Showing posts with label required. Show all posts
Showing posts with label required. Show all posts

Friday, April 14, 2017

When Doctors Resist Compliance Training

"No doctor, compliance training is not optional"

We often receive calls from clients asking for creative ways or guidance to get the doctors in their practice to do compliance training along with the rest of the office staff. The doctor doesn't have time or just wants to "review" the policies and procedures, which they won't. This seems to be a fairly common thread with compliance training and doctors.
Many offices have similar issues with doctors resisting training and as a medical office manager or compliance training administrator you may need to be less coddling or creative and more firm and direct. 

The bottom line is that HIPAA, OSHA and Medicare do not simply suggest training. It is REQUIRED that ALL EMPLOYEES receive compliance training annually (including management and particularly doctors). They don’t simply recommend this or say if it is convenient but that it is REQUIRED for compliance.

It may be necessary to send a message reminding ALL staff members of this fact and the importance of being in compliance for the safety of patients and staff, privacy issues, the legal requirements and financial/reputation ramifications for the practice as a whole due to violation or non-compliance.

Including the information on specific regulations may be useful to get the message across. For example:

The HIPAA Privacy CFR discussing administrative requirements for training can be located in 45 CFR § 164.530(b)(1) and for HIPAA Security 45 CFR § 164.308(a)(5).

Similar resources for OSHA can be found on the Guide to Compliance with OSHA Standards for Medical and Dental offices website. Note that each standard requires training.

Medicare and most insurance companies also require attestation (to affirm to be correct, true, or under oath) that ALL staff receives Fraud, Waste and Abuse training to maintain receipt of payment.

As for HR and Employment Law, we were recently contacted by a client about an unemployment claim issue. Because of the Doctor making a poor decision they will likely end up paying that unemployment claim when normally they would have been able to contest it. Due to that doctors lack of HR training, his bad decision will now cost the practice unnecessarily. Please see this previous article that spawned from this incident:
The greatest risk to any organization comes from within.


Another key item of importance is that workforce member can't just read over some notes on policies or procedures and be considered "trained". There needs to be a formalized consistent method of training that includes Documentation of the training processes, dates, etc. As the saying goes, if it isn't documented it didn't happen.

Compliance and Compliance Training is not optional and is very crucial to the legitimacy and success of your practice or medical facility. Make these requirements clear to your Entire Workforce as a fundamental part of your organization's culture and a non-negotiable condition of employment at your practice. End of story!




To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, July 20, 2016

Patient Authorization For Disclosure Of PHI

Required Elements Of A Patient Authorization
 HCSI

HIPAA requires that certain elements be present on the authorization that the patient is to sign.  Whenever you receive an authorization (or “release”) asking you to disclose PHI and HIPAA requires an authorization for the disclosure, use this checklist to verify that the authorization meets the HIPAA requirements. If any ONE of the following elements is missing, you should NOT release the patient’s PHI until you have a valid authorization signed by the patient. If ALL the elements are present, the authorization is valid. 


•    A description of the PHI to be used or disclosed that identifies it in a specific and meaningful fashion.  They may request the entire medical record, all records between specific dates, or other specific items. 


•    The name or other specific identification of the person(s), or class of persons, who can make the requested use or disclosure.  For example, the signed request should list either your organization or someone in your organization by name.

•    The person(s), or class of persons, to whom you may make the requested disclosure.  The specific entity(ies) to receive the information should be identified.  A cover sheet stating who should receive the information is NOT sufficient.

•    A description of each purpose of the requested use or disclosure.  The statement “at the request of the individual” is a sufficient description of the purpose when a patient initiates the authorization and does not, or elects not to, provide a statement of the purpose. The above statement or some other description must be present.

•    An expiration date or an expiration event that is related to the individual or the purpose of the use and disclosure.  The statement “end of research study”, “none”, or similar language is sufficient if the authorization is for a use or disclosure of PHI for research.  Again, the statement must be present.

•   Signature of the patient and date.  If the authorization is signed by a personal representative of the individual, a description of such representative’s authority to act for the individual must also be provided.

•    The individual’ s right to revoke the authorization in writing, any exceptions to that right, and a description of how the individual may revoke the authorization.

•    The ability or inability to condition treatment on the authorization by stating either:  (A) The covered entity may not condition treatment on whether the individual signs the authorization or (B) The consequences to the individual for refusal to sign the authorization.  (Remember that there are very limited circumstances in which action can be a condition on a patient signing an authorization.)

•    A statement that informs of the potential for information to be re-disclosed by the person or organization to which it is sent.  The privacy of this information may not be protected under the Federal Privacy Rule depending on whom the information is disclosed to.

•    If the requested use or disclosure is for marketing purposes.  If the marketing involves direct or indirect remuneration to the covered entity from a third party, the authorization must state such remuneration.


--For more healthcare compliance information and discussion please join the LinkedIn group forum: The Healthcare Compliance Solutions Administrative Alert

To subscribe to this blog, enter your email address:


Delivered by FeedBurner