Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Wednesday, March 21, 2012

WEBINAR: Tactical Solutions Supporting the Challenges of ANOC/EOC Creation-Print-Distribution-Reporting Requirements

Merrill Corporation is hosting a Free Webinar and You're Invited!


Title: Tactical Solutions Supporting the Challenges of ANOC/EOC Creation-Print-Distribution-Reporting Requirements.
Date: Wed, March 28
Time: 1:00pm Central Time
Duration: 1-hour
Cost: FREE!

A streamlined process for the creation, print, distribution and reporting of your ANOC/EOC program is crucial to successfully meeting the regulatory requirements as well as ensuring the integrity of PHI, and minimizing the risk associated with HIPAA violations. 

In this webinar you will:
  • Review current technology and manufacturing workflow innovations and best practices associated with ensuring the final product is produced on time and correctly.  We will examine everything from the latest dynamic document creation technology to effective use of the postal intelligent mail barcode.
  • Learn how our advanced reporting allows you to track delivery at the piece level.  See how the use of a personalized 2D barcode scan during manufacturing translates into member level reporting. 
  • Discover what options are available for a hybrid print and e-fulfillment workflow. 
 
Click below to register for this webinar today!



http://bit.ly/MerrillWebinar328

Thursday, May 12, 2011

HIPAA Regulations and New Technology: May 2011

We have received a lot of feedback on our post about HIPAA and new technology, and because of that, we will continue to share news on this very important issue that will play a major role in how the industry evolves.

It is well documented how doctors and other medical practitioners have been slow to adopt social media, and there is next to no following available for those that do. A recent poll revealed that only 11% of those interviewed would participate in social network interaction with their doctor if it was offered. Unlike the compliance issues that are holding health plans back, the only thing keeping physicians out of social media is a lack of interest. Many argue, however, that a lack of interest does not create a lack of responsibility. More and more patients are turning to social networks for advice on medical treatment, pharmaceuticals, and diagnoses. As a result, it is the responsibility of medical professionals to ensure that the information they find is accurate and up to date.

Obviously, some restraint is necessary. Doctors are just as required to follow HIPAA policies online as they are in any public setting. There should be no harm, however, in presenting generalized and accurate medical information, as long as the required compliance issues are handled responsibly.

HIPAA regulations also come into play with mobile technologies. Thousands of companies, in and out of the medical industry, are turning to mobile devices like smartphones and tablet computers to simplify the logistics of their operations. New advances in mobile tech have lowered the cost and time-consumption of training programs, and eased the transition of work materials from one workplace to the next.

The problem with this ease of access is just that; the access. In the wrong hands, a major company’s mobile technology could provide private data on hundreds, if not thousands, of clients and customers. Mobile devices need to be very well secured in order to meet HIPAA standards. This required level of compliance does not seem to be affecting the devices’ popularity, however.

So how do you take advantage of social networks and mobile technology without worrying about misinformation and HIPAA involvement? By creating your own network, of course. OrthoMind, by orthopedic surgeon Jon Hyman, MD, is a social network open only to other orthopedic surgeons. The exclusive community allows for the simple exchange of thoughts, practices, and techniques without the added downsides of outside influence. Because the network is not marketing toward any consumers, or sharing patient-doctor conversations, there is also no worry of HIPAA reprisal.

Networks like OrthoMind are extremely important for physicians, who may find themselves bombarded when patients that believe they are informed show up with armfuls of inaccurate medical advice. While it is superficially wonderful that patients are being empowered by social media to research things on their own, a doctor needs to be just as informed in order to be capable of separating the good advice from the bad.

Thursday, April 28, 2011

HIPAA Regulations as it relates to New Technology

We have written about HIPAA on several occassions on this blog (and even when we aren't writing about it, we are staying abreast on the subject). In the course of our recent research, we have found a number of articles discussing ideas on how new (and growing) technologies can fit into HIPAA regulations. We feel that, while this isn't the start, the fact that more consistent reporting is happening in this capacity will help bring the industry together to work towards a solution.


The risk of fines (or worse) is still a major concern for those reluctant to convert to EHR, so the idea of a transition to developing mobile sites and apps is beyond most physicians' range of thought. However, Diversenet, a company focused on strengthening mobile health technology capabilities, recently developed a whitepaper with nine mobile security best practices, such as encrypting PHI on mobile devices, authentication of users prior to transmitting PHI and automatic session timeout, logoff and device locking. Additionally, it lists 10 questions about mobile health data that healthcare organizations should ask when evaluating mobile technology.

The problems with mobile devices are obvious. Once information leaves a server, there are any number of complications that can result in breaches, and mobile technology has not proven itself to be anywhere near consistently secure. However, according to the article, a number of small mobile health companies are providing targeted wireless personal health monitoring devices and services that collect and transmit health data, while others have developed mHealth apps for patient monitoring, scheduling medical appointments and medication reminders, all of which work. And, at the security end, global technology service providers are adapting existing security products for the healthcare sector.

This just leaves the actual mobile device as the key problem, but Diversinet has a solution for that as well.




The advent of cloud computing, as it relates to HIPAA, is allowing certain organizations to reconsider certain security protocols and, according to a recent article in Tech News World. The story addresses how organizations are typically confused as how to meet the addressable requirements of the Security Rule, causing a refrain from full implementation, leaving the institution in the precarious position of not fully complying with the law -- at least not in the manner intended by HHS.

However, with cloud computing scenario, most security activities occur in partnership between vendor and client. So, while the onus still resides with the covered entity, components of the implementation can be handled by the business associate cloud provider. An organization that could commit, at some level, to helping maintain the HIPAA security requirements, would have a significant leg up.



"HIPAA is a well-intentioned, but poorly implemented law that is unnecessarily scaring doctors and keeping them in an unrealistic 'technology lockdown'."
This is a quote from Mark Britton, Founder and CEO of Avvo, a company that helps physicians deal with the legalities of new technology, such as social media. While Avvo has the ability to deal with specific issues, they do offer these five basic pieces of advice for managing their career online in relationship to HIPAA:
  1. Use email, SMS and social media messaging
  2. Feel free to share information with other providers
  3. Feel free to answer general patient questions
  4. Keep family members in the loop
  5. Exercise common sense and reasonable practices in all instances
For more details on these tips and other potential issues, click here...

-------------------------------------------------------------------------------------------

Pam Argeris is a thought leader in the Healthcare Industry and possesses extensive, hands-on experience with CMS compliance, and multiple regulatory bodies such as NCQA, JACHO, and DOI. In her role at Merrill Corp., Pam focuses on developing solutions for compliance and quality assurance, delivered in a cost effective manner to improve beneficiary and prospect communications. You can contact Pam at Pamela.Argeris@merrillcorp.com.

Thursday, July 29, 2010

HHS Strengthens Health Information Privacy and Security through New Rules

“To improve the health of individuals and communities, health information must be available to those making critical decisions, including individuals and their caregivers. While health information technology will help America move its health care system forward, the privacy and security of personal health data is at the core of all our work.”

--U.S. Health and Human Services Secretary Kathleen Sebelius

On July 8, Secretary Sebelius announced important new rules to strengthen the Health Insurance Portability and Accountability Act of 1996 (HIPAA), improve the privacy of health information and help all Americans understand their rights and the resources available to safeguard their personal health data.

In short, the proposed rule would strengthen and expand enforcement by:
  • Expanding individuals’ rights to access their information and to restrict certain types of disclosures of protected health information to health plans;
  • Requiring business associates of HIPAA-covered entities to be under most of the same rules as the covered entities;
  • Setting new limitations on the use and disclosure of protected health information for marketing and fundraising; and
  • Prohibiting the sale of protected health information without patient authorization.
“The benefits of health IT can only be fully realized if patients and providers are confident that electronic health information is kept private and secure at all times,” said Georgina Verdugo, Office for Civil Rights director at HHS. “This proposed rule strengthens the privacy and security of health information, and is an integral piece of the administration’s efforts to broaden the use of health information technology in health care today.”

In addition, HHS also launched a privacy website to help visitors easily access information about existing HHS privacy efforts and the policies supporting them. The site emphasizes the deep commitment to privacy in the collection, use and exchange of personally identifiable information. This new resource provides Americans with confidence that their personal information is secure and underscores HHS’ goal of greater openness and transparency in government.

For more information about the new rule, click HERE.

For other HHS Recovery Act programs, click HERE.