Shayne Magee, director, Client Solutions, Diversified Information Technologies
When you talk to prospects, what do they tell you is their biggest document processing challenge, and why?
Our prospects and clients typically have many customers. The relationship they have is one that requires efficient management of inbound and outbound documents and data. The biggest challenge has been finding a partner that has a complete solution. The solutions needs to seamlessly capture, output, processing, and preservation of increasingly compliant centric environments.
What is your company doing to address this challenge?
Diversified is continuing to develop our virtual mailroom and information lifecycle management solutions. Our solutions can be combined and interfaced seamlessly with our clients infrastructure and systems. All of our offerings are specifically designed to deploy quickly and solve this previously unmet industry challenge for a single source solution.
Additionally, We have been adding integrated document facilities across the country to support the requirements of our financial, healthcare, enterprise and government clients. We added five in the last 12 months and continue to invest in quality programs and certification to support our clients needs. Currently, Diversified holds the following certifications: NARA, ISO 9001, SaS 70 Type II, HIPAA, and, most recently, NAID.
What do you believe will be the major storyline in document processing over the next 12 months, and why?
We are in the middle of a swiftly moving trend of SaaS technology, which is allowing organizations to collaborate and communicate in real time streamlined processes that in many cases eliminate previous steps, antiquated systems, and documents. We feel SaaS-deployed applications, and the inclusion of the mobile Internet tsunami, will be the major ECM storyline in the next 12 months.
What’s the most interesting thing in the documents processing space that you’ve read about recently (that wasn’t put out by your own company)?
Some new data points from some AIIM research have been very interesting regarding the change in paper-based policies in a Facebook era. They forecast an evolution from systems of records to systems of engagement and potentially the end of email, wet signatures, and paper based transactions.
What do you think?
Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts
Wednesday, April 20, 2011
Wednesday, November 17, 2010
Efficiency and Transparency Key Issues in Healthcare Payments Automation
By Lee Barrett of EHNAC
There are major industry shifts already underway that will change how the payment and document industry transacts business. With the complexity of changes taking place in relation to how ARRA, HITECH and HIPAA affect our industries, every payment processor and document manager would be wise to keep a finger on the pulse of the hot topics of the day and trends that provide indication of future directions for the industry.
One important change is the fact that providers and banks will be able to provide reconciled data streams so that any needed claim adjustments can be minimized and there can be a marrying of the remittance and electronic funds transfer. The benefit of this reconciliation is that manual intervention becomes minimal for inputting data into accounts payable applications, and there are few additional contractual adjustments required as compared to the large number needed today. This is, of course, all to the benefit of the provider organization and ultimately the patient or payer.
The second recent trend is, in fact, the revitalization of an old trend. With the ever-increasing cost of health insurance, organizations are seeking more economical solutions to meet the needs of their employees. As a result of this, the industry is seeing healthcare savings plans regaining traction at a significant rate. Health savings accounts or HSAs are most frequently used in conjunction with a benefit debit card, and give employees the benefit of being able to put pre-tax dollars toward deductible payment or coverage of other health related services. Given the complexities of HITECH, HIPAA and COBRA, organizations and financial institutions offering HSAs are required to keep track of changing regulations regarding excise taxes and concerns related to health and financial data security, privacy and confidentiality.
A third recent trend the industry is witnessing arises from the consumer demand for transparency in their healthcare experience, and the desire to have all healthcare payment and records available through a single portal. These “Wealth Care portals” provide for connections and efficient processing of all healthcare needs for a patient, allowing a patient to determine what they owe different providers, by tracking their invoices and payments through a single site. These portals would also give patients the ability to make better-informed decisions, make use of calculators and tools to determine costs and savings and track the status of claims made to their health insurance.
The electronic healthcare and payment-document processing worlds are changing rapidly, with exciting developments coming to light almost daily. To ensure that these trends truly benefit our own customers, it makes sense to stay abreast of the changes, and constantly analyze what the changes mean to our organizations as well as to our stakeholders.
Lee Barrett is executive director of the Electronic Healthcare Network Accreditation Commission (EHNAC).
There are major industry shifts already underway that will change how the payment and document industry transacts business. With the complexity of changes taking place in relation to how ARRA, HITECH and HIPAA affect our industries, every payment processor and document manager would be wise to keep a finger on the pulse of the hot topics of the day and trends that provide indication of future directions for the industry.
One important change is the fact that providers and banks will be able to provide reconciled data streams so that any needed claim adjustments can be minimized and there can be a marrying of the remittance and electronic funds transfer. The benefit of this reconciliation is that manual intervention becomes minimal for inputting data into accounts payable applications, and there are few additional contractual adjustments required as compared to the large number needed today. This is, of course, all to the benefit of the provider organization and ultimately the patient or payer.
The second recent trend is, in fact, the revitalization of an old trend. With the ever-increasing cost of health insurance, organizations are seeking more economical solutions to meet the needs of their employees. As a result of this, the industry is seeing healthcare savings plans regaining traction at a significant rate. Health savings accounts or HSAs are most frequently used in conjunction with a benefit debit card, and give employees the benefit of being able to put pre-tax dollars toward deductible payment or coverage of other health related services. Given the complexities of HITECH, HIPAA and COBRA, organizations and financial institutions offering HSAs are required to keep track of changing regulations regarding excise taxes and concerns related to health and financial data security, privacy and confidentiality.
A third recent trend the industry is witnessing arises from the consumer demand for transparency in their healthcare experience, and the desire to have all healthcare payment and records available through a single portal. These “Wealth Care portals” provide for connections and efficient processing of all healthcare needs for a patient, allowing a patient to determine what they owe different providers, by tracking their invoices and payments through a single site. These portals would also give patients the ability to make better-informed decisions, make use of calculators and tools to determine costs and savings and track the status of claims made to their health insurance.
The electronic healthcare and payment-document processing worlds are changing rapidly, with exciting developments coming to light almost daily. To ensure that these trends truly benefit our own customers, it makes sense to stay abreast of the changes, and constantly analyze what the changes mean to our organizations as well as to our stakeholders.
Lee Barrett is executive director of the Electronic Healthcare Network Accreditation Commission (EHNAC).
Friday, November 12, 2010
The Top 5 Compliance Issues That Smolder Beneath The Surface
By Dan Wilhelms
When firefighters arrive at a burning building, their first priority (of course) is to knock down the visible flames. Yet experienced firefighters know that when those flames are extinguished, the job isn’t done yet. That’s the time they go in and start looking for the hidden flames – the smoldering materials in a ceiling or behind a wall that could suddenly erupt and engulf them when they’re not expecting it. They know those hidden fires can be the most dangerous of all simply because they can’t be seen until it’s too late.
For the past few years, IT and compliance managers have been like those firefighters first arriving on the scene. You’ve been putting out the compliance fires – the big issues that have been burning brightly since SOX legislation was passed in the early part of the millennium. You’ve done a good job too, creating a new compliance structure where roles are defined, segregation of duties (SOD) is the standard and transactions are well-documented.
Yet just like those firefighters, the job isn’t finished yet. There are still all kinds of compliance issues that, while not as visible as the first ones you tackled, can still create a back-draft that will burn your organization if you’re not careful. Following are five of the most pressing (and potentially dangerous).
Excessive access – With the complexity of the security architecture that is part of modern ERP systems, it’s easier than you might think to accidentally give some users access to potentially sensitive transactions that might be far outside their job descriptions. Access is usually assigned by the help desk, and in the heat of battle, with many pressing issues, they may not be as careful about assigning or double-checking authorizations as they should be. When that occurs, it can lead to all types of dangers.
Imagine a parts picker in the warehouse being given access to every SAP transaction in the organization (which has happened, by the way). In that instance, the warehouse worker started running and looking at transactions (including financial transactions) just out of curiosity. But what if he’d had a different agenda? He could have changed the data, either accidentally or maliciously, or executed a fraudulent transaction, creating a serious compliance breech.
Even if he didn’t change anything, there’s still a productivity issue. After all, if he’s busy running a myriad of SAP transactions, he’s not busy picking orders.
Excessive access is not the type of issue that will show up in a SOD report. The best way to address it is by installing governance, risk and compliance (GRC) software that makes managing security and authorization easier. The software should also provide you with tools that help you measure and monitor actual system usage so you can see whether the things users are doing and the places they’re going within the system are appropriate to their job requirements. Having automated systems in place is particularly important in smaller enterprises that usually do not have the resources for a lot of manual inspection.
Access to sensitive data – Users don’t necessarily need access to a broad variety of data to pose a risk; they just need access to particular data. For example who can open and close posting periods. Who can view HR salary and benefits information? Again, this is nothing that is likely to show up on a SOD report, yet it’s a very real risk.
We’ve all heard the stories about how a certain soft drink manufacturer’s formula is better-guarded than the launch codes for nuclear weapons. Imagine if the formula was sitting on the ERP system and the wrong person was given access to it – or given access to payroll, HIPAA or other sensitive information.
One key to controlling access to sensitive data, of course, is to exercise more care when assigning authorizations. This is called preventative controls. It’s also important to use reverse business engineering tools to see who does have access to sensitive transactions, whether that access is appropriate, and what they did with the information once they had it. This is called detective controls. It’s like following the smoke to discover where the hidden fire is.
Poor segregation of duties – Although SOD has already been mentioned, some organizations are not familiar with what it is and its purpose. Let’s look at the nuclear missiles analogy again. In order to launch, there are two keys controlled by two different people. Two keys are used to assure that no one person has control of the missiles in case someone decides to “go rogue.”
It’s the same with financial transactions in an enterprise. You don’t want one person to be able to create a vendor in your SAP system and then initiate payment of that same vendor; you’re just asking people to steal from you.
That’s why it’s important to have value-added tools that analyze user access against the enterprise’s SOD rulebook and flag any conflicting functions. An ongoing analysis will point out any areas of risk so they can be remediated, and keep you informed should the situation change.
Of course, in a smaller organization, conflicting duties may not be avoidable. Everyone is expected to wear multiple hats, and sometimes those hats do not allow for proper segregation. In those instances, you need to have tools that can monitor actual transactions and report against them so you can see if a compliance violation is occurring. In other words, if someone has to carry both keys, you know when they’ve inserted them both into the control panel through mitigating controls.
Even with the proper tools, it’s unlikely you’ll ever bring SOD conflicts down to zero. But you can get awfully darned close, and keep an eye on what happens from there.
Introduction of malicious programs into production systems – The modern reality is that ERP systems are rarely steady state. Often enterprises have multiple initiatives going on that introduce new data, configuration and programs into the production systems.
With lean staffing and urgent deadlines, often changes are not properly tested or audited. In other words, they don’t use proper change management. A developer who has the means to do it, the motive to do it and knows whether he/she can get away with it can wreak all kinds of havoc by including malicious code along with legitimate code when new applications are moved into production. Malicious code can download sensitive data, create fraudulent transactions, delete data or crash the systems.
It is critical to have a second person reviewing any changes at every step of the way. What that means is the person who requests the change can’t be the person who develops it; the developer can’t be the person who tests it; the person who tests it can’t be the same person who migrates it into production. In other words, transport development and approvals cannot be given by a single person – instead, an independent approver or even a committee must be controlling the entire process.
Change management duties need to be segregated and managed throughout the entire process. Even if not malicious, poorly coded, untested programs can result in a catastrophic outage. Given that in a large enterprise an hour of downtime can cost $1 million, it’s easy to see why proper change management is worth the investment.
Emergency access – In large ERP environments, there’s always the chance that emergency maintenance of production systems will need to be performed. When it does, and the enterprise is dialing 9-1-1, someone needs to be given emergency “super user” access to everything in the system. Such emergency maintenance is often by outside parties (e.g. the software vender or 3rd party consultants).
The problem is these emergency all-access passes aren’t always tracked very well. Everyone is so fixed on putting out the fire – for example unlocking a sales order that has frozen the entire system – that they never think about documenting what transactions were performed or what data was changed. The risk is increased by the widespread use of generic “firefighter” user IDs whereby the individual performing the actions isn’t definitively known.
You’d like to think that the person you give super user access to can be trusted. But blind trust is what has gotten other enterprises into trouble in the past. The person with full access may make other changes while he/she is in there – either accidentally or on purpose. You need to be able to monitor who has all-access and what they do while they have it.
It is critical to have tools that allow you to track what these super-users do while they’re in the system. Not just for the day-to-day operation of the business, but for the auditors as well. When auditors see someone has been given this additional emergency access, their job is to immediately assume the person did something nefarious. It will be your job to prove they didn’t. You’ll need to show why access was granted, what was done while the person was in there, when/how long the person was in the system, what changes were made and when the person exited.
While it’s important to put out the big compliance blazes, keep in mind those are the ones that are also easy to see. Once they’re under control, take a tip from the professional firefighters and be sure to check for the smaller, smoldering flashpoints. It’s your best insurance against getting burned.
Dan Wilhelms is President and CEO of SymSoft Corporation (www.controlpanelGRC.com, the makers of ControlPanelGRC, professional solutions for compliance automation. He can be reached at dwilhelms@sym-corp.com.
When firefighters arrive at a burning building, their first priority (of course) is to knock down the visible flames. Yet experienced firefighters know that when those flames are extinguished, the job isn’t done yet. That’s the time they go in and start looking for the hidden flames – the smoldering materials in a ceiling or behind a wall that could suddenly erupt and engulf them when they’re not expecting it. They know those hidden fires can be the most dangerous of all simply because they can’t be seen until it’s too late.
For the past few years, IT and compliance managers have been like those firefighters first arriving on the scene. You’ve been putting out the compliance fires – the big issues that have been burning brightly since SOX legislation was passed in the early part of the millennium. You’ve done a good job too, creating a new compliance structure where roles are defined, segregation of duties (SOD) is the standard and transactions are well-documented.
Yet just like those firefighters, the job isn’t finished yet. There are still all kinds of compliance issues that, while not as visible as the first ones you tackled, can still create a back-draft that will burn your organization if you’re not careful. Following are five of the most pressing (and potentially dangerous).
Excessive access – With the complexity of the security architecture that is part of modern ERP systems, it’s easier than you might think to accidentally give some users access to potentially sensitive transactions that might be far outside their job descriptions. Access is usually assigned by the help desk, and in the heat of battle, with many pressing issues, they may not be as careful about assigning or double-checking authorizations as they should be. When that occurs, it can lead to all types of dangers.
Imagine a parts picker in the warehouse being given access to every SAP transaction in the organization (which has happened, by the way). In that instance, the warehouse worker started running and looking at transactions (including financial transactions) just out of curiosity. But what if he’d had a different agenda? He could have changed the data, either accidentally or maliciously, or executed a fraudulent transaction, creating a serious compliance breech.
Even if he didn’t change anything, there’s still a productivity issue. After all, if he’s busy running a myriad of SAP transactions, he’s not busy picking orders.
Excessive access is not the type of issue that will show up in a SOD report. The best way to address it is by installing governance, risk and compliance (GRC) software that makes managing security and authorization easier. The software should also provide you with tools that help you measure and monitor actual system usage so you can see whether the things users are doing and the places they’re going within the system are appropriate to their job requirements. Having automated systems in place is particularly important in smaller enterprises that usually do not have the resources for a lot of manual inspection.
Access to sensitive data – Users don’t necessarily need access to a broad variety of data to pose a risk; they just need access to particular data. For example who can open and close posting periods. Who can view HR salary and benefits information? Again, this is nothing that is likely to show up on a SOD report, yet it’s a very real risk.
We’ve all heard the stories about how a certain soft drink manufacturer’s formula is better-guarded than the launch codes for nuclear weapons. Imagine if the formula was sitting on the ERP system and the wrong person was given access to it – or given access to payroll, HIPAA or other sensitive information.
One key to controlling access to sensitive data, of course, is to exercise more care when assigning authorizations. This is called preventative controls. It’s also important to use reverse business engineering tools to see who does have access to sensitive transactions, whether that access is appropriate, and what they did with the information once they had it. This is called detective controls. It’s like following the smoke to discover where the hidden fire is.
Poor segregation of duties – Although SOD has already been mentioned, some organizations are not familiar with what it is and its purpose. Let’s look at the nuclear missiles analogy again. In order to launch, there are two keys controlled by two different people. Two keys are used to assure that no one person has control of the missiles in case someone decides to “go rogue.”
It’s the same with financial transactions in an enterprise. You don’t want one person to be able to create a vendor in your SAP system and then initiate payment of that same vendor; you’re just asking people to steal from you.
That’s why it’s important to have value-added tools that analyze user access against the enterprise’s SOD rulebook and flag any conflicting functions. An ongoing analysis will point out any areas of risk so they can be remediated, and keep you informed should the situation change.
Of course, in a smaller organization, conflicting duties may not be avoidable. Everyone is expected to wear multiple hats, and sometimes those hats do not allow for proper segregation. In those instances, you need to have tools that can monitor actual transactions and report against them so you can see if a compliance violation is occurring. In other words, if someone has to carry both keys, you know when they’ve inserted them both into the control panel through mitigating controls.
Even with the proper tools, it’s unlikely you’ll ever bring SOD conflicts down to zero. But you can get awfully darned close, and keep an eye on what happens from there.
Introduction of malicious programs into production systems – The modern reality is that ERP systems are rarely steady state. Often enterprises have multiple initiatives going on that introduce new data, configuration and programs into the production systems.
With lean staffing and urgent deadlines, often changes are not properly tested or audited. In other words, they don’t use proper change management. A developer who has the means to do it, the motive to do it and knows whether he/she can get away with it can wreak all kinds of havoc by including malicious code along with legitimate code when new applications are moved into production. Malicious code can download sensitive data, create fraudulent transactions, delete data or crash the systems.
It is critical to have a second person reviewing any changes at every step of the way. What that means is the person who requests the change can’t be the person who develops it; the developer can’t be the person who tests it; the person who tests it can’t be the same person who migrates it into production. In other words, transport development and approvals cannot be given by a single person – instead, an independent approver or even a committee must be controlling the entire process.
Change management duties need to be segregated and managed throughout the entire process. Even if not malicious, poorly coded, untested programs can result in a catastrophic outage. Given that in a large enterprise an hour of downtime can cost $1 million, it’s easy to see why proper change management is worth the investment.
Emergency access – In large ERP environments, there’s always the chance that emergency maintenance of production systems will need to be performed. When it does, and the enterprise is dialing 9-1-1, someone needs to be given emergency “super user” access to everything in the system. Such emergency maintenance is often by outside parties (e.g. the software vender or 3rd party consultants).
The problem is these emergency all-access passes aren’t always tracked very well. Everyone is so fixed on putting out the fire – for example unlocking a sales order that has frozen the entire system – that they never think about documenting what transactions were performed or what data was changed. The risk is increased by the widespread use of generic “firefighter” user IDs whereby the individual performing the actions isn’t definitively known.
You’d like to think that the person you give super user access to can be trusted. But blind trust is what has gotten other enterprises into trouble in the past. The person with full access may make other changes while he/she is in there – either accidentally or on purpose. You need to be able to monitor who has all-access and what they do while they have it.
It is critical to have tools that allow you to track what these super-users do while they’re in the system. Not just for the day-to-day operation of the business, but for the auditors as well. When auditors see someone has been given this additional emergency access, their job is to immediately assume the person did something nefarious. It will be your job to prove they didn’t. You’ll need to show why access was granted, what was done while the person was in there, when/how long the person was in the system, what changes were made and when the person exited.
While it’s important to put out the big compliance blazes, keep in mind those are the ones that are also easy to see. Once they’re under control, take a tip from the professional firefighters and be sure to check for the smaller, smoldering flashpoints. It’s your best insurance against getting burned.
Dan Wilhelms is President and CEO of SymSoft Corporation (www.controlpanelGRC.com, the makers of ControlPanelGRC, professional solutions for compliance automation. He can be reached at dwilhelms@sym-corp.com.
Thursday, September 23, 2010
Online Storage and Privacy Laws
Posted by Mark Brousseau
If you store sensitive files on your personal computer which law enforcement authorities wish to examine, they generally cannot do so without first obtaining a search warrant based upon probable cause. But what if you store personal information online—say, in your Gmail account, or on Dropbox? What if you’re a business owner who uses Salesforce CRM or Windows Azure? How secure is your data from unwarranted governmental access?
Both the U.S. Senate and the House of Representatives are investigating these crucial questions in two separate hearings this week. Congress hasn’t overhauled the privacy laws governing law enforcement access to information stored with remote service providers since 1986. The Electronic Communications Privacy Act (ECPA), the key federal law governing electronic privacy, has grown increasingly out of touch with reality as technology has evolved and Americans have grown increasingly reliant on cloud services like webmail and social networking. As a result, government can currently compel service providers to disclose the contents of certain types of information stored in the cloud without first obtaining a search warrant or any other court order requiring the scrutiny of a judge.
Against this backdrop, the Competitive Enterprise Institute has joined with The Progress & Freedom Foundation, Americans for Tax Reform, Citizens Against Government Waste, and the Center for Financial Privacy and Human Rights in submitting a written statement to the U.S. Senate and House Judiciary Committees urging Congress to reform U.S. electronic privacy laws to better reflect users’ privacy expectations in the information age. The groups also belong to the Digital Due Process coalition, a broad array of public interest organizations, businesses, advocacy groups, and scholars who are working to strengthen U.S. privacy laws while also preserving the building blocks of law enforcement investigations.
“The success of cloud computing—and its benefits for the U.S. economy—depends largely on updating the outdated federal statutory regime that currently governs electronic communications privacy,” the statement argues. “If Congress wants to ensure Americans enjoy the full benefits of the cloud computing revolution, it should simply reform ECPA in accordance with the principles proposed by the Digital Due Process coalition.”
What do you think?
If you store sensitive files on your personal computer which law enforcement authorities wish to examine, they generally cannot do so without first obtaining a search warrant based upon probable cause. But what if you store personal information online—say, in your Gmail account, or on Dropbox? What if you’re a business owner who uses Salesforce CRM or Windows Azure? How secure is your data from unwarranted governmental access?
Both the U.S. Senate and the House of Representatives are investigating these crucial questions in two separate hearings this week. Congress hasn’t overhauled the privacy laws governing law enforcement access to information stored with remote service providers since 1986. The Electronic Communications Privacy Act (ECPA), the key federal law governing electronic privacy, has grown increasingly out of touch with reality as technology has evolved and Americans have grown increasingly reliant on cloud services like webmail and social networking. As a result, government can currently compel service providers to disclose the contents of certain types of information stored in the cloud without first obtaining a search warrant or any other court order requiring the scrutiny of a judge.
Against this backdrop, the Competitive Enterprise Institute has joined with The Progress & Freedom Foundation, Americans for Tax Reform, Citizens Against Government Waste, and the Center for Financial Privacy and Human Rights in submitting a written statement to the U.S. Senate and House Judiciary Committees urging Congress to reform U.S. electronic privacy laws to better reflect users’ privacy expectations in the information age. The groups also belong to the Digital Due Process coalition, a broad array of public interest organizations, businesses, advocacy groups, and scholars who are working to strengthen U.S. privacy laws while also preserving the building blocks of law enforcement investigations.
“The success of cloud computing—and its benefits for the U.S. economy—depends largely on updating the outdated federal statutory regime that currently governs electronic communications privacy,” the statement argues. “If Congress wants to ensure Americans enjoy the full benefits of the cloud computing revolution, it should simply reform ECPA in accordance with the principles proposed by the Digital Due Process coalition.”
What do you think?
Sunday, February 28, 2010
ARRA: A Whole New World
By Mark Brousseau
Last year was a year of transition for HIPAA, medical privacy and medical banking, Richard D. Marks of McLean, VA-based Patient Command, Inc. (www.patientcommand.com), told attendees this afternoon at the Medical Banking Project Boot Camp at the HIMSS10 conference in Atlanta.
“ARRA changes the rules for security of health information in the United States,” Marks said. “It creates an entirely new framework because it changes HIPAA so much and because it changes privacy in medical records. And, most significantly, it changes the whole approach to enforcement.”
“It’s fair to say that for the last decade, there has not been any real attempt on the part of the federal government to enforce HIPAA,” Marks explained. “ARRA changes that. What it brings into law, for the first time, is the hierarchy of diligence and culpability. There are increased, tiered civil and criminal monetary penalties, topping out at $50,000 per violation, with an annual limit of $1,500,000. These numbers are enough to get your attention. But the statute also includes civil and criminal liability for individuals, as well as organizations. Which individuals, you ask? Well, it could be you! And some people won’t figure this out, and you will see some prosecutions,” Marks predicted.
Integrated health information security is inherent in ARRA, Marks added.
References in business associate contracts now, by law, apply mutually to covered entities and business associates, Marks pointed out. “The impact of that is to rebalance all of the risk allocation that is in these agreements, and it creates a whole new set of possibilities for liabilities. Some folks will be less affected than others. But some of you will be affected will be enormously,” Marks said.
For instance, security is now an active responsibility of the board of directors and senior executives, if you are doing anything that touches healthcare, Marks said. “If you’re a public company you’ve really go to ask yourself how you do disclosure when you have to take on a much greater risk for your information systems,” Marks said. “What this all means is that you must have integrated, shared systems security that is comprehensive and fast, and upgraded from what you now have.”
Some of the changes in ARRA won’t go into effect until 2011. “But some of this is in effect now, because people, such as ambitious state attorneys general, are going to start enforcing HIPAA,” Marks said. “The bottom line is that ARRA makes it a whole new world in healthcare.”
Last year was a year of transition for HIPAA, medical privacy and medical banking, Richard D. Marks of McLean, VA-based Patient Command, Inc. (www.patientcommand.com), told attendees this afternoon at the Medical Banking Project Boot Camp at the HIMSS10 conference in Atlanta.
“ARRA changes the rules for security of health information in the United States,” Marks said. “It creates an entirely new framework because it changes HIPAA so much and because it changes privacy in medical records. And, most significantly, it changes the whole approach to enforcement.”
“It’s fair to say that for the last decade, there has not been any real attempt on the part of the federal government to enforce HIPAA,” Marks explained. “ARRA changes that. What it brings into law, for the first time, is the hierarchy of diligence and culpability. There are increased, tiered civil and criminal monetary penalties, topping out at $50,000 per violation, with an annual limit of $1,500,000. These numbers are enough to get your attention. But the statute also includes civil and criminal liability for individuals, as well as organizations. Which individuals, you ask? Well, it could be you! And some people won’t figure this out, and you will see some prosecutions,” Marks predicted.
Integrated health information security is inherent in ARRA, Marks added.
References in business associate contracts now, by law, apply mutually to covered entities and business associates, Marks pointed out. “The impact of that is to rebalance all of the risk allocation that is in these agreements, and it creates a whole new set of possibilities for liabilities. Some folks will be less affected than others. But some of you will be affected will be enormously,” Marks said.
For instance, security is now an active responsibility of the board of directors and senior executives, if you are doing anything that touches healthcare, Marks said. “If you’re a public company you’ve really go to ask yourself how you do disclosure when you have to take on a much greater risk for your information systems,” Marks said. “What this all means is that you must have integrated, shared systems security that is comprehensive and fast, and upgraded from what you now have.”
Some of the changes in ARRA won’t go into effect until 2011. “But some of this is in effect now, because people, such as ambitious state attorneys general, are going to start enforcing HIPAA,” Marks said. “The bottom line is that ARRA makes it a whole new world in healthcare.”
Friday, February 26, 2010
The Other Story at HIMSS
By Mark Brousseau
While Electronic Health Records (EHR) and the impact of the recent definition of the meaningful use requirements will be hot topics at next week's HIMSS Conference in Atlanta, HERAE CEO Jim Ribelin thinks a program underwritten by the new HIMSS Medical Banking Project bears watching.
The project, called Designing the Healthcare Financial Network of the Future, is "right on target," Ribelin says. "The program will assemble key stakeholders to discuss what a strong financial network for healthcare could look like. A future that doesn’t siphon 20 cents of every healthcare dollar spent, and works to advance the balance between responsible financial management and clinical needs of patients," Ribelin says. The program's objective is to determine how the healthcare system can enhance value, reduce costs, and empower the shift from simple disease management to improved health for consumers, while at the same time creating better business models for the healthcare providers.
"EHRs are receiving a lot of attention, but the payment system, where a lot of new processes are in place with standards and systems defined such as bank ACH transactions, HIPAA 835s and ERA files, provides a real opportunity for significant change. A chance to create a network that will reduce costs and create efficiencies without negative impact on patient care,” says Ribelin. “Fix the healthcare payment system, create a strong financial healthcare network and the industry would see a savings of resources without sacrificing quality healthcare.”
What do you think?
While Electronic Health Records (EHR) and the impact of the recent definition of the meaningful use requirements will be hot topics at next week's HIMSS Conference in Atlanta, HERAE CEO Jim Ribelin thinks a program underwritten by the new HIMSS Medical Banking Project bears watching.
The project, called Designing the Healthcare Financial Network of the Future, is "right on target," Ribelin says. "The program will assemble key stakeholders to discuss what a strong financial network for healthcare could look like. A future that doesn’t siphon 20 cents of every healthcare dollar spent, and works to advance the balance between responsible financial management and clinical needs of patients," Ribelin says. The program's objective is to determine how the healthcare system can enhance value, reduce costs, and empower the shift from simple disease management to improved health for consumers, while at the same time creating better business models for the healthcare providers.
"EHRs are receiving a lot of attention, but the payment system, where a lot of new processes are in place with standards and systems defined such as bank ACH transactions, HIPAA 835s and ERA files, provides a real opportunity for significant change. A chance to create a network that will reduce costs and create efficiencies without negative impact on patient care,” says Ribelin. “Fix the healthcare payment system, create a strong financial healthcare network and the industry would see a savings of resources without sacrificing quality healthcare.”
What do you think?
Labels:
EHR,
EMR,
EOB,
healthcare records,
healthcare reform,
HERAE,
HIMSS,
HIPAA,
Jim Ribelin,
Mark Brousseau,
meaningful use,
TAWPI
Saturday, February 20, 2010
Compliance and Outsourcing
By Mark Brousseau
While new compliance, security and privacy regulations are likely to take a bigger bite out of operations budgets this year, most organizations believe they can meet the stricter rules without having to outsource their payments and document processing. Just 20 percent of respondents to a recent TAWPI Question of the Week said new compliance, security and privacy regulations would force their organization to consider outsourcing. Sixty-five percent of respondents said the tougher regulations wouldn't force them to consider, and 15 percent of respondents said they weren't sure.
The time and cost associated with meeting compliance, security and privacy regulations continues to rise -- giving pause to any company entrusted with sensitive data that must be stored and shared.
"Regulatory compliance is very expensive and extremely time-consuming," says R. Edwin Pearce (epearce@egisticsinc.com), executive vice president of sales and corporate development for eGistics, Inc. "Companies have two choices for meeting regulatory demands for privacy and security: assume the full expense of the resources and time associated with meeting each regulation, or work with an outsource provider that can spread the costs of meeting the regulations across its customer base."
Pearce also believes that organizations should ask themselves whether it makes sense to go through the cost and trouble of becoming compliant, when there are outsource providers that already are.
"Companies don't necessarily have to absorb the full capital burden of meeting various certification and compliancy tests," Pearce explains. "For example, organizations that store images and data for multiple years may have to meet PCI, SAS 70 and HIPAA regulations. Rather than engineer a data center environment that meets all of these requirements -- including policy and procedural standards -- it may make better sense for the organization to partner with a compliant outsource provider."
"The result is faster compliance, at a significantly lower cost," Pearce adds.
With new regulations on the horizon, this is a decision more organizations will have to make.
What do you think?
While new compliance, security and privacy regulations are likely to take a bigger bite out of operations budgets this year, most organizations believe they can meet the stricter rules without having to outsource their payments and document processing. Just 20 percent of respondents to a recent TAWPI Question of the Week said new compliance, security and privacy regulations would force their organization to consider outsourcing. Sixty-five percent of respondents said the tougher regulations wouldn't force them to consider, and 15 percent of respondents said they weren't sure.
The time and cost associated with meeting compliance, security and privacy regulations continues to rise -- giving pause to any company entrusted with sensitive data that must be stored and shared.
"Regulatory compliance is very expensive and extremely time-consuming," says R. Edwin Pearce (epearce@egisticsinc.com), executive vice president of sales and corporate development for eGistics, Inc. "Companies have two choices for meeting regulatory demands for privacy and security: assume the full expense of the resources and time associated with meeting each regulation, or work with an outsource provider that can spread the costs of meeting the regulations across its customer base."
Pearce also believes that organizations should ask themselves whether it makes sense to go through the cost and trouble of becoming compliant, when there are outsource providers that already are.
"Companies don't necessarily have to absorb the full capital burden of meeting various certification and compliancy tests," Pearce explains. "For example, organizations that store images and data for multiple years may have to meet PCI, SAS 70 and HIPAA regulations. Rather than engineer a data center environment that meets all of these requirements -- including policy and procedural standards -- it may make better sense for the organization to partner with a compliant outsource provider."
"The result is faster compliance, at a significantly lower cost," Pearce adds.
With new regulations on the horizon, this is a decision more organizations will have to make.
What do you think?
Labels:
compliance,
computer security,
data privacy,
Ed Pearce,
eGistics,
HIPAA,
hosted solutions,
Mark Brousseau,
outsourcing,
PCI,
SaaS,
SAS 70,
TAWPI
Monday, February 15, 2010
Healthcare Standardization
Posted by Mark Brousseau
Standardization of industry practices is critical to the strength of the healthcare market. Lee Barrett, executive director of the Electronic Healthcare Network Accreditation Commission (EHNAC) explains:
As the healthcare industry continues to evolve to meet regulations and requirements outlined in ARRA, HITECH and HIPAA, more than ever, there’s need for standardization of industry practices and optimization of stakeholder cooperation. Coupled with the complex issues surrounding interoperability, privacy, security and access is the fact that healthcare networks, financial service firms, payer networks, e-Prescribing and other solution providers and vendors need to overtly demonstrate their readiness, competence and capability to address these issues and comply with a complex web of regulations.
When any industry goes through the process of defining the standards to which industry participants should adhere, that industry becomes stronger in its own operations and earns greater respect from affiliated and external stakeholders. This is precisely the case with the electronic healthcare transaction industry.
EHNAC, or the Electronic Healthcare Network Accreditation Commission, is focused on establishing, developing, updating and filtering the criteria that define whether organizations operating in the healthcare electronic transaction industry receive accreditation or not. Through a dialogic process, that builds on stakeholder recommendations, insights and comments, EHNAC develops and promotes criteria for best practices, which focus on simplifying administrative processes, maintaining open competition and enhancing operational integrity.
In January, EHNAC announced the finalization and adoption of program criteria for 2010. This announcement concluded a 60-day public comment period for the following programs:
1. ASPAP-EHR – Application Service Provider Accreditation Program for Electronic Health Records
2. ePAP – e-Prescribing Accreditation Program
3. FSAP EHN – Financial Services Accreditation Program for Electronic Health Networks
4. FSAP Lockbox – Financial Services Accreditation Program for Lockbox Services
5. HNAP EHN – Healthcare Network Accreditation Program for Electronic Health Networks
6. HNAP Medical Biller – Healthcare Network Accreditation Program for Medical Billers
7. HNAP TPA – Healthcare Network Accreditation Program for TPAs
8. HNAP-70 – Healthcare Network Accreditation Plus Select SAS 70© Criteria Program
9. OSAP – Outsourced Services Accreditation Program
In addition, the commission developed draft criteria for Health Information Exchange (HIE) entities. In February, this draft criteria was released for 60-day public comment and review and will be finalized during the second quarter 2010.
The issues addressed through the criteria review and approval process become increasingly complex, as the industry responds to specific provisions in the federal acts. Criteria for accreditation programs today address health data processing response times and security; privacy and confidentiality for financial service providers; and e-Prescribing timeliness and security. As regulatory guidelines become more complex, industry participants are called on to make sure their operations are simplified, secure and compliant.
Accreditation also simplifies the process of discerning between those who are adhering to industry standards, and those who are not.
Standardization of industry practices is critical to the strength of the healthcare market. Lee Barrett, executive director of the Electronic Healthcare Network Accreditation Commission (EHNAC) explains:
As the healthcare industry continues to evolve to meet regulations and requirements outlined in ARRA, HITECH and HIPAA, more than ever, there’s need for standardization of industry practices and optimization of stakeholder cooperation. Coupled with the complex issues surrounding interoperability, privacy, security and access is the fact that healthcare networks, financial service firms, payer networks, e-Prescribing and other solution providers and vendors need to overtly demonstrate their readiness, competence and capability to address these issues and comply with a complex web of regulations.
When any industry goes through the process of defining the standards to which industry participants should adhere, that industry becomes stronger in its own operations and earns greater respect from affiliated and external stakeholders. This is precisely the case with the electronic healthcare transaction industry.
EHNAC, or the Electronic Healthcare Network Accreditation Commission, is focused on establishing, developing, updating and filtering the criteria that define whether organizations operating in the healthcare electronic transaction industry receive accreditation or not. Through a dialogic process, that builds on stakeholder recommendations, insights and comments, EHNAC develops and promotes criteria for best practices, which focus on simplifying administrative processes, maintaining open competition and enhancing operational integrity.
In January, EHNAC announced the finalization and adoption of program criteria for 2010. This announcement concluded a 60-day public comment period for the following programs:
1. ASPAP-EHR – Application Service Provider Accreditation Program for Electronic Health Records
2. ePAP – e-Prescribing Accreditation Program
3. FSAP EHN – Financial Services Accreditation Program for Electronic Health Networks
4. FSAP Lockbox – Financial Services Accreditation Program for Lockbox Services
5. HNAP EHN – Healthcare Network Accreditation Program for Electronic Health Networks
6. HNAP Medical Biller – Healthcare Network Accreditation Program for Medical Billers
7. HNAP TPA – Healthcare Network Accreditation Program for TPAs
8. HNAP-70 – Healthcare Network Accreditation Plus Select SAS 70© Criteria Program
9. OSAP – Outsourced Services Accreditation Program
In addition, the commission developed draft criteria for Health Information Exchange (HIE) entities. In February, this draft criteria was released for 60-day public comment and review and will be finalized during the second quarter 2010.
The issues addressed through the criteria review and approval process become increasingly complex, as the industry responds to specific provisions in the federal acts. Criteria for accreditation programs today address health data processing response times and security; privacy and confidentiality for financial service providers; and e-Prescribing timeliness and security. As regulatory guidelines become more complex, industry participants are called on to make sure their operations are simplified, secure and compliant.
Accreditation also simplifies the process of discerning between those who are adhering to industry standards, and those who are not.
Thursday, December 17, 2009
Best Practices for Gateway EDI
Posted by Mark Brousseau
For Gateway EDI, EHNAC accreditation shows the way to best practices. EHNAC Executive Director Lee Barrett explains:
As one of the fastest-growing providers of healthcare electronic data interchange, Gateway EDI processes transactions for more than 10,000 medical offices representing 50,000 providers in all 50 states. Gateway EDI also connects to more than 3,000 payers and offers services ranging from standard claims processing and status reports to more advanced capabilities such as technology for flagging rejected claims.
Founded in 1983, Gateway EDI has continuously pursued innovations, business practices and opportunities to improve its services. In 2006, just such an opportunity arose through a relationship with the Electronic Healthcare Network Accreditation Commission (EHNAC).
“Our initial interest in EHNAC was prompted by a state of Maryland requirement,” recalls Dave Cheli, chief information officer, at Gateway EDI. “But the accreditation process proved to be a real eye-opener for us.”
An industry veteran, Cheli was already familiar with EHNAC’s work, which dates to the early 1990s. Though the Gateway EDI team knew generally what to expect, they were pleasantly surprised with the advantages of achieving full accreditation in March 2006.
“It provided a great framework for bringing together a wide range of security, privacy and operational aspects,” says Cheli. “Seeing it all from EHNAC’s perspective in a comprehensive overview was an interesting experience. It shined some light on some aspects of our business where there had been missing pieces.”
Taking a closer look
Transaction auditing serves as a case in point. Gateway EDI manages more than 15 million transactions a month, and the EHNAC criteria require that electronic health networks demonstrate the ability to produce detailed audit trails for all of them.
“Most clearinghouses handle millions of transactions on a monthly basis,” says Cheli. “You might think you can account for every transaction, but EHNAC forces you to show that you can. When you start looking at reports and doing the research, you learn more about your business. For us, the process highlighted some areas where we were able to shore up our capability to reconcile every single transaction.”
In addition to these operational enhancements, EHNAC accreditation has impacted the customer service side. “As a result of our original accreditation in 2006, we added some processes that have benefitted our clients, such as closer monitoring of customer service status,” says Cheli.
In response to marketplace trends, Gateway EDI has grown its business on the strength of value-added services and strong support. And in the years since it began working with EHNAC, Gateway EDI has further built on that advantage. In May 2008, Gateway EDI was included in the “Ambulatory EDI Claims Clearinghouse” report published by KLAS, the Orem, Utah-based research firm (www.KLASresearch.com) specializing in monitoring and reporting the performance of healthcare vendors.
Gateway EDI’s results included 100 percent positive commentary regarding the vendor relationship, and perfect scores, 100 percent, for Would Recommend to a Friend or Peer, and Services Delivered within Budget/Cost. With most Gateway EDI customers “feeling well taken care of”, Gateway EDI earned an 89 overall rating score, a functional strength rating of 4.5 out of 5.0., and first-place for practice management integration. It also captured the top rating in several categories, including “Quality of Services Staff” and “Real Problem Resolution.”
Standards as best practices
As a self-governing non-profit, EHNAC maintains a comprehensive set of publicly-available standards criteria covering privacy and confidentiality; technical performance; business practices; physical, human and administrative resources; and security.
The EHNAC standards development process is fully open and transparent. Based on years of research, it’s the result of continuous input from electronic health networks, payers, hospitals, physicians, consumer groups, financial services firms, security organizations and vendors.
“Because it’s built on years of studying the industry and it’s so broad based, the EHNAC criteria have essentially become a collection of best practices,” says Cheli.
A credible process
EHNAC’s accreditation process, which is based on these established standards, begins with a candidate organization’s submission of an in-depth self-assessment. Later, an EHNAC site reviewer visits to evaluate the accreditation candidate more closely. This hands-on approach helps companies identify issues as well as opportunities.
“In 2006 and again, with our re-accreditation in 2008, the EHNAC assessor spent time understanding our processes. They’ve asked a lot of insightful questions and shared some wonderful tips with us,” says Cheli. “For example, this year we got some very valuable advice on improving our disaster recovery and business continuity measures.”
An operational catalyst
Cheli believes that EHNAC has served as a sort of catalyst, helping Gateway EDI expand privacy and security measures, make decisions about business practices and set meaningful operational objectives. “We now have a lot of people setting departmental goals and monitoring performance metrics that are built around EHNAC criteria,” he says. “Getting a set percentage of claims out in a certain time frame, for example, is now crystallized for us as a monthly goal. And we’re more meticulous about monitoring against those goals.”
“Would we have gotten there without EHNAC driving a lot of this?” Cheli asks. “Probably. But not as quickly. EHNAC is the only organization that provides a comprehensive accreditation service for clearinghouses. HIPAA-related issues are just a part of the overall criteria. They look at it from a total operational perspective.”
Truth in advertising
One also can see the results of Gateway EDI’s efforts with a quick visit to its website. Gateway EDI customers have an average overall error rate of only seven percent. Ninety-eight percent of customer service calls are answered directly by a real person. Gateway EDI solves 92 percent of customer questions on the first call.
And prospects can rest assured that these claims about claims are real. In addition to performance standards and policies and procedures, EHNAC accreditation encompasses “truth-in-advertising” criteria. So statements like these are verifiable.
What began as a requirement has become a resource for Gateway EDI — and relationship, too. “The people behind EHNAC are experienced, smart and very passionate about what they do,” says Cheli. “They’ve been extremely supportive of us, and our relationship has been wonderful.”
For Gateway EDI, EHNAC accreditation shows the way to best practices. EHNAC Executive Director Lee Barrett explains:
As one of the fastest-growing providers of healthcare electronic data interchange, Gateway EDI processes transactions for more than 10,000 medical offices representing 50,000 providers in all 50 states. Gateway EDI also connects to more than 3,000 payers and offers services ranging from standard claims processing and status reports to more advanced capabilities such as technology for flagging rejected claims.
Founded in 1983, Gateway EDI has continuously pursued innovations, business practices and opportunities to improve its services. In 2006, just such an opportunity arose through a relationship with the Electronic Healthcare Network Accreditation Commission (EHNAC).
“Our initial interest in EHNAC was prompted by a state of Maryland requirement,” recalls Dave Cheli, chief information officer, at Gateway EDI. “But the accreditation process proved to be a real eye-opener for us.”
An industry veteran, Cheli was already familiar with EHNAC’s work, which dates to the early 1990s. Though the Gateway EDI team knew generally what to expect, they were pleasantly surprised with the advantages of achieving full accreditation in March 2006.
“It provided a great framework for bringing together a wide range of security, privacy and operational aspects,” says Cheli. “Seeing it all from EHNAC’s perspective in a comprehensive overview was an interesting experience. It shined some light on some aspects of our business where there had been missing pieces.”
Taking a closer look
Transaction auditing serves as a case in point. Gateway EDI manages more than 15 million transactions a month, and the EHNAC criteria require that electronic health networks demonstrate the ability to produce detailed audit trails for all of them.
“Most clearinghouses handle millions of transactions on a monthly basis,” says Cheli. “You might think you can account for every transaction, but EHNAC forces you to show that you can. When you start looking at reports and doing the research, you learn more about your business. For us, the process highlighted some areas where we were able to shore up our capability to reconcile every single transaction.”
In addition to these operational enhancements, EHNAC accreditation has impacted the customer service side. “As a result of our original accreditation in 2006, we added some processes that have benefitted our clients, such as closer monitoring of customer service status,” says Cheli.
In response to marketplace trends, Gateway EDI has grown its business on the strength of value-added services and strong support. And in the years since it began working with EHNAC, Gateway EDI has further built on that advantage. In May 2008, Gateway EDI was included in the “Ambulatory EDI Claims Clearinghouse” report published by KLAS, the Orem, Utah-based research firm (www.KLASresearch.com) specializing in monitoring and reporting the performance of healthcare vendors.
Gateway EDI’s results included 100 percent positive commentary regarding the vendor relationship, and perfect scores, 100 percent, for Would Recommend to a Friend or Peer, and Services Delivered within Budget/Cost. With most Gateway EDI customers “feeling well taken care of”, Gateway EDI earned an 89 overall rating score, a functional strength rating of 4.5 out of 5.0., and first-place for practice management integration. It also captured the top rating in several categories, including “Quality of Services Staff” and “Real Problem Resolution.”
Standards as best practices
As a self-governing non-profit, EHNAC maintains a comprehensive set of publicly-available standards criteria covering privacy and confidentiality; technical performance; business practices; physical, human and administrative resources; and security.
The EHNAC standards development process is fully open and transparent. Based on years of research, it’s the result of continuous input from electronic health networks, payers, hospitals, physicians, consumer groups, financial services firms, security organizations and vendors.
“Because it’s built on years of studying the industry and it’s so broad based, the EHNAC criteria have essentially become a collection of best practices,” says Cheli.
A credible process
EHNAC’s accreditation process, which is based on these established standards, begins with a candidate organization’s submission of an in-depth self-assessment. Later, an EHNAC site reviewer visits to evaluate the accreditation candidate more closely. This hands-on approach helps companies identify issues as well as opportunities.
“In 2006 and again, with our re-accreditation in 2008, the EHNAC assessor spent time understanding our processes. They’ve asked a lot of insightful questions and shared some wonderful tips with us,” says Cheli. “For example, this year we got some very valuable advice on improving our disaster recovery and business continuity measures.”
An operational catalyst
Cheli believes that EHNAC has served as a sort of catalyst, helping Gateway EDI expand privacy and security measures, make decisions about business practices and set meaningful operational objectives. “We now have a lot of people setting departmental goals and monitoring performance metrics that are built around EHNAC criteria,” he says. “Getting a set percentage of claims out in a certain time frame, for example, is now crystallized for us as a monthly goal. And we’re more meticulous about monitoring against those goals.”
“Would we have gotten there without EHNAC driving a lot of this?” Cheli asks. “Probably. But not as quickly. EHNAC is the only organization that provides a comprehensive accreditation service for clearinghouses. HIPAA-related issues are just a part of the overall criteria. They look at it from a total operational perspective.”
Truth in advertising
One also can see the results of Gateway EDI’s efforts with a quick visit to its website. Gateway EDI customers have an average overall error rate of only seven percent. Ninety-eight percent of customer service calls are answered directly by a real person. Gateway EDI solves 92 percent of customer questions on the first call.
And prospects can rest assured that these claims about claims are real. In addition to performance standards and policies and procedures, EHNAC accreditation encompasses “truth-in-advertising” criteria. So statements like these are verifiable.
What began as a requirement has become a resource for Gateway EDI — and relationship, too. “The people behind EHNAC are experienced, smart and very passionate about what they do,” says Cheli. “They’ve been extremely supportive of us, and our relationship has been wonderful.”
Subscribe to:
Posts (Atom)