Showing posts with label Meaningful Use. Show all posts
Showing posts with label Meaningful Use. Show all posts

Wednesday, May 4, 2016

Do You Understand The HIPAA Security Risk Management Process?

Risk Analysis Requirements Under The Security Rule
HCSI
The HIPAA Security Rule requires that covered entities (your practice) conduct a Security Risk Analysis/Assessment for your organization, at minimum, once per year. It is critical that practices perform the Security Risk Analysis for several reasons. Not only is it important to comply with HIPAA, Health and Human Services (HHS) and Office of Civil Rights' (OCR) rules and regulations, but also for what you should consider to be a more motivational reason, to protect your practice (and bank account) from what could become debilitating fines and penalties.

The Security Management Process standard in the Security Rule requires each organization to “implement policies and procedures to prevent, detect, contain, and correct security violations.” (45 C.F.R. § 164.308(a)(1).), that apply to their particular practice. Risk Analysis is one of four required implementation specifications that provide instructions to implement the Security Management Process standard. This article will cover the Risk Analysis implementation specification of that standard. Section 164.308(a)(1)(ii)(A) states:
RISK ANALYSIS (Required). 

Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the organization. (Each organization must evaluate for itself the most appropriate answers to the questions contained in your own Risk Analysis.) From the information gained while conduction your Risk Analysis you should prepare a Security Risk Action Plan documenting your findings, your conclusions and plans to address risk issues.

This Action Plan should identify the current state of your practice from 3 areas: Environmental, Facility and Hardware/Software controls, [aka human, natural, and environmental threats].  It should also correlate issues from high to low risk and prescribe plans of action to address these issues in priority as deemed necessary.  Document your plans based on those risk analysis findings and your practice's available resources to best approach the reduction of your higher risk level issues and document your best practice policies and procedures going forward to mitigate damage, disruption or loss of Protected Health Information (PHI). The Security Rule requires the Risk Analysis to be documented but does not require a specific format. (See 45 C.F.R. § 164.316(b)(1).) The Risk Analysis documentation is a direct input to your Risk Action Plan and overall Risk Management Process.
The following questions are examples that your organization could consider as part of a risk analysis. These sample questions are not prescriptive and merely identify issues an organization may wish to consider in implementing the Security Rule:

1. Have you identified the e-PHI within your organization? This includes e-PHI that you create, receive, maintain or transmit.
2. What are the external sources of e-PHI? For example, do vendors or consultants create, receive, maintain or transmit your e-PHI?
3. What are the human, natural, and environmental threats to information systems that contain e-PHI?

In addition to an express requirement to conduct a Risk Analysis, the Rule indicates that a Risk Analysis is a necessary tool in reaching substantial compliance with many other standards and implementation specifications. For example, the Rule contains several implementation specifications that are labeled “addressable” rather than “required.” (68 FR 8334, 8336 (Feb. 20, 2003).) An addressable implementation specification is not optional; rather, if an organization determines that the implementation specification is not reasonable and appropriate the organization must document why it is not reasonable and appropriate and adopt an equivalent measure if it is reasonable and appropriate to do so. (See 68 FR 8334, 8336 (Feb. 20, 2003); 45 C.F.R. § 164.306(d)(3).)   

The OCR in recent months has acknowledged that providers are not making compliance implementation a priority to their practices. Thus, the increased risk of unauthorized access, use, and disclosure of protected (yet quite vulnerable) PHI is still a factor. Not to mention the risk of practices not appropriately implementing other critical areas of compliance, which also pose significant vulnerability to practices as well as the heightened risk of significant fines and penalties. While this information only briefly describes the risk to your practice, providers, workforce, and patients, the message to take away here is that the Office of Civil Rights means business - so much, in fact, that it was decided that the best and only way to make sure that practices understand the significance of compliance is for OCR (along with governing entities such as HIPAA, and others) to increase efforts of enforcement.

There is no such thing as "under the radar" or "off the grid" for practicing providers today. One component of enforcement is in HIPAA Security. It's a priority for HIPAA to ensure that potentially patient identifying and vulnerable information is secure. And rightfully so, when you consider the risk of potential identity theft, medical identity theft, and other dangers posed to patients due to the amount and types of information that health care providers have on each patient. Not to mention, the difficulty in finding the source of and stopping the effects of identity theft or medical identity theft, should that occur (which it does, all too often).
 
Organizations should use the information gleaned from their Risk Analysis as they, for example:
  1. Design appropriate personnel screening processes. (45 C.F.R. § 164.308(a)(3)(ii)(B).) 
  2. Identify what data to backup and how. (45 C.F.R. § 164.308(a)(7)(ii)(A).) 
  3. Decide whether and how to use encryption. (45 C.F.R. §§ 164.312(a)(2)(iv) and (e)(2)(ii).) 
  4. Address what data must be authenticated in particular situations to protect data integrity. (45 C.F.R. § 164.312(c)(2).)
  5. Determine the appropriate manner of protecting health information transmissions. (45 C.F.R. § 164.312(e)(1).)
Though there are other components of compliance, the Security Risk Analysis is one very essential component to compliance, and for many reasons. The Security Risk Assessment shows your practice's good faith effort in establishing and maintaining appropriate policies and procedures that meet guidelines and minimize risk to your practice, patients and their protected information. The Security Risk Analysis is required as a way for practices to show ongoing monitoring of critical business systems.

Enforcement of this area is at an all time high and will continue to gain steam. The best thing practices can do is to be proactive and show initiative. Also, note that the Security Risk Analysis/Assessment is also required for Meaningful Use attestation. Practices that are found to have received incentive payments through Meaningful Use but have not appropriately conducted a Security Risk Analysis/Assessment per attestation requirements are having to refund all of the incentive payments received as well as run the very high risk of more in depth investigations and other potential penalties.

Risk Analysis is the first step in an organization’s Security Rule compliance efforts. Risk analysis is an ongoing process that should provide the organization with a detailed understanding of the risks to the confidentiality, integrity, and availability of e-PHI. The outcome of the risk analysis process is a critical factor in assessing whether a required implementation specification or an equivalent measure is reasonable and appropriate. 



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, January 26, 2016

Clarification comes a week after one CMS official had discussed the end of Meaningful Use

Meaningful Use Stage Three to Continue Even As the Agency Moves to Implement MACRA’s Value-Based Payment Law

Talk about mixed messages! Is the federal Meaningful Use (MU) program about to end? Or is it going to continue and evolve in significant new ways?

Alert pathologists and clinical laboratory executives may have picked up on the conflicting statements about the future plans for Meaningful Use that have been made in recent weeks by certain officials from the Centers for Medicare and Medicaid Services (CMS).

Because thousands of hospitals and hundreds of thousands of physicians have made substantial capital investments in electronic health records to qualify for federal incentives, any major change to the Meaningful Use requirements will have broad consequences.

Medical laboratories have a big stake in this issue as well, since they must invest substantial money into creating the interfaces needed to connect their labs’ laboratory information systems (LIS) to the EHRs of client hospitals and physicians.

CMS Drops Bombshell at J.P. Morgan Healthcare Conference

The first significant discussion about major changes to the Meaningful Use program came on January 12, 2016. That’s when CMS Administrator Andy Slavitt, MBA, made the surprise announcement during a speech to the J. P. Morgan Healthcare Conference in San Francisco.

“Now that we effectively have technology into virtually every place [health]care is provided, we are now in the process of ending meaningful use and moving to a new regime culminating with the Medicare Access and Children’s Health Insurance Program Reauthorization Act of 2015 (MACRA) implementation,” declared Slavitt to a surprised audience. “The meaningful use program as it has existed will effectively be over and replaced with something better.”

During his presentation, Slavitt indicated that three provider-reporting programs will be sunset and aligned into a single new program, but he said details of the next stage would not emerge for several months.

Andy Slavitt, MBA, Acting Administrator at the Centers for Medicare and Medicaid Services, surprised physicians and healthcare executives when he announced on Jan. 12 that the meaningful use program, which had rewarded providers for demonstrating their use of electronic health records, would be phased out this year. “The Meaningful Use program as it has existed will now be effectively over and replaced with something better,” he said. (Photo copyright: Politico.)

Slavitt’s comments about ending Meaningful Use were widely reported. While addressing the group, he said that, by phasing out the MU incentive program this year, the agency wanted to streamline and simplify programs in preparation for the implementation of MACRA, which repealed the Medicare sustainable growth rate (SGR) formula that calculated payment cuts for physicians. The new legislation also established a timeline for replacing Medicare’s existing fee-for-service payments with two payment tracks:


2. Alternative payment models (APMs) by January 2019.

Slavitt described the MACRA legislation as a “major item squarely on our punch list [at CMS].”
“The stakes for this program are high,” he told the audience. “As any physician will tell you, physician burden and frustration levels are real. Programs that are designed to improve often distract. Done poorly, measures are divorced from how physicians practice and add to the cynicism that the people who build these programs just don’t get it.”

CMS Gave No Warning MU Was Ending

Given the content of Slavitt’s announcement, reaction to his statements about the impending end to the Meaningful Use program as it now exists caused a big stir among healthcare executives tasked with handling information technologies at their hospitals or physician practices.

Apparently officials at CMS noticed the reaction generated by Slavitt’s presentation at the J.P. Morgan 34th Annual Healthcare Conference. About one week later, a blog post titled, “EHR Incentive Programs: Where We Go Next” was published by CMS on its website. The blog’s authors were Andy Slavitt and Karen DeSalvo, the National Coordinator at CMS. It was a message to the healthcare industry that, in fact, Meaningful Use was to continue. What was changing was that Meaningful Use—the measurement of certified EHR technology by providers—would be managed by CMS in a manner that is consistent with the requirements of the Medicare Access and CHIP Reauthorization Act (MACRA) that Congress passed in 2015.

In a related story about CMS’ new direction for Meaningful Use titled, “CMS, ONC: Transition to MACRA Will Not Mean the Elimination of MU, EHR Incentives,” FierceEMR wrote, “The Meaningful Use incentive program is transitioning, but it’s not over, and electronic health record incentives are here to stay, the Centers for Medicare & Medicaid Services and the Office of the National Coordinator for Health IT clarified on Tuesday [January 19, 2015].”

In their blog comments, Slavitt and DeSalvo also emphasized that CMS is bound, under current law, to continue forward with measuring provider use of EHRs, as required by the Meaningful Use rules. They noted that Stage Three MU would continue. Meanwhile, the agency is moving forward to implement the requirements of MACRA, they said.

Further, the CMS officials noted that the agency had heard the comments and complaints by hospitals and physicians about the burdensome aspect of using EHRs and attempting to comply with the Stage Three Meaningful Use requirements. They wrote, “The approach to meaningful use under MACRA won’t happen overnight. Our goal in communicating our principles now is to give everyone time to plan for what’s next and to continue to give us input. We encourage you to look for the MACRA regulations this year; in the meantime, our existing regulations—including meaningful use stage three—are still in effect.”

Source(s): Andrea Downing Peck http://www.darkdaily.com, www.cms.com

For more information on this and other healthcare compliance topics related to HIPAA, OSHA, Medicare and HR, simply email your questions to support@hcsiinc.com
visit our website at http://www.hcsiinc.com or post a question on our LinkedIn group at: http://bit.ly/1FWmtq6


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, October 15, 2015

Meaningful Use program for 2015-2017 and implementing Stage 3

CMS Unveils Final Meaningful Use Rule
The Centers for Medicare and Medicaid Services and the Office of the National Coordinator for Health Information Technology have issued the long-awaited final rules changing the requirements of the Meaningful Use program for 2015-2017 and implementing Stage 3 of the program.

The rules “shift the paradigm so health IT becomes a tool for care improvement, not an end in itself,” according to the October 6 announcement. The rule eases the reporting burdens, simplifies requirements, adds flexibility, supports interoperability and improves outcomes. It also transitions to a new and more responsive regulatory framework based on the Medicare Access and CHIP Reauthorization Act (MACRA), which essentially moves physicians out of the Meaningful Use program into a new Merit-based Incentive Payment System (MIPS).  
Some of the changes include:
        Providers and state Medicaid agencies will now have until Jan. 1, 2018, to prepare for and comply with the next set of system improvements;
        Stage 3 will now be optional in 2017;
        Stage 3 will have eight objectives, with more than 60 percent requiring interoperability;
        Public health reporting will have flexibility options;
        APIs will be required;
        Cybersecurity requirements have been strengthened; and
        The reporting period for 2015 will be only 90 days for all providers, for new providers in 2016 and 2017 and for any provider moving to Stage 3 of the program in 2017
HHS had received more than 2,500 comments on the proposed rules.
Addressing concerns that the rule is coming out too late for providers to report in 2015, Patrick Conway M.D., acting principal deputy administrator and chief medical officer at CMS, pointed out that the deadlines could be extended and that providers can apply for hardship exemptions.
The rules also do not delay Stage 3, although many stakeholders have been asking that Stage 3 be “paused” and reevaluated. Conway indicated in a media call that a 60-day comment period will “get us to a similar place.” He also pointed out that HHS had to combine the alteration and Stage 3 rules; using a comment period is just a different mechanism to do so.
CMS will accept comments on the EHR Incentive Programs final rule for 60 days after it appears in the Federal Register, which is expected on October 16. The feedback will help shape future EHR rulemaking and will also be considered as CMS works to develop rulemaking around MACRA, which was passed by Congress earlier this year to replace the sustainable growth rate. Additional information about MACRA is expected in spring 2016.
A fact sheet on the new rule can be found here on the CMS website.

For more information on this and other topics related to HIPAA, OSHA, Medicare and HR, please emailsupport@hcsiinc.com or visit our website at http://www.hcsiinc.com
Become a member of our LinkedIn group at: http://bit.ly/1FWmtq6