Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Wednesday, October 22, 2008

COMING SOON: HEALTHCARE REFORM IN THE NEXT FOUR YEARS!

And thats regardless of who becomes the next President. I dont think Im being overly optimistic since the signs are there.

The momentum that started with HIPAA, the escalating spiral of healthcare costs, and the fact that about one out of every six Americans does not have adequate health coverage have made healthcare reform a priority in the next administration.

According to the Commonwealth Fund, a New York-based private foundation whose mission is to promote a high-performing healthcare system:
In 2007, nearly two-thirds of U.S. adults, or an estimated 116 million people, struggled to pay medical bills, went without needed care because of cost, were uninsured for a time, or were underinsured (i.e., were insured but not adequately protected from high medical expenses).

(Losing Ground: How the Loss of Adequate Health Insurance is Burdening Working Families, August 2008)
Both Democrats and Republicans agree on the objectives but differ on the ways to achieve those objectives. Nevertheless the following bills are actively being legislated. They’re listed in the approximate order of their progress. A Senate bill is abbreviated as SB and a bill from the House of Representatives is abbreviated HR. Clicking on a link will open a new tab or window containing the PDF copy of the document.

SB 2408/HR 4295: The Medicare Electronic Medication and Safety Protection Act.
As it’s currently written, this act has both carrot and stick. On the one hand it encourages physicians to use e-prescriptions by offering a bonus payment equivalent to one percent of every claim submitted that is based on an e-prescription. On the other, it would impose a pre-claim financial penalty on physicians who still hand write prescriptions in 2011.

This bill was introduced in December 2007 by Senator John Kerry (D-Mass.) and co-sponsored by Republicans John Ensign (Nev.), Norm Coleman (Minn.), John Cornyn (Tex.), and fellow Democrats Charles Schumer (N.Y.), Richard Durbin (Ill.), and Maria Cantwell (Wash.).
HR 4296 is the House version of the former and is called the Medicare Electronic Medication and Safety Protection (E-MEDS) Act of 2007.
It supplements HR 4295 by requiring physicians that participate in Medicare to e-prescribe.
HR 2991: The Independent Health Record Trust Act.
This could be the big one! It requires the national healthcare system to provide for the establishment of a nationwide health information technology network.
There are two more bills winding their way through the Senate and the House, respectively. These bills elaborate further on the need to develop a national interoperable health information network.

The Senate bill is SB 1693: The Wired for Healthcare Quality Act.

The House bill is HR 6357: PRO(TECH) Act of 2008: Promotion of Health Information Technology.

Finally, credit must also go to the federal government for actively working to develop the network of the future. Click here to see the program's status.


Sphere: Related Content

Sunday, September 28, 2008

LESSONS FROM CONDUCTING A SECURITY GAP ANALYSIS

There are many reasons for ensuring that you have a secure information system. It becomes a question of how instead of why. How do you create and maintain a secure system?

I participated in my first security gap analysis project in 2006, blogged it that year, lost that blog, and found my notes again. It was an eye-opening experience especially since it was conducted in one of the largest hospitals—whether public or private—in the country. It serves the second most populous county in the U.S. According to 2006 US Census Bureau estimates, the county had 5.3 million residents—larger than the populations of 29 individual U.S. states or the combined populations of the six smallest US states.

There are many reasons for ensuring that you have a secure information system. It becomes a question of how instead of why. How do you create and maintain a secure system? Starting with what you have, the first step is to create a baseline—a model of your expectations about the security of your information system. If your business belongs to one of several industries that are governed by laws and regulations then you should start with the security requirements of those same laws and regulations.

A hospital, for instance, would be directly governed by the Health Insurance Portability & Accountability Act (HIPAA). It is also subject to other regulations like the eDiscovery rules but we will keep it simple by focusing on HIPAA alone.

The second step is to categorize the sensitivity of your data, identify its source, its location within the system, how its accessed, and who can access it.

Sensitive data can take the form of intellectual property. For a hospital, sensitive data is frequently legally protected. An example is the X-ray images of a patient.

Armed with this information, you can begin your gap analysis. Before this discussion goes further, it must be understood that gap analysis is an ongoing process. The environment is constantly changing. Your information system is constantly changing with it and, naturally, your security gaps are changing as well.

Comparing your actual practices with security requirements will identify the gaps in your system. Once identified, the gaps can be prioritized (by severity, for instance). Then a plan can be created for eliminating (or at least minimizing) those vulnerabilities.

Gap analysis is a specialized form of risk analysis. Risk analysis recognizes the fact that risks are everywhere and that you have limited resources to deal with them. The goal of risk analysis, therefore, is to learn how to deploy your resources in the most effective manner to eliminate or minimize the worst or most likely threats.

It is best to approach gap analysis as a project and like any project, senior management must support it. Security gap analysis must be conducted on a regular basis. It must be thorough and objective. The degree of thoroughness will establish the scope of the analysis. Will the project include physical as well as electronic security? Will it be limited to customer-facing applications?


Objectivity requires a fresh set of eyes. It wouldn’t make sense for an accountant to audit himself. It makes a lot of sense therefore to hire an outside firm to lead the project.

These are the lessons I learned when we conducted a security gap analysis at one of the largest hospitals—whether public or private—in the country.

Our presence was announced with a bang! When you stage a systems break-in, attack the system like a team of hackers would. A team attack is just as likely to happen in real life as a solitary attempt would. The ease and speed of our break-in convinced the hospital’s administration of the risks it faced.

Your project team should have members from different disciplines. I came away convinced that if the core team could only have two groups then the two should be your IT and your HR departments. Why HR? It’s because people will be the primary source of vulnerabilities.

Hospitals are very politicized organizations. In addition to having senior management’s blessing, we created a RACI matrix that was jointly accepted by all department heads.

RACI stands for Responsible-Accountable-Consulted-Informed. A RACI matrix will identify the authority and responsibility of all roles involved in the project. We had determined that our scope was going to be limited to electronic security and to customer-facing applications only. Due to the size of the hospital and the number of applications it ran, our gap analysis focused on the two most heavily implemented applications: lab and accounting.

This was the first gap analysis conducted on this hospital and the spotlight was on it. (And did it ever need it!)

WE ANALYZED THE GAP IN FIVE AREAS

FIRST AREA

AAA – Authorization, Access, and Accounting on an enterprise level. This included single sign-on, a primary aspect of federated identity. Our goal was to standardize the security infrastructure. We discovered numerous instances where Nurse-A could log in at Station-1, stay logged in while logging in again as herself at Station-2, and be granted a different access level.

All current authentication processes were reviewed. Possible vendor solutions were evaluated. A general implementation plan was developed.

SECOND AREA

Awareness. How security-conscious are the employees? Did they know about the different security levels of information?
  1. Unclassified
  2. Classified
  3. Confidential
  4. Restricted
  5. Secret
  6. Top Secret
Our goal was to heighten the security awareness of workers throughout the organization. Make it clear that this is everyone’s responsibility and request for their cooperation. A regular familiarization course was developed and all employees have to attend it every six months. A hotline was also established.

THIRD AREA

Incident Notification & Response. The security awareness course and the hotline are just two of the responsibilities of a new IT-based group. Our goal was to create a first-response team and proactive overseer of enterprise security. They did not make policy; instead they implemented it. At the same time, they tracked actual user practices, compared it to best practices, and submitted progress reports to the Chief Security Officer (a position that was newly created).

FOURTH AREA

Technical Security. We conducted a comprehensive review of the existing security framework. The framework covered firewalls, DMZs, intrusion detection & prevention tools, and the like. Security logs were audited. Patch management was taken seriously. Password policies were enacted. Our goal was to optimize the hospital’s technical security. These efforts were primarily focused at the hospital’s data center. Technical security briefly touched on Disaster Recovery but DR was going to be a separate project.

FIFTH AREA

Best Practices. Our objective was to train users to work using best practices. This was easier said than done since this was change management and most of the staff were lifers, i.e., employees of long tenure. We had to start over several times. In the end, we learned that the best way to coax them to accept change was to first listen to them. This is the area where our business analysts really proved their worth!

CONCLUSION

Several areas above, e.g., Technical Security and Best Practices, were longer and more difficult than expected. The entire project took eight months—two months past schedule and 40% over budget! The core project team consisted of three full-time members. I was one of them.

Would I consider it successful? Yes. We achieved the project's goals. Were the customers happy? The end-users were. Management was not. From the beginning, we articulated to senior management that they had an unrealistic schedule especially because they were ripping out an old application software system. Delays cost money.

At the project onset, they practiced an all too familiar but ill-advised tactic. They asked us for a "realistic" budget. We were outside consultants. Specifically we were the subcontractors of a (politically-connected) contractor. We used parametric and bottom-up estimates, got the agreement from our contractor, and we jointly submitted it to hospital management.

I remember the incident vividly. We were in the office of the hospital administrator. He glanced at it, asked us a few questions, crossed out our figure, deducted 30%, and wrote that down and signed off beside his scribbled amount. Furthermore, he slashed a month of our projected schedule.


Sphere: Related Content

Thursday, January 3, 2008
















HIPAA-MANDATED CODE SETS


Title II of HIPAA contains "Administrative Simplifications" provisions. One provision requires a standard code set for all electronic transactions. There are three accepted code sets. This article discusses the primary one.

Most of the material for this blog entry came from the book shown here.

I had written a blog entry that went over the substance of the “Administrative Simplification” provisions of HIPAA. Among other things, the entry mentioned the HIPAA-mandated standards for electronically transferring medical data from one party to another. Click here to open a new tab or window of that blog entry.

In the process of finalizing the blog entry, I came across an excellent book that filled in some gaps. Its title is “Learning to Code with ICD-9-CM for Health Information management and Health Services Administration 2007” (Falen, Liberman). The tome is a student textbook meant for aspiring medical coders but its opening chapters succinctly explain medical codes and their role in HIPAA.

This blog entry is outlined like so:
  1. The primary purpose of medical coding
  2. The secondary purpose of medical coding
  3. Other uses of medical coding
  4. History of the ICD-9-CM (this is the name of the set of medical codes)
  5. Format & Content of ICD-9-CM
  6. The future of medical coding
  7. Summary
The relevance of medical coding in the HIPAA scheme of things is explained in the sixth section. It’s located near the end because preceding sections provide useful background information. Here’s how medical coding fits in the big picture:
Medical codes have been standardized for electronic health care transactions. HIPAA requires every provider who does business electronically to use the same health care transactions, code sets, and identifiers. This applies to ten types of electronic transactions that must meet these standards. Examples are: claims, claims status, payments, and remittances. These transactions must use three code sets approved by HIPAA. These are ICD-9-CM, HCPCS, and CPT. The healthcare industry is, by and large, already familiar with these sets since they’re already being used.
Images of the two most-commonly used transaction forms are also shown. The codes are used in these forms.
  • Form UB-92 is used by hospitals for electronic transactions.
  • Form CMS-1500 is used by physicians for electronic transactions.
You can click on any image to enlarge it.

THE PRIMARY PURPOSE OF MEDICAL CODING


Data on the types and number of diseases in the U.S. provide important information to help us understand the overall condition of our nation’s health. Information contained in patients’ medical records, whether paper-based or electronic, holds great value in letting us know what is happening in health care. It is through the study of patient diseases and treatments that we can begin to understand, improve, and standardize quality health care; improve patients’ medical outcomes; and improve patient services at reduced cost. Each individual success at the patient provider and the institutional level (micro level) adds to our collective health success at a national level (macro level).

Codes tell us the important story of each patient’s health-care encounter. The quality of coded data provides us with health-care information to support our best decisions to improve the quality of patient care.

The International Classification of Diseases, 9th Revision, Clinical Modification (ICD-9-CM) is a widely used classification system for coding, classifying, and identifying patient diseases and procedures in the United States. It is a standardized medical communication tool that serves all health-care stakeholders, including physicians, health-care networks, hospitals, long-term care and outpatient facilities, insurers or other payers of care, employers, government officials, managed care organizations, patients, and countless other interested parties.

To quickly process and communicate important health-care data within this complex and dynamic health-care environment, medical coding systems transform verbal medical descriptions of patient diseases and procedures into codes that are communicated electronically (e.g., diagnosis code 428.0 indicates congestive heart failure). Codes, rather than long narrative descriptions of diseases and procedures, can be quickly entered into information systems and processed to create health-care information.

This information is used for medical research to study and improve the quality of patient care, and can also be transmitted to third-party payers to facilitate payments to health-care providers. Codes also inform payers the medical services they are paying for. They can substantiate that the care rendered was medically necessary, health-care resources were properly utilized, and that the health-care provider’s chargers were reasonable.

THE SECONDARY PURPOSE OF MEDICAL CODING

The secondary purpose of medical coding is to simplify the reimbursement processes of prospective payment systems (PPS).

Over the past several years, to control and reduce skyrocketing health-care costs, the U.S. government’s Medicare and Medicaid programs and most other private third-party payers of health-care services have used medical coding systems to structure prospective payment rates to health-care providers for services to their patients.

Prospective payment systems (PPS) are reimbursement formulas determined in advance of the health-care services rendered that are not based on the provider’s costs to treat the patient. The provider knows prospectively what the payment will be for health-care services rendered. These payments are predetermined based on the average cost of health-care resources necessary to treat the patient’s condition as revealed through diagnosis and procedure codes.

OTHER USES OF MEDICAL CODING

In addition to reimbursement, coded information is used by health-care facilities to determine and plan for the types of services that are needed within communities. For example, coded data revealing a high incidence of coronary artery disease within a hospital may indicate the need to recruit more cardiologists and open a diagnostic heart catheter laboratory. Also, coded data can be analyzed to help develop and implement local, state, and national health-care policy (e.g., smoking cessation, obesity education, anti-drug policies, and early-pregnancy education) and to determine mechanisms to contain health-care costs.

Coded information helps to identify patient cases to develop best-care practices as clinical guidelines to assist physicians in providing consistent quality care for particular diseases and to identify patient cases to further clinical research. With the growth of managed care organizations, coding also serves as the basis for disease management through various health-care settings and provider networks. For example, as a patient travels from the doctor’s office to a hospital to a home health agency or skilled nursing facility, coding provides a flow of patient information to promote the continuity of patient care and preventive care services. Foremost, quality coded data provide information to help health-care administrators make good decisions to improve Medicare for the patients they serve. Providing quality care to patients within their communities is the unifying mission of all health-care providers.

HISTORY OF THE ICD-9-CM

Historically, the ICD-9-CM's Tabular List of Diseases (volume 1) and the Alphabetic Index to Diseases (volume 2) represent a clinical modification (CM) to the World Health Organization’s (WHO) publication International Classification of Diseases, 9th Revision (ICD-9). The WHO collaborates with the Unite Nations and assists governments in strengthening their health services whenever possible. Through ICD, the WHO collects international information of the diseases of member populations. However, this international version does not completely meet the needs of the United States because of its emphasis on the more acute infectious diseases seen in developing countries rather than on the chronic diseases seen in the United States (such as arteriosclerosis and hypertension). For that reason, WHO's ICD-9 has been clinically modified (CM) for use in the United States. The result is the ICD-9-CM (for International Classification of Diseases, 9th Revision, Clinically Modified).

The United States added a third volume to accommodate the U.S.-specific diseases. This is the Alphabetic Index to Procedures and Tabular List of Procedures (volume 3). Code revisions and new codes for the ICD-9-CM have been developed annually by the Centers for Medicare & Medicaid Services (CMS) and the National Center for Health Statistics (NCHS). ICD-9-CM codes are updated twice a year.

FORMAT & CONTENT OF ICD-9-CM

An effective (coding) classification system such as ICD-­9-CM must follow three basic rules:
  1. the set of categories should be derived from a “single classification prin­ciple,” meaning that the classification should be organized by anatomic body sites (e.g., appendix and heart), causes of disease (e.g., infection and tumors), or names of diseases;
  2. the set of categories should be “exhaustive,” meaning that there is a code provided for every disease and procedure (i.e., a place to code ev­erything); and
  3. the categories within the classification should be “mutually exclusive” (i.e., each disease and procedure must have a unique code to retain the integrity of the data).
ICD-9-CM is “officially” published by the federal government as a three-volume set that includes the Tabular List of Diseases (volume 1), the Alphabetic Index to Diseases (volume 2), and the Alphabetic Index to Procedures and Tabular List of Procedures (volume 3).

THE FUTURE OF MEDICAL CODING

The World Health Organization (WHO) published ICD-10 in 1992. Since then, CMS has made considerable progress with its clinical modification (CM) of ICD-10. The resulting code set will be ICD-10-CM.

HIPAA will eventually be amended to make ICD-10-CM the official coding standard. Under the Title II “Administrative Simplification” provisions of HIPAA, federal standards mandate the simplification of the electronic transfer of medical data for health-care providers, health plans, and health-care clearinghouses. The “Administrative Simplification” provisions have four parts that specify the requirements for:
  1. Electronic health transaction standards including standard code sets.
  2. Unique identifiers for patients, providers, employers, and health plans.
  3. Security and Electronic Signature Standards for health information maintained or transmitted electronically.
  4. Privacy and Confidentiality Standards for protected health information (PHI).
Within the provision for electronic health transaction standards, health-care organizations must use standard code sets for all health transactions. HIPAA currently uses three code sets: ICD-9-CM, Current Procedural Terminology (CPT), and Healthcare Common Procedure Coding System (HCPCS).

Currently, hospital inpatient services use the entire ICD-9-CM code set. Hospital outpatient encounters are reported and billed using ICD-9-CM diagnosis codes only.

Physicians use ICD-9-CM diagnosis codes and CPT and/or HCPCS procedure codes to report and bill for their services.

Hospitals use the Uniform Bill 92 (UB-92) and physicians use the CMS-1500 as standardized billing forms to report required patient information to Medicare, Medicaid, and other third party payers. Patient data within the claim forms are encoded with ICD-9-CM diagnosis codes. Procedure codes, on the other hand, use either ICD-9-CM, CPT, and/or HCPCS. These are the claim forms—UB-92 and CMS-1500—that are routinely submitted elec­tronically by providers to a fiscal intermediary, carrier, insurance company, or health plan for processing and payment.

For paper claims, hospitals use a different form, UB-04. This is the form used to bill Medicare Part-A and to report services to other insurance companies for payment.

The electronic exchange of data between a provider and insurance com­pany is called electronic data interchange (EDI). Sometimes a provider con­tracts with a clearinghouse to assist in the processing of electronic claims due to the varied data formats required by different insurance companies and health-care plans. By standardizing health-care administration, HIPAA expects to eventually simplify, improve, and reduce the cost of health-care administration. The goal is to redi­rect the savings to patient-care focused activities.

Physicians use the CMS-1500 to bill Medicare Part-B and insurance companies for payment.

SUMMARY

Medical records contain valuable information about a patient's medical his­tory. Classification systems such as ICD-9-CM translate verbal descrip­tions from these medical records into codes that tell an important story. Codes are a standard form of medical communication that allow us to identify diseases and procedures, as well as study health-care trends, facilitate payment, substantiate the medical necessity of care rendered, and help vali­date that the provider's charges are reasonable.

The ICD-9-CM classification system is used throughout the United States in inpatient and outpatient facilities for medical coding. This is one of the three code sets—and the major one—that is mandated by HIPAA.



Sphere: Related Content

Monday, February 12, 2007

HIPAA’S ADMINISTRATIVE SIMPLIFICATION REQUIREMENTS

It surprised me at how many affected healthcare providers and business partners were still trying to finish the steps that are needed to comply with HIPAA. This is the substance of a primer I prepared on August 16, 2003, exactly two months before the compliance deadline. That was three and a half years ago. The last physician clinic we helped become compliant was in summer 2006. I wouldn’t be surprised if we got several more engagements like that.

This primer covers HIPAA’s key administrative aspects.

One of HIPAA's important objectives is to simplify the administrative requirements of the healthcare industry. The administrative simplification requirements consist of four parts:
  1. Electronic transactions and code sets
  2. Security
  3. Unique identifiers
  4. Privacy
If (you) the healthcare provider or its billing company or clearinghouse transacts business electronically, then all related parties are covered by HIPAA.

Business transactions are any of the following:
  1. Claims
  2. Payment and remittance advices
  3. Claim status inquiries and responses
  4. Eligibility inquiries and responses
  5. Referral authorization inquiries and responses
HIPAA strongly encourages the designation of a “point of contact” in the covered entity. This could be your office manager. This person is responsible for all HIPAA-related activities. You should provide this person with some level of authority, resources, and assistance.

Your office
  1. Ensure that your medical office administrative software is HIPAA-compliant. Check with your vendor.
  2. Clarify the documents that are transmitted electronically and on paper. Determine what needs to be done differently. Under HIPAA, certain data are required that your existing paper forms do not have.
The health insurance payers
  1. If they haven’t done so yet, learn when they will distribute a guide for HIPAA-mandated coding and transaction requirements. Local codes have been eliminated by HIPAA as part of its administrative simplification objective.
  2. Confirm whether they will provide you with partner agreements that specify transmission methods as well as the coding and transaction requirements specified above.
  3. Ensure that they have tested their software for HIPAA-compliance. Ensure that you participated in these tests.
I edited this entry to add this link to the coding system. The next version of the coding system was released after I wrote that entry although the substance is virtually identical.


Sphere: Related Content