More than ever before, HIM is being recognized as an enterprise profession important to ambulatory, acute, and postacute settings. A good example of the transformation is HIM's involvement in CMS' risk adjustment and Hierarchical Condition Category coding system.
As the use of electronic health records (EHR) surges and organizations work toward meaningful use attestation, more in-depth monitoring of electronic patient records is becoming increasingly necessary.
The intent of quality and safety programs is to evaluate and monitor performance and to improve results. Organizations develop annual quality and safety plans with measurable objectives that departments adopt and include as integral aspects of their performance improvement plans.
Q: I am familiar with the HIPAA Security Rule requiring information system review audits. Are there any HIPAA Privacy Rule requirements?other than to perform audits?that require the examination of inappropriate access for an alleged breach? Currently, our security team performs monthly information system review audits and issues reports to leadership on a quarterly basis. Will this suffice, or are there audits that the privacy team should perform as well?
In my experience, most organizations in the health-care industry?both covered entities and business associates?have taken the steps to put policies, business processes, and training programs in place to help ensure compliance with the HIPAA Security Rule. Still, there's a gaping hole in many healthcare compliance and security programs: a lack of technical security testing of Web applications, mobile applications, and network systems.