Friday, May 20, 2016

New Overtime Rule and You

New overtime rule could very likely affect your job directly or even indirectly

The United States Department of Labor has released the final rule on changes being made to overtime pay. This rule will be effective December 1, 2016.

Previous Rule:

If you were considered an exempt employee and got paid an annual salary of at least $23,660, you were not eligible for overtime pay if you worked more than 40 hours in a work week.

New Rule:

If you are considered an exempt employee and get paid an annual salary below $47,476 and above $23,660, you could now be eligible for overtime pay if you work more than 40 hours in a work week.

Options for the Employer:

Employers could respond to this new overtime rule in a variety of ways:
  1. Employers could begin paying overtime pay to the employees who now fit the new criteria. This could lead to a raise in cost of the organizations products/services.
  2. Employers could raise salaried employees pay to the new minimum of $47,476. This could lead to a raise in cost of the organizations products/services.
  3. Employers could reclassify the exempt salaried positions to full-time hourly positions. This would limit the ability of employee being able to work additional hours to accomplish their assigned duties.
  4. Employers could eliminate the affected positions that would otherwise be considered eligible for overtime pay. This would require the employer to redistribute those job duties to other employees within the organization.
  5. Employers could eliminate the affected positions and replace each of those positions with two part-time employee positions. This would also enable the organization to save on paying full-time benefits.
In order for a worker to be exempt from overtime, they must meet the criteria. For example, performing "executive" duties means supervising the work of two or more employees and "administrative" duties requires the exercise of discretion and independent judgment. For more information, please review the Department of Labors fact sheet on overtime exemption.

If you feel that you work in a position that could fall under these new overtime rules, please consult your Human Resource department or immediate supervisor. As always, be sure to review your state specific overtime rules.

These new overtime rules will have effect an estimated 4.5 million workers and have a residual effect on their co-workers and products/services.

Here is the new overtime rule as stated by the Department of Labor:
Key Provisions of the Final Rule
The Final Rule focuses primarily on updating the salary and compensation levels needed for Executive, Administrative and Professional workers to be exempt. Specifically, the Final Rule:
1.    Sets the standard salary level at the 40th percentile of earnings of full-time salaried workers in the lowest-wage Census Region, currently the South ($913 per week; $47,476 annually for a full-year worker);
2.    Sets the total annual compensation requirement for highly compensated employees (HCE) subject to a minimal duties test to the annual equivalent of the 90th percentile of full-time salaried workers nationally ($134,004); and
3.    Establishes a mechanism for automatically updating the salary and compensation levels every three years to maintain the levels at the above percentiles and to ensure that they continue to provide useful and effective tests for exemption.
Additionally, the Final Rule amends the salary basis test to allow employers to use nondiscretionary bonuses and incentive payments (including commissions) to satisfy up to 10 percent of the new standard salary level.
The effective date of the final rule is December 1, 2016. The initial increases to the standard salary level (from $455 to $913 per week) and HCE total annual compensation requirement (from $100,000 to $134,004 per year) will be effective on that date. Future automatic updates to those thresholds will occur every three years, beginning on January 1, 2020.






To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, May 13, 2016

Employee Breaks and Your Business

Breaks are important to your employees, but those breaks have an effect on your business.


Alice has been helping customers for nearly four hours straight. She gets into an argument with a customer. That argument escalates quickly and a supervisor then gets involved. Things are deescalated, the customer leaves angry, and Alice gets a tongue lashing from her supervisor.

The situation described above has been played out many times in many businesses. Ask yourself this question:

Who's at fault for the above situation?

Everyone will have his or her answer based on their own personal experiences and practices. My answer is simple; it is the supervisor's fault. People are human and they need to be recognized as such. Alice should have not been helping customers for nearly four hours without a break. Despise all of the training provided, it was the fault of the supervisor for not treating Alice as a human that lead to this situation.

Let's take a moment and see how employee breaks effect the business and the employees:

Effects of Breaks on Business
Employees are only productive when they are working. When employees are productive, business is able to get done. When an employee is on break, they are not being productive, but they are still getting paid (outside of a unpaid lunch break).

Effects of Breaks on Employees
When an employee goes on break, they are able to "wind down" and decompress. They take a few minutes to relax and socialize, read, get some refreshment, or step away. This helps employees feel rejuvenated and refreshed. Breaks are just as much mental as they are physical.

State laws vary with this issue. For example, one State says that an employer must give its employee a 10 minute break every four hours and a 30 minute lunch break if working more than six hours. Typical employment law does not take into account the various industries, the type of work being done, and the mental/physical stress on employees.

Perplexing Facts
  • Businesses want employees to be highly productive for the maximum time possible.
  • Most employees want to be highly productive and do quality work. If a business has employees that don't meet this criteria, then they should find ones who do.
  • Employees are humans and humans need time to re-energize, refocus, regroup, and refresh.
  • Employees who are given shorter periods of time to work between breaks are typically more productive, effective, energized, and focused. They tend to be highly productive.
  • Giving employees the opportunity to be highly productive and appreciating them as humans, will improve morale and decrease turnover. This saves the business money.
In order for businesses to achieve a high level of productivity from its employees and for employees to produce at a high level with high quality work, here is my recommendation:
  • Employees get a 10 minute break every 2 hours
  • Employees who work 8 hours should get a 30 minute unpaid lunch break every four hours
  • Employees who work six hours get one 10 minute break after two hours worked and another 20 minute food break after their next two hours
You should always check with local state laws before creating a break policy. In addition, some flexibility should be considered based on industry and type of work.

If a business treats their employees well, then it is more likely that those employees will treat the customers well!



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Am I a Good Compliance Officer?

 HCSI
What Does It Take To Be A Good Compliance Officer?

What makes a good Compliance Officer?  It’s a question every hiring manager, General Counsel and Board must consider when faced with the need or opportunity to bring that critical person into the business. 
The compliance profession is still in its infancy.  A couple of decades ago it started in the United States in the financial services and health care sectors, growing out of legal and audit and into its own role.  As the UK Bribery Act came into force and more multi-national organizations were stung with fines for failing to comply with all sorts of laws, companies began to hire compliance officers in order address the ever-increasing legal and regulatory expectations placed on them from all angles.  As compliance departments grow throughout Europe, Asia and South America, businesses must evaluate who to hire and how to determine what makes a good compliance officer.

What are the primary roles a compliance officer must undertake?

In many businesses, compliance is in charge of both compliance and ethics.  Compliance tends to deal with the policies and procedures that are put in place in order for the business to ensure compliance with the law.  Ethics revolves around doing the right thing, corporate values and training people to behave in a way that creates a culture of compliance.  While some organizations, particularly in financial services, separate the ethics and compliance elements, for most businesses compliance and ethics go hand-in-hand in one role. 

Compliance Officers are generally charged with three tasks: awareness, advice and reporting.  The Compliance Officer creates the compliance program and ensures that people throughout the organization are aware of it, which includes ensuring understanding of the law, rules and procedures enforced by the company.  Compliance Officers must also be able to advise on legal and compliant ways of conducting business, and then report to the business about program implementation and specific issues requiring resources or response.

What skills does a Compliance Officer need to have?

The most important thing a Compliance Officer needs is a deep understanding of the business.  Without a desire to know the business, the Compliance Officer will not be able to give helpful solutions to problems. 

Communication skills are also vital for a Compliance Officer.  Most Compliance Officers perform training or give updates to the employee population, managers or Board, so clear, compelling communication is essential.  Compliance Officers also need to be terrific listeners so that they can hear and understand the pressure points between the business and the law.  Compliance Officers must be persuasive and able to influence the business, especially when the procedures or policies may be unpopular or difficult but necessary. 

Lastly, Compliance Officers need to be skilled at designing simple and understandable procedures in order to mitigate the risks identified by the business.

How important is independence for a Compliance Officer?

Capacity for independent thought is crucial, as is a strong moral compass.  Although it is very important that the Compliance Officer be able to get along well with others in the business, there will invariably be times when the Compliance Officer must stand up for what is right, and not what is popular.  Ideally the Compliance Officer will have a direct reporting line to the Board and C-suite, so that any highly-contentious issue is dealt with at the highest levels of the business without the dilution of another function speaking for Compliance.  There is a strong trend right now in Financial Services and in U.S. enforcement actions to demand that the Compliance Department function outside the Legal Department.  This trend is likely to continue and is likely to become best practice throughout the world.

What else can a Compliance Officer do to be effective?

The best Compliance Officers are those who can embrace change.  The regulatory environment is an ever-evolving one, and just when a Compliance Officer thinks that the program is perfect, another law will come into force or an enforcement action will require the program to shift.  Compliance Officers need to be naturally curious with a can-do attitude.  If a Compliance Officer learns to say “no” effectively to the business using empathy and giving an explanation, it will go a long way toward building the trust that is critical for the Compliance Officer to maintain with management.

What role does enthusiasm or charisma play in becoming a good compliance officer?

Ideally Compliance Officers come to the job with a belief that what they are doing is important, valuable and helpful to the business.  It’s been said that the Compliance Department’s job is to protect the business in five years.  Therefore, short-term sales goals and actions which may create reputational risk must be eschewed in favour of long-term thinking about what is going to make the business sustainable and profitable in the future.  Compliance Officers who maintain a sense of mission, justice and proportionality will be successful.  A sense of purpose, enthusiasm for the job and natural charisma will draw people within the business to listen to the Compliance Officer, which can be helpful.

The definition of what makes a “good” Compliance Officer different when the person is working in a multi-national business?

Compliance roles inevitably become more complex when the business is multi-national.  Not only does the Compliance Officer have to manage differing, and sometimes competing laws, but there will also be questions of language and culture that can make the job more difficult.  Compliance Officers working in multi-national environments need to be incredibly attuned to the cultural differences within the countries in which their business operates.  A strong desire to learn about the other cultures will make a big difference.  People tend to listen to people who listen to them.  A good Compliance Officer in a multi-national company will be one who is aware that everyone comes with a set of expectations created by their culture of origin, and that listening and being aware is critical to the success of the compliance program in a multi-national environment.

What’s the number one way to determine whether or not you are, or have hired, a good Compliance Officer?

You know you are a good Compliance Officer if members of the business frequently come to you to proactively seek your advice.  If you’re providing smart, helpful counsel and engaging with them so that they trust you, then you are likely doing your job effectively.



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, May 4, 2016

Do You Understand The HIPAA Security Risk Management Process?

Risk Analysis Requirements Under The Security Rule
HCSI
The HIPAA Security Rule requires that covered entities (your practice) conduct a Security Risk Analysis/Assessment for your organization, at minimum, once per year. It is critical that practices perform the Security Risk Analysis for several reasons. Not only is it important to comply with HIPAA, Health and Human Services (HHS) and Office of Civil Rights' (OCR) rules and regulations, but also for what you should consider to be a more motivational reason, to protect your practice (and bank account) from what could become debilitating fines and penalties.

The Security Management Process standard in the Security Rule requires each organization to “implement policies and procedures to prevent, detect, contain, and correct security violations.” (45 C.F.R. § 164.308(a)(1).), that apply to their particular practice. Risk Analysis is one of four required implementation specifications that provide instructions to implement the Security Management Process standard. This article will cover the Risk Analysis implementation specification of that standard. Section 164.308(a)(1)(ii)(A) states:
RISK ANALYSIS (Required). 

Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the organization. (Each organization must evaluate for itself the most appropriate answers to the questions contained in your own Risk Analysis.) From the information gained while conduction your Risk Analysis you should prepare a Security Risk Action Plan documenting your findings, your conclusions and plans to address risk issues.

This Action Plan should identify the current state of your practice from 3 areas: Environmental, Facility and Hardware/Software controls, [aka human, natural, and environmental threats].  It should also correlate issues from high to low risk and prescribe plans of action to address these issues in priority as deemed necessary.  Document your plans based on those risk analysis findings and your practice's available resources to best approach the reduction of your higher risk level issues and document your best practice policies and procedures going forward to mitigate damage, disruption or loss of Protected Health Information (PHI). The Security Rule requires the Risk Analysis to be documented but does not require a specific format. (See 45 C.F.R. § 164.316(b)(1).) The Risk Analysis documentation is a direct input to your Risk Action Plan and overall Risk Management Process.
The following questions are examples that your organization could consider as part of a risk analysis. These sample questions are not prescriptive and merely identify issues an organization may wish to consider in implementing the Security Rule:

1. Have you identified the e-PHI within your organization? This includes e-PHI that you create, receive, maintain or transmit.
2. What are the external sources of e-PHI? For example, do vendors or consultants create, receive, maintain or transmit your e-PHI?
3. What are the human, natural, and environmental threats to information systems that contain e-PHI?

In addition to an express requirement to conduct a Risk Analysis, the Rule indicates that a Risk Analysis is a necessary tool in reaching substantial compliance with many other standards and implementation specifications. For example, the Rule contains several implementation specifications that are labeled “addressable” rather than “required.” (68 FR 8334, 8336 (Feb. 20, 2003).) An addressable implementation specification is not optional; rather, if an organization determines that the implementation specification is not reasonable and appropriate the organization must document why it is not reasonable and appropriate and adopt an equivalent measure if it is reasonable and appropriate to do so. (See 68 FR 8334, 8336 (Feb. 20, 2003); 45 C.F.R. § 164.306(d)(3).)   

The OCR in recent months has acknowledged that providers are not making compliance implementation a priority to their practices. Thus, the increased risk of unauthorized access, use, and disclosure of protected (yet quite vulnerable) PHI is still a factor. Not to mention the risk of practices not appropriately implementing other critical areas of compliance, which also pose significant vulnerability to practices as well as the heightened risk of significant fines and penalties. While this information only briefly describes the risk to your practice, providers, workforce, and patients, the message to take away here is that the Office of Civil Rights means business - so much, in fact, that it was decided that the best and only way to make sure that practices understand the significance of compliance is for OCR (along with governing entities such as HIPAA, and others) to increase efforts of enforcement.

There is no such thing as "under the radar" or "off the grid" for practicing providers today. One component of enforcement is in HIPAA Security. It's a priority for HIPAA to ensure that potentially patient identifying and vulnerable information is secure. And rightfully so, when you consider the risk of potential identity theft, medical identity theft, and other dangers posed to patients due to the amount and types of information that health care providers have on each patient. Not to mention, the difficulty in finding the source of and stopping the effects of identity theft or medical identity theft, should that occur (which it does, all too often).
 
Organizations should use the information gleaned from their Risk Analysis as they, for example:
  1. Design appropriate personnel screening processes. (45 C.F.R. § 164.308(a)(3)(ii)(B).) 
  2. Identify what data to backup and how. (45 C.F.R. § 164.308(a)(7)(ii)(A).) 
  3. Decide whether and how to use encryption. (45 C.F.R. §§ 164.312(a)(2)(iv) and (e)(2)(ii).) 
  4. Address what data must be authenticated in particular situations to protect data integrity. (45 C.F.R. § 164.312(c)(2).)
  5. Determine the appropriate manner of protecting health information transmissions. (45 C.F.R. § 164.312(e)(1).)
Though there are other components of compliance, the Security Risk Analysis is one very essential component to compliance, and for many reasons. The Security Risk Assessment shows your practice's good faith effort in establishing and maintaining appropriate policies and procedures that meet guidelines and minimize risk to your practice, patients and their protected information. The Security Risk Analysis is required as a way for practices to show ongoing monitoring of critical business systems.

Enforcement of this area is at an all time high and will continue to gain steam. The best thing practices can do is to be proactive and show initiative. Also, note that the Security Risk Analysis/Assessment is also required for Meaningful Use attestation. Practices that are found to have received incentive payments through Meaningful Use but have not appropriately conducted a Security Risk Analysis/Assessment per attestation requirements are having to refund all of the incentive payments received as well as run the very high risk of more in depth investigations and other potential penalties.

Risk Analysis is the first step in an organization’s Security Rule compliance efforts. Risk analysis is an ongoing process that should provide the organization with a detailed understanding of the risks to the confidentiality, integrity, and availability of e-PHI. The outcome of the risk analysis process is a critical factor in assessing whether a required implementation specification or an equivalent measure is reasonable and appropriate. 



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, April 27, 2016

OSHA & CDC Issue Zika Virus Guidance for Healthcare Workers

 Healthcare Compliance Solutions Inc.
To combat the spread of the Zika virus through occupational exposure, the Occupational Safety and Health Administration (OSHA) and the Centers for Disease Control and Prevention (CDC) have issued interim guidelines to protect healthcare workers.
Current evidence suggests that 1 in 5 people with the Zika virus infection develop symptoms. If present, mild symptoms begin 2 to 7 days after receiving a mosquito bite, and can include fever, rash, joint pain, red or pink eyes, myalgia, and headache; typically, symptoms can last for 1 week. During the first week of infection, Zika virus can be spread from an infected person to a mosquito via a mosquito bite. Additional transmission may occur through direct contact with blood or other bodily fluids of an infected individual.

“Employers and workers in healthcare settings and laboratories should follow good infection control and biosafety practices as appropriate, to prevent or minimize the risk of transmission of infectious agents,” the guidelines stated.

Employers and employees should meet OSHA’s bloodborne pathogen (BBP) standard, and laboratories should ensure that their facilities and practices meet the appropriate Biosafety Level (BSL) for the work being conducted.

“[The] CDC recommends healthcare workers use standard precautions during patient care regardless of suspected or confirmed Zika infection status,” according to the report.

The following are some additional suggestions for protecting healthcare employees from Zika virus:

● Wash with soap and water, using alcohol-based hand rubs of at least 60% alcohol content.

● Wash hands before and after contact with patients or potentially infectious material.

● Wash hands before and after putting on or removing personal protective equipment (PPE).

● Do not bend, recap, or removed contaminated needles or sharps.

● Properly disposed of contaminated needles or sharps in closable, leak-proof, puncture-resistant, labeled or color-coded containers.

● Use sharps only with sharps engineered injury protection (SESIP) to avoid sharps-related injuries.

● Report all needlesticks, lacerations, and exposures to supervisors as soon as possible.

If an employee becomes infected, the CDC recommends that infected individuals rest, drink fluids, and take acetaminophen for fever and pain reduction. Infected persons should avoid further mosquito bites by covering skin and using an insect repellent containing DEET.

Employers should ensure that workers receive prompt and appropriate medical care for suspected Zika infection. If the exposure falls under OSHA’s BBP standard, employers must comply with OSHA medical evaluation and follow-up requirements. Also employers should consider options for granting sick leave during the active period of infection.

Further information regarding the guidance can be found here.


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, April 22, 2016

Don’t Let Rude Staff Ruin Your Patients’ Experience

"Too many healthcare workers learn their customer service skills from the "University of the Abrupt" that offers a major in brusque with a minor in terse”

Something is seriously wrong when a patient is made to feel like a recruit in military basic training being shouted at by a drill sergeant, writes George Korda, a Knoxville News Sentinel columnist. That was his feeling after an encounter during a recent doctor’s visit with the office receptionist who yelled out his name despite the fact he was the only person in the waiting room.
Korda recalled his first visit at another doctor’s office where he was greeted with a command from the young woman behind the desk. “Last name,” she said, without a smile or a please.
“Healthcare workers have a tough job, and a good many work at being kind as well as professional. Nevertheless, some don’t,” he writes. “Courtesy and respect in the process, though costing nothing, are a significant investment in the bank of good will.”
Physicians who want to see good patient satisfaction scores need to ensure that they and their staff don’t treat patients rudely, Korda says. Here are some tips on creating a better experience for patients in your practice:
        Recognize and celebrate team members who provide especially compassionate care
        Hire compassionate employees and provide empathy training to current staff
        Give doctors in the practice feedback from their patients on a quarterly basis to help them improve their bedside manner

Prioritize the needs of employees by offering mindfulness training programs, expressive therapy and weekly wellness conferences.



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, April 19, 2016

Afraid of Improving Your Employees

Are you afraid of improving your employees skills out of fear that they might leave?

The above question is one that has been pondered by many organizations. Some organizations have minimized training all together in order to keep their employees skill sets limited and thus minimizing their potential to leave for greener pastures. While other organizations have maximized training and the development of their employees while understanding the risks.

This is a discussion that needs to be had within every organization. What is the correct answer? There are four key points that will help any organization formulate the answer for their own situation.

Not All Employees Are the Same

When an employee is hired, nobody knows that employees true potential. When additional responsibilities are given to that employee, an organization is able to begin to see what the employee can offer. When an employee develops new skills through training and professional development, an employer is able to observe the true character and potential of that employee. When some employees are given new skills, they rise to the challenge and embrace the exciting change. These employees are looking to utilize their new found skills. While other employees who are given new skills do nothing with them and go right back to where they were before the new skills were learned. Giving employees new skills is an opportunity for an organization to identify employees with potential and possible future leaders. Not all employees will react to receiving new skills the same way. In regards to their potential, each employee is an individual and should be treated as such.

Resources or Cogs?

Every organization has a different mindset when it comes to their employees. Neither mindset is good or bad. Each mindset is derived from the business goals of the organization.
  • Resource - Your employees are the greatest resource within the organization. Identifying, guiding, and developing employees with great potential and placing those employees into the areas of the organization where they can have the biggest impact. This is a process that takes time and some serious investment from the organization. As a resource to the organization, employees are developed and given new skills. Once those new skills are fully utilized, then that employee becomes more valuable to the organization.
  • Cog - Your employees have been hired to do a job and it is expect that they will do that job well. Minimal amount of training or investment will be made by the organization as the employee only needs to know what is required for their particular job. Each employee is a cog working within a larger machine. If that cog is no longer effective and productive, then it will be quickly replaced by a new cog. All cogs are replaceable and are expected to burnout after a given amount of time.
Some people may object to employees being treated as a cog in a machine while others may object to investing too much into an expendable resource. As stated earlier, neither mindset is good or bad, but rather how a particular business operates.

Employee Value

Jack has just completed a week long training course. He is excited to begin implementing what he has learned into his job. There is a lack of enthusiasm from his supervisor about Jack's newly acquired skills. Nevertheless, Jack begins utilizing his newly learned skills and sees an increase in his productivity. Jack's confidence grows as he becomes a bigger contributor to the organization. However, as time passes, nothing changes with his job, responsibilities and perceived value. His supervisor did not appear to value the additional training Jack received nor the increased value of Jack himself. By this point, Jack has begun to feel frustrated and under valued. He got hired at a different company where Jack feels they value his skills, talents, and true value. After receiving Jack's two-week-notice, Jack's supervisor says to him, "I don't understand what happened. I thought everything was going as it always has." Jack then turned and said to his supervisor, "if that is what you think, then you don't know me."

When an employee receives training that adds to their professional skill set, they perceive that they become more valuable to the organization. If the organization sees that the added skill set did indeed make the employee more valuable, then that perceived value has become a reality and must be recognized. Recognition could come in many forms, including, but not limited to, increased responsibility of a leadership nature, monetary bonus, raise in salary, or a promotion. If the employee perceives their increased value, but the organization does not, then that employee-employer relationship will sour quickly and the employee will look for value validation elsewhere.

Succession Plan

What are your organizations future plans for leadership roles? Will those roles be filled with new employees outside of the organization or will those future roles be filled by developing talent within the organization? If an organization plans on filling future leadership roles with in-house talent, then giving employees new skills and knowledge is a critical component. As stated earlier, when you give employees new skills and knowledge through training and professional development, the true character and potential of that employee begins to surface. Once those potential future leaders are identified, then they must be valued and placed on a track of continued development. An organization's in-house talent will already have an understanding of your organization's culture and will be an example to other employees. There is a risk to developing in-house talent as some of that talent the organization has invested in will leave for another opportunity elsewhere. Should an organization only develop in-house talent? No, this tends to create group think and does not lead to new ideas or a fresh approach. It is important to fill some of the leadership roles with outside talent.

Conclusion

Deciding weather to give employees professional development and add to their skill set is a business decision that needs to be made by every organization. This decision should be based on the organizations' business goals and expected outcomes. There is no right or wrong answer to this question. Take a moment to think about this and ask yourself, "am I afraid of improving my employees?"




To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, April 8, 2016

Being Clear on Healthcare Social Media Policies

 Healthcare Compliance Solutions INC.
Define Your Social Media Policies Now To Reduce Future Issues

Love it or hate it, social media is a fact of life. It can be a great means for medical practices to raise awareness, educate, and engage patients.
However, it's also easy to find stories about social media gone wrong in healthcare. Many of these involve HIPAA violations by staff who don't understand the inherent lack of privacy in social media posts. ProPublica, an investigative news organization, recently reported on more than 30 incidents where staff inappropriately shared images and other patient information over social media networks.

In light of the horror stories, there is a temptation for practices to construct a "defensive" policy focused solely on restricting staff use of social media; essentially "What you don't say can't hurt us." Instead, you should seek a balance that not only protects patient privacy and discourages public relations gaffes, but also allows those who know your practice best — its staff — to show pride in their work and promote it. Designing a good social media policy for your practice can tip that balance to the positive.

Here are some ways to help you get there:

1. Keep it simple. Staff will view a policy that is too long and tries to cover everything negatively — if it's read at all. Further, because social media is constantly evolving, too much specificity will virtually guarantee your policy will quickly become obsolete.

2. Be clear about your goals. To provide context for your social media policy, put the focus on what you are trying to accomplish. These goals may be things such as maintaining patient confidentiality, compliance with applicable laws and regulations, protecting the practice from negative outcomes, enhancing the practice's professional image, and ensuring a productive and focused workplace.

3. Don't reinvent the wheel. There are many easily adaptable, great policies available online. You can find many examples here and can even view policies by professional sector, including healthcare of course.

4. Get beyond the "thou shalt not." See the positive as well as the negative. Don't be so afraid of the worst-case disaster that you stop staff from telling your practice's story. The average adult Facebook user has about 300 friends, meaning that even in a small practice you could easily reach thousands of people with a positive message. Imagine someone saying, "I'd love to tell my Facebook friends about the money we raised at the local charity event, but our social media policy won't allow us to post on work-related topics."

5. Don't just dictate, educate. Beyond the policy itself, staff may need help in thinking through how this all works "in real life." Again, there already are some great resources to give you a running start on this. One example is "A Nurse's Guide to the Use of Social Media." You can offer real examples and scenarios that help your staff understand the repercussions on using social media to represent your practice.
6. Listen and respond to feedback. This allows you to not only hear concerns staff may have, but also get a sense whether they understand your social media policy. Initial staff reaction to a social media policy may not be warm and fuzzy. Most staff will easily understand rules on using practice equipment and network connections for personal use during the workday. However, you may get pushback on "restrictions" outside of work time. Point out that HIPAA violations hurt patients — and they can have negative legal consequences for not only the practice, but also the individual staff member. Be upfront and explain that your policy covers both staff social media activity at work and off the clock. Respond to any concerns by communicating the practice's expectations of staff professionalism, both on and off the clock.

7. Back it up. Enforcement and sanctions may be unpleasant, but they are an absolute necessity. Having a policy but not enforcing it may be worse than no policy at all, since this sends staff the message that you're not serious. It also can create liability for the practice if you have a policy in place and make no effort to ensure that it is followed. Your medical practice's sanctions for policy violations — especially those involving HIPAA — should be documented and consistently applied to all staff.

If you are successful, your social media policy and staff education efforts will offer bright-line guidance prohibiting illegal or unethical activity, while also encouraging staff to share their successes at your practice. That is a win-win for patients, the practice, and staff.

Source(s): Stephen McCallisterhttp://www.physicianspractice.com, www.hcsiinc.com

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, April 1, 2016

An Effective Termination Procedure Will Protect Your Organization

Help protect your  office from potential liability by having a written termination procedure as part of your office policies and procedures.


Two facts of employment: people get hired and people get fired (or resign).

Few supervisors and managers savor the idea of being good at firing people. Nevertheless, you need to know how to terminate employees in a way that preserves their dignity while meeting your organization's needs. Even the most experienced managers will experience stress and anxiety when they go through the termination process. Having a clear idea of the process won’t make it any more pleasant, but could prevent you from making costly mistakes.

The key to a "successful termination" begins with hiring and continues throughout the employer/employee relationship. Performance Reviews also play a critical role in a "successful termination". But the actual process of termination is what stays in everyone’s mind the longest time. Remember that a termination impacts everyone.

Outline of the Termination Process
  • An employee’s manager or direct supervisor should call and conduct the termination meeting. Hold the meeting in a private location other than the employee’s normal work area to limit any embarrassment the employee may experience. Information to be covered in the meeting follows.
  • Notify the employee how and why he or she is no longer working at the company. Tell the truth, such as facts about an employee’s poor performance, regardless of how uncomfortable it is. However, never make remarks about an employee’s personal character.
  • Inform the employee that the decision is final and when the termination will be effective. (For example, immediately as is common with termination for poor performance or at sometime in the future as is common with a layoff due to reduction in workforce.)
  • Let the employee know what benefits (unemployment, health insurance, severance pay, etc.) are available. State laws typically govern how and when final pay and vacation pay is handled.
  • Give the employee a written termination notice. Send a written termination notice—by certified mail—to an employee that is being terminated because he or she has failed to come to work as required.
  • If you are concerned that an employee may become violent or take legal action, you might consider preparing a statement explaining the termination and read it verbatim to the employee.
  • Consider offering assistance to the employee for finding another job. You might offer company assistance in preparing and mailing resumes, making copies or job search coaching tips.
Following the termination meeting, document it with a written, detailed description of the meeting. Include what the employee was told and what the employee said in the notes.

How to Fire an Employee Checklist
  • Decide exactly, and succinctly, why you want to fire the employee.
  • Compare your reasons for wanting to fire the employee with the job descriptions for that employee’s position. Does at least one of your reasons include that the employee is actually not doing the job properly?
  • If you have specific procedures for termination of an employee, follow those procedures.
  • If the employee is working pursuant to a contract, you must comply with the terms of the contract having to do with termination; otherwise you may be in breach of contract.
  • Be sure to tell employees why they are being fired and give them these reasons in writing. (This can be mailed to them later if more convenient.)
  • After you tell employees why they are being fired, allow them to tell you any defenses or other responses they have to your reasons for termination. IT just may be that you are making a terrible mistake, or the employee may confirm your decision to fire them
  • Make sure employees’ files include a copy of the written reasons you gave the employees for their firing. Also, make a note in the file of any comments or defenses employees made in response to being fired.
  • Be sure all wages, benefits, property, or other things belonging to the employee, or to which the employee is entitled, are given to the employee.
  • At all stages of the termination process, from deciding to do so until the employee files is closed for good, treat the employee with common respect and courtesy.
  • Never, ever do anything to humiliate the employee. Simply being fired is humiliation enough for an employee.
  • Firing an employee is not a pleasant thing. However, being sure of your decision, following proper procedures, and keeping objective records of the decision and the event can put you in the best position possible in case the employee later makes accusations against you, or even if they sue you.
Final Mental Checklist:

  • Plan what you are going to say
  • Be calm
  • Be humane
  • Avoid surprises
  • Have a strong paper trail
  • Write a letter of termination to the employee
  • Change the employee’s computer password and eliminate all of their IT access (don't forget email group lists)
  • During the termination meeting, make notes of what was said and exchanged
Related articles:




To subscribe to this blog, enter your email address:


Delivered by FeedBurner