Q: The chief executive officer of the hospital where I work is talking about having our hospital coding done in India. What are the potential ramifications of this plan for our hospital? I know a prominent hospital in Palo Alto, California, was going to do this in 2011.
Have any U.S. hospitals actually outsourced their medical record coding to foreign countries? What are the liability risks? What do we need to be aware of in terms of HIPAA compliance?
A: Yes, many organizations send coding and transcription work overseas. Despite business associate agreements (which you must get with any such vendor, offshore or not), it may be difficult to ensure that these vendors are HIPAA compliant, although one could make the same argument about U.S. vendors as well. Be sure to do your due diligence by carefully checking your vendor's references (and documenting the results) should you choose to go this route. You might also discuss this with your organization's insurance carrier and/or attorney for an assessment of the risks.
Editor's note: Chris Simons, MS, RHIA, the director of health information and privacy officer at Maine General Medical Center in Augusta, answered these questions. Simons is also an HIMB advisory board member. This information does not constitute legal advice. Consult legal counsel for answers to specific privacy and security questions. Send your questions related to HIPAA compliance to Editor Jaclyn Fitzgerald atjfitzgerald@hcpro.com.
Faxing, like many other efforts to protect health information, comes down to basics. Call the recipient to ensure they are near the fax machine. Double- and triple-check fax numbers. Send a cover sheet that clearly addresses to whom the fax is intended. Follow up with a call.
"We try to call the recipient and tell them, 'Hey we're going to fax something to you. If you're at a public fax machine go stand by that machine,' " Wallach says.
Basic stuff, right? But for busy healthcare systems who can send a massive amount of faxes each day, the human error rate is high, says Frank Ruelas, MBA, who serves as principal at HIPAA College in Casa Grande, Arizona, and facility compliance professional at Dignity Health's St. Joseph's Hospital and Medical Center in Phoenix. Ruelas is also a BOH editorial advisory board member.
"Just because you're in a hurry doesn't make it right," says Ruelas. "Do we need something this sophisticated and scientific here? This is a process that should have a really low error rate. Or it should be much lower than it is."
Break down faxing policies into rudimentary steps where employees are comfortable and deploy them, he says.
To find the right solution for your organization, you must understand how and why employees are using messaging and email services.
"You want a solution that's easy to use, and that's within the work environment of whoever is sending the message," Apgar says. Apgar's case in point is Oregon's state-sponsored CareAccord Direct Secure Messaging email service. The service doesn't connect to all EHRs or an organization's email service. Users have to log in through the website to send a message. Busy employees, he points out, particularly clinical staff like physicians, are unlikely to use a service that requires them to go out of their way, making it a poor choice.
Text messaging solutions directed at the healthcare industry were not always common and user friendly. Until about a year ago, there were few mature products on the market for securing text messages, Apgar says. The ones that did provide good security had serious usability limitations as most could only be used to communicate with other people in your network. A specialist, Apgar says, wouldn't have been able to send a quick, secure text to his or her patient's primary care doctor if the doctor was not part of the specialist's organization. Some services, like Tiger Text and HipaaChat, offer a solution to this problem. (See the March 2015 issue of BOH for more information about Tiger Text.) If the sender uses Tiger Text, but the recipient does not, Tiger Text delivers a text message that includes a link to the now encrypted text message. When the recipient clicks the link, the browser on the mobile device opens up to the text message, which is encrypted at a National Institute of Standards and Technology standard 256-bit encryption.
Keep in mind, however, that you have to treat text messaging the same as email. Device security and storage need to be analyzed. Burton warns that some may not realize the text messages on their phones leave traces of data behind.
Apgar agrees. "They don't understand that ultimately the cell phone carrier has servers that back up your texts, and you have it [stored] on your phone," he says.
Over-querying is a common concern in CDI. It can influence productivity and workflow. It can cause delays in documentation and coding processes. It can also overwhelm and frustrate physicians, who in turn may be less likely to support or engage with CDI program efforts.
The American Hospital Association asked CMS to clarify some aspects of its new outpatient notification requirement, Notice of Observation Treatment and Implication for Care Eligibility Act, which is supposed to go into effect in the summer of 2016.