How To Assess Records Risk In An Ehr System
|
|
|
- Oswald York
- 5 years ago
- Views:
Transcription
1 EHR Records Risk Assessments An Evolving Use of the EHR System Functional Model Standard HIMSS HL7 April 15, 2015 Reed D. Gelzer, MD, MPH Co-Chair, HL7 EHR Workgroup Co-Faciltator, HL7 EHR Records Management and Evidentiary Support Workgroup and HL7 EHR/Security Vocabulary Alignment Workgroup Provider Resources, Inc.
2 Overview EHR-S FM R2: Normative Standard The HL7 EHR-S Functional Model defines a standardized model of the functions that may be present in EHR Systems. 2
3 Overview What is Records Risk? What does Records Risk look like? How does the EHR-S FM R2 (aka R2) help? 3
4 Records Risk Records: Representations of acts and events in the real world Risks to their value as accurate representations: Reliable means of origination Security Authenticity Persistence 4
5 Origination Risk A group of inexperienced and uncertified inspectors for the Department of Licenses and Inspection conducted around 600 inspections of unsafe buildings in a single week last month, the Inquirer has learned. Each of the newly hired inspectors then recorded their work in L&I s database under the name of another man, an experienced inspector with the agency. 5
6 Origination Risk 6
7 8
8 EHR Systems: Systems of Systems Recommendation: Release of Information (ROI) Risk Assessment Evaluating: 1. Authorship 2. Log ( Audit ) functions 3. Amendments 9
9 Origination For Authenticity Recommendation: Release of Information (ROI) Risk Assessment Examples: Records releases for business or clinical requests (legal process or claims support/revenue integrity) Data extracts to support Quality measures Transitions of Care Support 10
10 EHR Functional Model
11
12 R2 Checklist: Originate & Retain 13
13 R2 Checklist: Originate & Retain 1. The system SHALL provide the ability to capture (originate) a Record Entry instance corresponding to an Action instance and context. 14
14 Checklist: Evidence of Originate & Retain 15
15 Know Your Objectives Risk Identification: Keep it simple and practical Risk Mitigation Mapping -Training? -Configuration? -Design? 16
16 Objectives Risk Mitigation: Keep it actionable Medical Staff Bylaws (Hospitals) Medical Records P&P EHR FM R2-Derived Due-Diligence Templates 17
17 Notables HIMSS presentation slides for Medical-Legal Cases That Went South by Dr. Keith Klein Electronic Health Records Systems: Testing The Limits of Digital Records Reliability and Trust in Ave Maria Law Review, Summer 2014 by Drury, Gelzer, Trites, and Paul.
18 Questions Reed D. Gelzer, MD, MPH Co-Chair, HL7 EHR Standards Workgroup Co-Facilitator, HL7 Records Management and Evidentiary Support Workgroup Trustworthy EHR, LLC Newbury, NH Philadelphia, PA
HL7 and HIT Standards
HL7 and HIT Standards Navigating the Strange, the Magical, and the Bizarre Reed D. Gelzer, MD, MPH September 25, 2014 1:30PM Smart Data Solutions 2014 Symposium Outline: I. Understanding the environmental
HL7 EHR-S Records Management & Evidentiary Support Functional Profile
HL7 EHR-S Records Management & Evidentiary Support Functional Profile Michelle Dougherty, RHIA, CHP HIT Standards AHIMA for the Legal EHR [email protected] An educational update to the HIMSS
HL7 PHR System Functional Model
HL7 PHR System Functional Model Presented by: Donald T. Mon, PhD Co-Chair, EHR Work Group HIMSS, 2013 2013 Health Level Seven International. All Rights Reserved. HL7 and Health Level Seven are registered
Health Level Seven Records Management & Evidentiary Support (RM-ES) Supporting Clinical Documentation for Legal and Billing Purposes
Health Level Seven Records Management & Evidentiary Support (RM-ES) Supporting Clinical Documentation for Legal and Billing Purposes HIT Policy Committee Meaningful Use WG/Certification & Adoption WG Public
6/8/2012. Cloning and Other Compliance Risks in Electronic Medical Records
Cloning and Other Compliance Risks in Electronic Medical Records Lori Laubach, Partner, Moss Adams LLP Catherine Wakefield, Vice President, Corporate Compliance and Internal Audit, MultiCare 1 AGENDA Basic
HL7 EHR System Functional Model and Standard (ISO/HL7 10781), Release 2
HL7 EHR System Functional Model and Standard (ISO/HL7 10781), Release 2 Health Information Management Systems Society (HIMSS) Las Vegas, NV 20 Feb 2012 Presented by: Mark G. Janczewski, MD, MPH Deloitte
ISO/HL7 10781 EHR System Functional Model Standard
ISO/HL7 10781 EHR System Functional Model Standard Presented by: Gary Dickinson Director, Healthcare Standards CentriHealth Co-Chair, HL7 EHR Work Group Lead, S&I Framework Cross-Initiative Simplification
Meaningful Use HL7 Version 2
Meaningful Use HL7 Version 2 HL7 Version 2 and Immunization Registries, HIMSS 2011, Orlando, FL John Quinn, HL7 CTO February 2011 Attribution of this content In addition to ONC final rules, this presentation
Health IT Enabled Quality Measurement and Improvement: The HL7 Clinical Quality Information Workgroup
Health IT Enabled Quality Measurement and Improvement: The HL7 Clinical Quality Information Workgroup Walter G. Suarez, MD, MPH Executive Director, Health IT Strategy and Policy Kaiser Permanente Co-Chair,
This document is a preview generated by EVS
INTERNATIONAL STANDARD ISO 10781 Second edition 2015-08-01 Health Informatics HL7 Electronic Health Records-System Functional Model, Release 2 (EHR FM) Informatique de santé Modèle fonctionnel d un système
Newcomer s Session *
Talking Stick Resort reservations: 866-877-9897. call before the cut-off date of October 25, 2011. With world class gaming, gourmet dining, first-rate entertainment, more than 100,000 square feet of function
Functional Profile Starter Pack based on HL7 EHR System Functional Model Release 2 (EHRS FM) 7 March 2014
Functional Profile Starter Pack based on HL7 EHR System Functional Model Release 2 (EHRS FM) Status HL7 EHR System Functional Model Release 2 Approved for HL7 Publication Release 2.1 awaiting conclusion
How To Use A Medical Student Note For A Billable Service
Electronic Health Records in Academic Health Centers TOPIC 1: Medical Student Documentation January 2011 Purpose Medical students are learners. In no state are they given a license to practice medicine
AN ANALYSIS OF ELECTRONIC HEALTH RECORD-RELATED PATIENT SAFETY CONCERNS
AN ANALYSIS OF ELECTRONIC HEALTH RECORD-RELATED PATIENT SAFETY CONCERNS 1 HARDEEP SINGH, MD, MPH MICHAEL E. DEBAKEY VA MEDICAL CENTER BAYLOR COLLEGE OF MEDICINE DEAN SITTIG, PHD UNIVERSITY OF TEXAS HEALTH
Audit Compliance and Internal Audit Analysis for Dynamics
Fastpath Audit Compliance and Internal Audit Analysis for Dynamics: Better Audit Results with a Reliable, Repeatable Process using Fastpath Fastpath 11107 Aurora Ave. Urbandale, IA 50322 (515) 276-1779
HIPAA for HIT and EHRs. Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals
HIPAA for HIT and EHRs Latest on Meaningful Use and EHR Certification: For Privacy and Security Professionals Donald Bechtel, CHP Siemens Health Services Patient Privacy Officer Fair Information Practices
2015 List of Major Management Challenges for the CFPB
September 30, 2015 MEMORANDUM TO: FROM: SUBJECT: Richard Cordray Director Consumer Financial Protection Bureau Mark Bialek Inspector General 2015 List of Major Management Challenges for the CFPB We are
AUSTIN INDEPENDENT SCHOOL DISTRICT INTERNAL AUDIT DEPARTMENT TRANSPORTATION AUDIT PROGRAM
GENERAL: The Technology department is responsible for the managing of electronic devices and software for the District, as well as the Help Desk for resolution of employee-created help tickets. The subgroups
HEALTH IT! LAW & INDUSTRY
A BNA, INC. HEALTH IT! LAW & INDUSTRY Meaningful Use REPORT VOL. 2, NO. 15 APRIL 12, 2010 BNA Insights: Toward Achieving Meaningful Use: HHS Establishes Certification Criteria for Electronic Health Record
Private Circulation Document: IST/35_07_0075
Private Circulation Document: IST/3_07_007 BSI Group Headquarters 389 Chiswick High Road London W4 4AL Tel: +44 (0) 20 8996 9000 Fax: +44 (0) 20 8996 7400 www.bsi-global.com Committee Ref: IST/3 Date:
EHR Interoperability Framework Overview
Hospital Health Information System EU HIS Contract No. IPA/2012/283-805 Final version July 2015 Visibility: Public Target Audience: EHR Developers EHR Administrators EPR Systems Developers This document
THE CHALLENGE OF COORDINATING EMR
THE CHALLENGE OF COORDINATING EMR CLINICAL CONNECT: TWO YEARS OF REGIONAL ELECTRONIC HEALTH INFORMATION EXCHANGE NANCY A. LANDMAN, CIO INTERNATIONAL & COMMERCIAL SERVICES, UPMC 10/8/2014 2 UPMC Today:
U.S. Department of Energy Office of Inspector General Office of Audits and Inspections
U.S. Department of Energy Office of Inspector General Office of Audits and Inspections Audit Report The Department's Configuration Management of Non-Financial Systems OAS-M-12-02 February 2012 Department
ALLOWING MEDICAL STUDENT DOCUMENTATION IN THE ELECTRONIC HEALTH RECORD. Background and Purpose
ALLOWING MEDICAL STUDENT DOCUMENTATION IN THE ELECTRONIC HEALTH RECORD One example of the transformation of the U.S. health system is the expanding presence of the electronic health record in teaching
Hospital Certified Electronic Health Record (EHR) Technology Questionnaire
Page 1 of 10 Hospital Certified Electronic Health Record (EHR) Technology Questionnaire Thank you for taking time to complete this questionnaire. The Office of Inspector General (OIG) is conducting this
Interim Final Rule on Standards, Implementation Specifications, and Certification Criteria
Interim Final Rule on Standards, Implementation Specifications, and Certification Criteria NIST/OCR Conference Safeguarding Health Information: Building Assurance through HIPAA Security Steven Posnack,
7 Directorate Performance Managers. 7 Performance Reporting and Data Quality Officer. 8 Responsible Officers
Contents Page 1 Introduction 2 2 Objectives of the Strategy 2 3 Data Quality Standards 3 4 The National Indicator Set 3 5 Structure of this Strategy 3 5.1 Awareness 4 5.2 Definitions 4 5.3 Recording 4
Session 17 Windows 7 Professional DNS & Active Directory(Part 2)
Session 17 Windows 7 Professional DNS & Active Directory(Part 2) Fall 2011 ITE153 Operating Systems 1 Session 17 Windows 7 Professional Operating in Microsoft Networks Fall 2011 ITE153 Operating Systems
Meaningful Use and Release of Information
Meaningful Use and Release of Information Understanding IOD s Role IOD Incorporated 1030 Ontario Road Green Bay, WI 54311 800.236.3355 iodincorporated.com INTRODUCTION According to HIMSS, Meaningful Use
Navigating Compliance Landmines in EHR Documentation
Navigating Compliance Landmines in EHR Documentation Brian T. Bates, CPA, CHC, Mac Corporate Compliance Officer University of Alabama Health Services Foundation, P.C. DISCLAIMER: The views and opinions
Personal data protection in Electronic Health Records and the mandatory use of HL7 standards in Mexico
Personal data protection in Electronic Health Records and the mandatory use of HL7 standards in Mexico Dr. Maki Esther Ortiz Domínguez Viceminister of Integration and Development of the Public Health Sector
Process Improvement: Impact on Provider Efficiency and Patient Care
Col(s) Kevin Kaps, D.O., Chief, Customer Deployment Support Ms. Mildred Bostick, Acting Chief, Business Process Mgmt Major Matthew Barnes M.D., Chief, Tri-Service Workflow 2015 Defense Health Information
The KHIE ConnectionPartnering to Improve Patient Health Outcomes
The KHIE ConnectionPartnering to Improve Patient Health Outcomes About KHIE The Commonwealth of Kentucky strives to be a leader in our nation s journey to advance health information technology to transform
BEING MOBILE WITH WINDOWS 8.1
www.realdolmen.com BEING MOBILE WITH WINDOWS 8.1 OCTOBER 28, 2014 SLIDE 1 SPEAKERS INTRO #Name: D Hoker Gino #Function: Technology Expert #Email: [email protected] #Twitter: @GinoDH #Blog: #Mobile:
This document explains how to use Skyward s ACA Tracker to analyze employee ACA Hours and forecast future hours.
This document explains how to use Skyward s ACA Tracker to analyze employee ACA Hours and forecast future hours. The ACA Tracker is used to report total ACA hours as well as weekly and monthly averages
WEDI National Pre-Conference Program May 19, 2008
WEDI National Pre-Conference Program May 19, 2008 WEDI is pleased to present the Health IT Certification, LLC s training and certification program for Electronic Health Records (EHR), Health Information
HL7 Personal Health Record System Functional Model and Standard & Industry Update
HL7 Personal Health Record System Functional Model and Standard & Industry Update Presented by: R. Lenel James, CPHIT, CPEHR HL7 Co-Lead, EHR WG, Publishing HL7 Co-Lead, PHR WG, Conformance HIMSS, Member
How To Use Haccp 4.1.1
Standard V4.1 Announcing Version 4.1 Standard has been updated to version 4.1. The goal was to make the program more user friendly, implement customer feedback and to present the user with a more focussed
Fluency Direct. Proof of Concept Requirements
Fluency Direct Proof of Concept Requirements Contents Overview... 3 Standard Information... 3 Environment Requirements... 3 Target Applications... 3 Use Cases... 4 Configuration... 4 Training... 4 Support
York Catholic District School Board
Ministry of Education York Catholic District School Board Follow-up Report to the Operational Review August 2012 TABLE OF CONTENTS 1. INTRODUCTION... 1 2. STATUS AND IMPLEMENTATION UPDATE... 3 3. GOVERNANCE
Structured Data Capture (SDC) Trial Implementation
Integrating the Healthcare Enterprise 5 IHE Quality, Research, and Public Health Technical Framework Supplement 10 Structured Data Capture (SDC) 15 Trial Implementation 20 Date: October 27, 2015 Author:
HL7 FHIR The Argonaut Project C-CDA
HEALTH LEVEL SEVEN INTERNATIONAL HL7 FHIR The Argonaut Project C-CDA HL7 is people, almost all volunteers, from organizations around the world. HL7 is solutions, innovative ideas and resources for interoperability.
Self-Assessment of eresearch Compliance with 21 CFR Part 11, Electronic Record; Electronic Signatures
Self-Assessment of eresearch Compliance with 21 CFR Part 11, Electronic Record; Electronic Signatures Subpart A General Provisions Sec. 11.1 Scope. (a) The regulations in this part set forth the criteria
HL7 Clinical Genomics and Structured Documents Work Groups
HL7 Clinical Genomics and Structured Documents Work Groups CDA Implementation Guide: Genetic Testing Report (GTR) Amnon Shabo (Shvo), PhD [email protected] HL7 Clinical Genomics WG Co-chair and Modeling
MEDITECH CUSTOMERS & THE OIG QUESTIONNAIRE
MEDITECH CUSTOMERS & THE OIG QUESTIONNAIRE Hospitals that have received Medicare incentive payments for meaningful use of electronic health records have been asked by the Office of Inspector General of
CHAPTER 5 - SAFETY ASSESSMENTS, LOG OF DEFICIENCIES AND CORRECTIVE ACTION PLANS
CHAPTER 5 - SAFETY ASSESSMENTS, LOG OF DEFICIENCIES AND CORRECTIVE ACTION PLANS A. INTRODUCTION... 1 B. CHAPTER-SPECIFIC ROLES AND RESPONSIBILITIES... 1 C. SAFETY PROGRAM ASSESSMENT PROCESS... 3 D. FACILITY-MAINTAINED
Healthcare Information Exchange Software Testing
Healthcare Information Exchange Software Testing AFour Technologies May 20, 2009 AFour Technologies 2009 1 Healthcare Background With increasing healthcare costs and looming Medicare bankruptcy, President
International Trade Administration
U.S. DEPARTMENT OF COMMERCE Office of Inspector General International Trade Administration FY 2007 FISMA Assessment of Core Network General Support System (ITA-012) Final Inspection Report No. OSE-18840/September
IT Service Continuity Management PinkVERIFY
-11-G-001 General Criteria Does the tool use ITIL 2011 Edition process terms and align to ITIL 2011 Edition workflows and process integrations? -11-G-002 Does the tool have security controls in place to
Aberdeen City Council IT Security (Network and perimeter)
Aberdeen City Council IT Security (Network and perimeter) Internal Audit Report 2014/2015 for Aberdeen City Council August 2014 Internal Audit KPIs Target Dates Actual Dates Red/Amber/Green Commentary
Assessing a Scientific Data Center as a Trustworthy Digital Repository
Assessing a Scientific Data Center as a Trustworthy Digital Repository Robert R. Downs 1 and Robert S. Chen 2 1 [email protected] 2 [email protected] NASA Socioeconomic Data and Applications
5/16/2014. Revenue Cycle Impact Documentation risks in an EMR AGENDA. EMR Challenges Related to Billing and Revenue Cycle
EMR Challenges Related to Billing and Revenue Cycle Lori Laubach, Principal Health Care Consulting California Primary Care Association Billing Managers Peer Conference May 20 21, 2014 1 The material appearing
Auditing After a Cyber Attack JAX IIA Chapter Meeting Cybersecurity and Law Enforcement
Auditing After a Cyber Attack JAX IIA Chapter Meeting Cybersecurity and Law Enforcement Copyright Elevate Consult LLC. All Rights Reserved 1 Presenter Ray Guzman MBA, CISSP, CGEIT, CRISC, CISA Over 25
Effectively Assessing IT General Controls
Effectively Assessing IT General Controls Tommie Singleton UAB AGENDA Introduction Five Categories of ITGC Control Environment/ELC Change Management Logical Access Controls Backup/Recovery Third-Party
CITY OF VAUGHAN EXTRACT FROM COUNCIL MEETING MINUTES OF MARCH 24, 2015
CITY OF VAUGHAN EXTRACT FROM COUNCIL MEETING MINUTES OF MARCH 24, 2015 Item 2, Report No. 7, of the Finance, Administration and Audit Committee, which was adopted, as amended, by the Council of the City
Your responses will be saved every time you click the NEXT button.
Hospital Certified Electronic Health Record (EHR) Technology Questionnaire Thank you for taking time to complete this questionnaire The Office of Inspector General (OIG) is conducting this survey as part
Service Asset & Configuration Management PinkVERIFY
-11-G-001 General Criteria Does the tool use ITIL 2011 Edition process terms and align to ITIL 2011 Edition workflows and process integrations? -11-G-002 Does the tool have security controls in place to
Compliance Risk Management IT Governance Assurance
Compliance Risk Management IT Governance Assurance Solutions That Matter Introduction to Federal Information Security Management Act (FISMA) Without proper safeguards, federal agencies computer systems
Intel Entry Storage System SS4200-E Active Directory Implementation and Troubleshooting
Intel Entry Storage System SS4200-E Active Directory Implementation and Troubleshooting 1 Active Directory Overview SS4200-E Active Directory is based on the Samba 3 implementation The SS4200-E will function
HIPAA 203: Security. An Introduction to the Draft HIPAA Security Regulations
HIPAA 203: Security An Introduction to the Draft HIPAA Security Regulations Presentation Agenda Security Introduction Security Component Requirements and Impacts Administrative Procedures Physical Safeguards
Electronic Health Records - An Overview - Martin C. Were, MD MS March 24, 2010
Electronic Health Records - An Overview - Martin C. Were, MD MS March 24, 2010 Why Electronic Health Records (EHRs) EHRs vs. Paper Components of EHRs Characteristics of a good EHRs A Kenyan EHRs implementation
The presentation will begin in a few moments
Welcome To Today s Webinar: Top 5 SOX Concerns for Dynamics AX The presentation will begin in a few moments Participants will receive an email within 48 hours with a link to the slide deck and recording.
A Database Security Management White Paper: Securing the Information Business Relies On. November 2004
A Database Security Management White Paper: Securing the Information Business Relies On November 2004 IPLocks, Inc. 441-A W. Trimble Road, San Jose, CA 95131 USA A Database Security Management White Paper:
THE CASL COUNTDOWN. Your week-by-week checklist to ensure your organization is CASL-ready for July 1st
THE CASL COUNTDOWN Your week-by-week checklist to ensure your organization is CASL-ready for July 1st Inbox Marketer s CASL Countdown is a checklist of tasks for your organization to complete to ensure
An Overview of Information Security Frameworks. Presented to TIF September 25, 2013
An Overview of Information Security Frameworks Presented to TIF September 25, 2013 What is a framework? A framework helps define an approach to implementing, maintaining, monitoring, and improving information
Privacy Impact Assessment (PIA) for the. Certification & Accreditation (C&A) Web (SBU)
Privacy Impact Assessment (PIA) for the Cyber Security Assessment and Management (CSAM) Certification & Accreditation (C&A) Web (SBU) Department of Justice Information Technology Security Staff (ITSS)
SharePoint Case Management System an Introduction
SharePoint Case Management System an Introduction SharePoint Case Management System (SCMS) is an innovative ticketing & a case management tool, which is being utilized by several business establishments
Aligning CMMI & ITIL. Where Am I and Which Way Do I Go? 2006 - cognence, inc.
Aligning CMMI & ITIL Where Am I and Which Way Do I Go? 2006 - cognence, inc. Agenda Where Am I? Current Situation Process Improvement Objectives How Do I Get There? CMMI ITIL Mapping, Commonalities, Differences
