SlideShare una empresa de Scribd logo
1 de 19
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 1 Adhering to Healthcare Industry Regulations
Proposal to Healthcare Providers
on how to adhere to
Regulatory Requirements, and insure a Safe Workplace
(Related to “Patient Protection and Affordable Care Act” – PPACA)
including:
• HIPAA, HITECH, ePHI, and the Final Ombudsman Rule (Medicare / Medicaid)
• Workplace Safety, Security and Threat Elimination Via Workplace Violence
Prevention (OSHA, DHS, NFPA 1600 and OEM), and mandated
• Workflow Optimization / Employee Training Management.
Proposed by:
Thomas Bronack, President
Data Center Assistance Group, Inc.
15180 20th Avenue
Whitestone, New York 11357
Email: bronackt@dcag.com
Cell Phone: (917) 673-6992
Audience Includes:
• Hospitals, Clinics, Doctors Offices; and
• Business Associates providing services to
Healthcare Organizations.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 2 Adhering to Healthcare Industry Regulations
Healthcare is Sick and Needs to be Fixed (Medicare / Medicaid)
• Patient Costs Soar, while Services Suffer:
• Redundant Testing and Litigation Fears;
• Inefficient workflow and supply chain operations;
• New Patient Freedoms allow for the Sharing of Patient Authorized
Medical Records, while restricting unauthorized use and sale of data;
• Improved Electronic Collaboration for remote assistance;
• Examining Medical Information to uncover trends , diagnose symptoms,
and formulate remediation's.
• Laws and Regulations must be adhered to, including:
• HIPAA – Health Insurance Portability and Accountability Act (1996) to improve
awareness and efficiency;
• HITECH - Health Information Technology for Economic and Clinical Health (2009) includes more stringent
regulations and sanctions;
• ePHI – electronic Personal Health Information (2009) to safeguard all forms of patient information (paper,
electronic, video, audio, etc.) against unauthorized use and sale;
• Final Omnibus Rule (1/25/2013) states specific compliance guidelines and defines the final Privacy, Security, and
enforcement fines and sanctions:
• “Meaningful Use” clause can reimburse electronic record conversion ($40-60K);
• Patient Protection and Affordable Care Act (PPACA), sometimes known as Obama Care;
• Healthcare Organizations and their Business Associates must comply by 9/23/2013;
• States Attorney Generals can bring lawsuits on behalf of private individuals for breach of Privacy Rules; and,
• Compliance will be aggressively enforced to reduce cost and improve patient services.
• Applies to Healthcare Organizations and their Business Associates.
• Designed to improve services and reduce costs through new technologies and procedures.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 3 Adhering to Healthcare Industry Regulations
Purpose of Presentation and Deliverables that can be achieved
• Define healthcare industry New and Existing Compliance Regulations;
• Review Patient Protection and Affordable Care Act (referred to as - Obama Care);
• Discuss New Patient Freedoms related to patient information sharing;
• Show how “Joint Commission Accrediting Healthcare Organization” (JCAHO) certification can
be achieved and why it is a benefit;
• Suggest methods to perform Risk Management, Auditing, and Incident Reporting;
• Demonstrate how better utilization of Information Technology, Data Management, and Access
Controls can create a safeguarded and efficient environment;
• Determine Security and Emergency Response Planning needed to “Protect the Workplace”,
“Safeguard Patients Rights”, and “Comply with Regulatory Requirements”;
• Create a project plan / road map to Implement Physical and Data Security;
• Assist in the development and Implementation of Emergency Response Plans;
• Implement a Workflow Management System to insure Forms Management and Controls;
• Document new Standards and Procedures needed to better protect patients, achieve a
safeguarded environment, and improve efficiency;
• Provide Employee Awareness and Training; and,
• Provide Integration, Support, and Maintenance going forward.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 4 Adhering to Healthcare Industry Regulations
Audience and Compliance Requirements
Healthcare Industry
Patient Security & Safety
New Patient Freedoms
Workplace Protection
Penalties and Financial Losses
Training and Awareness
Risk Management
Response Identification and Planning
• Hospitals; Clinics; Doctors Offices; and,
• Business Associates and Sub-Contractors.
• HIPAA; HITECH; ePHI; and Final Omnibus Rule.
• “Meaningful Use” reimbursement for electronic data ($40-60K)
• Ability to have records transferred by request of patient or their
authorized representative (Record Sharing).
• Responsible for protecting employees, patients, and visitors;
• OSHA, DHS, OEM, and NFPA 1600;
• Workplace Violence Prevention;
• Workplace Physical Security and Evidence Capturing; and,
• Ability to evacuate patients in Emergency Mode.
• Criminal and Civil penalties; fines up to $1.5 million per
occurrence taking effect 9/23/2013.
• Staff must be aware of requirements and trained on how to
respond to a wide-range of disaster events.
• Identification of Risks and potential Disaster Event obstacles.
• Mitigate Gaps and Exceptions; Mediate obstacles blocking the
ability to respond to Disaster events; insure the ability to
respond to encountered incidents; have the ability to provide a
safeguarded environment capable of providing enhanced
protections and efficiency while achieving compliance.
Integrate within the everyday functions and environment.
Healthcare Provider Proposal Page: 5 Adhering to Healthcare Industry Regulations
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
• Physical (Guards, CCTV, Card Keys, etc.) and Data Security Service Providers;
• IT Equipment, Software, Consulting, and Support Vendors;
• Lawyers, Accountants, and Auditors;
• Leasing firms and other financial providers;
• Telephone and Communications Vendors;
• Shredding Vendors, Waste Disposal, and Transportation;
• Primary and Secondary Data Centers;
• Cloud Computing and Virtualization Service Providers;
• Answering Services for Medical Offices;
• Medical Billing Services;
• Medical Transcriptions Services;
• Medical Collection Agencies; and,
• Cleaning, Disposal, and internal Service staff.
The best protection is to perform a Risk Analysis to determine regulatory gaps and exceptions
that must be mitigated, along with impeding obstacles that must be mediated. Then implement
controls and procedures to create a safeguarded and compliant environment.
Who is effected by these changes?
Business Associates and Contractors including:
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 6 Adhering to Healthcare Industry Regulations
History and purpose of HIPAA rules and regulations, from original to current updates.
• 1996 - Initially HIPAA was introduced to improve efficiency and effectiveness of the U.S.
Healthcare System through guidelines and regulatory requirements.
• 2/2009 – (HITECH) Health Information Technology for Economic and Clinical Health Act was
introduced as part of the American Recovery and Reinvestment Act covering health records
from paper based through all types of current and future electronic health records.
• 1/25/2013 – The Final Omnibus Rule was published by the Federal Register to include
more stringent privacy and security protection for patients (to be en-acted 9/23/13).
• Rule also increased sanctions and penalties for failure to comply, including the right of States Attorneys General
to bring lawsuits on behalf of private individuals for breach of the Privacy Rule.
• The Security Rule expands data protection to include electronic media and electronic Personal Health
Information (ePHI) - covering paper, video, OCR, Social Media, and electronic media.
• Although HITECH has been enforceable since 2/2010 many organizations have failed to take action to fully
comply, thereby risking penalties, financial loss, patient services, and reputational loss that could damage the
ability to continue serving the public’s medical needs.
• Included in Patient Protection and Affordable Care Act (Obama Care) to reduce costs and improve service.
• HIPAA was developed to improve the education of hospital and medical record keepers on the
rules and regulations that must be followed to safeguard patients. The Final Omnibus Rule and
Patient Protection and Affordable Care Act provide a more detailed explanation of these
safeguards and how best to protect the rights and privacy of patients.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 7 Adhering to Healthcare Industry Regulations
HIPAA Contingency Planning and Security Guidelines (newly updated)
Administrative Safeguards include:
• Security Management Process (for People, Physical Environments and Data);
• Assigned Security Responsibility (Management through all levels of Personnel);
• Workforce Security (Procedures governing personnel Screening through Termination);
• Information Access Management (Data Sensitivity, Access Controls, Backup / Recovery, etc.)
• Security Awareness and Training;
• Security Incident Procedures (from identification through “Root Cause” analysis, resolution;
Logging, Tracking, Reporting, and Repository Maintenance);
• Contingency Plan (Disaster, Business, Emergency, and Crisis Management Responses);
• Evaluation (Risk Analysis and Periodic Reviews, with Attestation by Executive Management); and,
• Business Associate Contact and Other Arrangements (from definition to accreditation).
Physical Safeguards include:
• Facility Access Controls (Physical Security to produce a safe workplace);
• Workstation Use;
• Workstation Security; and,
• Device and Media Controls.
Technical Safeguards include:
• Access Controls (Data Security and elimination of Data Corruption);
• Audit Controls;
• Integrity;
• Person and Entity Authentications (User Entitlements); and,
• Transmission Security (Local and Remote / Encryption).
Violation Category
Section 1176 (a) (1):
A. Did Not Know
B. Reasonable Cause
C. 1. – Willful Neglect
– Corrected
C. 2. – Willful Neglect
– Not Corrected
Each Violation:
$100 to Max of
$5,000
$1,000 to Max of
$50,000
$10,000 to Max of
$50,000
$50,000
All such Violations of
an identical provision
in a calendar year:
$1,500,000
$1,500,000
$1,500,000
$1,500,000
Penalties for non-Compliance
CATEGORIES OF VIOLATIONS AND RESPECTIVE PENALTY AMOUNTS AVAILABLE
As you can see, penalties and loss of reputation can grow rapidly through repeated violations
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 8 Adhering to Healthcare Industry Regulations
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 9 Adhering to Healthcare Industry Regulations
Steps that lead to Achieving Compliance Goals and Objectives
• Perform a Risk Assessment, conduct a Physical / Data Security evaluation, and
review Emergency Response Plans regarding compliance issues;
• Conduct a Workflow Analysis to uncover inefficiencies and Supply Chain flaws;
• Define Gaps, Exceptions, and Obstacles that must be Mitigated and Mediated;
• Establish Direction / Project Plan to resolve issues and gain approval;
• Implement Mitigations and Mediations, including: Compliance, Controls,
Emergency Response Plans, and Incident Management procedures;
• Provide Awareness and Training to employees and business associates;
• Achieve compliance to HIPAA, ePHI, HITECH, and Final Omnibus Rule;
• Achieve JCAHO certification, leading to improved business and profitability;
and,
• Provide Implementation, Support, and Maintenance going forward.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 10 Adhering to Healthcare Industry Regulations
HIPAA Five Step Circle of Compliance
Global Tracking:
- Incidents Mediation;
- Gaps & Exception Mitigation;
- Training;
- Authorizations and Disclosures;
- Document Repository.
Reporting and Visualization:
- Audit Reports;
- Tracking Reports;
- Dashboard View;
- Change Management.
Compliance Management
Tools:
- Easy to Use (like MS Office based);
- Regulation Look-Up;
- Enterprise Level Access;
- Third Party Data Integration.
Account Management:
- Member Management;
- Vendor Management;
- Business Associate; and,
- Management and Technical Reporting.
Auditing and Remediation:
- Gap and Obstacle Collection;
- Reported Problems & Incidents;
- Remediation and Mitigation;
- Audit Workflow Definition;
- Audit Workflow Optimization.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 11 Adhering to Healthcare Industry Regulations
Accounts:
• Members (Staff and Affiliates);
• Vendors and Business Associates: and,
• Vendor Questionnaire Design and Completion.
Auditing:
• Audit Questionnaire; * Incidents;
• Gaps and Exceptions; * Obstacles; and,
• Remediation Planning and Execution.
Tracking:
• Training Sessions;
• Authorization and Disclosures;
• Document Manager (Version Control); and,
• Employee Policy / Procedure Viewer.
Reporting:
• Gap & Exception Analysis; * Remediation Summary;
• Questionnaire Results; * Incident Summary;
• Training History; * Authorization Summary;
• Disclosure Summary; * Member Breakdown;
• Vendor Breakdown; and, * Employee Policy /
Procedure Crosswalk.
Administration:
• Preferences; * Update Password;
• Guard Users; * Custom Mandates;
• Custom Regulations; * Custom Questions.
Technical Glossary:
• Technical Glossary; * Change Facilities;
• Status Alerts; * Help;
• Support; and * Logout.
Healthcare Industry Workflow Management System Goals
RDBMS
Programs Data
3. Service Transition
• Change Management (Problems & Enhancements)
• Project Management (Transition Planning and Support)
• Release and Deployment Management (V & R Mgmt.)
• Service Validation and Testing
• Application Development and Customization
• Service Asset and Configuration Management
• Knowledge Management (Training & Awareness)
4. Service Operation
• Event Management
• Incident Management
• Request Fulfillment
• Access Management
• Problem Management
• IT Operations Management
• Facilities Management
1. Service Strategy
• Service Portfolio Management (available
Services and Products)
• Financial Management (PO, WO, A/R, A/P,
G/L, Taxes, and Treasury)
2. Service Design
• Service Catalogue Management
• Service Level Management (SLA / SLR)
• Risk Management (CERT / COSO)
• Capacity / Performance Management
• Availability Management (SLA / SLR)
• IT Service Continuity Management (BCM)
• Information Security Management (ISMS)
• Compliance Management (Regulatory)
• Architecture Management (AMS, CFM)
• Supplier Management (Supply Chain)
ITIL Available Modules
ITIL Five Phase approach to IT Service Support
1. Service Strategy,
2. Service Design,
3. Service Transition,
4. Service Operation, and
5. Continual Service Improvement.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 12 Adhering to Healthcare Industry Regulations
Example of existing Workflow Management System
ITIL stands for:
Information
Technology
Information
Library
Workflow Management / Training System Interfaces & Flow
Work Request
Workflow
Analysis & Training
System
Analyze
Workload and
Type of Work
Log, Assign
And Track
Work
Workload
Too High
?
New
Work / Tool
?
Prioritize Work
on “To-do” List
(Date & Priority)
Move Work
To Designated
Worker
Automated
Personnel
System
Automated
Training
System
Completion &
movement to
last worker
Audit Trail
Analyze and
Report
Close Request
New Tool,
New Staff,
New Procedure
Staff Request
Based on Work
Volume
Workload level
and New Tool
Analysis
Workload levels can accept new work, without personnel change.
Y Y
N
N
Newly Recruited
Personnel
Newly Trained Personnel
Reports Audit Log
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 13 Adhering to Healthcare Industry Regulations
High
Low
Normal
(Request through fulfillment, with staffing increases and training as deemed necessary)
New Staff
New Training
Workflow
Life Cycle
Workload levels can accept new work, with new personnel updates /training changes.
Workflow Forms
Management
System
Existing
Personnel
• Mandated to insure patient safety (right medication and on-time delivery), staff training,
and certification in gain compliance to regulatory requirements.
• Create and respond to a Needs Analysis Questionnaire to identify Gaps & Exposures,
Obstacles, and to define deliverables, time lines, and scope.
• Review current forms, workflows, and controls.
• Identify personnel associated with forms processing.
• Redesign Forms and Workflow associated with forms, as needed.
• Develop Forms Data Base System.
• Implement Forms Management System functions and flows.
• Create User Interface to Forms Management System.
• Produce Management, Technical, and User Analysis Reports.
• Document Forms Management System.
• Supply Awareness and Training to staff, employees and associates.
• Roll-out Forms Management System / Training System.
• Support and Maintain Forms Management / Training System going forward.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 14 Adhering to Healthcare Industry Regulations
Building a Workflow Management / Training System
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 15 Adhering to Healthcare Industry Regulations
Joint Commission on Accreditation of Healthcare Organizations (JCAHO) review
• JCAHO is a pro-active investigator, while HIPAA is an exception driven investigator;
• Covers Hospitals, Nursing Homes, Office-Based Surgery Practices, Home Care
Providers and Laboratories, along with their Business Associates;
• Most prestigious Healthcare Industry Accreditation Organization;
• Certification assures patients and providers that the healthcare organization has
achieved the highest standards required by the industry;
• To achieve certification both healthcare organizations and their staff members
must be able to demonstrate proficiency across specific job competencies and
compliance issues;
• Both Healthcare Organizations and their Business Associates must adhere to
regulatory requirements and competencies;
• JCAHO Certification will help you achieve: a competitive edge; an educated staff;
an improved ability to retain and recruit staff; improved morale; new business; a
higher level of safety; and a safeguarded and compliant workplace.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 16 Adhering to Healthcare Industry Regulations
Sitting
Area
Admitting
Area
Financing
Area
Finance
Waiting Area
Emergency Room
Guards
Area
Sliding
Door
2
4
5
3
Patient Movement to gain entrance to Emergency Room:
1. Patients enter past Guards Desk (no verification or scan);
2. Patient waits for admittance in waiting area (unsupervised);
3. Patient is Admitted and Vital Signs Taken (ID Shown);
4. Patient goes to Finance where they are Identified and
insurance papers validated (first true check of identity);
5. Patient waits to be called to go to Emergency Room where
they are examined by staff; and
6. Patient is admitted to hospital, or treated and sent home.
Signifies where card key doors can be installed to
restrict access to hospital area by unauthorized
personnel (low cost solution to high cost problem)
Signifies patient movement
General
Hospital
Area
Initial
Area
Examined
Problem Analysis:
• Lack of security at ER area can lead to Threat:
• Identification at Entrance;
• Metal Scanner or Search for weapons;
• Surveillance and Cameras for evidence;
• Restrictive movement of patients.
• Possible Weaknesses:
• Unidentified people accompanying patients;
• Unrestrictive movement can lead to terrorism;
• Possible threat to people and hospital
reputation.
• Possible Threats include:
• Terrorism and Active Shooter;
• Deranged People acting out;
• Disgruntled personnel; and
• Civil Disorder.
• Possible Repercussions include:
• Bombs and Guns;
• Deaths and Destruction or property;
• Damage to facilities causing outage of service
to community;
• Loss of reputation; and
• Loss of business and many law suits, with
potential facility closing.
Card Key access requirements
can restrict movement at a low
cost and CCTV can provide
evidence to prosecute.
Initial Physical Security Review from Admittance to ER acceptance (Real World).
6
1
5
Discharged Admitted
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 17 Adhering to Healthcare Industry Regulations
Benefits, Savings, and New Business possibilities
• Learn existing and new Healthcare Industry compliance laws and regulations;
• Identifying audience that must comply to Healthcare Industry regulations;
• Risk Assessment to define current gaps, exceptions, and obstacles impeding compliance;
• Formulate direction plan to achieve compliance and implement a Workflow Management
System that improves efficiency and better safeguards patient information and services;
• Achieve Physical and Data Security requirements;
• Better utilize Information Technology to achieve goals and improve efficiency;
• Adhere to compliance requirements;
• Update Functional Responsibilities and Job Descriptions, as needed;
• Fully Document upgraded environment in Standards and Procedures Manual and Usage
Guides;
• Implement Awareness and Training programs, as required;
• Achieve JCAHO certification; and,
• Utilize compliance upgrade and JCAHO certification to advertise the healthcare
organization, attract new patient and insurance business, and retain and attract personnel
who have a high morale.
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
Healthcare Provider Proposal Page: 18 Adhering to Healthcare Industry Regulations
Achieving Compliance Goals, Objectives, and Tasks to be performed
Goals and Objectives are:
• Use this “Gateway” document to help achieve compliance requirements;
• Obtain JCHAO certification based on compliance;
• Obtain reimbursement via “Meaningful Use” directive for electronic data conversion;
• Implement a Safeguarded and efficient environment that complies with all laws and
regulations for both the Healthcare Organization and their Business Associates.
Tasks to be performed are:
• Presentation as a teaching tool and awareness vehicle for compliance issues;
• Stakeholder identification and team formulation;
• Team Awareness, Education, Work Plan, Assignments, and Reporting Schedule;
• Risk Assessment to define Gaps, Exceptions, and Obstacles;
• Repair / Control Plan to Mitigate Gaps & Exceptions, Mediate Obstacle & Impediments;
• Project Plan including deliverable’s, schedule, resources, time line, and costs;
• Perform tasks to certify Healthcare Organization, Associates, and Supply Chain;
• Perform tasks needed to gain compliance certification (JCHOA Compliant);
• Integrate Workflow Management, Compliance Procedures, and Response Plans;
• Develop and publish all needed documentation;
• Provide Awareness and Educational Training;
• Integrate process within everyday functions performed by personnel; and,
• Provide ongoing Support and Maintenance going forward.
Healthcare Provider Proposal Page: 19 Adhering to Healthcare Industry Regulations
Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13
I look forward to working with you to achieve the goals of this proposal.
Points that should be remembered include:
• The CEO is responsible for producing a safeguarded and efficient environment that is in compliance with
HIPAA, OSHA, NFPA 1600, and DHS regulations (at a minimum);
• Specific new healthcare regulatory requirements are identified in this presentation;
• “Meaningful Use” reimbursement for converting Medicare / Medicaid file conversion to electronic data can
be as high as $40 - $60K per conversion
• The CEO can not delegate his responsibility, only share some responsibilities with insurance companies;
• Damages from lawsuits can run into the multiple millions and over all damages can exceed billions;
• Loss of reputation can result in the closing of the facility;
• Damages to the community can be extensive;
• Criminal and Civil charges can result in jail time and extensive monetary penalties; and
• Only you can take the initiative to implement a safeguarded environment that is in compliance with all
regulatory requirements, while improving productivity and personnel morale. “It is better to set the
example than to be the example”.
I can be reached via the following contact information:
Thomas Bronack, President
Data Center Assistance Group, Inc.
15180 20th Avenue Cell Phone: (917) 673-6992
Whitestone, New York 11357 Email: bronackt@dcag.com
Thank you

Más contenido relacionado

La actualidad más candente

Responding To The Opportunity
Responding To The OpportunityResponding To The Opportunity
Responding To The Opportunityguest7042c6
 
HIPAA | HITECH
HIPAA | HITECHHIPAA | HITECH
HIPAA | HITECHrcabarloc
 
Role-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
Role-Based Access Governance and HIPAA Compliance: A Pragmatic ApproachRole-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
Role-Based Access Governance and HIPAA Compliance: A Pragmatic ApproachEMC
 
how to really implement hipaa presentation
how to really implement hipaa presentationhow to really implement hipaa presentation
how to really implement hipaa presentationProvider Resources Group
 
Healthcare - Customer-Centric Healthcare Best Practices for CIO and CISOs
Healthcare - Customer-Centric Healthcare Best Practices for CIO and CISOsHealthcare - Customer-Centric Healthcare Best Practices for CIO and CISOs
Healthcare - Customer-Centric Healthcare Best Practices for CIO and CISOsNicholas Christiano Jr.
 
Maninging Risk Exposure in Meaningful Use Stage 2
Maninging Risk Exposure in Meaningful Use Stage 2Maninging Risk Exposure in Meaningful Use Stage 2
Maninging Risk Exposure in Meaningful Use Stage 2Compliancy Group
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rssupportc2go
 
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...Health IT Conference – iHT2
 
Data and Network Security: What You Need to Know
Data and Network Security: What You Need to KnowData and Network Security: What You Need to Know
Data and Network Security: What You Need to KnowPYA, P.C.
 
HIPAA Training: Preventing Employees from Violating HIPAA
HIPAA Training: Preventing Employees from Violating HIPAAHIPAA Training: Preventing Employees from Violating HIPAA
HIPAA Training: Preventing Employees from Violating HIPAAjbhicks
 
E Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep PpE Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep Pphunterberney
 

La actualidad más candente (18)

Hipaa
HipaaHipaa
Hipaa
 
Responding To The Opportunity
Responding To The OpportunityResponding To The Opportunity
Responding To The Opportunity
 
HIPAA | HITECH
HIPAA | HITECHHIPAA | HITECH
HIPAA | HITECH
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
Role-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
Role-Based Access Governance and HIPAA Compliance: A Pragmatic ApproachRole-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
Role-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
 
how to really implement hipaa presentation
how to really implement hipaa presentationhow to really implement hipaa presentation
how to really implement hipaa presentation
 
Hipaa
HipaaHipaa
Hipaa
 
Healthcare - Customer-Centric Healthcare Best Practices for CIO and CISOs
Healthcare - Customer-Centric Healthcare Best Practices for CIO and CISOsHealthcare - Customer-Centric Healthcare Best Practices for CIO and CISOs
Healthcare - Customer-Centric Healthcare Best Practices for CIO and CISOs
 
Maninging Risk Exposure in Meaningful Use Stage 2
Maninging Risk Exposure in Meaningful Use Stage 2Maninging Risk Exposure in Meaningful Use Stage 2
Maninging Risk Exposure in Meaningful Use Stage 2
 
HITECH Act
HITECH ActHITECH Act
HITECH Act
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
 
Data and Network Security: What You Need to Know
Data and Network Security: What You Need to KnowData and Network Security: What You Need to Know
Data and Network Security: What You Need to Know
 
HIPAA Training: Preventing Employees from Violating HIPAA
HIPAA Training: Preventing Employees from Violating HIPAAHIPAA Training: Preventing Employees from Violating HIPAA
HIPAA Training: Preventing Employees from Violating HIPAA
 
Hb Emr
Hb EmrHb Emr
Hb Emr
 
Hipaa omnibus
Hipaa omnibusHipaa omnibus
Hipaa omnibus
 
HIPAA TITLE II (2)
HIPAA TITLE II (2)HIPAA TITLE II (2)
HIPAA TITLE II (2)
 
E Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep PpE Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep Pp
 

Similar a Updated Healthcare Industry Compliance Presentation

Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Kimberly Simon MBA
 
HIPAA Violations and Penalties power point
HIPAA Violations and Penalties power pointHIPAA Violations and Penalties power point
HIPAA Violations and Penalties power pointDeena Fetrow
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceJim Anfield
 
Implementing EHR in Behavioral Health Blog Post
Implementing EHR in Behavioral Health Blog PostImplementing EHR in Behavioral Health Blog Post
Implementing EHR in Behavioral Health Blog PostJeff Brevik, PMP
 
Hipaa privacy and security 03192014
Hipaa privacy and security 03192014Hipaa privacy and security 03192014
Hipaa privacy and security 03192014Samantha Haas
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTKimberly Simon MBA
 
AN20230811-3.pptx
AN20230811-3.pptxAN20230811-3.pptx
AN20230811-3.pptxHabibuKumar
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rssupportc2go
 
BUS 4126 Capella University Human Resource Paper.docx
BUS 4126 Capella University Human Resource Paper.docxBUS 4126 Capella University Human Resource Paper.docx
BUS 4126 Capella University Human Resource Paper.docxwrite4
 
BUS 4126 Capella University Human Resource Paper.docx
BUS 4126 Capella University Human Resource Paper.docxBUS 4126 Capella University Human Resource Paper.docx
BUS 4126 Capella University Human Resource Paper.docxstudywriters
 
Chapter 16 Managing InformationChapter Objectives .docx
Chapter 16 Managing InformationChapter Objectives .docxChapter 16 Managing InformationChapter Objectives .docx
Chapter 16 Managing InformationChapter Objectives .docxzebadiahsummers
 
HealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUSTHealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUSTKimberly Simon MBA
 
Becoming HITECH - 9/2009
Becoming HITECH - 9/2009Becoming HITECH - 9/2009
Becoming HITECH - 9/2009rogersons
 
Questions On The Healthcare System
Questions On The Healthcare SystemQuestions On The Healthcare System
Questions On The Healthcare SystemAmanda Gray
 
Patients Privacy and Confidentiality
Patients Privacy and ConfidentialityPatients Privacy and Confidentiality
Patients Privacy and ConfidentialityOluseyi Ilesanmi
 
Aami hitech mu impact on the future on HC IT
Aami hitech mu impact on the future on HC ITAami hitech mu impact on the future on HC IT
Aami hitech mu impact on the future on HC ITAmy Stowers
 
Mobile Health Symposium #HIMSS15 Session Mh5
Mobile Health Symposium #HIMSS15 Session Mh5Mobile Health Symposium #HIMSS15 Session Mh5
Mobile Health Symposium #HIMSS15 Session Mh53GDR
 
HLTH606 Facilitated Discussion - EHR (Oct 2011)
HLTH606 Facilitated Discussion - EHR (Oct 2011)HLTH606 Facilitated Discussion - EHR (Oct 2011)
HLTH606 Facilitated Discussion - EHR (Oct 2011)Katie Seeler Hoskins
 

Similar a Updated Healthcare Industry Compliance Presentation (20)

How good we are in adhering HIPAA rules
How good we are in adhering HIPAA rulesHow good we are in adhering HIPAA rules
How good we are in adhering HIPAA rules
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
HIPAA Violations and Penalties power point
HIPAA Violations and Penalties power pointHIPAA Violations and Penalties power point
HIPAA Violations and Penalties power point
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
Implementing EHR in Behavioral Health Blog Post
Implementing EHR in Behavioral Health Blog PostImplementing EHR in Behavioral Health Blog Post
Implementing EHR in Behavioral Health Blog Post
 
Hipaa privacy and security 03192014
Hipaa privacy and security 03192014Hipaa privacy and security 03192014
Hipaa privacy and security 03192014
 
Chapter 9
Chapter 9Chapter 9
Chapter 9
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
 
AN20230811-3.pptx
AN20230811-3.pptxAN20230811-3.pptx
AN20230811-3.pptx
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 
BUS 4126 Capella University Human Resource Paper.docx
BUS 4126 Capella University Human Resource Paper.docxBUS 4126 Capella University Human Resource Paper.docx
BUS 4126 Capella University Human Resource Paper.docx
 
BUS 4126 Capella University Human Resource Paper.docx
BUS 4126 Capella University Human Resource Paper.docxBUS 4126 Capella University Human Resource Paper.docx
BUS 4126 Capella University Human Resource Paper.docx
 
Chapter 16 Managing InformationChapter Objectives .docx
Chapter 16 Managing InformationChapter Objectives .docxChapter 16 Managing InformationChapter Objectives .docx
Chapter 16 Managing InformationChapter Objectives .docx
 
HealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUSTHealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUST
 
Becoming HITECH - 9/2009
Becoming HITECH - 9/2009Becoming HITECH - 9/2009
Becoming HITECH - 9/2009
 
Questions On The Healthcare System
Questions On The Healthcare SystemQuestions On The Healthcare System
Questions On The Healthcare System
 
Patients Privacy and Confidentiality
Patients Privacy and ConfidentialityPatients Privacy and Confidentiality
Patients Privacy and Confidentiality
 
Aami hitech mu impact on the future on HC IT
Aami hitech mu impact on the future on HC ITAami hitech mu impact on the future on HC IT
Aami hitech mu impact on the future on HC IT
 
Mobile Health Symposium #HIMSS15 Session Mh5
Mobile Health Symposium #HIMSS15 Session Mh5Mobile Health Symposium #HIMSS15 Session Mh5
Mobile Health Symposium #HIMSS15 Session Mh5
 
HLTH606 Facilitated Discussion - EHR (Oct 2011)
HLTH606 Facilitated Discussion - EHR (Oct 2011)HLTH606 Facilitated Discussion - EHR (Oct 2011)
HLTH606 Facilitated Discussion - EHR (Oct 2011)
 

Más de Thomas Bronack

Personnel Productivity System - Exec Pres
Personnel Productivity System - Exec PresPersonnel Productivity System - Exec Pres
Personnel Productivity System - Exec PresThomas Bronack
 
Utilizing Dashboards to improve efficiency
Utilizing Dashboards to improve efficiencyUtilizing Dashboards to improve efficiency
Utilizing Dashboards to improve efficiencyThomas Bronack
 
Optimizing the it and business environment through dashboards
Optimizing the it and business environment through dashboardsOptimizing the it and business environment through dashboards
Optimizing the it and business environment through dashboardsThomas Bronack
 
Dcag training on VMware DR Process
Dcag training on VMware DR ProcessDcag training on VMware DR Process
Dcag training on VMware DR ProcessThomas Bronack
 
Achieving enterprise resiliency and corporate certification through the use o...
Achieving enterprise resiliency and corporate certification through the use o...Achieving enterprise resiliency and corporate certification through the use o...
Achieving enterprise resiliency and corporate certification through the use o...Thomas Bronack
 
Enterprise resiliency and world-wide compliance, in-depth article.
Enterprise resiliency and world-wide compliance, in-depth article.Enterprise resiliency and world-wide compliance, in-depth article.
Enterprise resiliency and world-wide compliance, in-depth article.Thomas Bronack
 
Optimizing the IT and Business Environment
Optimizing the IT and Business EnvironmentOptimizing the IT and Business Environment
Optimizing the IT and Business EnvironmentThomas Bronack
 
Dcag service optimization offering01
Dcag service optimization offering01Dcag service optimization offering01
Dcag service optimization offering01Thomas Bronack
 
Recovery and Compliance Services provided by Tom Bronack
Recovery and Compliance Services provided by Tom BronackRecovery and Compliance Services provided by Tom Bronack
Recovery and Compliance Services provided by Tom BronackThomas Bronack
 
Auditing contingency Plans
Auditing contingency PlansAuditing contingency Plans
Auditing contingency PlansThomas Bronack
 
Equipment Redeployment and Termination Procedures
Equipment Redeployment and Termination ProceduresEquipment Redeployment and Termination Procedures
Equipment Redeployment and Termination ProceduresThomas Bronack
 
Article on Emergency Management and Corporate Certification
Article on Emergency Management and Corporate CertificationArticle on Emergency Management and Corporate Certification
Article on Emergency Management and Corporate CertificationThomas Bronack
 
Smaller Presentation on Enterprise Resiliency and Corporate Certification
Smaller Presentation on Enterprise Resiliency and Corporate CertificationSmaller Presentation on Enterprise Resiliency and Corporate Certification
Smaller Presentation on Enterprise Resiliency and Corporate CertificationThomas Bronack
 
Exec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate CertificationExec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate CertificationThomas Bronack
 
Personnel Productivity System - Updated 6-6-2013
Personnel Productivity System - Updated 6-6-2013Personnel Productivity System - Updated 6-6-2013
Personnel Productivity System - Updated 6-6-2013Thomas Bronack
 
Achieving Enterprise Resiliency and Corporate Certification
Achieving Enterprise Resiliency and Corporate CertificationAchieving Enterprise Resiliency and Corporate Certification
Achieving Enterprise Resiliency and Corporate CertificationThomas Bronack
 
Asset Management (Acquisition, Redeployment, and Termination)(
Asset Management (Acquisition, Redeployment, and Termination)(Asset Management (Acquisition, Redeployment, and Termination)(
Asset Management (Acquisition, Redeployment, and Termination)(Thomas Bronack
 
Application migration guideline document
Application migration guideline documentApplication migration guideline document
Application migration guideline documentThomas Bronack
 
Tape vaulting audit and encryption usage analysis
Tape vaulting audit and encryption usage analysisTape vaulting audit and encryption usage analysis
Tape vaulting audit and encryption usage analysisThomas Bronack
 
Achieving Enterprise Resiliency and Corporate Certification
Achieving Enterprise Resiliency and Corporate CertificationAchieving Enterprise Resiliency and Corporate Certification
Achieving Enterprise Resiliency and Corporate CertificationThomas Bronack
 

Más de Thomas Bronack (20)

Personnel Productivity System - Exec Pres
Personnel Productivity System - Exec PresPersonnel Productivity System - Exec Pres
Personnel Productivity System - Exec Pres
 
Utilizing Dashboards to improve efficiency
Utilizing Dashboards to improve efficiencyUtilizing Dashboards to improve efficiency
Utilizing Dashboards to improve efficiency
 
Optimizing the it and business environment through dashboards
Optimizing the it and business environment through dashboardsOptimizing the it and business environment through dashboards
Optimizing the it and business environment through dashboards
 
Dcag training on VMware DR Process
Dcag training on VMware DR ProcessDcag training on VMware DR Process
Dcag training on VMware DR Process
 
Achieving enterprise resiliency and corporate certification through the use o...
Achieving enterprise resiliency and corporate certification through the use o...Achieving enterprise resiliency and corporate certification through the use o...
Achieving enterprise resiliency and corporate certification through the use o...
 
Enterprise resiliency and world-wide compliance, in-depth article.
Enterprise resiliency and world-wide compliance, in-depth article.Enterprise resiliency and world-wide compliance, in-depth article.
Enterprise resiliency and world-wide compliance, in-depth article.
 
Optimizing the IT and Business Environment
Optimizing the IT and Business EnvironmentOptimizing the IT and Business Environment
Optimizing the IT and Business Environment
 
Dcag service optimization offering01
Dcag service optimization offering01Dcag service optimization offering01
Dcag service optimization offering01
 
Recovery and Compliance Services provided by Tom Bronack
Recovery and Compliance Services provided by Tom BronackRecovery and Compliance Services provided by Tom Bronack
Recovery and Compliance Services provided by Tom Bronack
 
Auditing contingency Plans
Auditing contingency PlansAuditing contingency Plans
Auditing contingency Plans
 
Equipment Redeployment and Termination Procedures
Equipment Redeployment and Termination ProceduresEquipment Redeployment and Termination Procedures
Equipment Redeployment and Termination Procedures
 
Article on Emergency Management and Corporate Certification
Article on Emergency Management and Corporate CertificationArticle on Emergency Management and Corporate Certification
Article on Emergency Management and Corporate Certification
 
Smaller Presentation on Enterprise Resiliency and Corporate Certification
Smaller Presentation on Enterprise Resiliency and Corporate CertificationSmaller Presentation on Enterprise Resiliency and Corporate Certification
Smaller Presentation on Enterprise Resiliency and Corporate Certification
 
Exec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate CertificationExec Presentation on Achieving Enterprise Resiliency and Corporate Certification
Exec Presentation on Achieving Enterprise Resiliency and Corporate Certification
 
Personnel Productivity System - Updated 6-6-2013
Personnel Productivity System - Updated 6-6-2013Personnel Productivity System - Updated 6-6-2013
Personnel Productivity System - Updated 6-6-2013
 
Achieving Enterprise Resiliency and Corporate Certification
Achieving Enterprise Resiliency and Corporate CertificationAchieving Enterprise Resiliency and Corporate Certification
Achieving Enterprise Resiliency and Corporate Certification
 
Asset Management (Acquisition, Redeployment, and Termination)(
Asset Management (Acquisition, Redeployment, and Termination)(Asset Management (Acquisition, Redeployment, and Termination)(
Asset Management (Acquisition, Redeployment, and Termination)(
 
Application migration guideline document
Application migration guideline documentApplication migration guideline document
Application migration guideline document
 
Tape vaulting audit and encryption usage analysis
Tape vaulting audit and encryption usage analysisTape vaulting audit and encryption usage analysis
Tape vaulting audit and encryption usage analysis
 
Achieving Enterprise Resiliency and Corporate Certification
Achieving Enterprise Resiliency and Corporate CertificationAchieving Enterprise Resiliency and Corporate Certification
Achieving Enterprise Resiliency and Corporate Certification
 

Último

Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service MumbaiLow Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbaisonalikaur4
 
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original PhotosBook Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photosnarwatsonia7
 
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Call Girls Thane Just Call 9910780858 Get High Class Call Girls Service
Call Girls Thane Just Call 9910780858 Get High Class Call Girls ServiceCall Girls Thane Just Call 9910780858 Get High Class Call Girls Service
Call Girls Thane Just Call 9910780858 Get High Class Call Girls Servicesonalikaur4
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...Miss joya
 
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% SafeBangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safenarwatsonia7
 
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service LucknowVIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknownarwatsonia7
 
call girls in munirka DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in munirka  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in munirka  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in munirka DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
Call Girl Koramangala | 7001305949 At Low Cost Cash Payment Booking
Call Girl Koramangala | 7001305949 At Low Cost Cash Payment BookingCall Girl Koramangala | 7001305949 At Low Cost Cash Payment Booking
Call Girl Koramangala | 7001305949 At Low Cost Cash Payment Bookingnarwatsonia7
 
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...narwatsonia7
 
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort ServiceCollege Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort ServiceNehru place Escorts
 
Glomerular Filtration rate and its determinants.pptx
Glomerular Filtration rate and its determinants.pptxGlomerular Filtration rate and its determinants.pptx
Glomerular Filtration rate and its determinants.pptxDr.Nusrat Tariq
 
Asthma Review - GINA guidelines summary 2024
Asthma Review - GINA guidelines summary 2024Asthma Review - GINA guidelines summary 2024
Asthma Review - GINA guidelines summary 2024Gabriel Guevara MD
 
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort ServiceCall Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Serviceparulsinha
 
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...narwatsonia7
 

Último (20)

sauth delhi call girls in Bhajanpura 🔝 9953056974 🔝 escort Service
sauth delhi call girls in Bhajanpura 🔝 9953056974 🔝 escort Servicesauth delhi call girls in Bhajanpura 🔝 9953056974 🔝 escort Service
sauth delhi call girls in Bhajanpura 🔝 9953056974 🔝 escort Service
 
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service MumbaiLow Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
 
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original PhotosBook Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
 
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
 
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
 
Call Girls Thane Just Call 9910780858 Get High Class Call Girls Service
Call Girls Thane Just Call 9910780858 Get High Class Call Girls ServiceCall Girls Thane Just Call 9910780858 Get High Class Call Girls Service
Call Girls Thane Just Call 9910780858 Get High Class Call Girls Service
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
 
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
Russian Call Girls in Pune Riya 9907093804 Short 1500 Night 6000 Best call gi...
 
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
 
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% SafeBangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
 
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service LucknowVIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
 
call girls in munirka DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in munirka  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in munirka  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in munirka DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
Call Girl Koramangala | 7001305949 At Low Cost Cash Payment Booking
Call Girl Koramangala | 7001305949 At Low Cost Cash Payment BookingCall Girl Koramangala | 7001305949 At Low Cost Cash Payment Booking
Call Girl Koramangala | 7001305949 At Low Cost Cash Payment Booking
 
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
 
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort ServiceCollege Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
 
Glomerular Filtration rate and its determinants.pptx
Glomerular Filtration rate and its determinants.pptxGlomerular Filtration rate and its determinants.pptx
Glomerular Filtration rate and its determinants.pptx
 
Asthma Review - GINA guidelines summary 2024
Asthma Review - GINA guidelines summary 2024Asthma Review - GINA guidelines summary 2024
Asthma Review - GINA guidelines summary 2024
 
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort ServiceCall Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
 
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
Call Girls Service in Bommanahalli - 7001305949 with real photos and phone nu...
 

Updated Healthcare Industry Compliance Presentation

  • 1. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 1 Adhering to Healthcare Industry Regulations Proposal to Healthcare Providers on how to adhere to Regulatory Requirements, and insure a Safe Workplace (Related to “Patient Protection and Affordable Care Act” – PPACA) including: • HIPAA, HITECH, ePHI, and the Final Ombudsman Rule (Medicare / Medicaid) • Workplace Safety, Security and Threat Elimination Via Workplace Violence Prevention (OSHA, DHS, NFPA 1600 and OEM), and mandated • Workflow Optimization / Employee Training Management. Proposed by: Thomas Bronack, President Data Center Assistance Group, Inc. 15180 20th Avenue Whitestone, New York 11357 Email: bronackt@dcag.com Cell Phone: (917) 673-6992 Audience Includes: • Hospitals, Clinics, Doctors Offices; and • Business Associates providing services to Healthcare Organizations.
  • 2. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 2 Adhering to Healthcare Industry Regulations Healthcare is Sick and Needs to be Fixed (Medicare / Medicaid) • Patient Costs Soar, while Services Suffer: • Redundant Testing and Litigation Fears; • Inefficient workflow and supply chain operations; • New Patient Freedoms allow for the Sharing of Patient Authorized Medical Records, while restricting unauthorized use and sale of data; • Improved Electronic Collaboration for remote assistance; • Examining Medical Information to uncover trends , diagnose symptoms, and formulate remediation's. • Laws and Regulations must be adhered to, including: • HIPAA – Health Insurance Portability and Accountability Act (1996) to improve awareness and efficiency; • HITECH - Health Information Technology for Economic and Clinical Health (2009) includes more stringent regulations and sanctions; • ePHI – electronic Personal Health Information (2009) to safeguard all forms of patient information (paper, electronic, video, audio, etc.) against unauthorized use and sale; • Final Omnibus Rule (1/25/2013) states specific compliance guidelines and defines the final Privacy, Security, and enforcement fines and sanctions: • “Meaningful Use” clause can reimburse electronic record conversion ($40-60K); • Patient Protection and Affordable Care Act (PPACA), sometimes known as Obama Care; • Healthcare Organizations and their Business Associates must comply by 9/23/2013; • States Attorney Generals can bring lawsuits on behalf of private individuals for breach of Privacy Rules; and, • Compliance will be aggressively enforced to reduce cost and improve patient services. • Applies to Healthcare Organizations and their Business Associates. • Designed to improve services and reduce costs through new technologies and procedures.
  • 3. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 3 Adhering to Healthcare Industry Regulations Purpose of Presentation and Deliverables that can be achieved • Define healthcare industry New and Existing Compliance Regulations; • Review Patient Protection and Affordable Care Act (referred to as - Obama Care); • Discuss New Patient Freedoms related to patient information sharing; • Show how “Joint Commission Accrediting Healthcare Organization” (JCAHO) certification can be achieved and why it is a benefit; • Suggest methods to perform Risk Management, Auditing, and Incident Reporting; • Demonstrate how better utilization of Information Technology, Data Management, and Access Controls can create a safeguarded and efficient environment; • Determine Security and Emergency Response Planning needed to “Protect the Workplace”, “Safeguard Patients Rights”, and “Comply with Regulatory Requirements”; • Create a project plan / road map to Implement Physical and Data Security; • Assist in the development and Implementation of Emergency Response Plans; • Implement a Workflow Management System to insure Forms Management and Controls; • Document new Standards and Procedures needed to better protect patients, achieve a safeguarded environment, and improve efficiency; • Provide Employee Awareness and Training; and, • Provide Integration, Support, and Maintenance going forward.
  • 4. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 4 Adhering to Healthcare Industry Regulations Audience and Compliance Requirements Healthcare Industry Patient Security & Safety New Patient Freedoms Workplace Protection Penalties and Financial Losses Training and Awareness Risk Management Response Identification and Planning • Hospitals; Clinics; Doctors Offices; and, • Business Associates and Sub-Contractors. • HIPAA; HITECH; ePHI; and Final Omnibus Rule. • “Meaningful Use” reimbursement for electronic data ($40-60K) • Ability to have records transferred by request of patient or their authorized representative (Record Sharing). • Responsible for protecting employees, patients, and visitors; • OSHA, DHS, OEM, and NFPA 1600; • Workplace Violence Prevention; • Workplace Physical Security and Evidence Capturing; and, • Ability to evacuate patients in Emergency Mode. • Criminal and Civil penalties; fines up to $1.5 million per occurrence taking effect 9/23/2013. • Staff must be aware of requirements and trained on how to respond to a wide-range of disaster events. • Identification of Risks and potential Disaster Event obstacles. • Mitigate Gaps and Exceptions; Mediate obstacles blocking the ability to respond to Disaster events; insure the ability to respond to encountered incidents; have the ability to provide a safeguarded environment capable of providing enhanced protections and efficiency while achieving compliance. Integrate within the everyday functions and environment.
  • 5. Healthcare Provider Proposal Page: 5 Adhering to Healthcare Industry Regulations Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 • Physical (Guards, CCTV, Card Keys, etc.) and Data Security Service Providers; • IT Equipment, Software, Consulting, and Support Vendors; • Lawyers, Accountants, and Auditors; • Leasing firms and other financial providers; • Telephone and Communications Vendors; • Shredding Vendors, Waste Disposal, and Transportation; • Primary and Secondary Data Centers; • Cloud Computing and Virtualization Service Providers; • Answering Services for Medical Offices; • Medical Billing Services; • Medical Transcriptions Services; • Medical Collection Agencies; and, • Cleaning, Disposal, and internal Service staff. The best protection is to perform a Risk Analysis to determine regulatory gaps and exceptions that must be mitigated, along with impeding obstacles that must be mediated. Then implement controls and procedures to create a safeguarded and compliant environment. Who is effected by these changes? Business Associates and Contractors including:
  • 6. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 6 Adhering to Healthcare Industry Regulations History and purpose of HIPAA rules and regulations, from original to current updates. • 1996 - Initially HIPAA was introduced to improve efficiency and effectiveness of the U.S. Healthcare System through guidelines and regulatory requirements. • 2/2009 – (HITECH) Health Information Technology for Economic and Clinical Health Act was introduced as part of the American Recovery and Reinvestment Act covering health records from paper based through all types of current and future electronic health records. • 1/25/2013 – The Final Omnibus Rule was published by the Federal Register to include more stringent privacy and security protection for patients (to be en-acted 9/23/13). • Rule also increased sanctions and penalties for failure to comply, including the right of States Attorneys General to bring lawsuits on behalf of private individuals for breach of the Privacy Rule. • The Security Rule expands data protection to include electronic media and electronic Personal Health Information (ePHI) - covering paper, video, OCR, Social Media, and electronic media. • Although HITECH has been enforceable since 2/2010 many organizations have failed to take action to fully comply, thereby risking penalties, financial loss, patient services, and reputational loss that could damage the ability to continue serving the public’s medical needs. • Included in Patient Protection and Affordable Care Act (Obama Care) to reduce costs and improve service. • HIPAA was developed to improve the education of hospital and medical record keepers on the rules and regulations that must be followed to safeguard patients. The Final Omnibus Rule and Patient Protection and Affordable Care Act provide a more detailed explanation of these safeguards and how best to protect the rights and privacy of patients.
  • 7. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 7 Adhering to Healthcare Industry Regulations HIPAA Contingency Planning and Security Guidelines (newly updated) Administrative Safeguards include: • Security Management Process (for People, Physical Environments and Data); • Assigned Security Responsibility (Management through all levels of Personnel); • Workforce Security (Procedures governing personnel Screening through Termination); • Information Access Management (Data Sensitivity, Access Controls, Backup / Recovery, etc.) • Security Awareness and Training; • Security Incident Procedures (from identification through “Root Cause” analysis, resolution; Logging, Tracking, Reporting, and Repository Maintenance); • Contingency Plan (Disaster, Business, Emergency, and Crisis Management Responses); • Evaluation (Risk Analysis and Periodic Reviews, with Attestation by Executive Management); and, • Business Associate Contact and Other Arrangements (from definition to accreditation). Physical Safeguards include: • Facility Access Controls (Physical Security to produce a safe workplace); • Workstation Use; • Workstation Security; and, • Device and Media Controls. Technical Safeguards include: • Access Controls (Data Security and elimination of Data Corruption); • Audit Controls; • Integrity; • Person and Entity Authentications (User Entitlements); and, • Transmission Security (Local and Remote / Encryption).
  • 8. Violation Category Section 1176 (a) (1): A. Did Not Know B. Reasonable Cause C. 1. – Willful Neglect – Corrected C. 2. – Willful Neglect – Not Corrected Each Violation: $100 to Max of $5,000 $1,000 to Max of $50,000 $10,000 to Max of $50,000 $50,000 All such Violations of an identical provision in a calendar year: $1,500,000 $1,500,000 $1,500,000 $1,500,000 Penalties for non-Compliance CATEGORIES OF VIOLATIONS AND RESPECTIVE PENALTY AMOUNTS AVAILABLE As you can see, penalties and loss of reputation can grow rapidly through repeated violations Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 8 Adhering to Healthcare Industry Regulations
  • 9. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 9 Adhering to Healthcare Industry Regulations Steps that lead to Achieving Compliance Goals and Objectives • Perform a Risk Assessment, conduct a Physical / Data Security evaluation, and review Emergency Response Plans regarding compliance issues; • Conduct a Workflow Analysis to uncover inefficiencies and Supply Chain flaws; • Define Gaps, Exceptions, and Obstacles that must be Mitigated and Mediated; • Establish Direction / Project Plan to resolve issues and gain approval; • Implement Mitigations and Mediations, including: Compliance, Controls, Emergency Response Plans, and Incident Management procedures; • Provide Awareness and Training to employees and business associates; • Achieve compliance to HIPAA, ePHI, HITECH, and Final Omnibus Rule; • Achieve JCAHO certification, leading to improved business and profitability; and, • Provide Implementation, Support, and Maintenance going forward.
  • 10. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 10 Adhering to Healthcare Industry Regulations HIPAA Five Step Circle of Compliance Global Tracking: - Incidents Mediation; - Gaps & Exception Mitigation; - Training; - Authorizations and Disclosures; - Document Repository. Reporting and Visualization: - Audit Reports; - Tracking Reports; - Dashboard View; - Change Management. Compliance Management Tools: - Easy to Use (like MS Office based); - Regulation Look-Up; - Enterprise Level Access; - Third Party Data Integration. Account Management: - Member Management; - Vendor Management; - Business Associate; and, - Management and Technical Reporting. Auditing and Remediation: - Gap and Obstacle Collection; - Reported Problems & Incidents; - Remediation and Mitigation; - Audit Workflow Definition; - Audit Workflow Optimization.
  • 11. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 11 Adhering to Healthcare Industry Regulations Accounts: • Members (Staff and Affiliates); • Vendors and Business Associates: and, • Vendor Questionnaire Design and Completion. Auditing: • Audit Questionnaire; * Incidents; • Gaps and Exceptions; * Obstacles; and, • Remediation Planning and Execution. Tracking: • Training Sessions; • Authorization and Disclosures; • Document Manager (Version Control); and, • Employee Policy / Procedure Viewer. Reporting: • Gap & Exception Analysis; * Remediation Summary; • Questionnaire Results; * Incident Summary; • Training History; * Authorization Summary; • Disclosure Summary; * Member Breakdown; • Vendor Breakdown; and, * Employee Policy / Procedure Crosswalk. Administration: • Preferences; * Update Password; • Guard Users; * Custom Mandates; • Custom Regulations; * Custom Questions. Technical Glossary: • Technical Glossary; * Change Facilities; • Status Alerts; * Help; • Support; and * Logout. Healthcare Industry Workflow Management System Goals RDBMS Programs Data
  • 12. 3. Service Transition • Change Management (Problems & Enhancements) • Project Management (Transition Planning and Support) • Release and Deployment Management (V & R Mgmt.) • Service Validation and Testing • Application Development and Customization • Service Asset and Configuration Management • Knowledge Management (Training & Awareness) 4. Service Operation • Event Management • Incident Management • Request Fulfillment • Access Management • Problem Management • IT Operations Management • Facilities Management 1. Service Strategy • Service Portfolio Management (available Services and Products) • Financial Management (PO, WO, A/R, A/P, G/L, Taxes, and Treasury) 2. Service Design • Service Catalogue Management • Service Level Management (SLA / SLR) • Risk Management (CERT / COSO) • Capacity / Performance Management • Availability Management (SLA / SLR) • IT Service Continuity Management (BCM) • Information Security Management (ISMS) • Compliance Management (Regulatory) • Architecture Management (AMS, CFM) • Supplier Management (Supply Chain) ITIL Available Modules ITIL Five Phase approach to IT Service Support 1. Service Strategy, 2. Service Design, 3. Service Transition, 4. Service Operation, and 5. Continual Service Improvement. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 12 Adhering to Healthcare Industry Regulations Example of existing Workflow Management System ITIL stands for: Information Technology Information Library
  • 13. Workflow Management / Training System Interfaces & Flow Work Request Workflow Analysis & Training System Analyze Workload and Type of Work Log, Assign And Track Work Workload Too High ? New Work / Tool ? Prioritize Work on “To-do” List (Date & Priority) Move Work To Designated Worker Automated Personnel System Automated Training System Completion & movement to last worker Audit Trail Analyze and Report Close Request New Tool, New Staff, New Procedure Staff Request Based on Work Volume Workload level and New Tool Analysis Workload levels can accept new work, without personnel change. Y Y N N Newly Recruited Personnel Newly Trained Personnel Reports Audit Log Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 13 Adhering to Healthcare Industry Regulations High Low Normal (Request through fulfillment, with staffing increases and training as deemed necessary) New Staff New Training Workflow Life Cycle Workload levels can accept new work, with new personnel updates /training changes. Workflow Forms Management System Existing Personnel
  • 14. • Mandated to insure patient safety (right medication and on-time delivery), staff training, and certification in gain compliance to regulatory requirements. • Create and respond to a Needs Analysis Questionnaire to identify Gaps & Exposures, Obstacles, and to define deliverables, time lines, and scope. • Review current forms, workflows, and controls. • Identify personnel associated with forms processing. • Redesign Forms and Workflow associated with forms, as needed. • Develop Forms Data Base System. • Implement Forms Management System functions and flows. • Create User Interface to Forms Management System. • Produce Management, Technical, and User Analysis Reports. • Document Forms Management System. • Supply Awareness and Training to staff, employees and associates. • Roll-out Forms Management System / Training System. • Support and Maintain Forms Management / Training System going forward. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 14 Adhering to Healthcare Industry Regulations Building a Workflow Management / Training System
  • 15. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 15 Adhering to Healthcare Industry Regulations Joint Commission on Accreditation of Healthcare Organizations (JCAHO) review • JCAHO is a pro-active investigator, while HIPAA is an exception driven investigator; • Covers Hospitals, Nursing Homes, Office-Based Surgery Practices, Home Care Providers and Laboratories, along with their Business Associates; • Most prestigious Healthcare Industry Accreditation Organization; • Certification assures patients and providers that the healthcare organization has achieved the highest standards required by the industry; • To achieve certification both healthcare organizations and their staff members must be able to demonstrate proficiency across specific job competencies and compliance issues; • Both Healthcare Organizations and their Business Associates must adhere to regulatory requirements and competencies; • JCAHO Certification will help you achieve: a competitive edge; an educated staff; an improved ability to retain and recruit staff; improved morale; new business; a higher level of safety; and a safeguarded and compliant workplace.
  • 16. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 16 Adhering to Healthcare Industry Regulations Sitting Area Admitting Area Financing Area Finance Waiting Area Emergency Room Guards Area Sliding Door 2 4 5 3 Patient Movement to gain entrance to Emergency Room: 1. Patients enter past Guards Desk (no verification or scan); 2. Patient waits for admittance in waiting area (unsupervised); 3. Patient is Admitted and Vital Signs Taken (ID Shown); 4. Patient goes to Finance where they are Identified and insurance papers validated (first true check of identity); 5. Patient waits to be called to go to Emergency Room where they are examined by staff; and 6. Patient is admitted to hospital, or treated and sent home. Signifies where card key doors can be installed to restrict access to hospital area by unauthorized personnel (low cost solution to high cost problem) Signifies patient movement General Hospital Area Initial Area Examined Problem Analysis: • Lack of security at ER area can lead to Threat: • Identification at Entrance; • Metal Scanner or Search for weapons; • Surveillance and Cameras for evidence; • Restrictive movement of patients. • Possible Weaknesses: • Unidentified people accompanying patients; • Unrestrictive movement can lead to terrorism; • Possible threat to people and hospital reputation. • Possible Threats include: • Terrorism and Active Shooter; • Deranged People acting out; • Disgruntled personnel; and • Civil Disorder. • Possible Repercussions include: • Bombs and Guns; • Deaths and Destruction or property; • Damage to facilities causing outage of service to community; • Loss of reputation; and • Loss of business and many law suits, with potential facility closing. Card Key access requirements can restrict movement at a low cost and CCTV can provide evidence to prosecute. Initial Physical Security Review from Admittance to ER acceptance (Real World). 6 1 5 Discharged Admitted
  • 17. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 17 Adhering to Healthcare Industry Regulations Benefits, Savings, and New Business possibilities • Learn existing and new Healthcare Industry compliance laws and regulations; • Identifying audience that must comply to Healthcare Industry regulations; • Risk Assessment to define current gaps, exceptions, and obstacles impeding compliance; • Formulate direction plan to achieve compliance and implement a Workflow Management System that improves efficiency and better safeguards patient information and services; • Achieve Physical and Data Security requirements; • Better utilize Information Technology to achieve goals and improve efficiency; • Adhere to compliance requirements; • Update Functional Responsibilities and Job Descriptions, as needed; • Fully Document upgraded environment in Standards and Procedures Manual and Usage Guides; • Implement Awareness and Training programs, as required; • Achieve JCAHO certification; and, • Utilize compliance upgrade and JCAHO certification to advertise the healthcare organization, attract new patient and insurance business, and retain and attract personnel who have a high morale.
  • 18. Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 Healthcare Provider Proposal Page: 18 Adhering to Healthcare Industry Regulations Achieving Compliance Goals, Objectives, and Tasks to be performed Goals and Objectives are: • Use this “Gateway” document to help achieve compliance requirements; • Obtain JCHAO certification based on compliance; • Obtain reimbursement via “Meaningful Use” directive for electronic data conversion; • Implement a Safeguarded and efficient environment that complies with all laws and regulations for both the Healthcare Organization and their Business Associates. Tasks to be performed are: • Presentation as a teaching tool and awareness vehicle for compliance issues; • Stakeholder identification and team formulation; • Team Awareness, Education, Work Plan, Assignments, and Reporting Schedule; • Risk Assessment to define Gaps, Exceptions, and Obstacles; • Repair / Control Plan to Mitigate Gaps & Exceptions, Mediate Obstacle & Impediments; • Project Plan including deliverable’s, schedule, resources, time line, and costs; • Perform tasks to certify Healthcare Organization, Associates, and Supply Chain; • Perform tasks needed to gain compliance certification (JCHOA Compliant); • Integrate Workflow Management, Compliance Procedures, and Response Plans; • Develop and publish all needed documentation; • Provide Awareness and Educational Training; • Integrate process within everyday functions performed by personnel; and, • Provide ongoing Support and Maintenance going forward.
  • 19. Healthcare Provider Proposal Page: 19 Adhering to Healthcare Industry Regulations Thomas Bronack © Data Center Assistance Group, Inc. Release Date; 4/27/13 I look forward to working with you to achieve the goals of this proposal. Points that should be remembered include: • The CEO is responsible for producing a safeguarded and efficient environment that is in compliance with HIPAA, OSHA, NFPA 1600, and DHS regulations (at a minimum); • Specific new healthcare regulatory requirements are identified in this presentation; • “Meaningful Use” reimbursement for converting Medicare / Medicaid file conversion to electronic data can be as high as $40 - $60K per conversion • The CEO can not delegate his responsibility, only share some responsibilities with insurance companies; • Damages from lawsuits can run into the multiple millions and over all damages can exceed billions; • Loss of reputation can result in the closing of the facility; • Damages to the community can be extensive; • Criminal and Civil charges can result in jail time and extensive monetary penalties; and • Only you can take the initiative to implement a safeguarded environment that is in compliance with all regulatory requirements, while improving productivity and personnel morale. “It is better to set the example than to be the example”. I can be reached via the following contact information: Thomas Bronack, President Data Center Assistance Group, Inc. 15180 20th Avenue Cell Phone: (917) 673-6992 Whitestone, New York 11357 Email: bronackt@dcag.com Thank you