Showing posts with label Medical Office Administrator. Show all posts
Showing posts with label Medical Office Administrator. Show all posts

Thursday, February 25, 2016

Your Compliance Officer Needs A Seat At The Table


Put Your Compliance Officer On Speed Dial

At most healthcare facilities, the compliance officer is very busy, as are the administrator, privacy officer, security officer, and the person in charge of purchasing and contracting. These people wear many hats, and don't have time to collaborate - or the organization doesn't have processes in place to facilitate collaboration. 

Does this sound familiar? This scenario is common, perhaps even the norm. It's also very risky from a compliance standpoint. Here are some examples of what can go wrong when the compliance officer is left out of business decisions at a nursing home.

A director of nursing wants to buy laptops for nurses, in order to improve the accuracy of documentation. The administrator approves the cost, and IT makes the purchase. After the laptops arrive, the compliance officer finds out. She advises the organization to buy encryption and anti-virus software for HIPAA security purposes - and is told it's not in the budget.

In another example, the CEO or a board member comes across an opportunity to enter an arrangement with a nearby hospital. The hospital will pay a fee to reserve a number of SNF beds in case the hospital needs them for its patients. The CEO or board member works out the details without contacting the compliance officer. It turns out that the arrangement violates the Anti-Kickback Statute. If the officer had known, she could have involved legal counsel to structure the arrangement in a way that is appropriate. 
The compliance officer needs a seat at the table for business decisions in long-term care facilities to avoid these common pitfalls. Here are some steps you can take to make this happen: 
  • Use your compliance committee. If the committee meets quarterly, listens while the compliance officer reads the meeting agenda. If there's no discussion, you have a missed opportunity. Leverage your compliance resources - in this case, your leaders and experts - to share information about emerging risks and upcoming contracts and deals. By getting committee members in the habit of including each other in big decisions, you can avoid costly communication breakdowns. 
  • Work on your work flow. If your managers aren't used to collaborating, it might be hard to get started. Get everyone together, and write down examples of situations where the compliance officer (or another compliance leader, such as a HIPAA officer), should be involved. For example, you might write down "IT purchase" and "contract with a referral source," to start. Encourage your team to add to this list and share it at regular compliance committee meetings. 
  • Put the compliance officer on speed dial. This one is pretty basic, but can make a big difference. Identify who needs the compliance officer on speed dial, starting with your HIPAA officers, and anyone in a position to enter a contract. You might even add a "Call the Compliance Officer" sticker to their phone or computer as a friendly reminder. You have a compliance officer for a reason: to keep your organization compliant. Make sure everyone in your organization understands when and how to use this person, and everyone will make better decisions.
Source(s): Margaret Scavotto, http://www.mcknights.com, www.hcsiinc.cm

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, July 8, 2015

10 Business Associate Agreement Requirements

10 HIPAA Requirements for Business Associate Agreements


HIPAA requires that covered entities (CEs) enter into contracts with their business associates (BAs) to ensure that BAs will appropriately safeguard protected health information (PHI).  The business associate contract also serves to clarify and limit the permissible uses and disclosures of PHI based on the relationship between the parties and the services being performed.

The Department of Health and Human Services (HHS) Office for Civil Rights in 2013 issued extensive guidance on handling BA agreements under the HIPAA privacy and security rules. This guidance has been condensed down to the following 10 requirements. Some requirements are commonly included in a business associate agreement, but others may not be.

1.      Determine when and how the business associate is allowed to use or disclose PHI.
2.      Require that the BA will not use or disclose PHI other than what has been permitted by the contract or required by law.
3.      Establish what safeguards will be put in place to prevent unauthorized PHI disclosure. This includes implementing HIPAA requirements surrounding electronic PHI.
4.      Require the BA to report to the CE any use or disclosure of PHI not covered by the contract, including incidents or breaches of unsecured PHI.
5.      Ensure the BA will disclose PHI as specified in the contract to satisfy a CE’s obligation with respect to individuals’ requests for copies of their PHI. PHI should be available for amendments as well.
6.      To the extent the BA is to carry out a CE’s obligation under HIPAA, require that the BA comply with the requirement relevant to the obligation.
7.      Ensure internal practices, books and records relating to the use and disclosure of PHI by the BA will be made available to HHS to determine the CE’s HIPAA compliance.
8.      Require that the BA return or destroy all PHI received from, or created or received by the BA on the CE’s behalf, upon termination of the contract.
9.      Require that BAs enter into agreements with their subcontractors that may have access to PHI.
10.  Allow the CE to terminate the contract if the BA violates a material term of the contract.

Other helpful tips include:

        Keep all agreements in a centralized location that can be accessed anytime;
        Know when agreements expire;
        Continually monitor BA compliance by issuing assessments; and
        Include BAs in your risk analyses.


(SourceMedia website)