Thursday, November 5, 2015

HIPAA Workforce Security

HIPAA policies and procedures ensure all employees have appropriate ePHI access


Security Rule Language: Implement policies and procedures to ensure all members of its workforce have appropriate access to electronic protected health information (ePHI), as provided under paragraph (a) (4) of this section, and to prevent those workforce members who do not have access under paragraph (a) (4) of this section from obtaining access to electronic protected health information.”
45 CFR 164.308 (a)(3)(i)

The Workforce Security standard requires that you implement policies and procedures to ensure that all members of your workforce have appropriate access to ePHI and to prevent those workforce members who do not have access from obtaining access to ePHI. The type and extent of access to your information systems containing ePHI must be based on your Risk Analysis. Your Risk Analysis must consider the following factors:

• The importance of the applications running on the information system
• The value or sensitivity of the ePHI on the information system
• The extent to which the information system is connected to other information systems

Access to your information systems containing ePHI must be authorized only for your properly trained workforce members having a legitimate need for specific information in order to accomplish job responsibilities. All such access must be defined and documented. Such access must be regularly reviewed and revised as necessary.

Access to your information systems containing ePHI must be established through a formal, documented process. This process must include:

• Identification and definition of permitted access methods
• Identification and definition of how long access will be granted to user
• Procedure for granting a workforce member an access method (e.g. password or token) or changing an existing access method
• Procedure for managing access rights in networked environment
• Appropriate tracking and logging of actions of authorized workforce members on our information systems containing ePHI.

Your workforce members must not attempt to gain access to your information systems containing ePHI for which they have not been given proper authorization.

Following these policies and procedures will help prevent unauthorized access to ePHI while giving appropriate access to designated employees so that they can do their job.

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Wednesday, November 4, 2015

Employee Engagement Determines the Quality of Patient Care

Improving patient care has always been a healthcare priority, but outcomes are now tied directly to the bottom line.

More and more CMS is taking into account quality care and patient satisfaction measures to determine how much they will reimburse providers.
Interactions between healthcare employees and patients can often determine the patient satisfaction measures that influence this reimbursement. In addition, it’s these interactions that can convert a single visit into a loyal customer relationship or ensure a one-time customer.  If the patient/employee relationship is going to determine a large portion of the financial viability for healthcare organizations, it makes good fiscal sense to find ways of improving the quality of patient care through employee and patient interactions.  Employee engagement may be the single best way to make these improvements.
An HR Solutions case study using nearly 29,000 healthcare employee opinion surveys revealed compelling evidence that employee engagement has a direct tie to patient satisfaction. In the survey, it was determined that:
       85 percent of engaged employees displayed a genuinely caring attitude toward patients, compared to only 38 percent of disengaged employees.
       91 percent of engaged employees recognize their workplace as dedicated to patient care, compared to only 42 percent of disengaged employees.
It’s readily accepted that happy, connected, and supported employees offer diligent patient care. Unfortunately, according to a global workforce study, less than 44 percent of those who work in US healthcare facilities are considered highly engaged.
According to this study, one of the markers of high employee engagement is that employees have clear, measurable goals that allow them to understand how their performance drives success for the organization. However, employees also need clear feedback and guidance to reach those goals. Management can help accomplish these objectives by connecting individual employee goals with organization-wide initiatives, and implementing a recognition program for those that meet and exceed their targets.
Another key element in employee engagement, according to a study by Northwestern University, is communication. When employees feel their suggestions have no value to leadership, they stop offering them and disengage from the organization. This leads to faster turnover and lower work quality. In order to increase employee engagement, management must focus on building up employees through positive feedback and coaching. Employees should be able to assess this feedback, along with their own performance goals, so that they are engaged in the improvement process.
You may not immediately see the results of these engagement activities, but you need to remember the ultimate goal: Improved patient care. Building engagement takes time; it is not a seasonal activity for leadership, management, or HR to tackle and then forget about. Instead, it should be a slow and steady build that draws in more and more employees, and you must implement processes that will maintain your newly engaged culture.

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Tuesday, November 3, 2015

OSHA Means Business Going Forward


OSHA Now Targeting The Health Care and Nursing Care Industries
Here’s more evidence your company needs to stay current on safety training: OSHA fines are heading skyward.  

Since 2010, the number of companies facing total OSHA fines above $100,000 has tripled.

This month, OSHA issued three penalties that topped one-million dollars and levied nearly a dozen citations carrying six-figure fines.

There’s more: Outgoing GOP house speaker John Boehner’s final peace offering – negotiating a compromised budget deal that would extend the debt limit and boost spending – took labor officials by surprise after finding that the agreement included a provision to hike OSHA fines nearly 50% in 2016.

The House approved the bill Oct. 28 and the Senate was scheduled to consider it Oct. 29. The bill includes a provision to adjust OSHA penalties annually based on the inflation rate.

Repeat and willful violations – which carry a maximum of $70,000 in penalties – contributed to the high dollar value of these fines. Machine guarding, lockout/tagout, trenching and fall hazards were among the common citations.

Here’s a sampling of October’s enforcement activities:
  • Regulators hit a Nebraska cleaning company with 30 citations and $963,000 in fines after a railcar exploded, killing two employees and injuring a third. OSHA said the company sent the workers to clean a tanker car filled with dangerous fumes despite warnings that the air quality inside the car showed a high risk of explosion.
  • Troubled Midwest furniture giant Ashley Furniture – already facing $1.7 million in OSHA fines from an inspection earlier this year – was hit for lockout/tagout hazards carrying $431,000 in penalties. In February, OSHA leveled 38 violations after inspectors discovered there were more than 1,000-work-related injuries at the plant over a 3 1/2 year period.
  • An Ohio chicken processing facility found itself facing $414,000 in fines after two workers were maimed while attempting to clean unguarded machines. Penalties levied against Case Farms now total over $1.4 million.
  • A commercial laundry company was hit with $305,300 in fines for repeatedly exposing workers to machine hazards. Three years ago, a 24-year old worker was killed when he was crushed by a conveyor belt.
  • osha finesOSHA orders pilot to be reinstated after being fired for refusing to fly unsafe medical transport helicopter
    A pilot working for Air Methods Corp. was illegally terminated for refusing to fly a medical transport helicopter with a faulty emergency locator transmitter. Following an investigation, OSHA ordered the company reinstate the pilot, pay $166,000 in back wages and damages and remove disciplinary information from the pilot’s personnel record. The company must also provide whistleblower rights information to all employees.
The Occupational Safety and Health Administration (“OSHA”) recently intensified its scrutiny of the health care and nursing care industries. On June 25, 2015, the agency announced a new enforcement initiative targeting inpatient health care and nursing care facilities. But this increased scrutiny of the health care and nursing care industries does not end there—OSHA is spreading its enforcement reach to other types of health care entities.
Recently, OSHA cited LifeFleet LLC, an Ohio medical patient transportation company, for training shortfalls and bloodborne pathogen violations. OSHA alleged multiple violations, including several costly willful violations, and is seeking fines totaling nearly $236,000—a notably large amount. Typically, the fines associated with OSHA citations are very low, unless they are associated with fatalities. There were no fatalities in this case.
In discussing the magnitude of the fines against LifeFleet, OSHA’s Cleveland Area Office Director Howard Eberts said, “Failing to protect workers from pathogens that can cause life-threatening diseases is unacceptable. As a medical service provider, LifeFleet should be setting the standard in employee protection – not ignoring it.”
What does this mean to health care and nursing care employers? OSHA is targeting all health care and nursing care facilities, not just inpatient facilities. The agency is sending a clear message to the health care and nursing care industries in issuing citations carrying unusually heavy fines.
Here are a few action steps that employers can take right now to prepare for an OSHA inspection:
  • Conduct an internal OSHA compliance audit. The cost of conducting an internal audit and addressing hazards before an OSHA inspection is trivial by comparison.
  • Review all health and safety training programs. Ensure that all employees have been thoroughly trained—and have received refresher training, when appropriate—on all aspects of the facility’s health and safety policies and that they can demonstrate that they understood the training. It is advisable to conduct a quiz after each training session in order for employees to demonstrate their comprehension of the training and to keep quiz results and training attendee lists on file.
  • Consult with an OSHA attorney regarding preparations for an OSHA inspection. Most health care and nursing care employers have never experienced an OSHA inspection (LifeFleet, for example, had never been inspected before) and may not be aware of strategies that can be used to minimize work disruption during an inspection and reduce the likelihood of receiving an unwarranted citation.
Sources:  - http://www.cfodailynews.comhttp://www.oshalawupdate.com/, http://www.dol.gov/ 


For more information on this and other healthcare topics related to HIPAA, OSHA, Medicare and HR compliance please email support@hcsiinc.com or visit our website at http://www.hcsiinc.com 
Join our LinkedIn group at: http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Importance of Correct Timekeeping

Know what is happening with your investment

Imagine if you just invested $50,000 into the stock market through a stock broker. When you gave your money to the stock broker, he told you that your money would be taken care of. You then asked him where he planned on investing your money, his response, “don’t worry about it”. Would you be okay with this investment scenario? If you put your hard earned money into the stock market, you want to know where it is going and how it is being spent.

Why would the scenario above be any different than you investing your hard earned money into your employees by paying them for the time? Your investment is the time employees use to help your company grow while getting paid. This is why correct timekeeping is a critical component of any organization.

Here are some of the issues that could occur by having incorrect or insufficient timekeeping:

  • Time Wasted – If you do not have a correct record of how much time your employees are really spending working, then it becomes very difficult to determine the return on your investment. It also becomes more difficult to identify processes that are inefficient.
  • Money Wasted – Every miscalculation in timekeeping records result in lost money for the organization. This will build over time resulting in a small miscalculation becoming a large monetary loss for the organization. To help eliminate these mistakes, it is important to spend a little more time on the timekeeping process.
  • Compliance with Tax Requirements – If your timekeeping records are inaccurate, then so are your tax filing for each of your employees.
  • Quality of Life for both Employee and Employer – Your employees are spending time working at your organization and they expect to be compensated appropriately. At the same time, you want to make sure that your organization is protected against time theft, human efforts, and other potential issues.


By having correct timekeeping processes and records, you help keep employees happy by paying them for the time they have worked and you help ensure that your monetary investment in your employees time is being used for it maximum potential.

For more questions on this topic, please feel free to email me at jhuff@hcsiinc.com

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Thursday, October 29, 2015

Healthcare Pornography?

What is Healthcare Pornography?
We are all human, and as such, are naturally curious. Much like the Porn industry, there is a growing problem caused by the unbridled curiosities of workers within the Healthcare Industry.
Workers are being fired, reputations are being tarnished, and medical practices throughout the United States are being fined. All because curiosity got the best of one or two people.
Fortunately, there are ways to safeguard against this cancerous disease that is plaguing healthcare professionals everywhere. The first step is understand what record snooping is. 

What is Record Snooping?
Record snooping is unauthorized access to a patient’s information. This type of privacy invasion happens when an employee accesses a patient’s health information without cause, but rather for their own personal or somebody else’s desire to have knowledge of that patient's personal health information (PHI).
As you know, protecting the privacy of patient records is top priority as a health care provider, and that means both internally and externally.

Who is Affected by Record Snooping?
Record snooping is an intrusive act that has been done by healthcare workers for a long time. However, with the HIPAA Privacy rules, there are now serious repercussions for the healthcare worker and the office they work for.
The results of record snooping include the employee losing their job, public humiliation for the office involved, heavy monetary fines, and potential legal action. This intrusive act is a big problem for the employee involved and for their employer.
In order to fully understand the varying degrees of record snooping, and how to prevent and develop safeguards against one of the leading causes of fines in 2015, make 30 minutes to learn from others who have been affected: 

          5 Record Snooping Stories Medical Practices That Cannot Be Ignored

                                                   Download Slides: Click Here

About the Author: Lance King works with the team at Healthcare Compliance Solutions, supporting medical practices in adequately preparing for HIPAA, OSHA, Medicare, and HR compliance audits. He is a husband, father, consultant, church and community leader, and athlete.
Upon receiving his Masters in Business Administration, he continued maturing his consultative skills in healthcare because boundary systems are constantly expanding with new developments in technology. His mission is to help practice management do more with less with technology and innovation.
Lance regularly publishes compliance, leadership, and management articles for healthcare practice administration. Find these on LinkedIn.
To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Truth about Employee Referrals


Employee referral programs can be effective, but they must allow for personal accountability.


Tina has been working in her current position for about three years. About six months ago, Tina’s friend Amy was hired into the organization. This hire was based largely on Tina’s referral. Amy was happy to have a job and Tina enjoyed the $100 bonus she received due to the organizational employee referral program. However, things have changed. Amy’s performance is not very impressive and the organization is talking about terminating her employment by the end of the week. In conjunction with Amy’s poor performance, the organization has begun looking at Tina in a different light. Tina’s supervisors have started being more critical of her performance and she is feeling the pressure. Nothing in Tina’s performance has changed for the negative since Amy’s hire, but the perception of Tina has been affected.

Employee referral is an internal recruitment method employed by organizations to identify potential candidates from their existing employees’ social networks. An employee referral program encourages a company's existing employees to select and recruit the suitable candidates from their social networks. Typically, when a new hire is brought into the organization and an employee referral was the source of that hire, then the referring employee would receive some sort of “reward” (monetary, gift card, event tickets, etc.) for that referral. This type of program usually works well as social connections already exist as does a certain level of trust.

  • Documentation – An employee referral program needs to be detailed and in writing.
  • Expectations – It is important that each employee understand the type of person and the character of a person the organization is looking for.
  • Personal Accountability – When somebody is referred and hired into an organization, that organization must hold the newly hired employee and the original employee accountable for their own performance. If the newly hired employee does not perform well, then that cannot be a representation of the original employee. This accountability should begin with the first interview. The referral got the person into the door, but from then on, it is up to the individual to get the job and, if hired, perform well.



There is however, another side of employee referrals that has become an issue in recent years. When a company hires somebody who another employee has referred, far too often, the fate of both employees become intertwined. If the new employee does well, then the organization will look favorable upon the original employee. However, if the newly hired employee’s performance falters, then the organization begins to think differently and more critically about the original employee. This is big reason why people, in general, hesitate referring anybody to their organization. If somebody works in an organization knows of a job opening within that organization, they are most likely going to stay quiet about it. Staying quiet is a lot safer for them and their job status. Rather than risk “rocking-the-boat” the employee will look away as unemployed and talented people around them look for a job.

If you want to have a successful employee referral program, then these are the attributes that must be a part of it:

If your organization has an effective employee referral program, then it will be a valuable tool for you to use when filling open positions. Happy and energetic employees will refer people they know and this could bring in new employees who have wonderful talents and will contribute greatly to the success of your organization.

For more information or questions on this topic, please feel free to email me at jhuff@hcsiinc.com

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Wednesday, October 28, 2015

OSHA Penalties

Types of OSHA Citations and Fines
                                                           
OSHA issues different types of citations, depending on the nature and severity of the violation. Penalties are proposed based on the type of violation.
                                                           
If you’re cited for OSHA violations following an inspection, penalties may vary depending on the type of citation. Note, however, that in settling a penalty, OSHA says it has a policy of reducing penalties for small employers and those acting in good faith.
                                                           
         ●       Willful
A willful violation exists under the OSH Act where an employer has demonstrated either an intentional disregard for the requirements of the Act or a plain indifference to employee safety and health. Penalties range from $5,000 to $70,000 per willful violation. If an employer is convicted of a willful violation of a standard that has resulted in the death of an employee, the offense is punishable by a court-imposed fine or by imprisonment for up to 6 months, or both. A fine of up to $250,000 for an individual, or $500,000 for a corporation, may be imposed for a criminal conviction.

       Serious
Section 17(k) of the OSH Act provides that “a serious violation shall be deemed to exist in a place of employment if there is a substantial probability that death or serious physical harm could result from a condition which exists, or from one or more practices, means, methods, operations, or processes which have been adopted or are in use, in such place of employment unless the employer did not, and could not with the exercise of reasonable diligence, know of the presence of the violation.” OSHA may propose a penalty of up to $7,000 for each violation.

        Other-Than-Serious
This type of violation is cited in situations where the accident/incident or illness that would be most likely to result from a hazardous condition would probably not cause death or serious physical harm, but would have a direct and immediate relationship to the safety and health of employees. OSHA may impose a penalty of up to $7,000 for each violation.

       De Minimis
De minimis conditions are those where an employer has implemented a measure different from one specified in a standard, that has no direct or immediate relationship to safety or health. These conditions do not result in citations or penalties.

       Failure to Abate
A failure to abate violation exists when a previously cited hazardous condition, practice or non-complying equipment has not been brought into compliance since the prior inspection (i.e., the violation remains continuously uncorrected) and is discovered at a later inspection. If, however, the violation was corrected, but later reoccurs, the subsequent occurrence is a repeated violation. OSHA may impose a penalty of up to $7,000 per day for each violation.

       Repeated
An employer may be cited for a repeated violation if that employer has been cited previously, within the last five years, for the same or a substantially similar condition or hazard and the citation has become a final order of the Occupational Safety and Health Review Commission (OSHRC). A citation may become a final order by operation of law when an employer does not contest the citation, or pursuant to court decision or settlement. Repeated violations can bring a civil penalty of up to $70,000 for each violation.

Additional violations for which citations and proposed penalties may be issued upon conviction:
•  Falsifying records, reports or applications can bring a fine of $10,000 or up to 6 months in jail, or both.
•  Violations of posting requirements can bring a civil penalty of up to $7,000.
•  Assaulting a compliance officer, or otherwise resisting, opposing, intimidating, or interfering with compliance officers while they are engaged in the performance of their duties is a criminal offense, subject to a fine of not more than $5,000 and imprisonment for not more than 3 years.

Don’t Take the Risk!
Why risk citations and penalties when you can ensure OSHA compliance with an affordable and effective compliance training program? For more information on this and other topics related to HIPAA, OSHA, Medicare and HR compliance please email support@hcsiinc.com or visit our website at http://www.hcsiinc.com 
Become a member of our LinkedIn group at: http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Tuesday, October 27, 2015

Proper Sharps Disposal and Containers

Handling Sharps and Needles

Sharps Containers (also referred to as Sharps Disposal Containers, Medical Waste Disposal Containers, Biomedical Waste Disposal Containers, etc.) are specially made containers used to contain hazardous "piercing" instruments and reduce the chance of spreading infection. It is standard practice in developed and even underdeveloped countries for used needles to be placed immediately into a sharps container after a single use, with only a few exceptions to the general rule. Needles are dropped into the container without touching the outside of the container. Needles should never be pushed or forced into the container, as damage to the container and/or needlestick injuries may result. Proper use of a sharps container includes pick up by or delivery to an approved "red bag" or medical waste treatment site. In addition to this pre-existing safety measure, all U.S. medical and educational staff are federally required to be tested on their knowledge of bloodborne pathogens.

A sharps container is a term for a specially-made container that is predominantly used for medical needles and any other sharp medical instruments, such as an IV catheter. They are available in one of two types:

Single-use sharps containers - which are disposed of with the waste inside.

Reusable sharps containers - which are robotically emptied and sterilized before being returned for re-use.

Sharps is the term used to describe any item that is capable of puncturing the skin such as syringes, needles, lancets, broken glass with blood on it, scalpels, etc. Because these 'sharps' potentially have disease-carrying blood or other potentially infectious materials on them, they are capable of 'injecting' that blood or fluid into anyone who comes in contact with them. Examples of sharps include:
  • Needles, syringes, lancets, broken glass with blood on it
  • Suture needles, scalpel blades, butterflies (both traditional and safety)
  • Vacutainer tubes (both plastic and glass)
  • Phlebotomy needles with vacutainer tube holder attached
  • Capillary tubes (both plastic and glass)
  • IV catheters
  • Dental anesthetic carpules with blood
  • Dental wires and endodontic files
  • Other sharp objects contaminated with blood such as box cutters and broken glass
For regulated businesses, such as healthcare faculties, in addition to sharps, regulated medical waste is defined by OSHA as:
  • Pathology and microbiological waste
  • Liquid or semi-liquid blood or other potentially infectious materials (OPIM*)
  • Items caked with dried blood or OPIM
  • Items that could release blood or OPIM
*OPIM: semen, vaginal secretions; fluids from around the spine, brain, joints, lungs, heart, and abdomen; saliva in a dental procedure; any body fluid with visible blood; any unidentifiable body fluid; and unfixed tissue.
Examples of non-sharps regulated medical waste include Tubing with blood in it and Blood-soaked gauze. Regulated medical waste does not include urine, feces, sputum, sweat, tears, or saliva or any items containing or once containing these fluids such as urine cups, incontinence pads, or diapers.

Preventing Injuries
Before you use a sharp object, such as a needle or scalpel, make sure you have all the items you need close by. This includes items like alcohol swabs, gauze, and bandages.

Also, know where the sharps disposal container is. Check to make sure there is enough room in the container for your object to fit. It should not be more than 2/3 full.

Some needles have a protective device, such as a needle shield, sheath, or blunting, that you activate after you remove the needle from the patient. This allows you to handle the needle safely, without the risk of exposing yourself to blood or body fluids. If you are using this kind of needle, make sure you know how it works before you use it.

Follow these guidelines when you work with sharps.
  • Do not uncover or unwrap the sharp object until it is time to use it.
  • Keep the object pointed away from you and other persons at all times.
  • Never recap or bend a sharp object.
  • Keep your fingers away from the tip of the object.
  • If the object is reusable, put it in a secure, closed container after you use it.
  • Never hand a sharp object to someone else or put it on a tray for another person to pick up.
  • Tell the people you are working with when you plan to set the object down or pick it up.

Sharps Disposal
Make sure the disposal container is made for disposing of sharp objects. Replace containers when they are 2/3 full.
Other important tips include:
  • Never put your fingers into the sharps container.
  • If the needle has tubing attached to it, hold the needle and the tubing when you put it in the sharps container.
  • Sharps containers should be at eye level and within your reach.
  • If a needle is sticking out of the container, do not push it in with your hands. Call to have the container removed. Or, a trained person may use tongs to push the needle back into the container.
  • If you find an uncovered sharp object outside of a disposal container, it is safe to pick it up only if you can grasp the non-sharp end. If you cannot, use tongs to pick it up and dispose of it. 
According to OSHA, healthcare employees must have access to sharps containers that are easily accessible to the immediate area where sharps are used (29 CFR 1910.1030(d)(4)(iii)(A)(2)(i)).
The FDA recommends that used needles and other sharps be immediately placed in FDA-cleared sharps disposal containers. The FDA has evaluated the safety and effectiveness of these containers and has cleared them for use by health care professionals and the public to help reduce the risk of injury and infections from sharps.
FDA-cleared sharps disposal containers are made from rigid plastic and come marked with a line that indicates when the container should be considered full, which means it’s time to dispose of the container.

How do the Bloodborne Pathogens standard and the Needlestick Safety and Prevention Act apply to you?  OSHA's Bloodborne Pathogens standard (29 CFR 1910.1030), including its 2001 revisions, applies to all employers who have an employee(s) with occupational exposure (i.e., reasonably anticipated skin, eye, mucous membrane, or parenteral contact with blood or other potentially infectious materials (OPIM) that may result from the performance of the employee's duties). These employers must implement the requirements set forth in the standard. Some of the new and clarified provisions in the standard apply only to healthcare settings, but other provisions, particularly the requirements to update the Exposure Control Plan and to keep a sharps injury log, apply to non-healthcare as well as healthcare settings. Make sure your staff are properly trained in OSHA compliance standards and have the required tools to perform their job safely.

Sources: www.osha.gov, www.fda.govU.S. National Library of Medicine and http://www.sharpscontainers.org/

For more information on this and other topics related to HR, HIPAA, OSHA, and Medicare, please email support@hcsiinc.com or visit our website at http://www.hcsiinc.com 
Become a member of our LinkedIn group at: http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

HIPAA Definitions

Here are some of the basic definitions of HIPAA compliance

Business Associate: A person or company that acts on behalf of a covered entity performing functions that involve the use or disclosure of Protected Health Information (PHI) for claims processing, billing, quality assurance, etc. Members of a covered entity’s work force are not business associates.

Covered Entity: All health plans, all health care clearinghouses, and any health care provider who transmits health information in electronic form in connection with a covered electronic transaction.

Designated Record Set (DRS): A record that contains information utilized and maintained for the purpose of making decisions about an individual’s health care.

Electronic Protected Health Information (ePHI): Individually identifiable health information that is transmitted, maintained or stored in electronic form.

Privacy: Scalable set of standards governing the patient’s rights over the use and disclosure of their own protected health information (PHI).

Protected Health Information (PHI): Individually identifiable health information maintained or stored in electronic or any other form or medium. It includes medical, demographic, and financial information about the patient.

Security: Specific measures a health care entity must take to protect ePHI from unauthorized breaches of privacy, or loss of integrity. It is scalable, flexible, and generally addressable.

Transactions: Electronic transmission of information between two parties to carry out financial or administrative activities related to health care.

Understanding these basic HIPAA terms is vital to your office being successfully compliant with the HIPAA regulations.


For questions about this topic, email me at jhuff@hcsiinc.com

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Monday, October 26, 2015

Do You Truly Understand the ADA?

Understanding the ADA and how it applies to your office will help you and your organization.


The Americans with Disabilities Act (ADA) is intended to enhance and protect the rights of individuals with disabilities in all life activities and to provide clear, consistent, enforceable standards for addressing discrimination against individuals with disabilities.

A disability under the ADA is defined as a known physical or mental impairment which substantially limits one or more of an individual’s major life activities. Individuals are also entitled to protection under the law if they have a record of such an impairment, are regarded as having such an impairment but who are not disabled, or have an association of an individual with a disability.

The Act is comprised of five separate titles which prohibit discrimination in employment, transportation, public accommodations, and telecommunications, as well as several other miscellaneous areas. Title I, employment, and Title II, public accommodations, have the greatest impact on employees and job applicants.

The employment title ensures that qualified individuals with disabilities, including both applicants and current employees, have available to them the same employment opportunities as people without disabilities. It includes, but is not limited to, the following areas:

  • Hiring (application procedures, recruitment, etc.)
  • Promotion and transfers
  • Discharge (layoffs, terminations, rehires, etc.)
  • All forms of compensation
  • Job training
  • Fringe benefits
  • Job descriptions/classification
  • All leaves of absence
  • Other aspects of employment

When working with a quailed individual with a disability, employers are required to determine whether there are any reasonable accommodations that could be made which would allow the individual to compete on the same level as those without disabilities.


Having an understanding of the ADA requirements will enable you to properly implement those requirements into your organization.

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Friday, October 23, 2015

HIPAA Breach Notification Rule

HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information.


The HIPAA Breach Notification Rule, 45 CFR §§ 164.400-414, requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information. Similar breach notification provisions implemented and enforced by the Federal Trade Commission (FTC), apply to vendors of personal health records and their third party service providers, pursuant to section 13407 of the HITECH Act.


Breach Notification Requirements

Following a breach of unsecured protected health information, covered entities must provide notification of the breach to affected individuals, the Secretary, and, in certain circumstances, to the media. In addition, business associates must notify covered entities if a breach occurs at or by the business associate.

  • Individual Notice
Covered entities must notify affected individuals following the discovery of a breach of unsecured protected health information. Covered entities must provide this individual notice in written form by first-class mail, or alternatively, by e-mail if the affected individual has agreed to receive such notices electronically. If the covered entity has insufficient or out-of-date contact information for 10 or more individuals, the covered entity must provide substitute individual notice by either posting the notice on the home page of its web site for at least 90 days or by providing the notice in major print or broadcast media where the affected individuals likely reside. The covered entity must include a toll-free phone number that remains active for at least 90 days where individuals can learn if their information was involved in the breach. If the covered entity has insufficient or out-of-date contact information for fewer than 10 individuals, the covered entity may provide substitute notice by an alternative form of written notice, by telephone, or other means.  
These individual notifications must be provided without unreasonable delay and in no case later than 60 days following the discovery of a breach and must include, to the extent possible, a brief description of the breach, a description of the types of information that were involved in the breach, the steps affected individuals should take to protect themselves from potential harm, a brief description of what the covered entity is doing to investigate the breach, mitigate the harm, and prevent further breaches, as well as contact information for the covered entity (or business associate, as applicable).
With respect to a breach at or by a business associate, while the covered entity is ultimately responsible for ensuring individuals are notified, the covered entity may delegate the responsibility of providing individual notices to the business associate.  Covered entities and business associates should consider which entity is in the best position to provide notice to the individual, which may depend on various circumstances, such as the functions the business associate performs on behalf of the covered entity and which entity has the relationship with the individual.
  
  • Media Notice
Covered entities that experience a breach affecting more than 500 residents of a State or jurisdiction are, in addition to notifying the affected individuals, required to provide notice to prominent media outlets serving the State or jurisdiction.  Covered entities will likely provide this notification in the form of a press release to appropriate media outlets serving the affected area.  Like individual notice, this media notification must be provided without unreasonable delay and in no case later than 60 days following the discovery of a breach and must include the same information required for the individual notice.

  • Notice to the Secretary
In addition to notifying affected individuals and the media (where appropriate), covered entities must notify the Secretary of breaches of unsecured protected health information. Covered entities will notify the Secretary by visiting the HHS web site (http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/brinstruction.html) and filling out and electronically submitting a breach report form. If a breach affects 500 or more individuals, covered entities must notify the Secretary without unreasonable delay and in no case later than 60 days following a breach. If, however, a breach affects fewer than 500 individuals, the covered entity may notify the Secretary of such breaches on an annual basis. Reports of breaches affecting fewer than 500 individuals are due to the Secretary no later than 60 days after the end of the calendar year in which the breaches are discovered.

  • Notification by a Business Associate
If a breach of unsecured protected health information occurs at or by a business associate, the business associate must notify the covered entity following the discovery of the breach.  A business associate must provide notice to the covered entity without unreasonable delay and no later than 60 days from the discovery of the breach.  To the extent possible, the business associate should provide the covered entity with the identification of each individual affected by the breach as well as any other available information required to be provided by the covered entity in its notification to affected individuals.

When a breach occurs in your office, it is required that you report it!

This information was supplied by: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/

For more information on this and other topics related to HIPAA, HR, OSHA, and Medicare, please emailsupport@hcsiinc.com or visit our website at http://www.hcsiinc.com

Be sure to become a member of our Linkedin group by visiting; http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:

Delivered by FeedBurner