Showing posts with label HealthIT. Show all posts
Showing posts with label HealthIT. Show all posts

Thursday, February 25, 2016

Your Compliance Officer Needs A Seat At The Table


Put Your Compliance Officer On Speed Dial

At most healthcare facilities, the compliance officer is very busy, as are the administrator, privacy officer, security officer, and the person in charge of purchasing and contracting. These people wear many hats, and don't have time to collaborate - or the organization doesn't have processes in place to facilitate collaboration. 

Does this sound familiar? This scenario is common, perhaps even the norm. It's also very risky from a compliance standpoint. Here are some examples of what can go wrong when the compliance officer is left out of business decisions at a nursing home.

A director of nursing wants to buy laptops for nurses, in order to improve the accuracy of documentation. The administrator approves the cost, and IT makes the purchase. After the laptops arrive, the compliance officer finds out. She advises the organization to buy encryption and anti-virus software for HIPAA security purposes - and is told it's not in the budget.

In another example, the CEO or a board member comes across an opportunity to enter an arrangement with a nearby hospital. The hospital will pay a fee to reserve a number of SNF beds in case the hospital needs them for its patients. The CEO or board member works out the details without contacting the compliance officer. It turns out that the arrangement violates the Anti-Kickback Statute. If the officer had known, she could have involved legal counsel to structure the arrangement in a way that is appropriate. 
The compliance officer needs a seat at the table for business decisions in long-term care facilities to avoid these common pitfalls. Here are some steps you can take to make this happen: 
  • Use your compliance committee. If the committee meets quarterly, listens while the compliance officer reads the meeting agenda. If there's no discussion, you have a missed opportunity. Leverage your compliance resources - in this case, your leaders and experts - to share information about emerging risks and upcoming contracts and deals. By getting committee members in the habit of including each other in big decisions, you can avoid costly communication breakdowns. 
  • Work on your work flow. If your managers aren't used to collaborating, it might be hard to get started. Get everyone together, and write down examples of situations where the compliance officer (or another compliance leader, such as a HIPAA officer), should be involved. For example, you might write down "IT purchase" and "contract with a referral source," to start. Encourage your team to add to this list and share it at regular compliance committee meetings. 
  • Put the compliance officer on speed dial. This one is pretty basic, but can make a big difference. Identify who needs the compliance officer on speed dial, starting with your HIPAA officers, and anyone in a position to enter a contract. You might even add a "Call the Compliance Officer" sticker to their phone or computer as a friendly reminder. You have a compliance officer for a reason: to keep your organization compliant. Make sure everyone in your organization understands when and how to use this person, and everyone will make better decisions.
Source(s): Margaret Scavotto, http://www.mcknights.com, www.hcsiinc.cm

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, February 9, 2016

ONC Clarifies TPO and Health IT Interoperability Under HIPAA

Some providers are not sharing PHI due to organizational policies, procedures or protocols, even if the sharing is permitted under HIPAA.


In general, a Covered Entity (CE) may use and disclose protected health information, without authorization, for treatment, payment, and health care operation activities (TPO). Treatment includes the provision, coordination, or management of health care and related services among health care providers; consultation between providers regarding a patient; or patient referrals from one provider to another. A CE may disclose PHI for its own treatment activities and the treatment activities of any another health care provider. Payment includes all health plan activities associated with obtaining premiums, fulfilling coverage responsibilities, providing plan benefits, and obtaining reimbursement for furnished health care and provider activities related to payment and reimbursement. A CE may use PHI for its own payment activities and may disclose PHI to another covered entity or health care provider for the payment activities of the entity receiving the information.

Many providers believe that HIPAA restrictions prevent them from moving protected health information (PHI) in certain patient care situation. However, that’s a common misconception potentially hindering health IT interoperability when, in fact, HIPAA enables PHI to be accessed, used or disclosed when and where it is needed for patient care.

In a blog post published Feb. 4 on Health IT Buzz, Lucia Savage, JD, and Aja Brooks, JD, of the Office of the National Coordinator for Health IT (ONC) introduced two new government fact sheets that give examples of when electronic PHI can be exchanged without requiring written authorization from the patient as long as other protections or conditions have been met.

ONC, which oversees interoperability aspects of handling PHI, developed the materials in conjunction with the Office of Civil Rights (OCR), which administers policy and enforcement of the HIPAA privacy rules.

“Some providers are not sharing PHI due to their health care organization’s policies, procedures, or protocols, even if the sharing is permitted under HIPAA, or because laws in the provider’s state apply in addition to HIPAA. Interestingly, this lack of exchange of PHI runs contrary to consumer perception, with research demonstrating that patients assume their PHI is automatically shared between their treating physicians,” wrote Savage and Brooks.

The new fact sheets describe permitted uses and disclosures of PHI by a HIPAA covered entity (CE) without first having to obtain written authorization from the patient.

In “Permitted Uses and Disclosures: Exchange for Health Care Operations” (available here), the agencies explain that HIPAA allows a CE to disclose PHI to another CE (or that CE’s business associate) for the following operations activities of the recipient CE without needing patient consent or authorization: 
  • Conducting quality assessment and improvement activities. 
  • Developing clinical guidelines. 
  • Conducting patient safety activities as defined in applicable regulations. 
  • Conducting population-based activities relating to improving health or reducing healthcare cost. 
  • Developing protocols. 
  • Conducting case management and care coordination (including care planning). 
  • Contacting healthcare providers and patients with information about treatment alternatives. 
  • Reviewing qualifications of health care professionals. 
  • Evaluating performance of health care providers and/or health plans. 
  • Conducting training programs or credentialing activities. 
  • Supporting fraud and abuse detection and compliance programs. 
The aforementioned activities are, however, subject to three requirements that must also be met: 
  1. Both CEs must have or have had a relationship with the patient (can be a past or present patient). 
  2. The PHI requested must pertain to the relationship. 
  3. The discloser must disclose only the minimum information necessary for the healthcare operation at hand. 

In “Permitted Uses and Disclosures: Exchange for Treatment” (available here), ONC and OCR explain permissible disclosure of PHI by CEs to another provider for treatment activities without needing patient consent or authorization.

The document explains what happens when a hospital discloses PHI in a permissible way to a receiving provider, who subsequently experiences a breach of the information. The receiving physician is “responsible for safeguarding the PHI and otherwise complying with HIPAA, including with respect to subsequent uses or disclosures or any breaches that occur.” At the same time, the disclosing hospital is responsible for transmitting the PHI in a permitted and secure manner, which includes taking reasonable steps to send it to the right address. The fact sheet also includes sample scenarios in the areas of PHI exchange for care planning and downstream treatment.

ONC and OCR plan to publish three additional blogs on PHI exchange as related to: the goal of nationwide health IT interoperability; care coordination, planning and management; and population-based activities.

Source(s):https://www.healthit.gov, http://www.hhs.gov/ocr/, http://www.healthinfolaw.org/,
http://healthitinteroperability.com, Frank Irving


For more information on this and other healthcare compliance topics related to HIPAA, OSHA, Medicare and HR, simply email your questions to support@hcsiinc.com
visit our website at http://www.hcsiinc.com or post a question on our LinkedIn group at: http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:


Delivered by FeedBurner