Categories
- Arts & Entertainment
- Business
- Advertising
- Bookkeeping
- Branding
- Careers
- Careers Employment
- Change Management
- Communication
- Corporate
- Customer Service
- Entrepreneurialism
- Ethics
- Financing
- Franchise
- Fundraising
- Human Resources
- Management
- Marketing
- Marketing Direct
- Negotiation
- Networking
- Outsourcing
- Partnerships
- PR
- Presentation
- Public Relations
- Resumes Cover Letters
- Sales
- Sales Management
- Sales Teleselling
- Sales Training
- Small Business
- Strategic Planning
- Team Building
- Top7 or 10 Tips
- Venture Capital
- Workplace Communication
- Communications
- Computers
- Culture & Society
- Disease & Illness
- Fashion
- Finance
- Food & Beverage
- Health & Fitness
- Hobbies
- Home & Family
- Home Based Business
- Internet Business
- Legal
- Pets & Animals
- Politics
- Product Reviews
- Recreation & Sports
- Reference & Education
- Religion
- Self Improvement
- Shopping
- Travel & Leisure
- Vehicles
- Writing & Speaking
Information
Medical Billing, HIPAA Compliance, and Role Based Access Control
HIPAA compliance requires special focus and effort as failure to comply carries significant risk of damage and penalties. A practice with multiple separate systems for patient scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. This article presents an integrated approach to HIPAA compliance and outlines key HIPAA terminology, principles, and requirements to help the practice owner to ensure HIPAA compliance by medical billing service and software vendors.
The last decade of the previous century witnessed accelerating proliferation of digital technology in health care, which, along with reduced costs and greater service quality, introduced new and greater risks for accidental disclosure of personal health information.
The Health insurance Portability and Accountability Act (HIPAA) was passed in 1996 by Congress to establish national standards for privacy and security of personal health data. The Privacy Rule, written by the US Department of Health and Human Services took effect on April 14, 2003.
Failure to comply with HIPAA risks accreditation and reputation damage, lawsuits by federal government, financial penalties, ranging from $100 to $250,000, and imprisonment, ranging from one year to ten years.
Protected Health Information (PHI)
The key term of HIPAA is Protected Health Information (PHI), which includes anything that can be used to identify an individual and any information shared with other health care providers or clearinghouses in any media (digital, verbal, recorded voice, faxed, printed, or written). Information that can be used to identify an individual includes:
- Name
- Dates (except year)
- Zip code of more than 3 digits, telephone and fax numbers, email
- Social security numbers
- Medical record numbers
- Health plan numbers
- License numbers
- Photographs
Information shared with other healthcare providers or clearinghouses
- Nursing and physician notes
- Billing and other treatment records
Principles of HIPAA
HIPAA intends to allow smooth flow of PHI for healthcare operations subject to patient's consent but prohibit any flow of unauthorized PHI for any other purposes. Healthcare operations include treatment, payment, care quality assessment, competence review training, accreditation, insurance rating, auditing, and legal procedures.
HIPAA promotes fair information practices and requires those with access to PHI to safeguard it. Fair information practices means that a subject must be allowed
- Access to PHI,
- Correction for errors and completeness, and
- Knowledge of others who use PHI
Safeguarding of PHI means that the persons that hold PHI must
- Be accountable for own use and disclosure
- Have a legal recourse to combat violations
HIPAA Implementation Process
HIPAA implementation begins upon making assumptions about PHI disclosure threat model. The implementation includes both pre-emptive and retroactive controls and involves process, technology, and personnel aspects.
A threat model helps understanding the purpose of HIPAA implementation process. It includes assumptions about
- Threat nature (Accidental disclosure by insiders? Access for profit? ),
- Source of threat (outsider or insider?),
- Means of potential threat (break in, physical intrusion, computer hack, virus?),
- Specific kind of data at risk (patient identification, financials, medical?), and
- Scale (how many patient records threatened?).
HIPAA process must include clearly stated policy, educational materials and events, clear enforcement means, a schedule for testing of HIPAA compliance, and means for continued transparency about HIPAA compliance. Stated policy typically includes a statement of least privilege data access to complete the job, definition of PHI and incident monitoring and reporting procedures. Educational materials may include case studies, control questions, and a schedule of review seminars for personnel.
Technology Requirements for HIPAA Compliance
Technology implementation of HIPAA proceeds in stages from logical data definition to physical data center to network.
- To assure physical data center security, the manager must
- Lock data center
- Manage access list
- Track data center access with closed circuit TV cameras to monitor both internal and external building activities
- Protect access to data center with 24 x 7 onsite security
- Protect backup data
- Test recovery procedure
- Secure networking - firewall protection, encrypted data transfer only
- Network access monitoring and report auditing
- Individual authentication - individual logins and passwords
- Role Based Access Control (see below)
- Audit trails - all access to all data fields tracked and recorded
- Data discipline - Limited ability to download data
Role Based Access Control (RBAC)
RBAC improves convenience and flexibility of systems management. Greater convenience helps reducing the errors of commission and omission in granting access privileges to users. Greater flexibility helps implement the policy of least privilege, where the users are granted only as much privileges as required for completing their job.
RBAC promotes economies of scale, because the frequency of changes of role definition for a single user is higher than the frequency of changes of role definitions across entire organization. Thus, to make a massive change of privileges for a large number of users with same set of privileges, the administrator only makes changes to the role definition.
Hierarchical RBAC further promotes economies of scale and reduces the likelihood of errors. It allows redefining roles by inheriting privileges assigned to roles in the higher hierarchical level.
RBAC is based on establishing a set of user profiles or roles according to responsibilities. Each role has a predefined set of privileges. The user acquires privileges by receiving membership in the role or assignment of a profile by the administrator.
Every time when the definition of the role changes along with the set of privileges that is required to complete the job associated with the role, the administrator needs only to redefine the privileges of the role. The privileges of all of the users that have this role get redefined automatically.
Similarly, if the role of a single user is changed, the only operation that needs to be performed is the reassignment of the user profile, which will redefine user's access privileges automatically according to the new profile.
Summary
HIPAA compliance requires special practice management attention. A practice with multiple separate systems for scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. An integrated system reduces the complexity of HIPAA implementation. By outsourcing technology to a HIPAA-compliant vendor of vericle-like technology solution on an ASP or SaaS basis, HIPAA management overhead can be eliminated (see companion papers on ASP and SaaS for medical billing).
Yuval Lirov, PhD, author of "Mission Critical Systems Management" (Prentice Hall, 1997), inventor of multiple patents in artificial intelligence and computer security, and CEO of Vericle.com Billing Technologies. Vericle delivers comprehensive practice workflow engine that integrates patient scheduling, electronic medical records (EMR), billing, transcription, and compliance management. It improves billing performance and reduces audit risk. Yuval invites you to post questions about and share your knowledge of medical billing and compliance at BillingWiki.com.
Article source: Expert Articles
Most Recent Articles in Outsourcing category
- Staff Leasing Services for Greater Progress - By: Joan Rivera
Staff leasing services are service features provided by BPO companies. These services are geared towards the completion of a business project which will be done by the BPO's employees using the BPO's resources. Such projects are usually consolidated to staff leasing services when the client is unable to hold local operations due to the cost of the project, employee availability issues, or inability to conduct operations management. Staff leasing services begin when an outsourcing agreement is sealed between the BPO and client. Qualifications such as level of expertise, work experience, and expected salary are taken into consideration when the BPO starts hiring employees. These employees will comprise the offshore team which will work on the client's business project. Because of the many advantages offered exclusively by staff leasing services, businesses should resort to outsourcing in order to attain greater progress in the business arena. - How and why to opt for a lease agreement with your photocopier - By: Mr Printer
If you do not want to buy a photocopier for whatever reason, financial or unsure of your future business circumstances, there is always the option to lease a photocopier. There are many advantages to leasing a photocopier. - Medical Devices Outsourcing from Asia - The Best Choice - By: KK Tsang
To keep their competitiveness due to price pressure, more and more medical device manufacturers of disposable devices from the US and Europe are coming to Asia to outsource the manufacturing of their products. They all have one big issue, how and where to locate the most suitable outsourcing partner? After reviewing a number of criteria, a Hong Kong medical device contract manufacturer with its manufacturing facility in Shenzhen, China is the best option. - Freelance Security Consultants - By: Peter Bolt
The functions of Security Consultants are described with supporting examples. - Outsourcing CAD,CAM,CAE,AEC projects, AutoCAD jobs, freelance work, CAD symbols - By: David Maxwell
Survival in the CAD industry is guaranteed only if you are willing to dedicate your skills, expertise and professional experience to the B2B CAD outsourcing market. Working as freelance CAD drafter is a potential option for you to increase your income and extend your CAD business. You can search for CAD projects and CAD jobs in search engines but it is far more efficient to use special sites that offer CAD work and CAD community like CADLore.com. - The Pros and Cons of Hiring a Freelancer - By: JR Pittman
If you're sitting at your desk wondering if using a freelance business resource is right for your company, here is a list of pros and cons that can help you make an intelligent decision. - Outsourcing Business Flyer Printing Over the Internet - By: Kaye Marks
Business process outsourcing or BPO is getting popular and popular especially in this global economy. Since the advent of the Internet, it is now possible to have a separate firm perform any kind of business process task that you need like flyer printing. - Same Day Couriers help to win the day! - By: Ian Sheldon
Have you ever ordered something, say from the Internet, and then wondered how it manages to get to you so quickly? - International Courier Solutions - By: Ian Sheldon
International courier services are a vital resource for many companies with global connections. From getting vital legal documents through to lawyers or customers to shipping samples and marketing materials, shipping items globally as fast as possible is something that a large number of companies require. - Advantages of IT Outsourcing to Ukraine and Eastern Europe - By: Alex Stasov
High-tech outsourcing to Eastern Europe has been growing rapidly due to a shortage of IT and other high-tech professionals in the United States and Europe. Outsourcing IT and high-tech projects offshore to Ukraine and Russia or hiring East European IT specialists for part or full-time jobs has become very common for corporations and start-up businesses. Numerous resources have been created online (e.g. High-Tech Hire) to facilitate the search of engineers, web designers and software developers.
