A Day in the Life of a HIM Director & Expectations of HealthPort

Size: px
Start display at page:

Download "A Day in the Life of a HIM Director & Expectations of HealthPort"

Transcription

1 A Day in the Life of a HIM Director & Expectations of HealthPort Rita K. Bowen, MA, RHIA, CHPS, SSGB Sr. VP HIM Best Practice and Privacy Officer Alisha R. Smith, RHIA Manager, HIM Education

2 Overview Who are HIMs? Characteristics of HIM Professionals Health Records Where do HIM Professionals Work? Roles of HIMs Foundation of Health Information Management E-HIM Data Quality Privacy A Day in the Life of a HIM Director Expectations from HealthPort Why they would outsource How to make the partnership successful 2

3 What Healthcare requires in the future? Goal Regenerate trust that a shared care system can eliminate avoidable errors, variance, waste, delays and friction

4 HIM s Shades of Grey It s Not a Black and White Situation Grey area: An area or part of something existing between two extremes and having mixed characteristics of both An area, situation, etc., lacking clearly defined characteristics

5 Who are Health Information Managers (HIMs)? Provide essential information for: Clinical Research Quality Improvement Utilization Review Budgeting Hospital Decisions 5

6 Who are Health Information Managers (HIMs)? Protect patient information and promote confidentiality and awareness Implement the Electronic Health Record (EHR) Work with health information systems and databases Health information data collection and analysis Pathophysiology knowledge 6

7 Health Information Management Professionals Experts in Managing patient information and health records Administering computer information systems Coding diagnoses and procedures

8 Health Information Management Professionals Experts in Maintaining patient confidentiality Collecting and storing information Using and transmitting information

9 Employment Opportunities Hospitals Doctors Offices Nursing Homes Government Offices Colleges/ Universities

10 Employment Opportunities Pharmaceutical Companies Insurance Companies Consulting Firms Law Firms Correctional Facilities

11 Characteristics of HIM Professionals Detail-oriented Team-player, but Able to work independently with minimal supervision for long periods of time Comfortable with confidentiality Responsible 11

12 Characteristics of HIM Professionals Proficient with computers HIGH expectations for team members Customer Satisfaction remains a continued focus 12

13 Characteristics of HIM Professionals Often achieved their success through meticulous attention to detail and extensive control over every aspect of their business/department. 13

14 Characteristics of HIM Professionals Expect adherence to policies and processes, quality in all areas and respect. Control Transparency Security Quality to P&P Respect 14

15 Data Quality Ensure patient information is: Accurate Reliable Consistent Timely = Ultimate goal is Patient Safety 15

16 Privacy We assure the public s privacy is protected by ensuring that all access to health information is: Ethical Moral Legal 16

17 HIM GOALS for ROI and HIM Practice Consistent message regarding privacy and security Consistent corrective disciplinary action (thus the accountability matrix) Compliance and integrity of the program Enhance public trust Strengthen response to legal actions Strengthen response to penalties and/or fines

18 Roles of HIM Professionals Clinical Analyst Clinical Applications Coordinator Clinical Research Associate Clinical Vocabulary Manager Data Analyst Database Manager Document Management Coordinator Health Systems Specialist Educator Information Solutions Consultant Privacy Officer Process Improvement Manager Project Manager, Clinical Applications Records and Information Coordinator Risk Management Officer 18

19 A Day In The Life of a HIM Director Most likely started with a 7 a.m. meeting (core measures, quality, safety, DNFB, etc.. All links to coding and some to ROI) Staffing issues (either not enough, FMLA issues or forced staff reductions and other Human Resource issues) DNFB/Cash flow or Revenue Cycle.. rules above all. Why it can t be coded Tracking necessary documentation Assuring SOI, M&M, ROM and DRG for payment Assuring there is an order and medical necessity justification for outpatient treatments

20 A Day In The Life of a HIM Director Meeting with IT/supporting technologies Data life cycle: Governance and Stewardship (includes data capture and quality, as well as appropriate informatics standards paramount is MPI or EMPI issues) Health Information Exchange issues (usually data quality or privacy related) Dealing with request for Record Amendments Legal Issues (court/certifications ROI plays major link here) gov

21 A Day In The Life of a HIM Director Project Management of the various moving parts Transition from ICD 9 to ICD 10 Education and leading this change effort E-HIM Governance E-HIM transition Envisioning the future of HIM Embrace current CORE model and adapt the model as required.

22 HIM Core Model POLICY R E S E A R C H Data Capture, Validation and Maintenance Health Information Governance and Stewardship Information Analysis, Transformation and Decision Support Health Information Resource Management and Innovation Quality and Patient Safety Information Dissemination and Liaison S T A N D A R D S EDUCATION

23 Information Data Governance

24 Five Core Educational Requirements for anyone working with an Electronic Health Record (EHR) 1. Basic computer literacy skills 2. Health information literacy and skills 3. Health information skills using the EHR 4. Privacy and confidentiality of health information 5. Health information data technical security

25 Outsource Risk Management Record keeping and Management Oversight Transparency & Billing Accuracy KPIs and Service Levels

26 The HIM Director s Expectations of HealthPort Best practices: breach prevention program, accountability matrix and application of policies Lessen ROI vulnerability Dashboard/Executive summary reports Report any breach occurrence area and ongoing mitigation process Report any customer dissatisfaction incident (timely acknowledgement with immediate contact of any customer dissatisfaction incident and corrective action plan) Full understanding of access, requests and disclosure of PHI Understanding of payers... knowing what to release for payment Regular contact by the DM and VP, not just when there is an issue

27 The HIM Director s Expectations of HealthPort On time delivery/performance of task maintaining customer expectation levels High quality of the work that is output Project management skills Outsource risk management in general Contract Management Service Level Agreement (SLA) Billing Accuracy Other Expectations and/or assistance in meeting: JC MU Omnibus

28 Monitoring the Spokes of the Wheel Customer Service Goals and Objectives Revenue Cycle Management Strategies Legal and Regulatory Risk Controls

29 Application of AHIMA s Best Practices: Accountability Matrix Have a clear accountability matrix with expected follow-up and training related to specific incidences. Adhere to a strict breach protocol that mandates notification of general counsel. Other best practices include: No password sharing ID checking at every critical point HIPAA compliant scanning and process workflow No PHI in s Data encryption at rest and in transit All field laptops are encrypted Two factor patient identification and EMPI look-up Quality control measures for work processes and performance

30 Best Practice: Expectations Staff awareness of HIPAA privacy and security regulations Staff understands how and where PHI is created, received, stored and transmitted Staff trained regarding breach notification requirements Policy and Procedures (P&P) versus actual practice

31 Best Practice: Breach Report Format Common issues (description of disclosure) Focus for best practices Linked to breach matrix with required educational follow-up Detail of sites or locations Watch list and discussions with Operations Calls and/or site visits to follow

32 Best Practice Expectation: Understanding Payer Request Specifically Medical Necessity Requests RAC, etc Linking request to the RA so that bills can be processed and cash flows in

33 Expectation: HealthPort Associates Understand Regulations and Laws Regarding ROI Knowledge of and how to utilize state HIM Legal Handbook Understanding of noncustodial parental rights Minors Foster Children Abuse Understanding of sensitive information Behavioral / Mental Substance Abuse HIV/AIDS, STDs and other communicable diseases Restriction to a health plan Genetic information Adoption

34 Expectation: HealthPort Associates Understand Regulations and Laws Regarding ROI Understanding Disclosure issues related to Deceased patients Active records of currently hospitalized patients Autopsy information Employee Health or Occupational Safety Antiterrorism Initiatives Duty to warn Laboratory test results Medical emergencies Insurance companies and government agencies payment requests Public figures or celebrities

35 Expectation: HealthPort Associates Understand Regulations and Laws Regarding ROI Understanding disclosure issues related to Social Security Administration State Disability Determination Services General/overall management of ROI processes Authorizations for various type of release Verification of requestor Mail, telephone and walk-ins Determining if disclosure is appropriate Accounting of disclosure and tracking releases

36 Other Expectations Assistance in Meeting JC & State Reviews OCR Site Visit Readiness and Investigation Response Meaningful Use Omnibus Data Analysis and Use/Registries

37 Internal Compliance Audits - Evaluation for: Assessments of privacy and security program Review breach detection and notification processes Assure Policy and Procedures (P&P) are referenced Observe staff adherence to the written P&P Ensure the workforce has been appropriately trained, especially newer staff and that they understand and are effective in protecting privacy Look for failures in: Practical Realities Human Error Limited Staff Time Limited Resources

38 Internal Compliance Audits - Evaluation for: Application of OCR criteria guidelines Crosswalk to internal policies; validation of CE policies Staff asked to verbalize various policy specifics Staff observed applying policy and best practices Determination if key conversations have occurred with management of the CE Other factors as required/based on prior privacy incidents

39 Top Reasons Why HIM Directors Outsource The company s CORE competencies seeking core HIM skill sets. Need for specialized capability skilled work force to meet regulatory and legal requirements access to first class capabilities Quality of service that is provided company reputation Reduction of operations cost or need to reduce headcount Current function may be difficult to manage or out of control

40 Top Reasons Why HIM Directors Outsource Improve the department s focus especially right now. All focus is toward ICD-10 conversion A means to share risks

41 TOP 10 - How to Make the Partnership Successful 1. Assure that the objectives are clearly defined and documented. Must make sure that you re on the same page about expectations. 2. If you believe expectations are not set correctly or are unrealistic, call your experts for assistance. 3. Always alert CE management before they alert you/healthport of an issue. 4. Communicate, Communicate, Communicate in the style preference of management Have regular scheduled meetings (go beyond the metrics). Pay attention to what kinds of questions are being asked of you learn what is critical to management. Keep an open mind and do not become defensive.

42 TOP 10 - How to Make the Partnership Successful 5. Do know the metrics, and assure that the CE receives reports. Make the HIM Manager/Director s job easier. Always suggest a solution have your act together! 6. Assure the HealthPort team understands the CE culture. 7. Adequate resources ability to obtain staff, expertise in the industry, P&Ps and ability to train resources to meet workflow demand. 8. Be aware of community issues, facility in the news, etc.. Anything that could be causing strain on the organization or its leadership.

43 TOP 10 - How to Make the Partnership Successful 9. Assure that management s needs are met to ensure that micromanagement is not needed. Usually a sign of poor transition practices Inadequate communication and/or lack of trust Inadequate recognition of local expectations/culture 10. Flexibility today s environment changes rapidly, so bring solutions, not reasons why something can t be done.

44 Overarching Goals for ROI and HIM Practice A consistent message regarding privacy and security A consistent corrective disciplinary action (thus the accountability matrix) Compliance and integrity of the program Enhanced public trust Strengthened response to legal actions Strengthened response to penalties and/or fines

45 Questions?

Our Commitment to Information Security

Our Commitment to Information Security Our Commitment to Information Security What is HIPPA? Health Insurance Portability and Accountability Act 1996 The HIPAA Privacy regulations require health care providers and organizations, as well as

More information

Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions

Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions Table of Contents Understanding HIPAA Privacy and Security... 1 What

More information

Final. National Health Care Billing Audit Guidelines. as amended by. The American Association of Medical Audit Specialists (AAMAS)

Final. National Health Care Billing Audit Guidelines. as amended by. The American Association of Medical Audit Specialists (AAMAS) Final National Health Care Billing Audit Guidelines as amended by The American Association of Medical Audit Specialists (AAMAS) May 1, 2009 Preface Billing audits serve as a check and balance to help ensure

More information

Evolving ROI Specialists into Health Record Ambassadors

Evolving ROI Specialists into Health Record Ambassadors Evolving ROI Specialists into Health Record Ambassadors By Rita Bowen, MA, RHIA, CHPS, SSGB; Alisha Smith, RHIA; and Keith W. Thomas Welcome to HIM! How may I assist you? HEALTH RECORD AMBASSADOR 30 /

More information

Trust 9/10/2015. Why Does Privacy and Security Matter? Who Must Comply with HIPAA Rules? HIPAA Breaches, Security Risk Analysis, and Audits

Trust 9/10/2015. Why Does Privacy and Security Matter? Who Must Comply with HIPAA Rules? HIPAA Breaches, Security Risk Analysis, and Audits HIPAA Breaches, Security Risk Analysis, and Audits Derrick Hill Senior Health IT Advisor Kentucky REC Why Does Privacy and Security Matter? Trust Who Must Comply with HIPAA Rules? Covered Entities (CE)

More information

Sustainable Compliance: A System for Ongoing Audit Readiness

Sustainable Compliance: A System for Ongoing Audit Readiness View the Replay on YouTube Sustainable Compliance: A System for Ongoing Audit Readiness FairWarning Executive Webinar Series November 14, 2013 Agenda Sustainable Compliance at St. Charles Health System

More information

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015 Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015 Katherine M. Layman Cozen O Connor 1900 Market Street Philadelphia, PA 19103 (215) 665-2746

More information

High Performance Health Systems: The Benefits of Centralization

High Performance Health Systems: The Benefits of Centralization High Performance Health Systems: The Benefits of Centralization Centralized Release of Information High performance, multi-facility health systems that standardize processes and spread best practices related

More information

Data Security and Integrity of e-phi. MLCHC Annual Clinical Conference Worcester, MA Wednesday, November 12, 2014 2:15pm 3:30pm

Data Security and Integrity of e-phi. MLCHC Annual Clinical Conference Worcester, MA Wednesday, November 12, 2014 2:15pm 3:30pm Electronic Health Records: Data Security and Integrity of e-phi Worcester, MA Wednesday, 2:15pm 3:30pm Agenda Introduction Learning Objectives Overview of HIPAA HIPAA: Privacy and Security HIPAA: The Security

More information

12/19/2014. HIPAA More Important Than You Realize. Administrative Simplification Privacy Rule Security Rule

12/19/2014. HIPAA More Important Than You Realize. Administrative Simplification Privacy Rule Security Rule HIPAA More Important Than You Realize J. Ira Bedenbaugh Consulting Shareholder February 20, 2015 This material was used by Elliott Davis Decosimo during an oral presentation; it is not a complete record

More information

REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI

REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI Healthcare Organizations Can Adopt Enterprise-Wide Disclosure Management Systems To Standardize Disclosure Processes,

More information

HIPAA Compliance: Are you prepared for the new regulatory changes?

HIPAA Compliance: Are you prepared for the new regulatory changes? HIPAA Compliance: Are you prepared for the new regulatory changes? Baker Tilly CARIS Innovation, Inc. April 30, 2013 Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed

More information

HIPAA PRIVACY OVERVIEW

HIPAA PRIVACY OVERVIEW HIPAA PRIVACY OVERVIEW OBJECTIVES At the completion of this course, the learner will be able to: Define the Purpose of HIPAA Define Business Associate Identify Patients Rights Understand the Consequences

More information

HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012

HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012 HIPAA Privacy and Security Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012 Goals and Objectives Course Goal: To introduce the staff of Munson Healthcare to the concepts

More information

What s new In the News Data Breach Discussion The 5 W s Risk Analysis: Why, What, how, When, and Who Common Issues Observed Q / A Session Purdue

What s new In the News Data Breach Discussion The 5 W s Risk Analysis: Why, What, how, When, and Who Common Issues Observed Q / A Session Purdue What s new In the News Data Breach Discussion The 5 W s Risk Analysis: Why, What, how, When, and Who Common Issues Observed Q / A Session Purdue Healthcare Advisors The # of data breaches is climbing The

More information

NEW PERSPECTIVES. Professional Fee Coding Audit: The Basics. Learn how to do these invaluable audits page 16

NEW PERSPECTIVES. Professional Fee Coding Audit: The Basics. Learn how to do these invaluable audits page 16 NEW PERSPECTIVES on Healthcare Risk Management, Control and Governance www.ahia.org Journal of the Association of Heathcare Internal Auditors Vol. 32, No. 3, Fall, 2013 Professional Fee Coding Audit: The

More information

Sustainable HIPAA Compliance: Protecting Patient Privacy through Highly Leveraged Investments

Sustainable HIPAA Compliance: Protecting Patient Privacy through Highly Leveraged Investments View the Replay on YouTube Sustainable HIPAA Compliance: Protecting Patient Privacy through Highly Leveraged Investments FairWarning Executive Webinar Series October 31, 2013 Today s Panel Chris Arnold

More information

Reining in Release of Information in the World of Electronic Health Records

Reining in Release of Information in the World of Electronic Health Records Reining in Release of Information in the World of Electronic Health Records Rita K. Bowen, MA, RHIA, CHPS, SSGB Sr. VP HIM, Privacy Officer HealthPort Harriet Hodges, Director, Health Information Management

More information

Grand Rapids Medical Education Partners Mercy Health Saint Mary s Spectrum Health. Pam Jager, GRMEP Director of Education & Development

Grand Rapids Medical Education Partners Mercy Health Saint Mary s Spectrum Health. Pam Jager, GRMEP Director of Education & Development Grand Rapids Medical Education Partners Mercy Health Saint Mary s Spectrum Health Pam Jager, GRMEP Director of Education & Development To understand the requirements of the federal Health Information Portability

More information

Information Governance includes the Core Record Set for Coding Compliance Bonnie S. Cassidy, MPA, RHIA, FHIMSS

Information Governance includes the Core Record Set for Coding Compliance Bonnie S. Cassidy, MPA, RHIA, FHIMSS Information Governance includes the Core Record Set for Coding Compliance Bonnie S. Cassidy, MPA, RHIA, FHIMSS DISCLAIMER: The views and opinions expressed in this presentation are those of the author

More information

Welcome to ChiroCare s Fourth Annual Fall Business Summit. October 3, 2013

Welcome to ChiroCare s Fourth Annual Fall Business Summit. October 3, 2013 Welcome to ChiroCare s Fourth Annual Fall Business Summit October 3, 2013 HIPAA Compliance Regulatory Overview & Implementation Tips for Providers Agenda Green packet Overview of general HIPAA terms and

More information

INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS. I. Introduction 2. II. Definitions 3

INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS. I. Introduction 2. II. Definitions 3 INDIANA UNIVERSITY SCHOOL OF OPTOMETRY HIPAA COMPLIANCE PLAN TABLE OF CONTENTS I. Introduction 2 II. Definitions 3 III. Program Oversight and Responsibilities 4 A. Structure B. Compliance Committee C.

More information

Lessons Learned from HIPAA Audits

Lessons Learned from HIPAA Audits Lessons Learned from HIPAA Audits October 29, 2012 Tony Brooks, CISA, CRISC Partner - IT Assurance and Risk Services HORNE LLP AGENDA HIPAA/HITECH Regulations Breaches and Fines OCR HIPAA/HITECH Compliance

More information

Are You Still HIPAA Compliant? Staying Protected in the Wake of the Omnibus Final Rule Click to edit Master title style.

Are You Still HIPAA Compliant? Staying Protected in the Wake of the Omnibus Final Rule Click to edit Master title style. Are You Still HIPAA Compliant? Staying Protected in the Wake of the Omnibus Final Rule Click to edit Master title style March 27, 2013 www.mcguirewoods.com Introductions Holly Carnell McGuireWoods LLP

More information

HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist

HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist HIPAA Omnibus Rule Overview Presented by: Crystal Stanton MicroMD Marketing Communication Specialist 1 HIPAA Omnibus Rule - Agenda History of the Omnibus Rule What is the HIPAA Omnibus Rule and its various

More information

HIPAA Omnibus Compliance How A Data Loss Prevention Solution Can Help

HIPAA Omnibus Compliance How A Data Loss Prevention Solution Can Help HIPAA Omnibus Compliance How A Data Loss Prevention Solution Can Help The Health Information Portability and Accountability Act (HIPAA) Omnibus Rule which will begin to be enforced September 23, 2013,

More information

Agenda. OCR Audits of HIPAA Privacy, Security and Breach Notification, Phase 2. Linda Sanches, MPH Senior Advisor, Health Information Privacy 4/1/2014

Agenda. OCR Audits of HIPAA Privacy, Security and Breach Notification, Phase 2. Linda Sanches, MPH Senior Advisor, Health Information Privacy 4/1/2014 OCR Audits of HIPAA Privacy, Security and Breach Notification, Phase 2 Linda Sanches, MPH Senior Advisor, Health Information Privacy HCCA Compliance Institute March 31, 2014 Agenda Background Audit Phase

More information

HIPAA Audits: How to Be Prepared. Lindsey Wiley, MHA, CHTS-IM, CHTS-TS HIT Manager Oklahoma Foundation for Medical Quality

HIPAA Audits: How to Be Prepared. Lindsey Wiley, MHA, CHTS-IM, CHTS-TS HIT Manager Oklahoma Foundation for Medical Quality HIPAA Audits: How to Be Prepared Lindsey Wiley, MHA, CHTS-IM, CHTS-TS HIT Manager Oklahoma Foundation for Medical Quality An Important Reminder For audio, you must use your phone: Step 1: Call (866) 906-0123.

More information

Privacy and Security Meaningful Use Requirement HIPAA Readiness Review

Privacy and Security Meaningful Use Requirement HIPAA Readiness Review Privacy and Security Meaningful Use Requirement HIPAA Readiness Review REACH - Achieving - Achieving meaningful meaningful use of your use EHR of your EHR Patti Kritzberger, RHIT, CHPS ND e-health Summit

More information

HIPAA: AN OVERVIEW September 2013

HIPAA: AN OVERVIEW September 2013 HIPAA: AN OVERVIEW September 2013 Introduction The Health Insurance Portability and Accountability Act of 1996, known as HIPAA, was enacted on August 21, 1996. The overall goal was to simplify and streamline

More information

View the Replay on YouTube

View the Replay on YouTube View the Replay on YouTube Privacy Implications of Texas HB 300: What Should You Be Doing Now? FairWarning Executive Webinar Series December 18, 2012 Agenda Privacy Implications of Texas HB 300: What Should

More information

How To Understand And Understand The Benefits Of A Health Insurance Risk Assessment

How To Understand And Understand The Benefits Of A Health Insurance Risk Assessment 4547 The Case For HIPAA Risk Assessment Leader s Guide IMPORTANT INFORMATION FOR EDUCATION COORDINATORS & PROGRAM FACILITATORS PLEASE NOTE: In order for this program to meet Florida course requirements,

More information

HIPAA Privacy & Breach Notification Training for System Administration Business Associates

HIPAA Privacy & Breach Notification Training for System Administration Business Associates HIPAA Privacy & Breach Notification Training for System Administration Business Associates Barbara M. Holthaus privacyofficer@utsystem.edu Office of General Counsel University of Texas System April 10,

More information

Patient Privacy and Security. Presented by, Jeffery Daigrepont

Patient Privacy and Security. Presented by, Jeffery Daigrepont Patient Privacy and Security Presented by, Jeffery Daigrepont Jeffery Daigrepont, SVP No Financial Conflicts to Report Jeffery Daigrepont, Senior Vice President of The Coker Group, specializes in health

More information

Bill Moran and Betta Sherman

Bill Moran and Betta Sherman Compliance TODAY July 2013 a publication of the health care compliance association www.hcca-info.org How an eye doctor s son sees compliance an interview with Stephen Kiess Assistant General Counsel for

More information

Art Gross President & CEO HIPAA Secure Now! How to Prepare for the 2015 HIPAA Audits and Avoid Data Breaches

Art Gross President & CEO HIPAA Secure Now! How to Prepare for the 2015 HIPAA Audits and Avoid Data Breaches Art Gross President & CEO HIPAA Secure Now! How to Prepare for the 2015 HIPAA Audits and Avoid Data Breaches Speakers Phillip Long CEO at Business Information Solutions Art Gross President & CEO of HIPAA

More information

TOP 10 Security Questions Introduction Breaches and other privacy and security incidents in healthcare are on the rise due to the vast size of the industry and the oneoffs of protected health information

More information

InfoGard Healthcare Services. 2015 InfoGard Laboratories Inc.

InfoGard Healthcare Services. 2015 InfoGard Laboratories Inc. InfoGard Healthcare Services 10 Steps To Protect My Covered Entity From Breach Your Presenters Alan Martin Account Manger Marvin Byrd Security Engineer Test and Certification Laboratory Healthcare Payment

More information

Document Imaging Solutions. The secure exchange of protected health information.

Document Imaging Solutions. The secure exchange of protected health information. The secure exchange of protected health information. 2 Table of contents 3 Executive summary 3 The high cost of protected health information being at risk 4 The compliance officer s dilemma: keeping PHI

More information

Client Privacy Notice (HIPAA)

Client Privacy Notice (HIPAA) Client Privacy Notice (HIPAA) Privacy Statement Northern Human Services is required by law to maintain the privacy of Protected Health Information (PHI) and to provide individuals, this NOTICE OF PRIVACY

More information

HIPAA Happenings in Hospital Systems. Donna J Brock, RHIT System HIM Audit & Privacy Coordinator

HIPAA Happenings in Hospital Systems. Donna J Brock, RHIT System HIM Audit & Privacy Coordinator HIPAA Happenings in Hospital Systems Donna J Brock, RHIT System HIM Audit & Privacy Coordinator HIPAA Health Insurance Portability and Accountability Act of 1996 Title 1 Title II Title III Title IV Title

More information

What do you need to know?

What do you need to know? What do you need to know? DISCLAIMER Please note that the information provided is to inform our clients and friends of recent HIPAA and HITECH act developments. It is not intended, nor should it be used,

More information

Population Health Management Program Notice of Privacy Practices

Population Health Management Program Notice of Privacy Practices Population Health Management Program Notice of Privacy Practices Premier Health provides population health management services to its health plan members. Services include wellness program tools and technology,

More information

Sunday March 30, 2014, 9am noon HCCA Conference, San Diego

Sunday March 30, 2014, 9am noon HCCA Conference, San Diego Meaningful Use as it Relates to HIPAA Compliance Sunday March 30, 2014, 9am noon HCCA Conference, San Diego CLAconnect.com Objectives and Agenda Understand the statutory and regulatory background and purpose

More information

HIM 111 Introduction to Health Information Management HIM 135 Medical Terminology

HIM 111 Introduction to Health Information Management HIM 135 Medical Terminology HIM 111 Introduction to Health Information Management 1. Demonstrate comprehension of the difference between data and information; data sources (primary and secondary), and the structure and use of health

More information

Regulatory Requirements, and insure a Safe Workplace

Regulatory Requirements, and insure a Safe Workplace Proposal to Healthcare Providers on how to adhere to Regulatory Requirements, and insure a Safe Workplace (Related to Patient Protection and Affordable Care Act PPACA) including: HIPAA, HITECH, ephi, and

More information

HIPAA Privacy and Security Rules: A Refresher. Marilyn Freeman, RHIA California Area HIPAA Coordinator California Area HIM Consultant

HIPAA Privacy and Security Rules: A Refresher. Marilyn Freeman, RHIA California Area HIPAA Coordinator California Area HIM Consultant HIPAA Privacy and Security Rules: A Refresher Marilyn Freeman, RHIA California Area HIPAA Coordinator California Area HIM Consultant Objectives Provide overview of Health insurance Portability and Accountability

More information

HIPAA Omnibus Rule Practice Impact. Kristen Heffernan MicroMD Director of Prod Mgt and Marketing

HIPAA Omnibus Rule Practice Impact. Kristen Heffernan MicroMD Director of Prod Mgt and Marketing HIPAA Omnibus Rule Practice Impact Kristen Heffernan MicroMD Director of Prod Mgt and Marketing 1 HIPAA Omnibus Rule Agenda History of the Rule HIPAA Stats Rule Overview Use of Personal Health Information

More information

Chapter 3 HIPAA Cost Considerations

Chapter 3 HIPAA Cost Considerations AU1953_C03.fm Page 23 Saturday, October 11, 2003 10:22 AM Chapter 3 HIPAA Cost Considerations Background Actual costs for HIPAA compliance will vary among covered entities (CEs) because of various factors

More information

ARKANSAS OFFICE OF HEALTH INFORMATION TECHNOLOGY (OHIT) PRIVACY POLICIES

ARKANSAS OFFICE OF HEALTH INFORMATION TECHNOLOGY (OHIT) PRIVACY POLICIES ARKANSAS OFFICE OF HEALTH INFORMATION TECHNOLOGY (OHIT) PRIVACY POLICIES OHIT wishes to express its gratitude to Connecting for Health and the Markel Foundation for their work in developing the Common

More information

HIPAA and Mental Health Privacy:

HIPAA and Mental Health Privacy: HIPAA and Mental Health Privacy: What Social Workers Need to Know Presenter: Sherri Morgan, JD, MSW Associate Counsel, NASW Legal Defense Fund and Office of Ethics & Professional Review 2010 National Association

More information

Presented by Jack Kolk President ACR 2 Solutions, Inc.

Presented by Jack Kolk President ACR 2 Solutions, Inc. HIPAA 102 : What you don t know about the new changes in the law can hurt you! Presented by Jack Kolk President ACR 2 Solutions, Inc. Todays Agenda: 1) Jack Kolk, CEO of ACR 2 Solutions a information security

More information

Privacy Officer Job Description 4/28/2014. HIPAA Privacy Officer Orientation. Cathy Montgomery, RN. Presented by:

Privacy Officer Job Description 4/28/2014. HIPAA Privacy Officer Orientation. Cathy Montgomery, RN. Presented by: HIPAA Privacy Officer Orientation Presented by: Cathy Montgomery, RN Privacy Officer Job Description Serve as leader Develop Policies and Procedures Train staff Monitor activities Manage Business Associates

More information

Whitefish School District. PERSONNEL 5510 page 1 of 5 HIPAA

Whitefish School District. PERSONNEL 5510 page 1 of 5 HIPAA Whitefish School District R PERSONNEL 5510 page 1 of 5 HIPAA Note: (1) Any school district offering a group health care plan for its employees is affected by HIPAA. School districts offering health plans

More information

HEALTHCARE & SECURITY OF DATA IN THE CLOUD

HEALTHCARE & SECURITY OF DATA IN THE CLOUD HEALTHCARE & SECURITY OF DATA IN THE CLOUD August 2014 LYNLEE ESPESETH Marketing Strategy Associate Denver Fargo Minneapolis 701.235.5525 888.9.sundog FAX: 701.235.8941 www.sundoginteractive.com In this

More information

Business Associates, HITECH & the Omnibus HIPAA Final Rule

Business Associates, HITECH & the Omnibus HIPAA Final Rule Business Associates, HITECH & the Omnibus HIPAA Final Rule HIPAA Omnibus Final Rule Changes Business Associates Marissa Gordon-Nguyen, JD, MPH Health Information Privacy Specialist Office for Civil Rights/HHS

More information

Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information

Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information about HIPAA, the HITECH-HIPAA Omnibus Privacy Act, how

More information

Zip It! Feds, State Strengthen Privacy Protection. Practice Management Feature July 2012. Tex Med. 2012;108(7):33-37.

Zip It! Feds, State Strengthen Privacy Protection. Practice Management Feature July 2012. Tex Med. 2012;108(7):33-37. Zip It! Feds, State Strengthen Privacy Protection Practice Management Feature July 2012 Tex Med. 2012;108(7):33-37. By Crystal Conde Associate Editor When it comes to enforcing HIPAA data security and

More information

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc. hhughes@uslegalsupport.com www.uslegalsupport.com HIPAA Privacy Rule Sets standards for confidentiality and privacy of individually

More information

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10

HIPAA 100 Training Manual Table of Contents. V. A Word About Business Associate Agreements 10 HIPAA 100 Training Manual Table of Contents I. Introduction 1 II. Definitions 2 III. Privacy Rule 5 IV. Security Rule 8 V. A Word About Business Associate Agreements 10 CHICAGO DEPARTMENT OF PUBIC HEALTH

More information

HITRUST CSF Assurance Program You Need a HITRUST CSF Assessment Now What?

HITRUST CSF Assurance Program You Need a HITRUST CSF Assessment Now What? HITRUST CSF Assurance Program You Need a HITRUST CSF Assessment Now What? Introduction This material is designed to answer some of the commonly asked questions by business associates and other organizations

More information

HIPAA and HITECH Compliance for Cloud Applications

HIPAA and HITECH Compliance for Cloud Applications What Is HIPAA? The healthcare industry is rapidly moving towards increasing use of electronic information systems - including public and private cloud services - to provide electronic protected health

More information

Compliance. TODAY February 2013. Meet Lew Morris

Compliance. TODAY February 2013. Meet Lew Morris Compliance TODAY February 2013 a publication of the health care compliance association www.hcca-info.org Meet Lew Morris Senior Counsel with Adelman, Sheff and Smith in Annapolis, Maryland; former Chief

More information

Why Lawyers? Why Now?

Why Lawyers? Why Now? TODAY S PRESENTERS Why Lawyers? Why Now? New HIPAA regulations go into effect September 23, 2013 Expands HIPAA safeguarding and breach liabilities for business associates (BAs) Lawyer is considered a business

More information

Surviving a HIPAA Audit: What you need to know NOW So you can cope THEN. Jonathan Krasner www.beinetworks.com www.hipaasecurenow.

Surviving a HIPAA Audit: What you need to know NOW So you can cope THEN. Jonathan Krasner www.beinetworks.com www.hipaasecurenow. Surviving a HIPAA Audit: What you need to know NOW So you can cope THEN Jonathan Krasner www.beinetworks.com www.hipaasecurenow.com Healthcare IT Landscape Meaningful Use Incentives Technology Advances

More information

Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know

Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know Note: Information provided to NCRA by Melodi Gates, Associate with Patton Boggs, LLC Privacy and data protection

More information

HIPAA and Privacy Policy Training

HIPAA and Privacy Policy Training HIPAA and Privacy Policy Training July 2015 1 This training addresses the requirements for maintaining the privacy of confidential information received from HFS and DHS (the Agencies). During this training

More information

PrivacyPro ; A Key Component of Privacy Information Management Overview Whitepaper

PrivacyPro ; A Key Component of Privacy Information Management Overview Whitepaper PrivacyPro ; A Key Component of Privacy Information Management Overview Whitepaper This Whitepaper is the first of a series published by CompliancePro Solutions Founder Kelly McLendon, RHIA which will

More information

HIPAA Compliance. 2013 Annual Mandatory Education

HIPAA Compliance. 2013 Annual Mandatory Education HIPAA Compliance 2013 Annual Mandatory Education What is HIPAA? Health Insurance Portability and Accountability Act Federal Law enacted in 1996 that mandates adoption of Privacy protections for health

More information

Reputation Management Surviving a HIPAA Breach or Audit

Reputation Management Surviving a HIPAA Breach or Audit Reputation Management Surviving a HIPAA Breach or Audit Carolyn P. Hartley, MLA President, CEO Physicians EHR, Inc Former VP, Media Relations Presented to MGMA October 7, 2013 What to Do in the Event of

More information

Privacy Compliance Health Occupations Students

Privacy Compliance Health Occupations Students Privacy Compliance Health Occupations Students Health Occupations Students The information in this power point is the same information provided to new SCHS caregivers at their orientation. We cannot stress

More information

HIPAA Compliance for Students

HIPAA Compliance for Students HIPAA Compliance for Students The Health Insurance Portability and Accountability Act (HIPAA) was passed in 1996 by the United States Congress. It s intent was to help people obtain health insurance benefits

More information

Surviving a HIPAA violation One Agency s Experience Presented by: Roger Shindell. Topics Covered Part One. Topics Covered Part Two.

Surviving a HIPAA violation One Agency s Experience Presented by: Roger Shindell. Topics Covered Part One. Topics Covered Part Two. Surviving a HIPAA violation One Agency s Experience Presented by: Roger Shindell President & CEO Carosh Compliance Solutions & Liz Mayer, RHIA Director, Organizational Integrity HCI Care Services and VNS

More information

HIPAA/HITECH Privacy and Security for Long Term Care. Association of Jewish Aging Services 1

HIPAA/HITECH Privacy and Security for Long Term Care. Association of Jewish Aging Services 1 HIPAA/HITECH Privacy and Security for Long Term Care 1 John DiMaggio Chief Executive Officer, Blue Orange Compliance Cliff Mull Partner, Benesch, Healthcare Practice Group About the Presenters John DiMaggio,

More information

Table of Contents. Page 1

Table of Contents. Page 1 Table of Contents Executive Summary... 2 1 CPSA Interests and Roles in ehealth... 4 1.1 CPSA Endorsement of ehealth... 4 1.2 CPSA Vision for ehealth... 5 1.3 Dependencies... 5 2 ehealth Policies and Trends...

More information

2/9/2012. 2012 HIPAA Privacy and Security Audit Readiness. Table of contents

2/9/2012. 2012 HIPAA Privacy and Security Audit Readiness. Table of contents 2012 HIPAA Privacy and Security Audit Readiness Mark M. Johnson National HIPAA Services Director Table of contents Page Background 2 Regulatory Background and HITECH Impacts 3 Office of Civil Rights (OCR)

More information

Commission on Certification for Health Informatics and Information Management (CCHIIM) Recertification Guide

Commission on Certification for Health Informatics and Information Management (CCHIIM) Recertification Guide Commission on Certification for Health Informatics and Information Management (CCHIIM) Recertification Guide Maintenance of Certification RHIA R E G I S T E R E D H E A LT H I N F O R M AT I O N A D M

More information

SecurityMetrics Business Associate HIPAA compliance program

SecurityMetrics Business Associate HIPAA compliance program SecurityMetrics Business Associate HIPAA compliance program IS YOUR PHI SAFE? Business associates help your business succeed, but are they a liability? When your BAs are not HIPAA compliant, your business

More information

Patti Levin, LICSW, Psy.D. Clinical Psychologist

Patti Levin, LICSW, Psy.D. Clinical Psychologist Patti Levin, LICSW, Psy.D. Clinical Psychologist 673 Boylston St. #4. 617.227.2008 Boston, MA02116 fax: 617.247.7523 www.drpattilevin.com email:patti@drpattilevin.com Notice of Privacy Practices (HIPAA)

More information

HYDE PARK PEDIATRICS

HYDE PARK PEDIATRICS HYDE PARK PEDIATRICS THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE READ THIS NOTICE CAREFULLY In the material

More information

Mobile Medical Devices and BYOD: Latest Legal Threat for Providers

Mobile Medical Devices and BYOD: Latest Legal Threat for Providers Presenting a live 90-minute webinar with interactive Q&A Mobile Medical Devices and BYOD: Latest Legal Threat for Providers Developing a Comprehensive Usage Strategy to Safeguard Health Information and

More information

Top Ten Technology Risks Facing Colleges and Universities

Top Ten Technology Risks Facing Colleges and Universities Top Ten Technology Risks Facing Colleges and Universities Chris Watson, MBA, CISA, CRISC Manager, Internal Audit and Risk Advisory Services cwatson@schneiderdowns.com April 23, 2012 Overview Technology

More information

HIPAA, PHI and Email. How to Ensure your Email and Other ephi are HIPAA Compliant. www.fusemail.com

HIPAA, PHI and Email. How to Ensure your Email and Other ephi are HIPAA Compliant. www.fusemail.com How to Ensure your Email and Other ephi are HIPAA Compliant How to Ensure Your Email and Other ephi Are HIPAA Compliant Do you know if the patient appointments your staff makes by email are compliant with

More information

HIPAA Employee Training Guide. Revision Date: April 11, 2015

HIPAA Employee Training Guide. Revision Date: April 11, 2015 HIPAA Employee Training Guide Revision Date: April 11, 2015 What is HIPAA? The Health Insurance Portability and Accountability Act of 1996 (also known as Kennedy- Kassebaum Act ). HIPAA regulations address

More information

Security Compliance, Vendor Questions, a Word on Encryption

Security Compliance, Vendor Questions, a Word on Encryption Security Compliance, Vendor Questions, a Word on Encryption Alexis Parsons, RHIT, CPC, MA Director, Health Information Services Security/Privacy Officer Shasta Community Health Center aparsons@shastahealth.org

More information

USES AND DISCLOSURES OF HEALTH INFORMATION

USES AND DISCLOSURES OF HEALTH INFORMATION HIPAA Privacy Policy NOTICE OF PRIVACY PRACTICES This notice describes how health information about you may be used and disclosed. Please review carefully. The privacy of your health information is important

More information

HIPAA regulation: The challenge of integrating compliance and patient care

HIPAA regulation: The challenge of integrating compliance and patient care HIPAA regulation: The challenge of integrating compliance and patient care January 2016 Contents Introduction 3 HIPAA s technology neutral structure 3 creates opportunity and challenge Compliance can pave

More information

COMPLIANCE ALERT 10-12

COMPLIANCE ALERT 10-12 HAWAII HEALTH SYSTEMS C O R P O R A T I O N "Touching Lives Every Day COMPLIANCE ALERT 10-12 HIPAA Expansion under the American Recovery and Reinvestment Act of 2009 The American Recovery and Reinvestment

More information

Knowledge Clusters (Curriculum Components)

Knowledge Clusters (Curriculum Components) 2011 AHIMA Curriculum and Knowledge Clusters Health Information Management Baccalaureate Degree Approved by AHIMA Education Strategy Committee HIM Baccalaureate Degree Entry-Level I. Domain: Health Data

More information

HIPAA Privacy Keys to Success Updated January 2010

HIPAA Privacy Keys to Success Updated January 2010 HIPAA Privacy Keys to Success Updated January 2010 HIPAA Job Specific Education 1 HIPAA and Its Purpose What is HIPAA? Health Insurance Portability and Accountability Act of 1996 Title II Administrative

More information

The HIPAA Omnibus Final Rule

The HIPAA Omnibus Final Rule WHITE PAPER The HIPAA Omnibus Final Rule Four risk exposure events that can uncover compliance issues leading to investigations, potential fines, and damage to your organization s reputation. By Virginia

More information

Answering to HIPAA. Who Answers Your Phone? Prepared by Kenneth E. Rhea, MD, FASHRM. Brought to you by. www.duxware.com

Answering to HIPAA. Who Answers Your Phone? Prepared by Kenneth E. Rhea, MD, FASHRM. Brought to you by. www.duxware.com Answering to HIPAA Who Answers Your Phone? Prepared by Kenneth E. Rhea, MD, FASHRM Brought to you by www.duxware.com The Event On February 20, 2014 at 8:00 PM an Internal Medicine specialist received a

More information

HIPAA Privacy Policies

HIPAA Privacy Policies HIPAA Privacy Policies Healthcare Insurance Portability and Accountability Act of 1996 (HIPAA) The HIPAA Privacy Rule created a national standard to protect patient s medical records and other personal

More information

Health Information Management System

Health Information Management System ANNUAL PROGRAM/DEPARTMENT ASSESSMENT FOR LEARNING PLAN Please send your Plan to the Assessment FOR Student Learning office via learning@cscc.edu. (Phone 287-3936) The Plan will be reviewed by members of

More information

REIMBURSEMENT CODING SERIES

REIMBURSEMENT CODING SERIES REIMBURSEMENT CODING SERIES Occ. Work Prob. Effective Last Code No. Class Title Area Area Period Date Action 4839 Reimbursement Coder 02 445 6 mo. 00/00/00 Rev. 4840 Reimbursement Coding Specialist 02

More information

HIPAA PRIVACY AND SECURITY AWARENESS

HIPAA PRIVACY AND SECURITY AWARENESS HIPAA PRIVACY AND SECURITY AWARENESS Introduction The Health Insurance Portability and Accountability Act (known as HIPAA) was enacted by Congress in 1996. HIPAA serves three main purposes: To protect

More information

PROTECTED HEALTH INFORMATION

PROTECTED HEALTH INFORMATION SUBJECT: PROTECTED HEALTH INFORMATION POLICY: Department of Origin: Compliance Department Responsible Position: Vice President, Compliance and Audit Date(s) of Review and Revision: 12/13; 05/14; 12/14

More information

HIPAA 101. March 18, 2015 Webinar

HIPAA 101. March 18, 2015 Webinar HIPAA 101 March 18, 2015 Webinar Agenda Acronyms to Know HIPAA Basics What is HIPAA and to whom does it apply? What is protected by HIPAA? Privacy Rule Security Rule HITECH Basics Breaches and Responses

More information

Notice of Privacy Practices

Notice of Privacy Practices Notice of Privacy Practices This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully. This Notice of

More information

HIPAA Privacy & Security Rules

HIPAA Privacy & Security Rules HIPAA Privacy & Security Rules HITECH Act Applicability If you are part of any of the HIPAA Affected Areas, this training is required under the IU HIPAA Privacy and Security Compliance Plan pursuant to

More information