Disclaimer This Presentation is provided “as is” without any express or implied warranty. This Presentation is for educational purposes only and does not.

Slides:



Advertisements
Similar presentations
Organizing Information Technology Resources
Advertisements

1 Health Insurance Portability and Accountability Act of 1996 IS&C Expo October 16 & 17, 2002 John Wagner Governor’s Office of Technology.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
Information Risk Management Key Component for HIPAA Security Compliance Ann Geyer Tunitas Group
Managing Access to Student Health Information per Federal HIPAA Guidelines Joan M. Kiel, Ph.D., CHPS Duquesne University Pittsburgh, Penna
Westbrook Technologies from Document Management’s Role in HIPAA.
Presents: Weekly HIPAA Teleconference Revised
NAU HIPAA Awareness Training
SLIDE 1 Westbrook Technologies from Fortis: A Healthcare Solution for Medical Records, Billing and HIPAA.
CHAPTER © 2011 The McGraw-Hill Companies, Inc. All rights reserved. 2 The Use of Health Information Technology in Physician Practices.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
Are you ready for HIPPO??? Welcome to HIPAA
Randy Benson RHQN Executive Director May, Compliance Issues During Survey Compliance Officers monitor healthcare facilities (hospitals and clinics)
HIPAA Security Rule Overview and Compliance Program Presented by: Lennox Ramkissoon, CISSP The People’s Hospital HIPAA Security Manager The Hospital June.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
Medication Reconciliation Networking Session Steve Rough, MS., RPh. Director of Pharmacy University of Wisconsin Hospital and Clinics.
2 The Use of Health Information Technology in Physician Practices.
Clinical Information System Implementation Project Prepared for Clinical Affairs Committee December 4, 2002.
Coordinating Center Overview November 18, 2010 SPECIAL DIABETES PROGRAM FOR INDIANS Healthy Heart Project Initiative: Year 1 Meeting 1.
Chapter 10 Information Systems Management. Agenda Information Systems Department Plan the Use of IT Manage Computing Infrastructure Manage Enterprise.
Documentation for Acute Care
A Primer on Healthcare Information Exchange John D. Halamka MD CIO, Harvard Medical School and Beth Israel Deaconess Medical Center.
Part II Objectives F Describe how policies and procedures are used F Identify different types of P & P F Describe the purpose and components of a Policy.
Corporate Ethics Compliance *
August 22, 2002 THE HIPAA COLLOQUIUM at Harvard University A. John Blair, III, MD Chairman and Chief Executive Officer Taconic IPA, Inc. Fishkill, NY HIPAA.
ICD-10 IMPLEMENTATION – ARE YOU WHERE YOU NEED TO BE? Maureen Doherty, CPC, CPC-H EisnerAmper Healthcare Services Group June 2012.
CHAA Examination Preparation
Rural Wisconsin Health Cooperative Information Technology Network (Achieving eHealth in Rural Hospitals) eHealth Summit (6/12/08) Prepared by Louis Wenzlow.
Information Security Compliance System Owner Training Richard Gadsden Information Security Office Office of the CIO – Information Services Sharon Knowles.
Revenue Cycle Management Medical Technology Acquisition and Assessment Team Members: Joseph Dixon, Michael Morotti, Mari Pirie-St. Pierre, David Robbins.
© 2009 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill Career Education Computers in the Medical Office Chapter 2: Information Technology.
Component 2: The Culture of Health Care Unit 3: Health Care Settings— The Places Where Care Is Delivered Lecture 3 This material was developed by Oregon.
Paula Peyrani, MD Medical/Project Director, HIV Program at the 550 Clinic Assistant Director, Research Design and Development Clinical and Translational.
The Use of Health Information Technology in Physician Practices
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
HIPAA Business Associates Leadership Group Meeting June 28, 2001.
Company LOGO Data Privacy HIPAA Training. Progress Diagram Function in accordance Apply your knowledge Learn the Basics Orientation Evaluation Training.
Integrating HIPAA Into Your Compliance Program Fifth Annual National Congress on Health Care Compliance February 7, 2002 Glenna S. Jackson Vice President.
1 Patient Access Management Leveraging Best Practices.
Health Insurance Portability and Accountability Act (HIPAA)
1 Secure Commonwealth Panel Health and Medical Subpanel Debbie Condrey - Chief Information Officer Virginia Department of Health December 16, 2013 Virginia.
Steps for Success in EHR Planning Bill French, VP eHealth Strategies Wisconsin Office of Rural Health HIT Implementation Workshop Stevens Point, WI August.
The views expressed in this presentation do not necessarily reflect those of the Federal Reserve Bank of New York or the Federal Reserve System Association.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
The Fifth National HIPAA Summit – October 30, 2002 What to Do Now: Operational Implementation of HIPAA Privacy and Security Training Presented by: Steven.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA Vendor Readiness Siemens/HDX Audio Telecast July 24, 2002.
Medical Manager Unit 9 ICBS 170. Medical Manager Electronic Data Interchange (EDI)  Ability to request, receive, transfer and integrate information electronically.
National Provider Identifier HIPAA Summit 13 September 25, 2006 Peter Barry Hospital Implementation Planning.
HIPAA Health Insurance Portability and Accountability Act of 1996.
ORGANIZING IT SERVICES AND PERSONNEL (PART 1) Lecture 7.
National HIPAA Audioconference: Analysis of the National Provider Identifier Preparing for the NPI Transition January 11, 2006.
This material was developed by Oregon Health & Science University, funded by the Department of Health and Human Services, Office of the National Coordinator.
Compliance August 18, Agenda Outline Status Draft of Answers.
Confidential 1 HIPAA Compliance at Blue Cross Blue Shield of Minnesota: A Case Study Tim Wittenburg Director of Corporate Architecture & Data Management.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
Hospital Accreditation Documentation Process & Standard Requirements
Chapter 1 Introduction to Electronic Health Records Copyright © 2011 by Saunders, an imprint of Elsevier Inc.
BMED DEPARTMENT. what you want Do you know to be when you grow up?
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
February 3, 2009 Bridging Academic and Medical Cultures Academic Research Systems and HIPAA William K. Barnett Anurag Shankar.
Health Information Professionals
eHealth Summit (6/12/08) Prepared by Louis Wenzlow RWHC ITN CIO
Health Care: Privacy in a Digital Age
Competencies in Health Information Systems
The Health Insurance Portability and Accountability Act
Presentation transcript:

Disclaimer This Presentation is provided “as is” without any express or implied warranty. This Presentation is for educational purposes only and does not constitute legal advice. If you require legal advice, you should consult with an attorney.

HIPAA Health Insurance Portability and Accountability Act or HIPAA

Developing the plan and managing the HIPPA “project” from an enterprise view

What is HIPAA? Healthcare In Pain And Agony (again)

Healthcare Information Sharing Managed care organizations;  Consulting physicians; Health insurance companies  Life insurance companies;  Self-insured employers; Pharmacies;  Pharmacy benefit managers;  Clinical laboratories; State and Federal statistical agencies; and  Medical information bureaus  Accrediting organizations;

What is Protected Health Information? Health Information - Is any information gathered by a health care provider, including non-health related data Protected Health Information - Is Health Information that contains data that may be used to directly or indirectly identify the patient  Also Described As: Identifiable Health Information Identifiable Patient Information

List of Data Elements that would make Health Information Identifiable! Name Address address Telephone No. Finger or voice prints Social security number Vehicle/device serial no. Health plan number Certificate/license No. Names of relatives Names of employers Fax number Birth date Photographic images / X-rays Internet (IP) address Medical record number Account Number Web URL

PHI is Covered by HIPAA, Regardless of Format Examples:  Database or Computer Stored Files   Images or X-rays  Conversations  Word Documents  PDA Stored Information  Hand written notes  Student Logs  Academic Curriculum

The eight steps to HIPPA implementation: project sample time frame

1. THINK AND EDUCATE The Big Choices  When to start?  Centralized vs. Decentralized approach?  Sponsorship / Executive Leadership  E-commerce integration?  Compliance vs. compliance plus significant benefits

1. THINK AND EDUCATE Create a HIPAA Vision  Business office  Financial performance  Referral management  Patient relations Billing / collections registration primary statement  Relationship with key trading partners  Define goals

1. THINK AND EDUCATE Proactive Vision  E-commerce based  Significant reduction in Business Office staff  Increased cash flow  Reduced bad debt  User friendly security technologies  HIPAA Security and Privacy aware staff  Collaborative relationship with business partners  Patient/subscriber friendly  Positive consumer public relations  Valued business partner relationships

1. THINK AND EDUCATE Compliance Focused Vision (Provider)  HIPAA claims only transacted, forget the rest  Increasing Business Office Staff  Growing accounts receivable  Increased bad debt  Complex, hard to use security measures that interfere with patient care  Staff have minimal HIPAA security and privacy awareness  Adverse relationship with Business Partners  Inadequate systems and administrative policies to support security and privacy

Sponsors / Steering Committee  CEO, CFO, CIO, COO  Compliance Officer  Risk Management  Human Resources  Government Relations  Chief Information Security Officer  General Counsel  Privacy Officer 1. THINK AND EDUCATE

Sponsors / Steering Committee  Patient Representative  Security (physical) Officer  E-commerce  Admitting / Registration  Business Office  Medical Records  Workflow / Change Management

1. THINK AND EDUCATE HIPAA Education  High level  Management level  Ongoing through all phases  Three tier strategy In person Internet / Intranet Paper

1. THINK AND EDUCATE Project Management Organization (assume enterprise approach)  Core staff (few or many)  Dedicated project team vs. Shared resources  Mix of staff and consulting resources  Mix of HIPAA and operations knowledge  Independent Verification and Validation (IVV)  Protecting the information Security Protection from discovery

1. THINK AND EDUCATE HIPAA Scope Definition  Suggested Initial Project HIPAA Regulation Scope Standard Transactions Employer (sponsor) Identifier Provider Identifier Payer Identifier Electronic Attachments Security (Privacy)  Business Applications  IS Applications  Key Trading Partner identification

HOSPITAL SYSTEMS EFFECTED BY HIPAA Business Applications Laboratory Pharmacy Radiology Registration (ADT) Orders Results Credentialling Data Warehouse Cost Accounting Materials Management Master Person (Patient) Index Patient Accounting Home Care Nursing home Physician practice Human Resources  HIPAA training management

HOSPITAL SYSTEMS EFFECTED BY HIPAA Business Applications Medical Records  Coding and Abstracting  Chart Tracking  Document Imaging  Electronic Medical records Clinical Data Repository Demand Management Patient Scheduling Referral Management Other Not Impacted  Payroll  General Ledger  Accounts Payable

HOSPITAL SYSTEMS EFFECTED BY HIPAA Business Applications Department Systems with Patient Specific Information (e.g., Cath lab) Telecommunication systems that contain patient identifiers, e.g., appointment call system Any special purpose database or application which includes patient specific information - - e.g. tumor registry

HOSPITAL SYSTEMS EFFECTED BY HIPAA IS Applications Internet and point-to-point data communications Interface Engine(s) EDI Engine(s) Infrastructure  Firewall  Network Security  Physical Security  Security Policies and Procedures  Security Audit Systems  Security Technology and Technology Mechanisms

1. THINK AND EDUCATE Get Involved / Share with Peers HIPAA Regulations Strategic Implementation Plan (SIP)  Professional Associations  Key Trading Partners  Local Networking

2. GATHER CURRENT STATE INFORMATION Inventory Everything Effected by HIPAA Risk Level Impact Assessment  Categorize risk level Business risk Security risk  Flag high cost remediation items

2. GATHER CURRENT STATE INFORMATION Use Electronic Tools to Document and Manage the Process  Impact Assessment Inventory database  Transaction Implementation Guides  (Business) Risk / Compliance Management tracking and documentation  Project Management

2. GATHER CURRENT STATE INFORMATION Cross Reference Regulations  Business applications  IS applications  Work processes  Administrative policies and procedures  Physical security issues  Other Develop HIPAA Project Plan  Eight Steps  Develop a mid-level plan with tasks  Phase by regulation timing  Basis for three year plus budget and resources plan

3. RISK AND COST BENEFIT ANALYSIS Staff Up  Technical  Legal  Workflow  Optional development and analysis  Change management Increase Education Activity Think Outside the Box Independent advisors

3. RISK AND COST BENEFIT ANALYSIS GAP Analysis Quantify Risks  Probability of incidents  Impact per incident Fines and jail Legal defense/insurance premiums Loss/delayed revenues and staff to rework “Urgent” fix cost and staff time Public image

3. RISK AND COST BENEFIT ANALYSIS Identify Options to Reduce Each Risk  Level of risk reduction (probability)  Cost to achieve risk reduction  Dependency factors Cost / Benefit Analysis  Identify greatest risk items  Identify benefit to cost ratio  Analyze items that are interrelated

3. RISK AND COST BENEFIT ANALYSIS Assess Current Vendors’ HIPAA Readiness Plans and Assurances Recommendations to Sponsors/Steering Committee  Rationale  By level of investment

4. PLAN Develop a Detailed Implementation Plan Include Current HIPAA Knowledge  Internal  External Coordinate with E-Commerce Initiatives Technology Strategy Administrative Strategy

4. PLAN Issue RFPs to Acquire New Systems if Needed Educate Assure Availability of Implementation Resources Coordinate with Trading Partners

5. IMPLEMENTATION Implement Changes  Transactions and Code Sets  Identifiers  Security -- Physical  Security -- Administrative  Security -- Technology and Technology Mechanisms

5. IMPLEMENT Training Independent Assessment of ongoing project  Budget  Timeliness  Goal achievement

5. IMPLEMENT Testing  Unit testing  Integration testing  Testing with trading partners Document the Risk Mitigation

6. REVIEW Readiness Review Include Knowledge Gained Since the Plan was Developed Update to Address Changes in HIPAA Regulations

7. CERTIFY AND GO LIVE Independent Review Certification Likely Only for Some Components

8. MONITOR HIPAA Regulations  New  Revisions Security Audit and Monitoring Business Risk Monitoring Measure Goal Achievements Feedback to Phase 3 Report to Leadership Measure Business Partner Relationships