The Office for Civil Rights (OCR) announced December 8, 2014 that it fined an Alaska behavioral health service $150,000 for potential HIPAA violations. OCR entered into a resolution agreement with Anchorage Community Mental Health Services (ACMHS), a nonprofit behavioral healthcare service, per the announcement (see www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/acmhs/amchs-capsettle...).
Even organizations with sound policies, procedures, training, and safeguards can experience a breach. When?not if?a breach occurs, traditional insurance may not be enough to cover the damages. Ensuring that your organization has adopted the appropriate cyber insurance can be valuable in the event of a breach.
Many hospitals and health systems include computer-assisted coding (CAC) systems as a strategic tool in their plan for ICD-10. CAC software is considered an antidote to the significant decrease in coder productivity anticipated with ICD-10.
While it can be challenging to define your organization's legal health record (LHR), one health system in Denver is proving that collaboration and perseverance can lead to an effective LHR and EHR.
Q: I am familiar with the HIPAA Security Rule requiring information system review audits. Are there any HIPAA Privacy Rule requirements?other than to perform audits?that require the examination of inappropriate access for an alleged breach? Currently, our security team performs monthly information system review audits and issues reports to leadership on a quarterly basis. Will this suffice, or are there audits that the privacy team should perform as well?
Coding for sepsis requires a strong knowledge of ICD-9-CM coding guidelines, as well as complete and accurate documentation. That's not a surprise to any coding professional. They need those two elements to successfully code any medical record.