News & Analysis

September 23, 2016
News & Insights

What is the current status of the Beneficiary and Family Centered Care Quality Improvement Organizations (BFCC-QIO) short-stay reviews?

August 1, 2016
Case Management Monthly

There's good news and bad news on the 2-midnight rule front. The good news: CMS has put short-stay inpatient audits related to the 2-midnight rule on hold as of May 4. The bad news: This isn't a free pass, and it isn't going to last.

July 26, 2016
Medicare Insider

This week’s updates include the quarterly update to the CCI edits; denial codes for missing or insufficient documentation; and more!

July 13, 2016
Medicare Insider

This week’s note is about laws impacting Medicare fraud and overpayments.

July 1, 2016
Briefings on HIPAA

Product watch

Maize Analytics audit log tool

by Chris Apgar, CISSP

Information systems activity review is a fancy way of saying you need to monitor your network and your applications including who is looking at and manipulating your patient information. That can be an expensive, or even almost impossible, proposition when it comes to regular monitoring of access to patient information stored in electronic health records (EHR). Two of the well-known automated audit logging tools on the market, FairWarning and Iatric, are well outside the budget for small- to medium-sized covered entities (CE). The manual option, checking audit logs by hand, is slow and ineffective.

July 1, 2016
Briefings on HIPAA

HIPAA audits

Phase 2 audit protocol

As Phase 2 of the HIPAA audit program begins, covered entities (CE) and business associates (BA) will be watching their email for an audit letter from OCR. Of those chosen for audit, most will be selected for a desk audit. They'll have 10 days after receipt of the email to gather requested documents for OCR's auditors.

But how will CEs and BAs know they are collecting the right information? A careful reading of the updated Phase 2 audit protocol (www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/protocol/index.html) will help guide CEs and BAs. But if the protocol isn't read carefully, and in full, important documents could easily be left out, leading to inaccurate audit reports and even a visit from OCR's investigators.

The Phase 2 audit protocol expands the Phase 1 compliance areas to reflect changes made by the 2013 HIPAA omnibus final rule. The updated audit protocol also includes information for BAs, which were not audited during Phase 1 but will be in the current round of audits. The protocol contains a description of the audit areas, general instructions and definitions, and a keyword-searchable table.

Phase 2 audits will be conducted in three rounds. The first two rounds will consist of desk audits of specific audit targets, while the third round will be comprehensive audits. Round one audits will target CEs and round two audits will target BAs.

Round one CE audit targets will target:

  • Security: risk analysis and risk management
  • Breach: content and timeliness of notifications
  • Privacy: notice and access

 

The round two BA audits will target:

  • Security: risk analysis and risk management
  • Breach: breach reporting to covered entities

 

Pages