licensed or registered as a public accounting firm and does not issue opinions on financial statements or offer attestation services Protiviti Inc. An Equal Opportunity Employer M/F/D/V. PRO-0814-PKIC097

Top Priorities for Internal Auditors in U.S. Healthcare Provider Organizations

Top Priorities for Internal Auditors in U.S. Healthcare Provider Organizations Top Priorities for Internal Auditors in U.S. Healthcare Provider Organizations Key Areas for Improvement Include Compliance, Social Media and Quality Assurance Activities INTRODUCTION In January 01, healthcare

More information

Priorities for Internal Auditors in U.S. Healthcare Provider Organizations. Chief Concerns Include Cybersecurity, Regulatory Compliance and Fraud

Priorities for Internal Auditors in U.S. Healthcare Provider Organizations. Chief Concerns Include Cybersecurity, Regulatory Compliance and Fraud Priorities for Internal Auditors in U.S. Healthcare Provider Organizations Chief Concerns Include Cybersecurity, Regulatory Compliance and Fraud INTRODUCTION Technology is a double-edged sword. From an

More information

Top Priorities for Internal Audit in Healthcare Provider Organizations

Top Priorities for Internal Audit in Healthcare Provider Organizations Top Priorities for Internal Audit in Healthcare Provider Organizations Assessing Healthcare Industry Results from the 202 Internal Audit Capabilities and Needs Survey INTRODUCTION The best gamblers typically

More information

From Cybersecurity to Collaboration: Assessing the Top Priorities for Internal Audit Functions. 2015 Internal Audit Capabilities and Needs Survey

From Cybersecurity to Collaboration: Assessing the Top Priorities for Internal Audit Functions. 2015 Internal Audit Capabilities and Needs Survey From Cybersecurity to Collaboration: Assessing the Top Priorities for Internal Audit Functions 2015 Internal Audit Capabilities and Needs Survey SECURITY IS, I WOULD SAY, OUR TOP PRIORITY BECAUSE FOR ALL

More information

2013 Internal Audit Capabilities and Needs Survey Report. Assessing the Top Priorities for Internal Audit Functions

2013 Internal Audit Capabilities and Needs Survey Report. Assessing the Top Priorities for Internal Audit Functions 2013 Internal Audit Capabilities and Needs Survey Report Assessing the Top Priorities for Internal Audit Functions Introduction IN THE STRUGGLE FOR SURVIVAL, THE FITTEST WIN OUT AT THE EXPENSE OF THEIR

More information

FPO. 2012 Internal Audit Capabilities and Needs Survey. 1 2012 Internal Audit Capabilities and Needs Survey

FPO. 2012 Internal Audit Capabilities and Needs Survey. 1 2012 Internal Audit Capabilities and Needs Survey FPO 2012 Internal Audit Capabilities and Needs Survey 1 2012 Internal Audit Capabilities and Needs Survey Introduction Technology is crucial to administering and managing the audit process from the beginning

More information

High Value Audits: An Update on Information Technology Auditing. Robert B. Hirth Jr., Managing Director

High Value Audits: An Update on Information Technology Auditing. Robert B. Hirth Jr., Managing Director High Value Audits: An Update on Information Technology Auditing Robert B. Hirth Jr., Managing Director The technology landscape and its impact on internal audit Technology is playing an ever-growing role

More information

PROTIVITI FLASH REPORT

PROTIVITI FLASH REPORT PROTIVITI FLASH REPORT HHS Announces Plans to Reconsider Implementation Timeline for U.S. Healthcare Industry s Transition to ICD-10 February 17, 2012 On Wednesday, February 15, the Department of Health

More information

Continuous Monitoring and Auditing: What is the difference? By John Verver, ACL Services Ltd.

Continuous Monitoring and Auditing: What is the difference? By John Verver, ACL Services Ltd. Continuous Monitoring and Auditing: What is the difference? By John Verver, ACL Services Ltd. Call them the twin peaks of continuity continuous auditing and continuous monitoring. There are certainly similarities

More information

Today s Financial Services IT Organization Delivering Security, Value and Performance Amid Major Transformation

Today s Financial Services IT Organization Delivering Security, Value and Performance Amid Major Transformation Today s Financial Services IT Organization Delivering Security, Value and Performance Amid Major Transformation Assessing the Financial Services Industry Results from Protiviti s 2014 IT Priorities and

More information

PROTIVITI FLASH REPORT

PROTIVITI FLASH REPORT PROTIVITI FLASH REPORT Cybersecurity Framework: Where Do We Go From Here? February 25, 2014 Just over a year ago, President Barack Obama signed an Executive Order (EO) calling for increased cybersecurity

More information

Healthcare Internal Audit: In a Time of Transition

Healthcare Internal Audit: In a Time of Transition The 2015 State of the Internal Audit Profession Study Healthcare Internal Audit: In a Time of Transition The healthcare industry in the United States is facing many challenges with the enactment of legislation

More information

Survey of more than 1,500 Auditors Concludes that Audit Professionals are Not Maximizing Use of Available Audit Technology

Survey of more than 1,500 Auditors Concludes that Audit Professionals are Not Maximizing Use of Available Audit Technology Survey of more than 1,500 Auditors Concludes that Audit Professionals are Not Maximizing Use of Available Audit Technology Key findings from the survey include: while audit software tools have been available

More information

Moving Internal Audit Back into Balance

Moving Internal Audit Back into Balance Moving Internal Audit Back into Balance A Post-Sarbanes-Oxley Survey Fourth Edition Table of Contents Introduction... 1 Executive Summary... 2 Overview of Rebalancing Initiatives... 4 Current Status of

More information

Amid Ongoing Transformation and Compliance Challenges, Cybersecurity Represents Top IT Concern in Financial Services Industry

Amid Ongoing Transformation and Compliance Challenges, Cybersecurity Represents Top IT Concern in Financial Services Industry Amid Ongoing Transformation and Compliance Challenges, Cybersecurity Represents Top IT Concern in Financial Services Industry IT leaders are battening down the hatches, according to Protiviti s latest

More information

FINANCIAL SERVICES FLASH REPORT

FINANCIAL SERVICES FLASH REPORT FINANCIAL SERVICES FLASH REPORT OCC Finalizes Its Heightened Standards for Large Financial Institutions September 15, 2014 Transforming Heightened Expectations to Minimum Standards On September 2, 2014,

More information

Top Priorities for Internal Audit in Telecommunications

Top Priorities for Internal Audit in Telecommunications Top Priorities for Internal Audit in Telecommunications Assessing Telecommunications Industry Results from the 2012 Internal Audit Capabilities and Needs Survey TELECOMMUNICATIONS COMPANIES OR COMMUNICATIONS

More information

Cloud Security Keeping Data Safe in the Boundaryless World of Cloud Computing

Cloud Security Keeping Data Safe in the Boundaryless World of Cloud Computing Cloud Security Keeping Data Safe in the Boundaryless World of Cloud Computing Executive Summary As cloud service providers mature, and expand and refine their offerings, it is increasingly difficult for

More information

Preventing Fraud: Assessing the Fraud Risk Management Capabilities of Today s Largest Organizations

Preventing Fraud: Assessing the Fraud Risk Management Capabilities of Today s Largest Organizations Preventing Fraud: Assessing the Fraud Risk Management Capabilities of Today s Largest Organizations Overview In late 2006 and 2007, Protiviti commissioned a study to gauge the fraud risk management (FRM)

More information

How To Get A Tech Startup To Comply With Regulations

How To Get A Tech Startup To Comply With Regulations Agile Technology Controls for Startups a Contradiction in Terms or a Real Opportunity? Implementing Dynamic, Flexible and Continuously Optimized IT General Controls POWERFUL INSIGHTS Issue It s not a secret

More information

ICD-10: Ready or Not?

ICD-10: Ready or Not? ICD-10: Ready or Not? Survey Results Provide an Overview of ICD-10 Implementation and Planning Status By Jerry Lear, CIA, CISA, and Kirra Phillips, RHIA, CCS CHAN Healthcare AHIA In only a few months,

More information

Top Priorities for Internal Audit in Retail. Assessing Retail Industry Results from the 2012 Internal Audit Capabilities and Needs Survey

Top Priorities for Internal Audit in Retail. Assessing Retail Industry Results from the 2012 Internal Audit Capabilities and Needs Survey Top Priorities for Internal Audit in Retail Assessing Retail Industry Results from the 2012 Internal Audit Capabilities and Needs Survey THE TERRAIN FOR RETAILERS IS UNFAMILIAR AS WELL AS UNEVEN PITTED

More information

Top Priorities for Internal Audit in Manufacturing

Top Priorities for Internal Audit in Manufacturing Top Priorities for Internal Audit in Manufacturing Assessing Manufacturing Industry Results from the 2012 Internal Audit Capabilities and Needs Survey LEADERSHIP TEAMS IN MANUFACTURING COMPANIES ARE LOOKING

More information

Customer Data and Reputational Risk in the Pharmaceutical Industry

Customer Data and Reputational Risk in the Pharmaceutical Industry 1 Customer Data and Reputational Risk in the Pharmaceutical Industry Sensitive Data: A Chain of Trust Organizations of all types, from banks to government agencies to healthcare providers, are taking steps

More information

FPO. 2013 IT Priorities Survey. Mobile Commerce, Social Media, Data Management and Business Continuity Dominate the Agendas of IT Departments

FPO. 2013 IT Priorities Survey. Mobile Commerce, Social Media, Data Management and Business Continuity Dominate the Agendas of IT Departments FPO Mobile Commerce, Social Media, Data Management and Business Continuity Dominate the Agendas of IT Departments 1 Introduction A cursory glance at nearly any information technology (IT) article, survey

More information

From Cybersecurity to IT Governance Preparing Your 2014 Audit Plan. Assessing the Results of Protiviti s Third Annual IT Audit Benchmarking Survey

From Cybersecurity to IT Governance Preparing Your 2014 Audit Plan. Assessing the Results of Protiviti s Third Annual IT Audit Benchmarking Survey From Cybersecurity to IT Governance Preparing Your 2014 Audit Plan Assessing the Results of Protiviti s Third Annual IT Audit Benchmarking Survey Table of Contents Introduction...2 Top Technology Challenges

More information

IT GOVERNANCE PANEL BRING VALUE BY AUDITING IT GOVERNANCE GET THE

IT GOVERNANCE PANEL BRING VALUE BY AUDITING IT GOVERNANCE GET THE 1 IT GOVERNANCE PANEL BRING VALUE BY AUDITING IT GOVERNANCE GET THE ANSWERS AND PRACTICAL TIPS FROM THE IT GOVERNANCE AUDIT PROFESSIONALS JOHAN LIDROS, PRESIDENT EMINERE GROUP KATE MULLIN, CISO, HEALTH

More information

Helping You Achieve Better Clinical and Financial Health

Helping You Achieve Better Clinical and Financial Health McKesson Business Performance Services Accountable Care Services Helping You Achieve Better Clinical and Financial Health 1 We recognized that fee-for-service would decrease and value-based care would

More information

CLOSING THE DOOR TO CYBER ATTACKS HOW ENTERPRISES CAN IMPLEMENT COMPREHENSIVE INFORMATION SECURITY

CLOSING THE DOOR TO CYBER ATTACKS HOW ENTERPRISES CAN IMPLEMENT COMPREHENSIVE INFORMATION SECURITY CLOSING THE DOOR TO CYBER ATTACKS HOW ENTERPRISES CAN IMPLEMENT COMPREHENSIVE INFORMATION SECURITY CLOSING THE DOOR TO CYBER ATTACKS Cybersecurity and information security have become key challenges for

More information

Insurance Industry Expertise

Insurance Industry Expertise Insurance Industry Expertise Delivered With High-Level Attention and Service Audit Tax Advisory Risk Performance The Unique Alternative to the Big Four For more than 50 years, clients in all sectors of

More information

HIPAA/HITECH Privacy and Security for Long Term Care. Association of Jewish Aging Services 1

HIPAA/HITECH Privacy and Security for Long Term Care. Association of Jewish Aging Services 1 HIPAA/HITECH Privacy and Security for Long Term Care 1 John DiMaggio Chief Executive Officer, Blue Orange Compliance Cliff Mull Partner, Benesch, Healthcare Practice Group About the Presenters John DiMaggio,

More information

Payment Card Industry Data Security Standards

Payment Card Industry Data Security Standards Payment Card Industry Data Security Standards Discussion Objectives Agenda Introduction PCI Overview and History The Protiviti Difference Questions and Discussion 2 2014 Protiviti Inc. CONFIDENTIAL: This

More information

Health & Life Sciences

Health & Life Sciences Health & Life Sciences Overview Taft s Health and Life Sciences group provides comprehensive and innovative legal services, assisting a wide range of health care providers and life science businesses in

More information

Managing Research Compliance Risks

Managing Research Compliance Risks Managing Research Compliance Risks James Moran, J.D., CPA Executive Director of Compliance, University of Pennsylvania School of Medicine Rick Rohrbach, MBA, CPA Senior Manager, Healthcare Consulting Practice

More information

Securing Patient Portals. What You Need to Know to Comply With HIPAA Omnibus and Meaningful Use

Securing Patient Portals. What You Need to Know to Comply With HIPAA Omnibus and Meaningful Use Securing Patient Portals What You Need to Know to Comply With HIPAA Omnibus and Meaningful Use September 2013 Table of Contents Abstract... 3 The Carrot and the Stick: Incentives and Penalties for Securing

More information

Beyond risk identification Evolving provider ERM programs

Beyond risk identification Evolving provider ERM programs Beyond risk identification Evolving provider ERM programs March 2016 At a glance PwC conducted research to assess the state of enterprise risk management (ERM) within healthcare providers and found many

More information

The Need to Embrace Profit Cycle Management in Healthcare

The Need to Embrace Profit Cycle Management in Healthcare GE Healthcare The Need to Embrace Profit Cycle Management in Healthcare Justin Steinman General Manager GE Healthcare IT Top 5 Takeaways 1. Healthcare leaders need to start analyzing and controlling costs

More information

HOW AND WHEN TO UTILIZE IT INTERNAL AUDITORS IN COMPLIANCE CHASE WHITAKER HCA HOSPITAL CORPORATION OF AMERICA

HOW AND WHEN TO UTILIZE IT INTERNAL AUDITORS IN COMPLIANCE CHASE WHITAKER HCA HOSPITAL CORPORATION OF AMERICA HOW AND WHEN TO UTILIZE IT INTERNAL AUDITORS IN COMPLIANCE CHASE WHITAKER HCA HOSPITAL CORPORATION OF AMERICA $37B annual net revenue $24B total assets $7B EBITDA $1.8B Net Income 215,000 employees 5%

More information

Sunday March 30, 2014, 9am noon HCCA Conference, San Diego

Sunday March 30, 2014, 9am noon HCCA Conference, San Diego Meaningful Use as it Relates to HIPAA Compliance Sunday March 30, 2014, 9am noon HCCA Conference, San Diego CLAconnect.com Objectives and Agenda Understand the statutory and regulatory background and purpose

More information

Is your practice prepared for ICD-9 to ICD-10 Transition?

Is your practice prepared for ICD-9 to ICD-10 Transition? Is your practice prepared for ICD-9 to ICD-10 Transition? How to embrace the change and be prepared. Is Your Practice Prepared for ICD-9 to ICD-10 Transition? ICD-10 implementation is now required for

More information

Fraud Prevention and Detection in a Manufacturing Environment

Fraud Prevention and Detection in a Manufacturing Environment Fraud Prevention and Detection in a Manufacturing Environment Introduction The Association of Certified Fraud Examiners (ACFE) estimated in its 2008 Report to the Nation on Occupational Fraud and Abuse

More information

The Critical Role of the Board of Directors in Acquisitions

The Critical Role of the Board of Directors in Acquisitions The Critical Role of the Board of Directors in Acquisitions Note: This paper originally was published in October 2013 by Transaction Advisors (www.transactionadvisors.com). Many are predicting the M&A

More information

Security & IT Governance: Strategies to Building a Sustainable Model for Your Organization

Security & IT Governance: Strategies to Building a Sustainable Model for Your Organization Security & IT Governance: Strategies to Building a Sustainable Model for Your Organization Outside View of Increased Regulatory Requirements Regulatory compliance is often seen as sand in the gears requirements

More information

Welcome to the Data Analytics Toolkit PowerPoint presentation on clinical quality measures, meaningful use, and data analytics.

Welcome to the Data Analytics Toolkit PowerPoint presentation on clinical quality measures, meaningful use, and data analytics. Welcome to the Data Analytics Toolkit PowerPoint presentation on clinical quality measures, meaningful use, and data analytics. According to the Centers for Medicare and Medicaid Services, Clinical Quality

More information

The Journey to ORSA Begins. Assessing the Results of the 2015 ORSA Survey from St. John s University and Protiviti

The Journey to ORSA Begins. Assessing the Results of the 2015 ORSA Survey from St. John s University and Protiviti The Journey to ORSA Begins Assessing the Results of the 2015 ORSA Survey from St. John s University and Protiviti Executive Summary PUBLIC COMPANIES HAVE SOX. FINANCIAL SERVICES ORGANIZATIONS (AND OTHERS)

More information

HIPAA: AN OVERVIEW September 2013

HIPAA: AN OVERVIEW September 2013 HIPAA: AN OVERVIEW September 2013 Introduction The Health Insurance Portability and Accountability Act of 1996, known as HIPAA, was enacted on August 21, 1996. The overall goal was to simplify and streamline

More information

Health care trend: Developing ACOs

Health care trend: Developing ACOs Health care trend: Health care trend: Accountable Care Organizations (ACOs) have been a significant topic within health care. While many organizations have embarked on a quest to embrace ACOs as quickly

More information

Time for an IT Check Up

Time for an IT Check Up Time for an IT Check Up Preventive IT Care Supports a Healthy Future for Medicare Advantage Plans ORACLE WHITE PAPER JULY 2014 Disclaimer The following is intended to outline our general product direction.

More information

Meaningful Use, ICD-10 and HIPAA 5010 Overview, talking points and FAQs

Meaningful Use, ICD-10 and HIPAA 5010 Overview, talking points and FAQs Meaningful Use, ICD-10 and HIPAA 5010 Overview, talking points and FAQs Providence Health & Services is committed to using technology and evidence-based practices to deliver the highest quality care in

More information

NEW PERSPECTIVES. Data Analysis Challenges: C1 is customer provided. Anticipate IRS Audits: System Development and Implementation Projects:

NEW PERSPECTIVES. Data Analysis Challenges: C1 is customer provided. Anticipate IRS Audits: System Development and Implementation Projects: NEW PERSPECTIVES on Healthcare Risk Management, Control and Governance www.ahia.org Journal of the Association of Heathcare Internal Auditors Vol. 31, No. 2, Summer, 2012 C1 is customer provided Data Analysis

More information

Securing the Cloud Infrastructure

Securing the Cloud Infrastructure EXECUTIVE STRATEGY BRIEF Microsoft recognizes that security and privacy protections are essential to building the necessary customer trust for cloud computing to reach its full potential. This strategy

More information

Road Map Identifying Financial Opportunities Through Data Analytics

Road Map Identifying Financial Opportunities Through Data Analytics Optimizing the business of healthcare ROAD MAP Road Map Identifying Financial Opportunities Through Data Analytics Identifying Financial Opportunities Through Data Analytics How important is collecting,

More information

When it Comes to ICD-10, Preparation is Everything

When it Comes to ICD-10, Preparation is Everything When it Comes to ICD-10, Preparation is Everything Addressing ICD-10 s negative revenue impacts before they happen Steven R. Gerst, MD, MBA, MPH, CHE Jvion Senior Medical Advisor Atlanta, GA Darien, CT

More information

Data Analytics - Current Market Landscape & Trends

Data Analytics - Current Market Landscape & Trends www.pwc.com Top Healthcare Risks: How Information Technologies & Controls Can Help Mitigate Organizational Risk ISACA Los Angeles Chapter November 17, 2015 Introductions Jack Flaherty Director Health Industries

More information

Automating Workforce Management in Healthcare

Automating Workforce Management in Healthcare Automating Workforce Management in Healthcare Have you considered the benefits of workforce management automation for patient care, employee engagement, and productivity? Automation of workforce management

More information

TENET HEALTHCARE CORPORATION S QUALITY, COMPLIANCE AND ETHICS PROGRAM CHARTER. Updated May 7, 2014

TENET HEALTHCARE CORPORATION S QUALITY, COMPLIANCE AND ETHICS PROGRAM CHARTER. Updated May 7, 2014 TENET HEALTHCARE CORPORATION S QUALITY, COMPLIANCE AND ETHICS PROGRAM CHARTER Updated May 7, 2014 PREAMBLE Tenet Healthcare Corporation ( THC ) hereby sets forth this Charter for its Quality, Compliance

More information

The Institute of Internal Auditors 247 Maitland Avenue Altamonte Springs, FL 32701-4201 USA

The Institute of Internal Auditors 247 Maitland Avenue Altamonte Springs, FL 32701-4201 USA INTERNATIONAL Professional Practices Framework (IPPF) Disclosure Copyright 2009 by The Institute of Internal Auditors Research Foundation (IIARF), 247 Maitland Avenue, Altamonte Springs, Florida 32701-4201.

More information

HIPAA Security Prepare Now or Wait and See?

HIPAA Security Prepare Now or Wait and See? HIPAA Security Prepare Now or Wait and See? Background An ounce of prevention is worth a pound of cure, a saying often used in a healthcare context, was first coined by Benjamin Franklin more than two

More information

Governance, Risk, and Compliance (GRC) White Paper

Governance, Risk, and Compliance (GRC) White Paper Governance, Risk, and Compliance (GRC) White Paper Table of Contents: Purpose page 2 Introduction _ page 3 What is GRC _ page 3 GRC Concepts _ page 4 Integrated Approach and Methodology page 4 Diagram:

More information

Identity: The Key to the Future of Healthcare

Identity: The Key to the Future of Healthcare Identity: The Key to the Future of Healthcare Chief Medical Officer Anakam Identity Services July 14, 2011 Why is Health Information Technology Critical? Avoids medical errors. Up to 98,000 avoidable hospital

More information

Internal Auditing Guidelines

Internal Auditing Guidelines Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may

More information

Future of Health Care: How Do You Fit In? Physician Leadership Institute February 28, 2015 Brian M. McCook, CPA

Future of Health Care: How Do You Fit In? Physician Leadership Institute February 28, 2015 Brian M. McCook, CPA Future of Health Care: How Do You Fit In? Physician Leadership Institute February 28, 2015 Brian M. McCook, CPA Learning Objectives Industry Transitions Challenges and Changes ACO s Look at the Future

More information

Healthcare Reform: The Road Ahead

Healthcare Reform: The Road Ahead Healthcare Reform: The Road Ahead Kevin Lyles, Esq. Partner, Jones Day kdlyles@jonesday.com (614) 281-3821 Frank E. Sheeder, Esq. Partner, DLA Piper frank.sheeder@dlapiper.com (214) 743-4560 Diane Meyer

More information

FROM HINDSIGHT TO FORESIGHT REPOSITIONING INTERNAL AUDIT TO DELIVER HIGHER VALUE

FROM HINDSIGHT TO FORESIGHT REPOSITIONING INTERNAL AUDIT TO DELIVER HIGHER VALUE FROM HINDSIGHT TO FORESIGHT REPOSITIONING INTERNAL AUDIT TO DELIVER HIGHER VALUE Repositioning Internal Audit FY 2016-FY2017 Audit Resource Deployment Plan Resources and Staffing Supplemental Materials

More information

6 Critical Impact Factors of Health Reform on Revenue Cycle Management

6 Critical Impact Factors of Health Reform on Revenue Cycle Management 6 Critical Impact Factors of Health Reform on Revenue Cycle Management Pyramid Healthcare Solutions Thought Leadership Series The healthcare industry is undergoing significant change in the face of the

More information

Schedule 46 SAO Certificate FAQs

Schedule 46 SAO Certificate FAQs Schedule 46 SAO Certificate FAQs Ensuring Correct Completion and Submission of the SAO Certificate The first submission of the Schedule 46 Finance Act 2009 (FA09) senior accounting officer (SAO) certificate

More information

Remaining Secure in an Evolving Industry. White Paper

Remaining Secure in an Evolving Industry. White Paper Remaining Secure in an Evolving Industry White Paper Remaining Secure in an Evolving Industry How Healthcare Organizations Can Manage Risk by Managing Data We live in interesting and exciting times. Our

More information

The Importance of Pay For Performance in Healthcare Transformation

The Importance of Pay For Performance in Healthcare Transformation Author: Mallory M. Johnson, MHA, Senior Consultant A push towards pay-for-performance The term pay-for-performance (P4P) has matured in healthcare over the last decade from concept to reality as healthcare

More information

Today s Enterprise - Cyberthreats Lurk Amid Major Transformation. Assessing the Results of Protiviti s 2015 IT Priorities Survey

Today s Enterprise - Cyberthreats Lurk Amid Major Transformation. Assessing the Results of Protiviti s 2015 IT Priorities Survey Today s Enterprise - Cyberthreats Lurk Amid Major Transformation Assessing the Results of Protiviti s 2015 IT Priorities Survey INTRODUCTION The very technologies that empower us to do great good can

More information

State of Compliance 2014 Healthcare provider industry brief

State of Compliance 2014 Healthcare provider industry brief Delve into the full analysis of the 2014 State of Compliance Survey at: pwc.com/us/ stateofcompliance State of Compliance 2014 Healthcare provider industry brief Introduction The healthcare provider industry

More information

EHR: The Good, Bad, and Ugly

EHR: The Good, Bad, and Ugly EHR: The Good, Bad, and Ugly Jonathan W. Lohr President Unibase Healthcare Solutions Kevin J. Corcoran, COE, CPC, CPMA, FNAO President, Corcoran Consulting Group Founder, Corcoran Compliance Connection

More information

Practice Guide ASSESSING ORGANIZATIONAL GOVERNANCE IN THE PUBLIC SECTOR

Practice Guide ASSESSING ORGANIZATIONAL GOVERNANCE IN THE PUBLIC SECTOR Practice Guide ASSESSING ORGANIZATIONAL GOVERNANCE IN THE PUBLIC SECTOR OCTOBER 2014 Table of Contents Executive Summary... 1 Introduction... 1 Public Sector Characteristics... 4 Public Sector Structure...

More information

The silver lining: Getting value and mitigating risk in cloud computing

The silver lining: Getting value and mitigating risk in cloud computing The silver lining: Getting value and mitigating risk in cloud computing Frequently asked questions The cloud is here to stay. And given its decreased costs and increased business agility, organizations

More information

Healthcare Cybersecurity Perspectives from the Michigan Healthcare Cybersecurity Council

Healthcare Cybersecurity Perspectives from the Michigan Healthcare Cybersecurity Council Healthcare Cybersecurity Perspectives from the Michigan Healthcare Cybersecurity Council Presented by Doug Copley, Chairman Michigan Healthcare Cybersecurity Council Mr. Chairman and Committee Members,

More information

HIPAA Secure Now! How MSPs Can Profit From Selling HIPAA security services

HIPAA Secure Now! How MSPs Can Profit From Selling HIPAA security services HIPAA Secure Now! How MSPs Can Profit From Selling HIPAA security services How MSPs can profit from selling HIPAA security services Managed Service Providers (MSP) can use the Health Insurance Portability

More information

Performing a Compliance Risk Assessment for Compliance Auditing & Monitoring in Healthcare Organizations

Performing a Compliance Risk Assessment for Compliance Auditing & Monitoring in Healthcare Organizations Performing a Compliance Risk Assessment for Compliance Auditing & Monitoring in Healthcare Organizations Author: Glen C. Mueller, Chief Audit & Compliance Officer, Scripps Health, San Diego, CA Introduction

More information

The electronic health record (EHR) has been a game-changer for CDI specialists.

The electronic health record (EHR) has been a game-changer for CDI specialists. Physician queries and the use of prior information: Reevaluating the role of the CDI specialist WHITE PAPER Summary: The following white paper examines the issue of whether to use information from a prior

More information

Streamlining Healthcare Business Interactions

Streamlining Healthcare Business Interactions WHITE PAPER Streamlining Healthcare Business Interactions Sponsored by: Axway Lynne Dunbrack December 2014 IDC HEALTH INSIGHTS OPINION Today's changing healthcare IT (HIT) environments are generating a

More information

A Guide to Choosing the Right EMR Software. A Guide to Choosing the Right EMR Software

A Guide to Choosing the Right EMR Software. A Guide to Choosing the Right EMR Software A Guide to Choosing the Right EMR Software A Guide to Choosing the Right EMR Software Eight Important Benchmarks for Community and Critical Access Hospitals Eight Important Benchmarks for Community and

More information

Microsoft s Compliance Framework for Online Services

Microsoft s Compliance Framework for Online Services Microsoft s Compliance Framework for Online Services Online Services Security and Compliance Executive summary Contents Executive summary 1 The changing landscape for online services compliance 4 How Microsoft

More information

These are some labor burden test queries that auditors can make if they have the contractor s or vendor s labor burden breakdown:

These are some labor burden test queries that auditors can make if they have the contractor s or vendor s labor burden breakdown: Applying Data Mining and Analytics to Efficiently Audit Vendors and Contractors By Paul Pettit, Protiviti Inc. Each year, companies spend billions of dollars to start up, operate and maintain their businesses

More information

Point-of-Care Medication Administration: Internal Audit s Role in Ensuring Control

Point-of-Care Medication Administration: Internal Audit s Role in Ensuring Control Point-of-Care Medication Administration: Internal Audit s Role in Ensuring Control The Institute of Medicine (IOM) estimates that more than a million injuries and almost 100,000 deaths annually can be

More information

6 Critical Impact Factors of Health Reform on Revenue Cycle Management

6 Critical Impact Factors of Health Reform on Revenue Cycle Management 6 Critical Impact Factors of Health Reform on Revenue Cycle Management Pyramid Healthcare Solutions Thought Leadership Series The healthcare industry is undergoing significant change in the face of the

More information

Leveraging a Maturity Model to Achieve Proactive Compliance

Leveraging a Maturity Model to Achieve Proactive Compliance Leveraging a Maturity Model to Achieve Proactive Compliance White Paper: Proactive Compliance Leveraging a Maturity Model to Achieve Proactive Compliance Contents Introduction............................................................................................

More information

INFORMATION TECHNOLOGY FLASH REPORT

INFORMATION TECHNOLOGY FLASH REPORT INFORMATION TECHNOLOGY FLASH REPORT ISACA Releases COBIT 5: Updated Framework for the Governance and Management of IT May 18, 2012 In April, ISACA released COBIT 5 as a replacement for its current globally

More information

Myriad changes in the healthcare landscape are making it difficult for providers to deliver

Myriad changes in the healthcare landscape are making it difficult for providers to deliver The Provider Crossroad to Value-Based Reimbursement The acceleration of VBR in the ambulatory/physician practice setting Authored by: Pamela Lewis Dolan, with Daniel Dooley and Ronald Spoltore Myriad changes

More information

Meaningful HIE to. Advance. your Connectivity

Meaningful HIE to. Advance. your Connectivity Meaningful HIE to Advance your Connectivity Meaningful Use interoperability, quality improvement, data analytics, patient health records (PHRs), health information exchange (HIE) These buzz words can create

More information

WHITEPAPER 6 EHR TRENDS to Watch in

WHITEPAPER 6 EHR TRENDS to Watch in WHITEPAPER 6 EHR TRENDS to Watch in 2015 INTRODUCTION Since the passage of the HITECH Act in 2009, the healthcare industry has undergone rapid changes in technology. The adoption of electronic health records

More information

#socialmediarisk Social Media and Consumer Marketing for Financial Services Organizations

#socialmediarisk Social Media and Consumer Marketing for Financial Services Organizations #socialmediarisk Social Media and Consumer Marketing for Financial Services Organizations Social media has created significant opportunities for organizations to connect with their customers and the overall

More information

2015 health care providers outlook United States

2015 health care providers outlook United States 2015 health care providers outlook United States The United States spends more on health care than any other country in the world, at an estimated 17.7 percent of Gross Domestic Product (GDP) in 2013.

More information

The Changing Role of the Healthcare Risk Manager. December 2012. Sponsored by:

The Changing Role of the Healthcare Risk Manager. December 2012. Sponsored by: The Changing Role of the Healthcare Risk Manager December 2012 The Changing Role of the Healthcare Risk Manager The healthcare sector is undergoing broad and rapid transformation, driven by changing demographics,

More information

DEVELOPING AN EFFECTIVE INTERNAL AUDIT TECHNOLOGY STRATEGY

DEVELOPING AN EFFECTIVE INTERNAL AUDIT TECHNOLOGY STRATEGY DEVELOPING AN EFFECTIVE INTERNAL AUDIT TECHNOLOGY STRATEGY SEPTEMBER 2012 DISCLAIMER Copyright 2012 by The Institute of Internal Auditors (IIA) located at 247 Maitland Ave., Altamonte Springs, Fla., 32701,

More information

How To Understand The Role Of An Internal Audit

How To Understand The Role Of An Internal Audit Top Ten Issues facing Internal Auditing in the Future The IIA Dallas Chapter April 6, 2006 Presented by: David A. Richards, CIA, CPA President The Institute of Internal Auditors drichards@theiia.org 1

More information

ICD-10-CM/PCS ICD-10 Education

ICD-10-CM/PCS ICD-10 Education Testimony of Ann M. Zeisset, RHIT, CCS, CCS-P On Behalf of the American Health Information Management Association To the Standards Subcommittee National Committee on Vital and Health Statistics June 17,

More information

The Role of Governance, Risk and Compliance in a Firm

The Role of Governance, Risk and Compliance in a Firm Technology Investment: Achieving Balance Between Business Requirements and Regulatory Compliance Over the past decade, IT organizations have endured a historic pendulum swing, from reckless IT development

More information

How To Use Predictive Analytics To Improve Health Care

How To Use Predictive Analytics To Improve Health Care Unlocking the Value of Healthcare s Big Data with Predictive Analytics Background The volume of electronic data in the healthcare industry continues to grow. Adoption of electronic solutions and increased

More information

Solutions and Services Overview

Solutions and Services Overview Solutions and Services Overview Origin is a premier provider of seamlessly integrated, data driven revenue cycle management and analytics solutions, all supported by world-class customer service and over

More information

PwC Advisory Internal Audit. PricewaterhouseCoopers State of the internal audit profession study: internal audit post Sarbanes-Oxley*

PwC Advisory Internal Audit. PricewaterhouseCoopers State of the internal audit profession study: internal audit post Sarbanes-Oxley* PwC Advisory Internal Audit PricewaterhouseCoopers State of the internal audit profession study: internal audit post Sarbanes-Oxley* Table of Contents Overview 02 As demands on internal audit escalate,

More information

As is the case in many industries today, corporate governance

As is the case in many industries today, corporate governance How Health Care Organizations Risk and Compliance Executives Can Become Strategic Board Advisors Terry Puchley, Partner, PwC, terry.puchley@us.pwc.com Mitchel Harris, Director, PwC, mitchel.s.harris@us.pwc.com

More information