Showing posts with label Policies and Procedures. Show all posts
Showing posts with label Policies and Procedures. Show all posts

Thursday, February 8, 2018

Protecting Doctors from Themselves

While practicing medicine, doctors must
protect their own integrity and reputation


It is a story that we were all shocked to hear about. USA Gymnastics Medical Professional and his inappropriate conduct with his patients and others. It is situations like this that make patients either grateful for or suspicious of the doctor they have.

Reality Time

When something so dramatic and public as the USA Gymnastics situation happens, it has numerous effects:
  1. Patients who are victims of such horrific acts may develop the courage to speak out and tell their story.
  2. Some people will begin looking for this type of situation in their life and find it, even if it does not exist.
  3. There are people who are looking for the social media spotlight and begin making accusations in order to gain attention.
What Can a Doctor Do?

It is vital that a doctor take appropriate steps to protect him or herself from a possibly career ending situation:
  • Continually communicate with the patient throughout their visit. They should know what the doctor is doing and why.
  • Have written policies and procedures in place that focus on harassment and inappropriate conduct within the office. These policies should also include appropriate interactions with patients. This training should include ALL staff members including doctors and be done annually as well being thoroughly documented.
  • Create a culture within the healthcare office of acting professionally and being current with all compliance laws.
  • Communicate with patients that if at anytime they do not feel comfortable with the doctor or other staff members, that they are welcome to have an additional person of the same gender in the room during their visit.
  • If the doctor does not feel comfortable being alone with the patient, then he or she should request and additional person (e.g. nurse or physician assistant) be present during the visit.
Possible Consequences

If a doctor is accused of some inappropriate behavior with a patient, then that doctor's reputation could be irrevocably damaged. It does not matter if the accusation has any truth to it, people will remember and the damage is done. It is best for the doctor to protect him or herself and avoid even the slightest hint of inappropriate behavior.

This type of situation cannot be taken lightly. Many doctors push away training, especially HR training, as inconvenient and a time waster. They do not understand that HR and other training's are in place for their protection. Documented HR and conduct training would play a key role in protecting a doctor and the reputation of the practice.

It is completely understandable that doctors want to focus only on practicing medicine, but they do not need to put themselves and their career at risk when doing so.



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, October 31, 2017

Importance of Written Time Off Policies

Managing time off requests effectively
will help reduce your liability

There are certain times of the year, summer and holidays, when a significant number of employees request time off from work. While it would be nice to accommodate all of the time off requests, work still needs to get done. In addition to reduced productivity, there is another factor with time off requests that increases liability, reduces morale, and sours the great culture that has been building within the organization. All of these are the result of unfair time off practices.

Reduce Liability
All of your time off requests should be done by following a written policy and procedure. Time off policies should be the same for the same type of employee (part-time or full-time). Be sure that the written time off policies are in no way discriminatory of gender, race, religion, or other factor.

Keep Morale High
If the written policies and procedures are not deviated from and are followed, then there should be no appearance of favoritism. It is the appearance or perception of favoritism that has a destructive influence on the morale of other employees.

Culture is Still Great
Any type of special allowances of time off could have a souring effect on the culture of an organization. Remember, everyone would like to have a special day off and get paid for it. If it is not written in the policies and procedures, don't do it. If someone really needs to have a day off and it is outside of the written policies, then the day off can be granted to the employee, but it would not be an unpaid day off. This would not have the same souring effect on the culture as a paid day off would have.

Reduce liability, keep the morale high, and maintain a great culture by having fair and written time off policies and procedures that are strictly followed.



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, March 31, 2017

Your Biggest Liability Is Standing Right Next To You

The greatest risk to any organization comes from within

Donna felt confident that she had terminated Kate's employment with just cause. Within a week of Kate's firing, Donna received notice that Kate filed for unemployment insurance. Donna was surprised with the news. Kate was let go because she was doing something that was against company policy. She was, in the eyes of the organization, steeling and falsifying documentation. Donna thought that not doing these things was simply common sense. During Donna's conversation with the unemployment representative, he asked her a question that stunned her. He asked, "do you have documentation that you trained Kate in these matters?" Donna's reply was very similar to how many others might have replied in her situation, "why would I need to do training on something that is common sense?" Kate began receiving unemployment benefits.

An organization relies on its employees and their productivity. Close relationships are sometimes formed. Even the occasional lifetime friendship is created. Employees are one of the greatest resources to an organization. It is for all of the reasons listed above, and many others, that an organizations biggest liability comes from its employees.

Yes, the statement above is cold and harsh, but so are certain workplace realities. Employees present the biggest risk to an organization. Here are some examples where employees are a liability:
  • Compliance (HIPAA, Medicare, etc) - Employees are human and sometimes their curiosity gets the better of them. They also tend to say or do things that could get an organization in trouble or audited.
  • Harassment - Employees have a bad history of being mean and spiteful to each other. If an employee enters a department where they are either not liked or resented, the other employees will make the unwanted employee's work environment unbearable until they are no longer there.
  • Social Media - People love to vent their frustrations. As it turns out, people now have a way to vent their frustrations about their jobs to the entire world. Employees of any organization are no different. If an employee feels slighted at their job or does not like their job, the world will hear about it.
  • Employment Termination - There is always a level of risk when an organization has to terminate an employees employment. Although the supervisor feels that he or she did everything right, there are times when something unexpected comes back to bite the organization right in the bank account. Here are two facts to remember: 1. some employees will lie and 2. unemployment officers and the courts tend to lean in favor of the employee (particularly if the employer has little or no documentation to back up their side of the story and it boils down to a "he said, she said" situation).
What has been said here is just a taste of reality. However, with that reality, there are things an organization can do to lessen its liability:
  • Training and Documentation - It is vital that an organization deliver training on every topic that is relevant to that organization. No matter how trivial it might appear. Do not assume that people will just know stuff because it's "common sense". In addition, it is critical that there is documentation of any given training. Include the names of the attendees, date, and the topics covered.
  • Policies and Procedures - Having established, written, and communicated policies and procedures will help an organization protect itself from employees who claim that they had no idea this or that was against the organization's policies. Having written policies and procedures will also protect an organization if an audit should occur.
  • Organizational Culture - What does the culture within an organization say about it? For employees, the culture of an organization says a lot. Having an organizational culture where the employees are supportive of one another, where there is a positive attitude, and where new ideas and thoughts are free to flow, helps lessen negative attitudes and bad feelings within the organization. It helps to bring in the right type of person who would fit the culture within an organization.
  • Employment Termination - This goes back to the idea of having effective policies, procedures and documentation in place. For example, if an employee quits, do not ask him or her to come back to the office to train another employee. When an employee quits, there IT access should be cut and they should not be doing any more work for an organization. This should be a written policy and followed the same way every time. Avoid showing favoritism towards employees and be sure that managers/supervisors know to avoid getting too close and personal with their employees. Managers and Supervisors should stay objective and focused on developing the employees in order to help them become more valuable within the organization.
Employees are a vital component to the success of an organization. Your employees will have diverse backgrounds, skills and personalities. However, they are still employees of an organization. Any organization who looses sight of this fact is putting itself at risk.

Organizations should treat their employees well and give them every opportunity to succeed in their position of employment. However, it is up to the organization to protect itself from the liability that comes with employees being imperfect people.



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, March 16, 2017

Policies and Procedures, Compliance Training and HR

Maintaining Compliance and also Keeping HR in the Loop
 HCSI
In your ongoing efforts to provide an office culture of compliance, it is important to remember that HIPAA requires covered entities to establish and implement written policies and procedures that are consistent with its Privacy and Security Rules.  It can also be important for your Human Resource officer(s) to be involved with HIPAA compliance related issues in the business.

The U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”) has begun its Phase 2 HIPAA Audit Program.  The Program will focus on the policies and procedures adopted and employed by covered entities and their business associates to meet the requirements of the Privacy, Security, and Breach Notification Rules.  Furthermore, if a group health plan is selected for an audit, it would have a very short time to produce its policies and procedures (i.e., 10 business days).  If the group health plan does not comply (for example, because it does not have policies and procedures), the OCR will likely impose corrective measures which could include costly civil monetary penalties.

HIPAA policies and procedures have important functions, including but not limited to:
  • Limiting uses and disclosures of Protected Health Information (“PHI”) to the minimum amount reasonably necessary to achieve the purpose of the use or disclosure;
  • Identifying the workforce members who need access to PHI and electronic PHI (“e-PHI”) to carry out their duties, the categories of PHI that they need, and any conditions under which they need the PHI to do their jobs;
  • Ensuring appropriate protection of e-PHI when it is transferred, removed, disposed and electronic media is re-used; and
  • Ensuring that e-PHI is not improperly altered or destroyed.
However, it is not sufficient for a covered entity to merely adopt its HIPAA policies and procedures.  The health practice office must also:
  • Designate a privacy and security official to develop and implement policies and procedures; 
  • Train applicable workforce members on its policies and procedures as necessary for them to carry out their functions, and apply appropriate sanctions against workforce members who violate its policies and procedures;
  • Periodically assess how well its policies and procedures meet the requirements of the Security Rule; and
  • Designate a contact person responsible for receiving complaints and providing individuals with information on the covered entity’s privacy practices.
There is no template for HIPAA policies and procedures.  Instead employers have the flexibility to design policies and procedures that are appropriate for their size, organizational structure, and risks to PHI and e-PHI.  Furthermore, as employers evolve, so should their policies and procedures.  For example, if an employer adopts a telework policy, it may wish to review whether its policies and procedures appropriately address issues involving remote access.


Summarizing, although not a new requirement, due to new technologies, evolving business and regulatory practices, along with impending HHS audits, employers may want to review their HIPAA policies and procedures to make sure that they are compliant and up-to-date. Many HIPAA policies inherently overlap with Human Resource's duties: training, disciplinary actions and employee health information for examples.
The increase in audits — combined with everything from changes in technology, the addition of a health and wellness program and concerns about hacking — serve as a good reminder why employers should revisit HIPAA training often and collaborate with HR to ensure compliance.

Many of the employers facing fines are healthcare providers, health plans or healthcare clearinghouses (organizations considered as covered entities under HIPAA). But most HR professionals also handle protected health information (PHI) to some extent, which puts them in danger of violating the HIPAA Privacy Rule.

Employers should have a written policy in place about how they handle PHI and designate PHI handlers and a HIPAA privacy officer. The policy should outline what types of information are considered PHI and how employers may and may not use it. It should also include a procedure for handling complaints and a process for employees to file them if they think their privacy rights are being violated.

Employees who may handle PHI should be trained on the dos and don’ts of handling protected health information, especially as it relates to electronic information. It’s vital for the HR team to understand the implications of handling PHI in emails, storing it on the cloud, or communicating about it over other electronic formats. And when discussing matters containing PHI with an employee, it’s important to have a signed HIPAA authorization form for the release of employee health information.

Lastly, the HIPAA privacy officer should review compliance documents and ensure that agreements with vendors who handle PHI, called “business associate agreements,” are up to date. The federal government considers vendors and subcontractors to be business associates if they handle PHI on behalf of the covered entity.

Source(s): http://www.hhs.com, http://www.jdsupra.comhttps://www.benefitnews.com, http://www.hcsiinc.com


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Monday, September 26, 2016

CMS Issues New Emergency Preparedness Rule

September is National Preparedness Month and CMS is Getting Involved  By Establishing New Emergency Preparedness Requirements for Medicare and Medicaid Health Care Providers.

The Centers for Medicare & Medicaid Services (CMS) has issued a final rule to establish consistent emergency preparedness requirements for health care providers participating in Medicare and Medicaid, stating that the regulation will increase patients’ safety during emergencies and ensure more coordinated response to natural and manmade disasters.
Are You Ready
“Over the past several years, and most recently in Louisiana, a number of natural and manmade disasters have put the health and safety of Medicare and Medicaid beneficiaries – and the public at large – at risk. These new requirements will require certain participating providers and suppliers to plan for disasters and coordinate with federal, state tribal, regional, and local emergency preparedness systems to ensure that facilities are adequately prepared to meet the needs of their patients during disasters and emergency situations,” the agency’s Sept. 8 news release stated.
“Situations like the recent flooding in Baton Rouge, Louisiana, remind us that in the event of an emergency, the first priority of health care providers and suppliers is to protect the health and safety of their patients,” said CMS Deputy Administrator and Chief Medical Officer Dr. Patrick Conway, M.D., MSc. “Preparation, planning, and one comprehensive approach for emergency preparedness is key. One life lost is one too many.”

“As people with medical needs are cared for in increasingly diverse settings, disaster preparedness is not only a responsibility of hospitals, but of many other providers and suppliers of health care services. Whether it’s trauma care or long-term nursing care or a home health service, patients’ needs for health care don’t stop when disasters strike; in fact, their needs often increase in the immediate aftermath of a disaster,” added Dr. Nicole Lurie, HHS’ assistant secretary for preparedness and response. “All parts of the health care system must be able to keep providing care through a disaster, both to save lives and to ensure that people can continue to function in their usual setting. Disasters tend to stress the entire health care system, and that’s not good for anyone.”
CMS reports that it reviewed current Medicare emergency preparedness regulations for providers and suppliers and concluded the regulatory requirements were not comprehensive enough to address the complexities of emergency preparedness; they did not address the need for communication to coordinate with other systems of care within cities or states; contingency planning; or training of personnel. So the final rule requires Medicare and Medicaid participating providers and suppliers to meet these four industry best practices:
1.Emergency plan: Based on a risk assessment, develop an emergency plan using an all-hazards approach focusing on capacities and capabilities that are critical to preparedness for a full spectrum of emergencies or disasters specific to the location of a provider or supplier.
2.Policies and procedures: Develop and implement policies and procedures based on the plan and risk assessment.
3.Communication plan: Develop and maintain a communication plan that complies with both federal and state laws.
4.Training and testing program: Develop and maintain training and testing programs, including initial and annual training, and conduct drills and exercises or participate in an actual incident that tests the plan.
CMS said these standards are adjusted to reflect the characteristics of each type of provider and supplier. For example, outpatient providers and suppliers such as ambulatory surgical centers and end-stage renal disease facilities won’t be required to have policies and procedures for provision of subsistence needs; hospitals, critical access hospitals, and long-term care facilities will be required to install and maintain emergency and standby power systems based on their emergency plan.
In response to comments, CMS removed the requirement for additional hours of generator testing, added flexibility to choose the type of exercise a facility conducts for its second annual testing requirement, and decided to allow a separately certified facility within a health care system to take part in that system’s unified emergency preparedness program.
The regulations will take effect on November 15, 2016.  Healthcare providers and suppliers affected by the rule must comply and implement all regulations one year after the effective date. More specific information about the Emergency Preparedness Rule can be found here.
Providers/Suppliers Facilities Impacted by the Emergency Preparedness Rule:
1. Hospitals
2. Religious Nonmedical Health Care Institutions (RNHCIs)
3. Ambulatory Surgical Centers (ASCs)
4. Hospices
5. Psychiatric Residential Treatment Facilities (PRTFs)
6. All-Inclusive Care for the Elderly (PACE)
7. Transplant Centers
8. Long-Term Care (LTC) Facilities
9. Intermediate Care Facilities for Individuals with Intellectual Disabilities (ICF/IID)
10. Home Health Agencies (HHAs)
11. Comprehensive Outpatient Rehabilitation Facilities (CORFs)
12. Critical Access Hospitals (CAHs)
13. Clinics, Rehabilitation Agencies, and Public Health Agencies as Providers of Outpatient Physical Therapy and Speech-Language Pathology Services
14. Community Mental Health Centers (CMHCs)
15. Organ Procurement Organizations (OPOs)
16. Rural Health Clinics (RHCs) and Federally Qualified Health Centers (FQHCs)

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, August 24, 2016

Discussion Point: Patients Making Recordings In Healthcare Settings

Policies Restricting Patient Recordings In Medical Settings

What are your opinions on a medical office or practice creating a policy to prevent/limit patients from making audio/video recordings in exam rooms or other common areas where HIPAA or patient privacy could be violated by improper use of these recordings?


Does the office or practice have free reign to create such a policy?  What if any limitations might apply?

What about the patient?  Do they have any "rights" providing them the freedom to be able to record a procedure or practitioner giving treatment instructions for example? 

What about recordings in a maternity ward/nursery or during child birth?  What about the potential for cell phones to disrupt sensitive medical equipment?  What about patient's using apps like Pokemon Go and inadvertently or covertly overhearing and recording sensitive patient information?
What HIPAA regulations or legal ramifications might be evoked by such a situation?  How does an office notify patients of and enforce such a policy?  Should the office require patients to sign an acknowledgement of said policy or is a posted sign or notice adequate?

I would love to hear all your thoughts on this topic and any addition related issues that might come up that I have not already listed in the situations above. 

 HCSI
To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, July 28, 2016

Preparing for Phase 2 of HIPAA Audits

Phase 2 HIPAA audits are here. It’s no longer a matter of when.
The question is: Are you ready?
 HCSI
On March 21, 2016, the HHS Office for Civil Rights (OCR) launched the second phase of audits for compliance with HIPAA privacy, security and breach notification rules. And in his July 18, article, Second phase of HIPAA audits shifts into high gear, HDM’s Managing Editor Greg Slabodkin informed us that according to OCR, letters were delivered via email to “167 health plans, healthcare providers and clearinghouses” on July 11. Unlike the pilot audits that focused only on covered entities, Phase 2 targets both covered entities and their business associates.
While most of the Phase 2 audits will be desk audits, some onsite audits will be conducted. Phase 2 audits will focus on areas with high occurrences of noncompliance in Phase 1, particularly issues raised during data breach investigations. These include risk analysis and management, notice of privacy practices, timeliness of breach notification, reasonable safeguards, facility access control, and workforce training on policies and procedures.

To prepare for Phase 2 audits, covered entities and business associates should review their HIPAA privacy, security and breach notification policies and confirm that the following requirements are in place and current:

Comprehensive documented risk assessment. Promptly address any deficiencies and complete all action items. Build on the assessment outcomes to create a strong risk assessment management program. Conduct a follow-up security risk analysis periodically to identify, address and document deficiencies that may occur.

Written HIPAA policies and procedures. These should reflect privacy and security standards along with any risks or vulnerabilities identified during the assessment process.

Incident response plan for responding to breach of protected health information (PHI). Implement breach notification policies and procedures that are aligned with requirements under the HIPAA breach notification standards. Conduct practice rounds to prepare staff for a real event should it occur. 

Current Notice of Privacy Practices. Provide printed copies of the most recent notice to patients and also make the notice available on the organization’s website. 

Safeguards to protect all forms of PHI. This applies to paper, electronic and verbal PHI, including mobile devices and storage media. For employees who have personal devices, implement a BYOD policy aligned with HIPAA standards. Keep an up-to-date inventory of all systems and mobile devices.

Workforce training program. Conduct and document training for new employees. Conduct and document ongoing training for all workforce members.


Business associate agreements. Organizations must maintain a current inventory of all business associates. Agreements should be updated and implemented in compliance with current HIPAA requirements.

PHI transmission policy. Verify that all PHI is encrypted, or document a risk analysis to support the decision not to use encryption technology. 

Even if your organization is not selected for a Phase 2 audit, implementing judicious measures now will support future audits and improve HIPAA compliance. 

It doesn’t just end with an audit occurring within the four walls of a healthcare organization. With more healthcare professionals working from home, there is growing concern about the possibility of “at-home” audits - if not now, these may happen in the near future. We’re operating in a virtual world - building a remote workforce, and many HIM departments are sending people home - coders, transcriptionists, even management staff. 

Suppose OCR conducts an onsite audit at your facility and finds that some employees work from home. You must be prepared for the inevitable questions. How are you protecting information offsite? What measures are you taking to make sure PHI is secure? What policies and procedures are in place to address specific issues of at-home worksites? If you’re preparing for OCR audits - or any audits - these are increasingly important points to consider.

Business associates should also be taking a proactive approach in case auditors want to know how workers at home are being audited. Options might include Skype, Facetime or Hangouts. Here are some basic questions to ask employees when evaluating at-home privacy and security risks: 
  • Where are you located in your personal residence? 
  • Is your workspace private? 
  • Are passcodes properly concealed, not posted in the workspace? 
  • Do you use a virtual privacy network (VPN)? 
  • Do you have the capability to print information? 
  • Do you have appropriate shredding capability? 
  • Is your computer set to shut down (encryption mode) in your absence? 
These questions are just the beginning of the conversation. It is critical to communicate clear expectations to employees who work at home - along with consequences if they fail to maintain privacy and security according to your policies and procedures.

A company’s work-from-home policy defines the telecommuting work arrangement, including comprehensive privacy and security practices. The telecommuting employee must sign an agreement to ensure the protection of proprietary information and PHI, and to maintain the same level of confidentiality that exists on the company premises. If issues arise, there are several options depending on the severity of noncompliance - corrective action, education and training, increased audits, return to in-house, or termination of employment.

Although current OCR requirements do not specifically require at-home audits, the regulations clearly state that all reasonable precautions must be taken to ensure that all information is secure and privacy is maintained.

The best way to mitigate regulation issues is to have a solid HIPAA program in place and be well prepared to demonstrate best practices that proactively identify and address risks to PHI.

HIM must work closely with IT and other departments - risk management, C-suite, compliance, training and HR - to properly prepare for audits. HIM directors and their staff understand the content and use of PHI, where it is most likely to be at risk, and how to protect it. As experts in HIPAA and information governance practices, HIM professionals and Compliance Support Partners can lead organizations through a successful audit.

Also See: OCR's Top 7 Areas of Focus During Phase Two Audits



To subscribe to this blog, enter your email address:

Delivered by FeedBurner