News & Analysis

January 1, 2016
Briefings on HIPAA

The Office of the Inspector General (OIG), which provides oversight of other government entities, released a report in September 2015, OCR Should Strengthen Its Followup of Breaches of Patient Health Information Reported by Covered Entities, that included recommendations on how the entity charged with administering the HIPAA privacy and security rules should improve.

January 1, 2016
Briefings on HIPAA

When President Barack Obama issued Executive Order 13636 February 12, 2013, Dena Boggan, CPC, CMC, CHPC, took notice. Boggan is the HIPAA privacy and security officer for St. Dominic Hospital, a 535-bed, 27-clinic facility headquartered in Jackson, Mississippi.

Engaging the board

An August 2014 American Hospital Association (AHA) article, "Cybersecurity and Hospitals: What Hospital Trustees Need to Know About Managing Cybersecurity Risk and Response" (www.aha.org/content/14/14cybersecuritytrustees.pdf), reported that hospitals and healthcare are part of the United States' "critical infrastructure," meaning "their systems and assets are considered so vital to the country that their impairment as a result of a cyber attack would pose a threat to the nation's public health and safety."

That's why Boggan and St. Dominic found it critical to ensure they have a robust cybersecurity program. A major part of that program was to get the hospital's board of directors and board of trustees in the know about cybersecurity. Boggan notes that at some of the organizations that suffered major breaches of PHI, investigators found that board members were generally unaware that cybersecurity programs even existed.

"They had that deer caught in the headlights look when asked about their program," she recalls of her research.

The AHA recommended, Boggan says, that organizations get their board of directors in the know. She started by developing a cybersecurity overview for her board. She reports up to St. Dominic's compliance committee, which includes some board members.

"We gave them a good definition of what cybersecurity is and identified that board of directors and trustees need to be responsible for understanding, at a high level, their organization's cybersecurity risks and vulnerabilities," Boggan says. "They need to understand the security response plan that is in place, who in management is responsible for delivering that plan, and when it's appropriate for board insight over that plan."

January 1, 2016
Briefings on APCs

Our coding experts answer questions about reporting twin births, tobacco use details in ICD-10-CM, and more. 

January 1, 2016
Briefings on APCs

Providers often struggle with modifiers‑even those they've had available to report for many years‑due to the unique scenarios they face at their facilities, staffing changes, and/or unclear or lacking authoritative guidance.

January 1, 2016
Briefings on APCs

CMS finalized its proposals regarding the 2-midnight rule, including moving responsibility for rule enforcement and education from Recovery Auditors to Quality Improvement Organizations (QIO). This latter change occurred October 1, 2015.

January 1, 2016
Briefings on APCs

The 2016 OPPS final rule includes the first negative payment update for the system, but CMS also listened to commenters' suggestions to make a variety of proposals less onerous either operationally or financially.

Pages