Transition to Electronic Medical Records (EMR)

Size: px
Start display at page:

Download "Transition to Electronic Medical Records (EMR)"

Transcription

1 Transitin t Electrnic Medical Recrds (EMR) CPSA Guideline September 2004 This infrmatin is prvided t assist practitiners in making decisins related t the transitin t using electrnic medical recrds in their practice. These cmments are nt intended t answer all questins r cver all ptential situatins nr shuld this dcument be interpreted as legal advice. Physicians are encuraged t cnsult specific references and surces fr detailed guidance regarding selectin f hardware, sftware and practice management issues. In this dcument electrnic medical recrd (EMR) refers t the physician s ffice system fr the management f their patients recrds as distinct frm an electrnic health recrd (EHR) which is a health system resurce f widely shared clinical infrmatin. A. Intrductin Medical recrds are an integral part f medical practice. The cntent and standards fr medical recrds are described in a separate Plicy f the Cllege f Physicians and Surgens f Alberta entitled Physicians Office Medical Recrds 1. The purpse f this guideline is t address quality f care, patient safety, ethical, and medic-legal aspects f the transitin f a medical practice frm paper based medical recrds t using an electrnic medical recrd (EMR). Within a physician s ffice, the medical recrd perfrms multiple functins in that it: Maintains the histry f patient care. Supprts the wrkflw f the clinical and administrative functins within the ffice fr physicians and staff. Supprts the cmmunicatin with external surces f medical infrmatin such as hspitals, labratry and radilgy clinics as well as cnsultatins and referrals with clleagues. Mving t an electrnic medical recrd represents a paradigm change fr the physician, bth in the ability t manage patient infrmatin, and in the design f clinical prcesses. It als establishes new and/r changing respnsibilities fr the use, disclsure and security f the medical recrd. As a result, the transitin frm paper t electrnic medical recrds is a cmplex task and must be managed frm many aspects - clinically, administratively, culturally and rganizatinally. The transitin activity must include nt nly the prcess changes inherent in the use f a new tl, but als the technical and prcedural training, and the resultant changes t physician and staff rles within the ffice. While the change in medical recrd mdality frm paper t electrnic systems represents a majr transitin, care shuld be taken nt t impact the patient-physician relatinship. Nr shuld the integrity f the clinical prcesses r the cntinuity f care be impaired during the transitin perid. Five key principles have been identified t guide the transitin prcess: Patient infrmatin must be secure. Privacy f patient infrmatin must be maintained. The integrity f the medical recrd cntent must be maintained. The integrity f the clinical wrkflw supprted by the medical recrd must be maintained. Cntinuity and quality f care must be maintained thrugh the transitin perid.

2 Transitin t Electrnic Medical Recrds: CPSA Guideline Page 2 f 8 Each principle has recmmendatins as well as cnsideratins fr their applicatin. Nte that the principles are nt discrete - they are intended t wrk interdependently. This dcument deals with a cmplex undertaking and has many technical references which may at first glance be verwhelming fr thse physicians at the beginning f the transitin r cntemplating a transitin. External resurces may be useful t assist in yur understanding f these recmmendatins and their applicatin t yur practice. These recmmendatins can be a valuable checklist befre, during and after the transitin t evaluate and guide yur implementatin. B. Principles and Implementatin 1. Patient infrmatin must be secure. The security f paper-based medical recrds is primarily based n physical security while electrnic medical recrds present many new issues and threats that must be cnsidered (e.g. denial f service with viruses, lss f data due t crruptin f cmputer hardware, theft f data due t intrusin, etc.). Effective security is a cmbinatin f administrative practices, physical security and technical security and shuld ensure the integrity, cnfidentiality and availability f the medical recrd. Recmmendatins: Practices shuld undertake a frmal risk assessment that cnsiders lcal risk factrs and dependencies, and develp a practice security plicy and system management practices. Standards are available t prvide guidance in these areas 9. Each practice shuld establish an initial assessment f the security risks including administrative practices, physical security and technical security t ensure the integrity, cnfidentiality and availability f the medical recrd. Security plicies and staff educatin shuld be implemented t address specific security threats. Mnitring f security lgs and reprts shuld be perfrmed n a regular basis t assess the perfrmance f the security measures. Majr security events r technical changes shuld trigger a security review. Physical security measures must be implemented t prevent unauthrized access r ptential lss r failure t the system. Risk factrs include theft, pwer failure, natural disasters and deliberate tampering. Access t hardware, sftware and strage media shuld be cntrlled, particularly t centralized data strage. Hardware that is accessible by unattended patients (i.e. in an examining rm) shuld always be explicitly lcked dwn t prevent access. Screens that are viewable by patients shuld nt display sensitive infrmatin f ther patients (i.e. scheduling infrmatin with diagnstic infrmatin). Access and authrizatin prcesses must be implemented t ensure nly legitimate users have access t the medical recrd and that each user has the apprpriate level f access t the medical recrd. Every user including staff, students, and lcums must have a unique identificatin and user-id with apprpriate passwrd cntrls. Audit lgging must be enabled t recrd actins taken by each user. Authrizatin rules are defined and implemented by user-id (r ID s attached t security grups) t prvide access t the medical recrd. Adequate netwrk security (such as firewalls, Virtual Private Netwrks, secnd factr authenticatin, etc.) is implemented t ensure that nly authrized and authenticated users can access the medical recrd.

3 Transitin t Electrnic Medical Recrds: CPSA Guideline Page 3 f 8 The integrity and cnfidentiality f the medical recrd must be ensured. Audit lgs are maintained t supprt the authenticity f medical recrd additins, r updates. Access t files r databases underlying the medical recrd sftware is restricted. Changes t lcally created data within the medical recrd are by addendum r strike-thrugh as per the medical recrds plicy 1. External dcuments stred in the medical recrd shuld be in read-nly frmats. Disclsures f the medical recrd via t patients r t prviders must have adequate prtectin. The CMPA has specific recmmendatins fr t patients r t ther health care prviders 12 including that messages that cntain patient infrmatin are encrypted and are supprted by a patient cnsent t utilize . Other ptins include the use f passwrd prtected attachments within an . Adequate virus prtectin must be in place t ensure data is nt mdified r destryed by external prcesses. Dispsal f strage media (including redundant hardware, temprary strage, back-up media, etc.) must be cmplete. This wuld include physical destructin f the media and/r re-frmatting t prevent unauthrized access deleting the infrmatin des nt physically delete the data, nly the indexing infrmatin. The reliability and accessibility f the applicatin hardware and sftware must be ensured. A back-up f the medical recrds shuld be perfrmed n a regular schedule (at least daily). There shuld be a cycle f back-up media t minimize expsure t failed backup media. Back-up media shuld be stred at a secure ff-site lcatin. Testing f the restre prcess and back-up media shuld be dne n a regular schedule. A cntingency plan shuld be in place fr disaster recvery and denial f service attacks. In the event f an emergency r disruptin t data accessibility, a predefined plan f actin shuld cme int play including technical and clinical resurces, data recvery plans, manual scheduling and charting, fllw-up n reprts, etc. Hardware and sftware (applicatin and perating systems) shuld be maintained at reasnable levels f currency fr supprt and maintenance by the vendr. Pearls The public visibility and emtinal threat f hackers are ften seen as the majr security threat hwever the vast majrity f security breaches ccur within rganizatinal dmains by persnnel with legitimate authrizatin. System back-ups are an integral part f system management, hwever the testing f the backups thrugh a recvery prcess is ften less rigid and may nt be fully understd. It is gd practice t ensure recvery testing is perfrmed n a regular basis, especially after a system upgrade (hardware r sftware), and that the prcess is dcumented. Enhanced security is required where netwrks are mre expsed (i.e. thse with wireless devices and remte access), r where equipment that stre infrmatin n lcal drives which are at risk f lss r theft (i.e. prtable devices such as laptps, PDA s, tablets). In these instances additinal encryptin r authenticatin prcesses are usually required. 2. Privacy f patient infrmatin must be maintained. Electrnic recrds enable a dramatically enhanced capacity fr the management f patient infrmatin. This increased ptential needs t be evaluated in terms f the prfessinal/ethical respnsibility t maintain patient recrds and als the legal respnsibilities as a custdian f health infrmatin. Recmmendatins: Physicians shuld establish frmal prtcls and prcedures t ensure that patient infrmatin is dcumented, maintained, and disclsed in accrdance with the current laws and standards set frth by the Health Infrmatin Act 3. The Office f the Infrmatin and Privacy Cmmissiner has prvided guidelines fr health infrmatin custdians and the Physician Office System Prgram have established a reference guide which can prvide guidance n specific

4 Transitin t Electrnic Medical Recrds: CPSA Guideline Page 4 f 8 plicies required by legislatin 2. Nte that the cmpletin and submissin f a Privacy Impact Assessment is required under the Health Infrmatin Act prir t the implementatin f an Electrnic Medical Recrd system 2,3,5. Physicians have a fiduciary and prfessinal respnsibility t cllect patient infrmatin with sufficient infrmatin t allw anther practitiner t assume the patient s care at any pint in the curse f treatment withut the lss f cntinuity 1. This respnsibility extends t disclsures fr the release and transfer f medical recrds and the cnfidentiality in the intra-prfessinal exchange f infrmatin. The Health Infrmatin Act 3 defines the parameters fr the disclsure and use f health infrmatin and the requirements fr the cllectin f cnsent. Physicians shuld be prepared t advise patients what their access cntrl plicies are within the practice. Patients requests t apply restrictins r t suppress infrmatin t ne r mre named clinicians shuld be cnsidered carefully, althugh ther legal r ethical factrs must be cnsidered. Electrnic medical recrds dramatically increase the ability f physicians t use patient infrmatin fr new purpses, based n the ability t search, aggregate, crrelate and therwise manipulate individual infrmatin. Care must be taken t ensure that any use r disclsure f health infrmatin cmplies with the Health Infrmatin Act and as such, apprpriate measures such as patient cnsents and ethics reviews are undertaken when utilizing this enhanced functinality. Persnal health infrmatin shuld nly be used fr the purpse it was cllected unless additinal cnsent is btained. Release f medical infrmatin is permitted r required in certain circumstances as defined by legislatin. Uses and disclsures f persnally identifiable health infrmatin fr the secndary purpse f research must have apprpriate ethics review and apprval, and patient cnsent if required. Pearls A patient handut n the privacy plicies f the practice may assist in the understanding and assurance f patients that their privacy is still being maintained. Sme individuals may have a limited understanding f the privacy framewrk and infrmatin exchange that exists tday in a paper-based envirnment (i.e. higher expectatins f the infrmatin sharing than what exists tday, and als miscnceptins f hw an EMR is used). Many may als cnfuse the physician s EMR with the Electrnic Health Recrd, a shared health system tl which has had sme media expsure. 3. The integrity f the medical recrd cntent must be maintained. Managing health infrmatin in a transitinal envirnment carries the risk that the quality f care may be adversely affected if the transitin is nt effectively managed. There will be a perid f time within mst practices where bth paper and electrnic recrds will be in use until all relevant patient data has been established in the EMR and all physicians in the practice use the electrnic recrd. Recmmendatins: As physicians remain the custdian f infrmatin regardless f the media in which the infrmatin is maintained, it is the respnsibility f the physician t ensure that: The cmplete medical recrd is accessible at all key clinical decisin pints. The infrmatin is current, accurate and cmprehensive fr the purpse fr which it is required. There must be an audit trail t ensure that if infrmatin is altered, there will be a recrd f the riginal, the date and time f the alteratin, and the identity f the persn wh made the change 1. Changes t the EMR are made either by a new nte r addendum r by a strke thrugh, r bth. If relevant patient infrmatin is maintained externally t the electrnic medical recrd (i.e. in a shared recrd such as a Prvincial r Reginal Electrnic Health Recrd), the physician must: Maintain prcedures and dcumentatin t supprt cntrls ensuring the receipt f result reprts and ther relevant rders and that apprpriate fllw-up actins have been taken 10. Ensure that defined prcedures are in place t prvide care in the event that the external surces f infrmatin are nt accessible.

5 Transitin t Electrnic Medical Recrds: CPSA Guideline Page 5 f 8 Take adequate steps t ensure that the custdian f the external infrmatin surce has, and can demnstrate an adequate plicy and prcedure in place regarding privacy, security, and peratinal integrity t ensure apprpriate standards fr netwrk access. Ensure that the custdian can and will supprt the retentin and subsequent access requirements as per the medical recrd plicy as defined by the CPSA 1. If external electrnic interfaces are integrated with the electrnic medical recrd, adequate testing must be perfrmed t ensure that cntrls are in place t ensure that all recrds are prcessed, accunted fr, and that existing data cannt be crrupted r lst during the integratin. Standards fr data quality, accuntability, and integrity need t be incrprated int the EMR within each practice and adpted t prmte unifrmity in the data fr grup practices. The features f quality data elements include: Accessibility data items shuld be easily btainable and legal t cllect Accuracy data are the crrect values and are valid Cmprehensiveness all required data items are included Cnsistency data is recrded in a cnsistent manner Currency the data shuld be up t date Definitin each data element shuld have a clear meaning and acceptable values Granularity the attributes and values f data shuld be defined at the crrect level f detail Relevancy data are meaningful fr the purpse fr which they were cllected In the initial transitin perid (which culd last frm 6 mnths t tw years) there will likely be a cmbinatin f electrnic and paper charts. A defined prcess and transfer date shuld be identified fr the EMR t becme the fficial medical recrd (the surce f truth) versus the paper chart r ther clinical recrd in use, t prevent failures in the receiving r fllwing up f medical reprts 10. Each type f dcument/reprt that is received int the ffice shuld have a defined prcess and destinatin t either the paper chart r the electrnic recrd, r bth. There must be a prcess in place t ensure that there are cntrls in place t specifically manage the changever perid f the handling f a dcument/reprt. All individuals using the recrds must understand the cntent and limitatins f each f the recrds in the perid f transitin. Each recrd must be clearly identifiable as t its status as the primary medical recrd, parallel recrd, r partial recrd. Fr the electrnic recrd t be deemed the primary medical recrd, relevant histry frm the paper chart must be transferred and/r referenced directly. This is ften dne in cnjunctin with a cmprehensive review f the chart (i.e. as part f a cmplete physical, r an insurance reprt) and shuld have a standardized prcess and cntent. The dispsitin f paper charts nce transitined t an electrnic chart must still fllw the parameters established in the Physician Office Medical Recrds plicy 1. If the paper chart has been transferred in its entirety in nn-editable frm (i.e. the entire chart has been scanned int the electrnic chart), the paper chart can be dispsed as per nrmal dispsitin guidelines and the electrnic frmat becmes the clinical histry. If paper charts have been summarized with the relevant histry transferred after a diligent ascertainment that the clinically relevant material frm the past ten years (r further if deemed necessary) has been included, the paper chart may be archived r destryed. The physician may find it useful t dcument the prcedure used in the transfer indicating the type r ratinale f material mitted frm the transfer as well as any summarizatins.

6 Transitin t Electrnic Medical Recrds: CPSA Guideline Page 6 f 8 Pearls Be cautius f features embedded within the sftware applicatin which may set default values that may create data in the medical recrd that was nt an actual bservatin, r the use f a template which may limit the additin f relevant data. Evaluate the requirements yu may have t create reprts r utging dcuments t determine the structure f yur input data (i.e. defining what is text, discrete data elements, scanned reprts, etc) s that future data analysis r practice review is enabled. Fr example, including a prescriptin within a textual cmment in a prgress nte may render it inaccessible when searching the recrd fr a specific drug based n a recall ntice. The Electrnic Health Recrd is an evlving tl which in time may alter the types f infrmatin which has traditinally been held within the physician s medical recrd (i.e. lab results) as this infrmatin may be held in centralized surce. Given the relative newness f these prcesses, extra diligence shuld be taken t evaluate the maturity f these tls, the retentin f data by the custdian, and the access prcesses fr histrical and medic-legal requirements prir t making the decisin t nt maintain this data in the physician s medical recrd. Cnfrmance with Vendr Cnfrmance and Usability Requirements (VCUR)-apprved prducts will help t ensure that acceptable prvince-wide standards are achieved The integrity f the clinical wrkflw supprted by the medical recrd must be maintained. There are many clinical prcesses directly r indirectly supprted by the medical recrd. The transitin t electrnic recrds may alter these prcesses which may include imprtant safety precautins r ther critical wrkflw items. Recmmendatins: The implementatin f an electrnic medical recrd will necessitate prcess changes in the practice wrkflw and ften the rles that the physician and assciated staff perfrm. Many f the wrkflw prcesses designed n the mvement f the paper chart will n lnger be valid and shuld be frmally evaluated and ptimized fr patient safety and quality f care. The tasks assigned t individuals must fall within guidelines fr prfessinal scpes f practice and have a defined delegatin f authrity. The implementatin f the technlgy t supprt electrnic medical recrds is ften accmpanied with the capability fr electrnic mail. can be used fr internal cmmunicatin within an ffice, physician t physician cmmunicatin, and fr patient t physician cmmunicatin. s are an explicit frm f cmmunicatin and therefre are part f the medical recrd. Care shuld be taken t ensure the is attached t the medical recrd in the same frmat and lcatin as ther external cmmunicatin. The CMPA has prvided guidelines regarding the use f 12 which shuld be cnsulted. At a minimum: handling rules (including service levels and purpse limitatins) shuld be explicit and clearly articulated t patients. Cnsent shuld be btained frm the patient t clarify the expectatins and prcessing f s. Physicians shuld be aware that emplyers and Internet Service Prviders can (and d) stre and read s. Therefre the cnfidentiality f s must be taken int accunt, and text and attachments shuld have adequate encryptin. Physicians shuld have prcedures fr the timely receipt, respnses and an escalatin prcess where standards fr management are nt met. Text based cmmunicatin can lack the cntext and dynamic nature f persnal cmmunicatin therefre the physician needs t recgnize the limitatins f this type f cmmunicatin. Clinical management prcesses and cntrls have traditinally been linked t the physical lcatin and transfer f the paper chart. The lack f a physical chart necessitates the implementatin f ther cntrl mechanisms t prevent fllw-up failures. Specific recmmendatins fr fllw-up failures are identified in a separate guideline 10, hwever the electrnic recrd shuld at a minimum factr in the fllw items:

7 Transitin t Electrnic Medical Recrds: CPSA Guideline Page 7 f 8 Fllw-up appintments Referral appintments Reprts received Reprts handled, signed ff and filed Cmmunicatin attempts Prcesses shuld be develped t ensure the integratin, inclusin, and update f multiple recrds as they becme available at all clinical decisin pints. Data and charting standards fr shared recrds via netwrks within and between practitiners shuld be develped t ensure that anther practitiner can assume care f the patient with full understanding f the cntent f the medical recrd. Pearl Planning fr the implementatin f an EMR prvides tremendus pprtunity fr imprvements in wrkflw f the practice, as well as with individual prcedures. Remember t balance explring pprtunities t imprve current prcesses, rles r timing based n the paradigm f the paper chart with the limits f the capacity fr change by the peple invlved. 5. Cntinuity and quality f care must be maintained thrugh the transitin perid. The verriding issue during this perid f transitin is that the level f patient care cannt suffer in a manner that risks patient safety r the quality f care. First, d n harm Recmmendatins: A gd management strategy is essential t ensure that the implementatin f the electrnic medical recrd des nt expse the patient t risk. This shuld include at a minimum: A readiness assessment Educatin & administrative needs Clinical practice and wrkflw definitins An evaluatin f technical requirements Definitin f staff rles & delegatin f authrity Design f the cnversin and hybrid system prcesses Implementatin f safety and cntrl prcesses There must be an assurance f the cmpetency f resurces in the use f the technlgy and f the prcess changes that have been implemented. Pearls Critical fr the successful implementatin is the appintment f a clinical technlgy leader fr the practice. This persn must have a dedicated allcatin f time t prvide technical supprt, design and manage enhancements t wrkflw and t develp data and charting standards. The intrductin f any frm f change usually is accmpanied by a perid f lst efficiency during the implementatin perid, and is als a perid f high stress. Care t manage the verall wrklad during this perid is essential. C. Cnclusin The transitin t electrnic medical recrds (beynd the implementatin f the hardware and sftware) represents a significant change t the clinical prcesses in a medical practice. These changes must be carefully cnsidered t ensure patient safety and quality f care thrughut the transitin perid, primarily thrugh the cntinued integrity f the medical recrd and the clinical

8 Transitin t Electrnic Medical Recrds: CPSA Guideline Page 8 f 8 prcesses that are supprted by the medical recrd. In additin, changes that are inherent with the change t electrnic recrds such as patient privacy and infrmatin security must be managed. The transitin t electrnic recrds is a majr step in its wn right. Hwever, this transitin is als the beginning step in a much larger transitin perid bth within the practice and in the health system as a whle. Once the medical recrd is in electrnic frm, there will be further pprtunities t initiate clinical practice changes at an individual patient level, at the practice level as well as at the ppulatin level. Imprtant Reference Surces 1. Physicians Office Medical Recrds. CPSA June HIA Guide t Plicies and Prcedures fr Physician Offices. POSP February 2003 HIA Guide t Privacy Impact Statements. POSP February Health Infrmatin Act f Alberta. OIPC Release f Medical Infrmatin: A Guide fr Alberta Physicians. CPSA. March Privacy Impact Assessments Release f Data fr Research Purpses CMA Health Infrmatin Privacy Cde Vendr Cnfrmance and Usability Requirements COACH Guidelines fr the Prtectin f Health Infrmatin Preventing Fllw-up Failures when Caring fr Patients. CPSA August The Referral/Cnsultatin Prcess. CPSA June Physician-Patient Cmmunicatin: Legal Risks. Canadian Medical Prtective Assciatin Infrmatin Letter. December

GUIDANCE FOR BUSINESS ASSOCIATES

GUIDANCE FOR BUSINESS ASSOCIATES GUIDANCE FOR BUSINESS ASSOCIATES This Guidance fr Business Assciates dcument is intended t verview UPMCs expectatins, as well as t prvide additinal resurces and infrmatin, t UPMC s HIPAA business assciates.

More information

HIPAA HITECH ACT Compliance, Review and Training Services

HIPAA HITECH ACT Compliance, Review and Training Services Cmpliance, Review and Training Services Risk Assessment and Risk Mitigatin: The first and mst imprtant step is t undertake a hlistic risk assessment that examines the risks and cntrls related t fur critical

More information

Personal Data Security Breach Management Policy

Personal Data Security Breach Management Policy Persnal Data Security Breach Management Plicy 1.0 Purpse The Data Prtectin Acts 1988 and 2003 impse bligatins n data cntrllers in Western Care Assciatin t prcess persnal data entrusted t them in a manner

More information

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy COPIES-F.Y.I., INC. Plicies and Prcedures Data Security Plicy Page 2 f 7 Preamble Mst f Cpies FYI, Incrprated financial, administrative, research, and clinical systems are accessible thrugh the campus

More information

Session 9 : Information Security and Risk

Session 9 : Information Security and Risk INFORMATION STRATEGY Sessin 9 : Infrmatin Security and Risk Tharaka Tennekn B.Sc (Hns) Cmputing, MBA (PIM - USJ) POST GRADUATE DIPLOMA IN BUSINESS AND FINANCE 2014 Infrmatin Management Framewrk 2 Infrmatin

More information

HIPAA Compliance 101. Important Terms. Pittsburgh Computer Solutions 724-942-1337

HIPAA Compliance 101. Important Terms. Pittsburgh Computer Solutions 724-942-1337 HIPAA Cmpliance 101 Imprtant Terms Cvered Entities (CAs) The HIPAA Privacy Rule refers t three specific grups as cvered entities, including health plans, healthcare clearinghuses, and health care prviders

More information

Data Protection Act Data security breach management

Data Protection Act Data security breach management Data Prtectin Act Data security breach management The seventh data prtectin principle requires that rganisatins prcessing persnal data take apprpriate measures against unauthrised r unlawful prcessing

More information

BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS

BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS SERIES: 1 General Rules RULE: 17.1 Recrd Retentin Scpe: The purpse f this rule is t establish the systematic review, retentin and destructin

More information

How To Ensure Your Health Care Is Safe

How To Ensure Your Health Care Is Safe Guidelines fr Custdians t assess cmpliance with the Persnal Health Infrmatin Privacy and Access Act (PHIPAA) This dcument is designed t help custdians evaluate readiness fr cmpliance with PHIPAA and t

More information

POLICY 1390 Information Technology Continuity of Business Planning Issued: June 4, 2009 Revised: June 12, 2014

POLICY 1390 Information Technology Continuity of Business Planning Issued: June 4, 2009 Revised: June 12, 2014 State f Michigan POLICY 1390 Infrmatin Technlgy Cntinuity f Business Planning Issued: June 4, 2009 Revised: June 12, 2014 SUBJECT: APPLICATION: PURPOSE: CONTACT AGENCY: Plicy fr Infrmatin Technlgy (IT)

More information

Version Date Comments / Changes 1.0 January 2015 Initial Policy Released

Version Date Comments / Changes 1.0 January 2015 Initial Policy Released Page 1 f 6 Vice President, Infrmatics and Transfrmatin Supprt APPROVED (S) REVISED / REVIEWED SUMMARY Versin Date Cmments / Changes 1.0 Initial Plicy Released INTENT / PURPOSE The Infrmatin and Data Gvernance

More information

Key Steps for Organizations in Responding to Privacy Breaches

Key Steps for Organizations in Responding to Privacy Breaches Key Steps fr Organizatins in Respnding t Privacy Breaches Purpse The purpse f this dcument is t prvide guidance t private sectr rganizatins, bth small and large, when a privacy breach ccurs. Organizatins

More information

University of Texas at Dallas Policy for Accepting Credit Card and Electronic Payments

University of Texas at Dallas Policy for Accepting Credit Card and Electronic Payments University f Texas at Dallas Plicy fr Accepting Credit Card and Electrnic Payments Cntents: Purpse Applicability Plicy Statement Respnsibilities f a Merchant Department Prcess t Becme a Merchant Department

More information

Chapter 7 Business Continuity and Risk Management

Chapter 7 Business Continuity and Risk Management Chapter 7 Business Cntinuity and Risk Management Sectin 01 Business Cntinuity Management 070101 Initiating the Business Cntinuity Plan (BCP) Purpse: T establish the apprpriate level f business cntinuity

More information

A96 CALA Policy on the use of Computers in Accredited Laboratories Revision 1.5 August 4, 2015

A96 CALA Policy on the use of Computers in Accredited Laboratories Revision 1.5 August 4, 2015 A96 CALA Plicy n the use f Cmputers in Accredited Labratries Revisin 1.5 August 4, 2015 A96 CALA Plicy n the use f Cmputers in Accredited Labratries TABLE OF CONTENTS TABLE OF CONTENTS... 1 CALA POLICY

More information

First Global Data Corp.

First Global Data Corp. First Glbal Data Crp. Privacy Plicy As f February 23, 2015 Ding business with First Glbal Data Crp. ("First Glbal", First Glbal Mney, "we" r "us", which includes First Glbal Data Crp. s subsidiary, First

More information

Data Protection Policy & Procedure

Data Protection Policy & Procedure Data Prtectin Plicy & Prcedure Page 1 Prcnnect Marketing Data Prtectin Plicy V1.2 Data prtectin plicy Cntext and verview Key details Plicy prepared by: Adam Haycck Apprved by bard / management n: 01/01/2015

More information

Privacy Policy. The Central Equity Group understands how highly people value the protection of their privacy.

Privacy Policy. The Central Equity Group understands how highly people value the protection of their privacy. Privacy Plicy The Central Equity Grup understands hw highly peple value the prtectin f their privacy. Fr that reasn, the Central Equity Grup takes particular care in dealing with any persnal and sensitive

More information

VCU Payment Card Policy

VCU Payment Card Policy VCU Payment Card Plicy Plicy Type: Administrative Respnsible Office: Treasury Services Initial Plicy Apprved: 12/05/2013 Current Revisin Apprved: 12/05/2013 Plicy Statement and Purpse The purpse f this

More information

Internal Audit Charter and operating standards

Internal Audit Charter and operating standards Internal Audit Charter and perating standards 2 1 verview This dcument sets ut the basis fr internal audit: (i) the Internal Audit charter, which establishes the framewrk fr Internal Audit; and (ii) hw

More information

Presentation: The Demise of SAS 70 - What s Next?

Presentation: The Demise of SAS 70 - What s Next? Presentatin: The Demise f SAS 70 - What s Next? September 15, 2011 1 Presenters: Jeffrey Ziplw - Partner BlumShapir Jennifer Gerasimv Senir Manager Delitte. SAS 70 Backgrund and Overview Purpse f a SAS

More information

THE CITY UNIVERSITY OF NEW YORK IDENTITY THEFT PREVENTION PROGRAM

THE CITY UNIVERSITY OF NEW YORK IDENTITY THEFT PREVENTION PROGRAM THE CITY UNIVERSITY OF NEW YORK IDENTITY THEFT PREVENTION PROGRAM 1. Prgram Adptin The City University f New Yrk (the "University") develped this Identity Theft Preventin Prgram (the "Prgram") pursuant

More information

CMS Eligibility Requirements Checklist for MSSP ACO Participation

CMS Eligibility Requirements Checklist for MSSP ACO Participation ATTACHMENT 1 CMS Eligibility Requirements Checklist fr MSSP ACO Participatin 1. General Eligibility Requirements ACO participants wrk tgether t manage and crdinate care fr Medicare fee-fr-service beneficiaries.

More information

STANDARDISATION IN E-ARCHIVING

STANDARDISATION IN E-ARCHIVING STANDARDISATION IN E-ARCHIVING R E Q U I R E M E N T S A N D C O N T R O L S F O R D I G I T I S AT I O N A N D E - A R C H I V I N G S E R V I C E P R O V I D E R S Alain Wahl 1 Requirements and cntrls

More information

TrustED Briefing Series:

TrustED Briefing Series: TrustED Briefing Series: Since 2001, TrustCC has prvided IT audits and security assessments t hundreds f financial institutins thrugh ut the United States. Our TrustED Briefing Series are white papers

More information

The Importance Advanced Data Collection System Maintenance. Berry Drijsen Global Service Business Manager. knowledge to shape your future

The Importance Advanced Data Collection System Maintenance. Berry Drijsen Global Service Business Manager. knowledge to shape your future The Imprtance Advanced Data Cllectin System Maintenance Berry Drijsen Glbal Service Business Manager WHITE PAPER knwledge t shape yur future The Imprtance Advanced Data Cllectin System Maintenance Cntents

More information

Information Services Hosting Arrangements

Information Services Hosting Arrangements Infrmatin Services Hsting Arrangements Purpse The purpse f this service is t prvide secure, supprted, and reasnably accessible cmputing envirnments fr departments at DePaul that are in need f server-based

More information

Privacy and Security Training Policy (PS.Pol.051)

Privacy and Security Training Policy (PS.Pol.051) Privacy and Security Training Plicy (PS.Pl.051) Purpse T define the plicies and prcedures fr prviding privacy and security training in respect f the CnnectingGTA Slutin. Definitins Electrnic Service Prvider

More information

CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT

CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT CASSOWARY COAST REGIONAL COUNCIL POLICY ENTERPRISE RISK MANAGEMENT Plicy Number: 2.20 1. Authrity Lcal Gvernment Act 2009 Lcal Gvernment Regulatin 2012 AS/NZS ISO 31000-2009 Risk Management Principles

More information

Remote Working (Policy & Procedure)

Remote Working (Policy & Procedure) Remte Wrking (Plicy & Prcedure) Publicatin Scheme Y/N Department f Origin Plicy Hlder Authrs Can be published n Frce Website Prfessinal Standards Department (PSD) Ch Supt Head f PSD IT Security Officer

More information

SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM

SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM Audit Manual Sectin J SECTION J QUALITY ASSURANCE AND IMPROVEMENT PROGRAM Ref. Plicy and Practice Requirements IIA Standards and Other references J 1 Plicy: The Head f Internal Audit shall develp and maintain

More information

Enrollee Health Assessment Program Implementation Guide and Best Practices

Enrollee Health Assessment Program Implementation Guide and Best Practices Enrllee Health Assessment Prgram Implementatin Guide and Best Practices March 2015 033129 (03-2015) This guide will help yu answer these questins: What is the Enrllee Health Assessment (EHA) prgram and

More information

NEW YORK STATE DEPARTMENT OF HEALTH BUREAU OF DENTAL HEALTH SCHOOL-BASED HEALTH CENTER DENTAL PROGRAM PERFORMANCE EFFECTIVENESS REVIEW TOOL (PERT)

NEW YORK STATE DEPARTMENT OF HEALTH BUREAU OF DENTAL HEALTH SCHOOL-BASED HEALTH CENTER DENTAL PROGRAM PERFORMANCE EFFECTIVENESS REVIEW TOOL (PERT) NEW YORK STATE DEPARTMENT OF HEALTH BUREAU OF DENTAL HEALTH SCHOOL-BASED HEALTH CENTER DENTAL PROGRAM PERFORMANCE EFFECTIVENESS REVIEW TOOL (PERT) March 1, 2007 TABLE OF CONTENTS SECTION I: INTRODUCTION

More information

FINANCIAL OPTIONS. 2. For non-insured patients, payment is due on the day of service.

FINANCIAL OPTIONS. 2. For non-insured patients, payment is due on the day of service. FINANCIAL OPTIONS 1. Fr thse patients wh carry dental insurance, all c-payments are due n date f service. We will file yur claim as a service t yu, and will d ur very best t maximize yur benefits. We accept

More information

We will record and prepare documents based off the information presented

We will record and prepare documents based off the information presented Dear Client: We appreciate the pprtunity f wrking with yu regarding yur Payrll needs. T ensure a cmplete understanding between us, we are setting frth the pertinent infrmatin abut the services that we

More information

PENETRATION TEST OF THE INDIAN HEALTH SERVICE S COMPUTER NETWORK

PENETRATION TEST OF THE INDIAN HEALTH SERVICE S COMPUTER NETWORK Department f Health and Human Services OFFICE OF INSPECTOR GENERAL PENETRATION TEST OF THE INDIAN HEALTH SERVICE S COMPUTER NETWORK Inquiries abut this reprt may be addressed t the Office f Public Affairs

More information

Nuance Healthcare Services Project Delivery Methodology

Nuance Healthcare Services Project Delivery Methodology NUANCE PROFESSIONAL SERVICES Nuance Healthcare Services 2008 Nuance Cmmunicatins, Inc. All rights reserved. Nuance Healthcare Services 1 INTRODUCTION This dcument describes the prject management methdlgy

More information

Financial Accountability Handbook

Financial Accountability Handbook Financial Accuntability Handbk >> Vlume 5 Reprting Systems Infrmatin Sheet 5.2 Preparatin f Financial Statements Intrductin The Financial Accuntability Act 2009 (the Act) and the Financial and Perfrmance

More information

Sources of Federal Government and Employee Information

Sources of Federal Government and Employee Information Inf Surce Surces f Federal Gvernment and Emplyee Infrmatin Ridley Terminals Inc. TABLE OF CONTENTS General Infrmatin Intrductin t Inf Surce Backgrund Respnsibilities Institutinal Functins, Prgram and Activities

More information

Hampton Roads Orthopaedics & Sports Medicine. Notice of Privacy Practices

Hampton Roads Orthopaedics & Sports Medicine. Notice of Privacy Practices This is being prvided t yu as a requirement f the privacy regulatins issued under the Health Insurance Prtability and Accuntability Act f 1996 (HIPAA). This ntice describes hw HROSM may use and disclse

More information

Software and Hardware Change Management Policy for CDes Computer Labs

Software and Hardware Change Management Policy for CDes Computer Labs Sftware and Hardware Change Management Plicy fr CDes Cmputer Labs Overview The cmputer labs in the Cllege f Design are clsely integrated with the academic needs f faculty and students. Cmputer lab resurces

More information

2008-2011 CSU STANISLAUS INFORMATION TECHNOLOGY PLAN SUMMARY

2008-2011 CSU STANISLAUS INFORMATION TECHNOLOGY PLAN SUMMARY 2008-2011 CSU STANISLAUS INFORMATION TECHNOLOGY PLAN SUMMARY OFFICE OF INFORMATION TECHNOLOGY AUGUST 2008 Executive Summary The mst recent CSU Stanislaus infrmatin technlgy (IT) plan was issued in 2003.

More information

IT CHANGE MANAGEMENT POLICY

IT CHANGE MANAGEMENT POLICY IT CHANGE MANAGEMENT POLICY Effective Date May 19, 2016 Crss-Reference 1. IT Operatins and Maintenance Plicy 2. IT Security Incident Management Plicy Respnsibility Apprver Review Schedule 1. Plicy Statement

More information

A. Early Case Assessment

A. Early Case Assessment Electrnic Discvery Reference Mdel Standards fr the identificatin f electrnically stred infrmatin in discvery http://www.edrm.net/resurces/standards/identificatin A. Early Case Assessment Once a triggering

More information

Unified Infrastructure/Organization Computer System/Software Use Policy

Unified Infrastructure/Organization Computer System/Software Use Policy Unified Infrastructure/Organizatin Cmputer System/Sftware Use Plicy 1. Statement f Respnsibility All emplyees are charged with the security and integrity f the cmputer system. Emplyees are asked t help

More information

RUTGERS POLICY. Responsible Executive: Vice President for Information Technology and Chief Information Officer

RUTGERS POLICY. Responsible Executive: Vice President for Information Technology and Chief Information Officer RUTGERS POLICY Sectin: 70.1.1 Sectin Title: Infrmatin Technlgy Plicy Name: Acceptable Use Plicy fr Infrmatin Technlgy Resurces Frmerly Bk: N/A Apprval Authrity: Senir Vice President fr Administratin Respnsible

More information

Internet and E-Mail Policy User s Guide

Internet and E-Mail Policy User s Guide Internet and E-Mail Plicy User s Guide Versin 2.2 supprting partnership in mental health Internet and E-Mail Plicy User s Guide Ver. 2.2-1/5 Intrductin Health and Scial Care requires a great deal f cmmunicatin

More information

Process for Responding to Privacy Breaches

Process for Responding to Privacy Breaches Prcess fr Respnding t Privacy Breaches 1. Purpse 1.1 This dcument sets ut the steps that ministries must fllw when respnding t a privacy breach. It must be read in cnjunctin with the Infrmatin Incident

More information

Guidelines on Data Management in Horizon 2020

Guidelines on Data Management in Horizon 2020 Guidelines n Data Management in Hrizn 2020 Versin 1.0 11 December 2013 Guidelines n Data Management in Hrizn 2020 Versin 16 December 2013 Intrductin In Hrizn 2020 a limited pilt actin n pen access t research

More information

FAYETTEVILLE STATE UNIVERSITY

FAYETTEVILLE STATE UNIVERSITY FAYETTEVILLE STATE UNIVERSITY IDENTITY THEFT PREVENTION (RED FLAGS RULE) Authrity: Categry: Issued by the Fayetteville State University Bard f Trustees. University-Wide Applies t: Administratrs Faculty

More information

New York Institute of Technology Faculty and Staff Email Retention Policy

New York Institute of Technology Faculty and Staff Email Retention Policy New Yrk Institute f Technlgy Faculty and Staff Email Retentin Plicy Nvember 2013 I. PURPOSE As electrnic mail (email) has becme the primary frm f cmmunicatin at NYIT and thrughut the wrld, the vlume f

More information

RATIONALE TERMS OF REFERENCE FOR THE QUALITY COMMITTEE UNDER THE EXCELLENT CARE FOR ALL ACT. Authority

RATIONALE TERMS OF REFERENCE FOR THE QUALITY COMMITTEE UNDER THE EXCELLENT CARE FOR ALL ACT. Authority RATIONALE With the intrductin f the Excellent Care fr All Act, hspital bards must nw have a quality cmmittee that reprts t the bard. The template prvides sample terms f references fr rganizatins t adapt

More information

Business Continuity Management Systems Foundation Training Course

Business Continuity Management Systems Foundation Training Course Certificatin criteria fr Business Cntinuity Management Systems Fundatin Training Curse CONTENTS 1. INTRODUCTION 2. LEARNING OBJECTIVES 3. ENABLING OBJECTIVES KNOWLEDGE & SKILLS 4. TRAINING METHODS 5. COURSE

More information

UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES

UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES UNIVERSITY OF CALIFORNIA MERCED PERFORMANCE MANAGEMENT GUIDELINES REFERENCES AND RELATED POLICIES A. UC PPSM 2 -Definitin f Terms B. UC PPSM 12 -Nndiscriminatin in Emplyment C. UC PPSM 14 -Affirmative

More information

SPECIFICATION. Hospital Report Manager Connectivity Requirements. Electronic Medical Records DRAFT. OntarioMD Inc. Date: September 30, 2010

SPECIFICATION. Hospital Report Manager Connectivity Requirements. Electronic Medical Records DRAFT. OntarioMD Inc. Date: September 30, 2010 OntariMD Inc. Electrnic Medical Recrds SPECIFICATION Hspital Reprt Manager Cnnectivity Requirements DRAFT Date: September 30, 2010 Versin: 1.0 2007-2010 OntariMD Inc. All rights reserved HRM EMR Cnnectivity

More information

BYOD and Cloud Computing

BYOD and Cloud Computing BYOD and Clud Cmputing AIIM First Canadian Chapter May 22, 2014 Susan Nickle, Lndn Health Sciences Centre Chuck Rthman, Wrtzmans Sheila Taylr, Erg Infrmatin Management Cnsulting Clud cmputing Agenda What

More information

Change Management Process

Change Management Process Change Management Prcess B1.10 Change Management Prcess 1. Intrductin This plicy utlines [Yur Cmpany] s apprach t managing change within the rganisatin. All changes in strategy, activities and prcesses

More information

FAFSA / DREAM ACT COMPLETION PROGRAM AGREEMENT

FAFSA / DREAM ACT COMPLETION PROGRAM AGREEMENT FAFSA / DREAM ACT COMPLETION PROGRAM AGREEMENT If using US Pstal Service, please return t: Califrnia Student Aid Cmmissin Prgram Administratin & Services Divisin ATTN: Institutinal Supprt P.O. Bx 419028

More information

CCHIIM ICD-10 Continuing Education Requirements for AHIMA Certified Professionals (& Frequently Asked Questions for Recertification)

CCHIIM ICD-10 Continuing Education Requirements for AHIMA Certified Professionals (& Frequently Asked Questions for Recertification) CCHIIM ICD-10 Cntinuing Educatin Requirements fr AHIMA Certified Prfessinals (& Frequently Asked Questins fr Recertificatin) The transitin t ICD-10-CM and ICD-10-PCS is anticipated t imprve the capture

More information

Plus500CY Ltd. Statement on Privacy and Cookie Policy

Plus500CY Ltd. Statement on Privacy and Cookie Policy Plus500CY Ltd. Statement n Privacy and Ckie Plicy Statement n Privacy and Ckie Plicy This website is perated by Plus500CY Ltd. ("we, us r ur"). It is ur plicy t respect the cnfidentiality f infrmatin and

More information

Army DCIPS Employee Self-Report of Accomplishments Overview Revised July 2012

Army DCIPS Employee Self-Report of Accomplishments Overview Revised July 2012 Army DCIPS Emplyee Self-Reprt f Accmplishments Overview Revised July 2012 Table f Cntents Self-Reprt f Accmplishments Overview... 3 Understanding the Emplyee Self-Reprt f Accmplishments... 3 Thinking Abut

More information

Systems Support - Extended

Systems Support - Extended 1 General Overview This is a Service Level Agreement ( SLA ) between and the Enterprise Windws Services t dcument: The technlgy services the Enterprise Windws Services prvides t the custmer. The targets

More information

Hillsborough Board of Education Acceptable Use Policy for Using the Hillsborough Township Public Schools Network

Hillsborough Board of Education Acceptable Use Policy for Using the Hillsborough Township Public Schools Network 2361/Page 1 f 6 Hillsbrugh Bard f Educatin Acceptable Use Plicy fr Using the Hillsbrugh Twnship Public Schls Netwrk It is the gal f the HTPS (Hillsbrugh Twnship Public Schls) Netwrk t prmte educatinal

More information

Electronic and Information Resources Accessibility Compliance Plan

Electronic and Information Resources Accessibility Compliance Plan Electrnic and Infrmatin Resurces Accessibility Cmpliance Plan Intrductin The University f Nrth Texas at Dallas (UNTD) is cmmitted t prviding a wrk envirnment that affrds equal access and pprtunity t therwise

More information

Overview of the Final Requirements for Meaningful Use - 2015 through 2017

Overview of the Final Requirements for Meaningful Use - 2015 through 2017 Overview f the Final Requirements fr Meaningful Use - 2015 thrugh 2017 On Oct. 6, 2015, the Centers fr Medicare & Medicaid Services (CMS) issued a final rule utlining the requirements fr eligible prfessinal

More information

Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply

Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply Sectin 1 General Infrmatin RFR Number: (Reference BPO Number) Functinal Area (Enter One Only) F50B3400026 7 Infrmatin System Security Labr Categry A single supprt resurce may be engaged fr a perid nt t

More information

Immaculate Conception School, Prince George Bring Your Own Device Policy for Students

Immaculate Conception School, Prince George Bring Your Own Device Policy for Students Bring Yur Own Device Plicy fr Students Purpse This plicy utlines the acceptable use f electrnic devices t maintain a safe and secure educatin envirnment with the gal f preparing students fr the future,

More information

Audit Committee Charter

Audit Committee Charter Audit Cmmittee Charter Membership The Audit Cmmittee (the "Cmmittee") f the Bard f Directrs (the "Bard") f Philip Mrris Internatinal Inc. (the "Cmpany") shall cnsist f at least three directrs all f whm

More information

Document Management/Archiving Records general guidelines for the UBC Department of Medicine

Document Management/Archiving Records general guidelines for the UBC Department of Medicine Dcument Management/Archiving Recrds general guidelines fr the UBC Department f Medicine ADMINISTRATIVE/FINACIAL FILES: Email/Crrespndence - An extremely difficult recrd type t schedule, sme email is clearly

More information

TITLE: RECORDS AND INFORMATION MANAGEMENT POLICY

TITLE: RECORDS AND INFORMATION MANAGEMENT POLICY TITLE: RECORDS AND INFORMATION MANAGEMENT POLICY REFERENCE NUMBER: 14/103368 RESPONSIBLE DEPARTMENT: Crprate Services APPLICABLE LEGISLATION: State Recrds Act 1997 Lcal Gvernment Act 1999 Crpratins Act

More information

Technical Writing - TheUsers Visa (SHR User Accunt)

Technical Writing - TheUsers Visa (SHR User Accunt) POLICY Number: 7311-25-004 Title: Saskatn Health Regin User Accunt Plicy Authrizatin [ ] President and CEO [X] Vice President, Finance and Crprate Services Surce: Directr, Infrmatin Technlgy Services Crss

More information

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013 Versin: Mdified By: Date: Apprved By: Date: 1.0 Michael Hawkins Octber 29, 2013 Dan Bwden Nvember 2013 Rule 4-004J Payment Card Industry (PCI) Patch Management (prpsed) 01.1 Purpse The purpse f the Patch

More information

DISASTER RECOVERY PLAN TEMPLATE

DISASTER RECOVERY PLAN TEMPLATE www.disasterrecveryplantemplate.rg The bjective f a disaster recvery plan is t ensure that yu can respnd t a disaster r ther emergency that affects infrmatin systems and minimize the effect n the peratin

More information

Chris Chiron, Interim Senior Director, Employee & Management Relations Jessica Moore, Senior Director, Classification & Compensation

Chris Chiron, Interim Senior Director, Employee & Management Relations Jessica Moore, Senior Director, Classification & Compensation TO: FROM: HR Officers & Human Resurces Representatives Chris Chirn, Interim Senir Directr, Emplyee & Management Relatins Jessica Mre, Senir Directr, Classificatin & Cmpensatin DATE: May 26, 2015 RE: Annual

More information

HEALTH INFORMATION EXCHANGE GRANTS CRITERIA

HEALTH INFORMATION EXCHANGE GRANTS CRITERIA 1 HEALTH INFORMATION EXCHANGE GRANTS CRITERIA INTRODUCTION On August, 20 th, the federal Office f the Natinal Crdinatr fr Health Infrmatin Technlgy (ONC) released an pprtunity fr states t apply fr between

More information

System Business Continuity Classification

System Business Continuity Classification Business Cntinuity Prcedures Business Impact Analysis (BIA) System Recvery Prcedures (SRP) System Business Cntinuity Classificatin Cre Infrastructure Criticality Levels Critical High Medium Lw Required

More information

Research Report. Abstract: The Emerging Intersection Between Big Data and Security Analytics. November 2012

Research Report. Abstract: The Emerging Intersection Between Big Data and Security Analytics. November 2012 Research Reprt Abstract: The Emerging Intersectin Between Big Data and Security Analytics By Jn Oltsik, Senir Principal Analyst With Jennifer Gahm Nvember 2012 2012 by The Enterprise Strategy Grup, Inc.

More information

IN-HOUSE OR OUTSOURCED BILLING

IN-HOUSE OR OUTSOURCED BILLING IN-HOUSE OR OUTSOURCED BILLING Medical billing is ne f the mst cmplicated aspects f running a medical practice. With thusands f pssible cdes fr diagnses and prcedures, and multiple payers, the ability

More information

Project Open Hand Atlanta. Health Insurance Portability and Accountability Act (HIPAA) NOTICE OF PRIVACY PRACTICES

Project Open Hand Atlanta. Health Insurance Portability and Accountability Act (HIPAA) NOTICE OF PRIVACY PRACTICES Prject Open Hand Atlanta Effective Date: April 14, 2003 Health Insurance Prtability and Accuntability Act (HIPAA) The Health Insurance Prtability and Accuntability Act f 1996 (HIPAA) directs health care

More information

HIPAA Notice of Privacy Practices. Central Ohio Surgical Associates, Inc.

HIPAA Notice of Privacy Practices. Central Ohio Surgical Associates, Inc. HIPAA Ntice f Privacy Practices Central Ohi Surgical Assciates, Inc. THIS NOTICE OF PRIVACY PRACTICES (THE NOTICE ) DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN

More information

Service Level Agreement (SLA) Hosted Products. Netop Business Solutions A/S

Service Level Agreement (SLA) Hosted Products. Netop Business Solutions A/S Service Level Agreement (SLA) Hsted Prducts Netp Business Slutins A/S Cntents 1 Service Level Agreement... 3 2 Supprt Services... 3 3 Incident Management... 3 3.1 Requesting service r submitting incidents...

More information

Health and Safety Training and Supervision

Health and Safety Training and Supervision Intrductin: Health and Safety Training and Supervisin University f Nttingham is cmmitted t maintaining and develping standards f excellence in all aspects f its business. T that end, the University aspires

More information

Care Plan Oversight. Home Health Certification. July 23, 2014. Agenda

Care Plan Oversight. Home Health Certification. July 23, 2014. Agenda Care Plan Oversight Hme Health Certificatin July 23, 2014 Agenda Care Plan Oversight Why We Are Prviding the Educatin Prcedure cdes Descriptin f Services Wh Can Perfrm Frequency f Services Face-t-Face

More information

HSBC Online Home Loan Application Process

HSBC Online Home Loan Application Process HSBC Online Hme Lan Applicatin Prcess Versin 1.0 Nvember 2005 Cpyright. HSBC Bank Australia Limited 2005 ALL RIGHTS RESERVED N part f this publicatin may be reprduced, stred in a retrieval system, r transmitted,

More information

EA-POL-015 Enterprise Architecture - Encryption Policy

EA-POL-015 Enterprise Architecture - Encryption Policy Technlgy & Infrmatin Services EA-POL-015 Enterprise ure - Encryptin Plicy Authr: Craig Duglas Date: 17 March 2015 Dcument Security Level: PUBLIC Dcument Versin: 1.0 Dcument Ref: EA-POL-015 Dcument Link:

More information

IT Help Desk Service Level Expectations Revised: 01/09/2012

IT Help Desk Service Level Expectations Revised: 01/09/2012 IT Help Desk Service Level Expectatins Revised: 01/09/2012 Overview The IT Help Desk team cnsists f six (6) full time emplyees and fifteen (15) part time student emplyees. This team prvides supprt fr 25,000+

More information

System Business Continuity Classification

System Business Continuity Classification System Business Cntinuity Classificatin Business Cntinuity Prcedures Infrmatin System Cntingency Plan (ISCP) Business Impact Analysis (BIA) System Recvery Prcedures (SRP) Cre Infrastructure Criticality

More information

FORM ADV (Paper Version) UNIFORM APPLICATION FOR INVESTMENT ADVISER REGISTRATION AND REPORT FORM BY EXEMPT REPORTING ADVISERS

FORM ADV (Paper Version) UNIFORM APPLICATION FOR INVESTMENT ADVISER REGISTRATION AND REPORT FORM BY EXEMPT REPORTING ADVISERS APPENDIX A FORM ADV (Paper Versin) UNIFORM APPLICATION FOR INVESTMENT ADVISER REGISTRATION AND REPORT FORM BY EXEMPT REPORTING ADVISERS Frm ADV: General Instructins Read these instructins carefully befre

More information

ALBAN CHURCH OF ENGLAND ACADEMY COMPUTER SECURITY POLICY. Approved by Governing Body on: 6 th May 2015

ALBAN CHURCH OF ENGLAND ACADEMY COMPUTER SECURITY POLICY. Approved by Governing Body on: 6 th May 2015 ALBAN CHURCH OF ENGLAND ACADEMY COMPUTER SECURITY POLICY Gvernrs Cmmittee: Finance and General Purpses Apprved by Gverning Bdy n: 6 th May 2015 Signed: (Chair f Cmmittee) Signed: (Headteacher) Date t be

More information

expertise hp services valupack consulting description security review service for Linux

expertise hp services valupack consulting description security review service for Linux expertise hp services valupack cnsulting descriptin security review service fr Linux Cpyright services prvided, infrmatin is prtected under cpyright by Hewlett-Packard Cmpany Unpublished Wrk -- ALL RIGHTS

More information

Professional Leaders/Specialists

Professional Leaders/Specialists Psitin Prfile Psitin Lcatin Reprting t Jb family Band BI/Infrmatin Manager Wellingtn Prfessinal Leaders/Specialists Band I Date February 2013 1. POSITION PURPOSE The purpse f this psitin is t: Lead and

More information

PADUA COLLEGE LIMITED ACN 072 693 700 ABN 20 072 693 700

PADUA COLLEGE LIMITED ACN 072 693 700 ABN 20 072 693 700 PADUA COLLEGE LIMITED ACN 072 693 700 ABN 20 072 693 700 Plicy Title Versin Number Date Issued Critical Incident Management Plicy 2.0 Nvember 2007 Reviewed April 2010 June 2015 Definitin Critical incidents

More information

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Audit Cmmittee Charter St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Versin 2.0, 22 February 2016 Apprver Bard f Directrs St Andrew

More information

National Australia Bank Limited Group Disclosure & External Communications Policy

National Australia Bank Limited Group Disclosure & External Communications Policy Natinal Australia Bank Limited Grup Disclsure & External Cmmunicatins Plicy Grup Disclsure & External Cmmunicatins Plicy Page 2 f 7 Grup Disclsure & External Cmmunicatins Plicy ( the Plicy ) 1. Overview

More information

FY 2014 Senior Level (SL) and Scientific or Professional (ST) Performance Appraisal System Opening Guidance

FY 2014 Senior Level (SL) and Scientific or Professional (ST) Performance Appraisal System Opening Guidance Office f Executive Resurces Office f the Chief Human Capital Officer U.S. Department f Energy FY 2014 Senir Level (SL) and Scientific r Prfessinal (ST) Perfrmance Appraisal System Opening Guidance Table

More information

Information Security Policy

Information Security Policy Purpse The risk t Charlestn Suthern University, its emplyees and students frm data lss and identity theft is f significant cncern t the University and can be reduced nly thrugh the cmbined effrts f every

More information

Vendor Management. Federal Deposit Insurance Corporation Division of Risk Management Supervision Atlanta Regional Office.

Vendor Management. Federal Deposit Insurance Corporation Division of Risk Management Supervision Atlanta Regional Office. Vendr Management Federal Depsit Insurance Crpratin Divisin f Risk Management Supervisin Atlanta Reginal Office June 18, 2014 1 Agenda Intrductin Vendr Management Overview Regulatry Expectatins Bard and

More information

Change Management Process For [Project Name]

Change Management Process For [Project Name] Management Prcess Fr [Prject Name] i 1 Intrductin The is fllwed during the Executin phase f the Prject Management Life Cycle, nce the prject has been frmally defined and planned. 1.1 What is a Management

More information