SlideShare a Scribd company logo
Opportunity Knocks:
   Modern Healthcare
Information Technology
Agenda


• HITECH/EHR Overview
• HITECH/EHR Services & Solutions

• Health Information Technology Risks
• ANSI PHI Project
HITECH/EHR Overview

     HITECH/EHR Overview
   HIPAA & PHI Data Breaches
      Enforcement Updates
HITECH/EHR Overview

• HC IT Project Drivers: Incentives
   ARRA HITECH – ―EHR … by 2014‖
     Nationwide HIT infrastructure
     Meaningful Use HIPAA security requirements
     Changing EHR MU Stage 2 & 3 requirements
     Upcoming ACO requirements
• HC IT Project Drivers: Sanctions
   PHI breach notification
   HIPAA enforcement
HIPAA and PHI Data Breaches

• Ponemon Institute: Data breaches cost hospitals nearly $6
  billion/year1
• Medical-related data breaches listed in Privacy Rights
  Clearinghouse2
        116 breaches listed in 2007-2008
        229 breaches listed in 2009-2010
• 86% of large-hospital employees surveyed believe the number of
  data breaches discovered will increase under HITECH3
• The Department of Justice secured ―$2.5 billion in health care
  fraud recoveries—the largest in history,‖ for the fiscal year
  ending 9-30-20104
     1- Source: Benchmark Study on Patient Privacy and Data Security, November 9, 2010, Ponemon Institute LLC.
     2- Source: http://www.privacyrights.org/
     3- Source: 2009 HIMSS Analytics Report:―Taking a Pulse on HITECH, Are Hospitals and Business Associates Ready?‖ November 17, 2009.
     4- Source: Department of Justice, November 22, 2010, http://www.justice.gov/opa/pr/2010/November/10-civ-1335.html


 5
Enforcement Updates

HIPAA Sanctions
• Periodic HHS CE & BA HIPAA Compliance Audits
• Violations range from $100 to $1.5 million (willful
  neglect)
• Extends criminal penalties to individual or employee of
  CE
• State attorneys general can file civil suit on behalf of
  residents
Enforcement Updates

OCR Commitment to HIPAA Enforcement
Program Increases
•   Regional Office Privacy Advisors (+$2.283 million)
•   Enforcement of the HIPAA Security Rule (+$1 million)
•   Investigation of the HITECH Breach Reports (+$1.335 million)
•   Compliance Review Program (+$1 million)
Enforcement Updates

HIPPA Enforcement Activities
• Cignet Health, 2011: $4.3 million – Denying access to
  medical records & refusing to cooperate with OCR
  investigation
   http://www.hhs.gov/news/press/2011pres/02/20110222a.html

• Massachusetts General Hospital Settles HIPAA Violations,
  2011: $1 million – Documents left on subway by employee
   http://www.hhs.gov/news/press/2011pres/02/20110224b.html

• Health Net, 2011: $55,000 + mandatory data-security audit 2
  years – Lost portable drive & misrepresentation of risk
   http://www.healthdatamanagement.com/news/breach_hipaa_privacy_security_hitech_lawsuit-39645-
       1.html

• Rite Aid, 2010: $1 Million – Poor disposal practices
   http://www.hhs.gov/news/press/2010pres/07/20100727a.html
HITECH/EHR Services &
      Solutions

  EHR Related Services BKD Provides
HITECH/EHR Services & Solutions

Outsourced Project Management
•     Assist management with development of project plan to manage all phases of EHR
      implementation project
•     Assist management with overseeing project milestones
•     Periodic project status & project risk reports
    EHR System Selection
•     Assist management with identifying & evaluating an EHR-compliant system
•     Demonstration scorecards—basis for purchase decisions
•     Total cost of ownership—three-year estimates that include software, equipment &
      implementation fees
EHR Readiness Assessment
•     IT & infrastructure inventory
•     EHR current capabilities assessment
•     IT Governance & process maturity measurements
•     Security compliance assessment

10
HITECH/EHR Services & Solutions

ARRA Reimbursement Analysis
•    Develop reimbursement projections
•    Develop multi-year cash flow analysis mapping EHR project timeline with federal
     funding timeline projections
EHR Meaningful Use Attestation Assistance
•    Review meaningful use objectives management has decided to report against
•    Develop audit procedures to determine if selected objectives are being met
•    Provide findings & recommendations based on executed audit procedures
HIPAA Data Security & Privacy Assessment
•    Data-flow analysis
•    Risk & control identification
•    IT Governance & process maturity measurements
•    Control design & effectiveness testing



11
Health Information
Technology Risks

    Understanding HIT Data-flow
Risk Associated with Clinical Systems
    Expanded Audit Procedures
Health Information Technology
Risks

• Developing clinical system & sub-system
  inventory
• Understanding flow of data in a healthcare
  system
• Identifying risks & controls




13
Health Information Technology
Risks




14
Health Information Technology
Risks




15
Health Information Technology
Risks




16
Health Information Technology
Risks

Expanded HIT Audit Procedures
• Data-flow analysis
• Computer Assisted Audit Techniques (CAAT)

• Evaluating security at clinical system level

• Evaluating intermediary data repositories &
  job scheduling/data integration systems


17
ANSI/Shared Assessments
       PHI Project

 Report & tools valuing financial impact
 of unauthorized disclosure of protected
        health information (PHI)
ANSI/Shared Assessments PHI
Project




 http://www.ansi.org/standards_activities/standards_boards_panels/idsp/protected_health_information.aspx


19
Thank You



Matt Lathrom, CISM, CISA, MCP
    Managing Consultant
     BKD IT Risk Services
    mlathrom@bkd.com
       816.221.6300

More Related Content

What's hot

Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KCTell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Kevin Perry
 
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
Brussels Briefings (brusselsbriefings.net)
 
Innovative project1
Innovative project1Innovative project1
Innovative project1
LillySheebaS1
 
Top 3 Changes in Technological Advances influencing Healthcare version 2
Top 3 Changes in Technological Advances influencing Healthcare version 2Top 3 Changes in Technological Advances influencing Healthcare version 2
Top 3 Changes in Technological Advances influencing Healthcare version 2Chris Dawson
 
Meaningful Use and Security Risk Analysis
Meaningful Use and Security Risk AnalysisMeaningful Use and Security Risk Analysis
Meaningful Use and Security Risk Analysis
Evan Francen
 
HIPAA Workloads on AWS - Pop-up Loft Tel Aviv
HIPAA Workloads on AWS - Pop-up Loft Tel AvivHIPAA Workloads on AWS - Pop-up Loft Tel Aviv
HIPAA Workloads on AWS - Pop-up Loft Tel Aviv
Amazon Web Services
 
BlueButton on FHIR @HXRconf
BlueButton on FHIR @HXRconf BlueButton on FHIR @HXRconf
BlueButton on FHIR @HXRconf
Mark Scrimshire
 
HSCIC: NHS Pathways - Intelligent Data Toolkit
HSCIC: NHS Pathways - Intelligent Data ToolkitHSCIC: NHS Pathways - Intelligent Data Toolkit
HSCIC: NHS Pathways - Intelligent Data Toolkit
The Health and Social Care Information Centre
 
The Path to Wellness through Big Data
The Path to Wellness through Big DataThe Path to Wellness through Big Data
The Path to Wellness through Big Data
DataWorks Summit/Hadoop Summit
 
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
Mark Scrimshire
 
Brisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage FrameworkBrisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage Framework
ARDC
 
How Best Are Medical Practices Prepared to Address HIPAA Breaches?
How Best Are Medical Practices Prepared to Address HIPAA Breaches? How Best Are Medical Practices Prepared to Address HIPAA Breaches?
How Best Are Medical Practices Prepared to Address HIPAA Breaches?
Medical Billers and Coders
 
#soteSlush: Antti Tuomi-Nikula
#soteSlush: Antti Tuomi-Nikula#soteSlush: Antti Tuomi-Nikula
#soteSlush: Antti Tuomi-Nikula
Sosiaali- ja terveysministeriö / yleiset
 
How Safe are mHealth Apps?
How Safe are mHealth Apps?How Safe are mHealth Apps?
How Safe are mHealth Apps?
Maria Wolters
 
Dennis Kehoe - ECO 15: Digital connectivity in healthcare
Dennis Kehoe - ECO 15: Digital connectivity in healthcareDennis Kehoe - ECO 15: Digital connectivity in healthcare
Dennis Kehoe - ECO 15: Digital connectivity in healthcare
Innovation Agency
 
Paul McGinness - ECO 21
Paul McGinness - ECO 21Paul McGinness - ECO 21
Paul McGinness - ECO 21
Innovation Agency
 
#soteSlush - Teemupekka Virtanen
#soteSlush - Teemupekka Virtanen#soteSlush - Teemupekka Virtanen
#soteSlush - Teemupekka Virtanen
Sosiaali- ja terveysministeriö / yleiset
 
Health IT Programmes - lifting performance across the sector
Health IT Programmes - lifting performance across the sectorHealth IT Programmes - lifting performance across the sector
Health IT Programmes - lifting performance across the sector
Health Informatics New Zealand
 
Medicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcareMedicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcare
Innovation Agency
 
Data Preparation and Visualization for Monitoring NCDs Mortality
Data Preparation and Visualization for Monitoring NCDs MortalityData Preparation and Visualization for Monitoring NCDs Mortality
Data Preparation and Visualization for Monitoring NCDs Mortality
Ramon Martinez
 

What's hot (20)

Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KCTell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
 
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
 
Innovative project1
Innovative project1Innovative project1
Innovative project1
 
Top 3 Changes in Technological Advances influencing Healthcare version 2
Top 3 Changes in Technological Advances influencing Healthcare version 2Top 3 Changes in Technological Advances influencing Healthcare version 2
Top 3 Changes in Technological Advances influencing Healthcare version 2
 
Meaningful Use and Security Risk Analysis
Meaningful Use and Security Risk AnalysisMeaningful Use and Security Risk Analysis
Meaningful Use and Security Risk Analysis
 
HIPAA Workloads on AWS - Pop-up Loft Tel Aviv
HIPAA Workloads on AWS - Pop-up Loft Tel AvivHIPAA Workloads on AWS - Pop-up Loft Tel Aviv
HIPAA Workloads on AWS - Pop-up Loft Tel Aviv
 
BlueButton on FHIR @HXRconf
BlueButton on FHIR @HXRconf BlueButton on FHIR @HXRconf
BlueButton on FHIR @HXRconf
 
HSCIC: NHS Pathways - Intelligent Data Toolkit
HSCIC: NHS Pathways - Intelligent Data ToolkitHSCIC: NHS Pathways - Intelligent Data Toolkit
HSCIC: NHS Pathways - Intelligent Data Toolkit
 
The Path to Wellness through Big Data
The Path to Wellness through Big DataThe Path to Wellness through Big Data
The Path to Wellness through Big Data
 
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
 
Brisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage FrameworkBrisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage Framework
 
How Best Are Medical Practices Prepared to Address HIPAA Breaches?
How Best Are Medical Practices Prepared to Address HIPAA Breaches? How Best Are Medical Practices Prepared to Address HIPAA Breaches?
How Best Are Medical Practices Prepared to Address HIPAA Breaches?
 
#soteSlush: Antti Tuomi-Nikula
#soteSlush: Antti Tuomi-Nikula#soteSlush: Antti Tuomi-Nikula
#soteSlush: Antti Tuomi-Nikula
 
How Safe are mHealth Apps?
How Safe are mHealth Apps?How Safe are mHealth Apps?
How Safe are mHealth Apps?
 
Dennis Kehoe - ECO 15: Digital connectivity in healthcare
Dennis Kehoe - ECO 15: Digital connectivity in healthcareDennis Kehoe - ECO 15: Digital connectivity in healthcare
Dennis Kehoe - ECO 15: Digital connectivity in healthcare
 
Paul McGinness - ECO 21
Paul McGinness - ECO 21Paul McGinness - ECO 21
Paul McGinness - ECO 21
 
#soteSlush - Teemupekka Virtanen
#soteSlush - Teemupekka Virtanen#soteSlush - Teemupekka Virtanen
#soteSlush - Teemupekka Virtanen
 
Health IT Programmes - lifting performance across the sector
Health IT Programmes - lifting performance across the sectorHealth IT Programmes - lifting performance across the sector
Health IT Programmes - lifting performance across the sector
 
Medicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcareMedicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcare
 
Data Preparation and Visualization for Monitoring NCDs Mortality
Data Preparation and Visualization for Monitoring NCDs MortalityData Preparation and Visualization for Monitoring NCDs Mortality
Data Preparation and Visualization for Monitoring NCDs Mortality
 

Viewers also liked

Sage MAS 90 Payment Solutions
Sage MAS 90 Payment SolutionsSage MAS 90 Payment Solutions
Sage MAS 90 Payment Solutions
Jeffrey Paulette
 
Sage MAS Intelligence vs. Biz Insights
Sage MAS Intelligence vs. Biz InsightsSage MAS Intelligence vs. Biz Insights
Sage MAS Intelligence vs. Biz Insights
Jeffrey Paulette
 
Financial Reporting Tools for Dynamics GP Shootout
Financial Reporting Tools for Dynamics GP ShootoutFinancial Reporting Tools for Dynamics GP Shootout
Financial Reporting Tools for Dynamics GP Shootout
Jeffrey Paulette
 
SSAE 16 Transitions Overview
SSAE 16 Transitions OverviewSSAE 16 Transitions Overview
SSAE 16 Transitions OverviewJeffrey Paulette
 
Internal Controls Over Information Systems
Internal Controls Over Information Systems Internal Controls Over Information Systems
Internal Controls Over Information Systems
Jeffrey Paulette
 
Basic tutorial how to use google calendar
Basic tutorial how to use google calendarBasic tutorial how to use google calendar
Basic tutorial how to use google calendar
Cherrylin Ramos
 

Viewers also liked (7)

Sage MAS 90 Payment Solutions
Sage MAS 90 Payment SolutionsSage MAS 90 Payment Solutions
Sage MAS 90 Payment Solutions
 
Sage MAS Intelligence vs. Biz Insights
Sage MAS Intelligence vs. Biz InsightsSage MAS Intelligence vs. Biz Insights
Sage MAS Intelligence vs. Biz Insights
 
Financial Reporting Tools for Dynamics GP Shootout
Financial Reporting Tools for Dynamics GP ShootoutFinancial Reporting Tools for Dynamics GP Shootout
Financial Reporting Tools for Dynamics GP Shootout
 
SSAE 16 Transitions Overview
SSAE 16 Transitions OverviewSSAE 16 Transitions Overview
SSAE 16 Transitions Overview
 
Internal Controls Over Information Systems
Internal Controls Over Information Systems Internal Controls Over Information Systems
Internal Controls Over Information Systems
 
How To Use Google Calendar
How To Use Google CalendarHow To Use Google Calendar
How To Use Google Calendar
 
Basic tutorial how to use google calendar
Basic tutorial how to use google calendarBasic tutorial how to use google calendar
Basic tutorial how to use google calendar
 

Similar to Modern Healthcare Information Technology

What Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sWhat Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​s
Iatric Systems
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture E
CMDLearning
 
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT SecurityRedspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin, Inc.
 
Panel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITPanel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HIT
mihinpr
 
Blockchain2[1].pptx
Blockchain2[1].pptxBlockchain2[1].pptx
Blockchain2[1].pptx
koretamirat
 
HITRUST CSF Meaningful use risk assessment
HITRUST CSF Meaningful use risk assessmentHITRUST CSF Meaningful use risk assessment
HITRUST CSF Meaningful use risk assessmentVinit Thakur
 
Regulatory Intelligence
Regulatory IntelligenceRegulatory Intelligence
Regulatory Intelligence
Armin Torres
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
Kimberly Simon MBA
 
data for Nursing.pptx
data for Nursing.pptxdata for Nursing.pptx
data for Nursing.pptx
calich88
 
Comp8 unit6a lecture_slides
Comp8 unit6a lecture_slidesComp8 unit6a lecture_slides
Comp8 unit6a lecture_slides
CMDLMS
 
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
Polsinelli PC
 
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
Michigan Primary Care Association
 
Direct Boot Camp 2 0 Federal Agency requirements for exchange via direct
Direct Boot Camp 2 0 Federal Agency requirements for exchange via directDirect Boot Camp 2 0 Federal Agency requirements for exchange via direct
Direct Boot Camp 2 0 Federal Agency requirements for exchange via directBrian Ahier
 
HIPAA
HIPAAHIPAA
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
Kimberly Simon MBA
 
Hb Emr
Hb EmrHb Emr
E Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep PpE Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep Pp
hunterberney
 
Trust and Governance in Health and Social Care
Trust and Governance in Health and Social Care Trust and Governance in Health and Social Care
Trust and Governance in Health and Social Care
Napier University
 
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
eringold
 
Health Information Exchange Workgroup 110310
Health Information Exchange Workgroup 110310Health Information Exchange Workgroup 110310
Health Information Exchange Workgroup 110310Brian Ahier
 

Similar to Modern Healthcare Information Technology (20)

What Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sWhat Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​s
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture E
 
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT SecurityRedspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
 
Panel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITPanel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HIT
 
Blockchain2[1].pptx
Blockchain2[1].pptxBlockchain2[1].pptx
Blockchain2[1].pptx
 
HITRUST CSF Meaningful use risk assessment
HITRUST CSF Meaningful use risk assessmentHITRUST CSF Meaningful use risk assessment
HITRUST CSF Meaningful use risk assessment
 
Regulatory Intelligence
Regulatory IntelligenceRegulatory Intelligence
Regulatory Intelligence
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
data for Nursing.pptx
data for Nursing.pptxdata for Nursing.pptx
data for Nursing.pptx
 
Comp8 unit6a lecture_slides
Comp8 unit6a lecture_slidesComp8 unit6a lecture_slides
Comp8 unit6a lecture_slides
 
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
 
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
 
Direct Boot Camp 2 0 Federal Agency requirements for exchange via direct
Direct Boot Camp 2 0 Federal Agency requirements for exchange via directDirect Boot Camp 2 0 Federal Agency requirements for exchange via direct
Direct Boot Camp 2 0 Federal Agency requirements for exchange via direct
 
HIPAA
HIPAAHIPAA
HIPAA
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
 
Hb Emr
Hb EmrHb Emr
Hb Emr
 
E Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep PpE Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep Pp
 
Trust and Governance in Health and Social Care
Trust and Governance in Health and Social Care Trust and Governance in Health and Social Care
Trust and Governance in Health and Social Care
 
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
 
Health Information Exchange Workgroup 110310
Health Information Exchange Workgroup 110310Health Information Exchange Workgroup 110310
Health Information Exchange Workgroup 110310
 

More from Jeffrey Paulette

Business Activity Monitoring in MAS 90 With KnowledgeSync
Business Activity Monitoring in MAS 90 With KnowledgeSyncBusiness Activity Monitoring in MAS 90 With KnowledgeSync
Business Activity Monitoring in MAS 90 With KnowledgeSync
Jeffrey Paulette
 
Sage MAS 500 Version 7.4 Sneak Peak
Sage MAS 500 Version 7.4 Sneak PeakSage MAS 500 Version 7.4 Sneak Peak
Sage MAS 500 Version 7.4 Sneak Peak
Jeffrey Paulette
 
Sage MAS 90 with Doc-Link
Sage MAS 90 with Doc-LinkSage MAS 90 with Doc-Link
Sage MAS 90 with Doc-Link
Jeffrey Paulette
 
Sage MAS Intelligence for MAS 90 & MAS 200
Sage MAS Intelligence for MAS 90 & MAS 200Sage MAS Intelligence for MAS 90 & MAS 200
Sage MAS Intelligence for MAS 90 & MAS 200
Jeffrey Paulette
 
Business Portal for Dynamics GP
Business Portal for Dynamics GPBusiness Portal for Dynamics GP
Business Portal for Dynamics GP
Jeffrey Paulette
 
Management Reporter for Dynamics GP
Management Reporter for Dynamics GPManagement Reporter for Dynamics GP
Management Reporter for Dynamics GP
Jeffrey Paulette
 
Dynamics GP Year End Closing Procedures 2010
Dynamics GP Year End Closing Procedures 2010Dynamics GP Year End Closing Procedures 2010
Dynamics GP Year End Closing Procedures 2010
Jeffrey Paulette
 
Microsoft Dynamics GP 2010 Sneak Peak
Microsoft Dynamics GP 2010 Sneak PeakMicrosoft Dynamics GP 2010 Sneak Peak
Microsoft Dynamics GP 2010 Sneak Peak
Jeffrey Paulette
 
Workflows For Microsoft Dynamics GP 2010
Workflows For Microsoft Dynamics GP 2010Workflows For Microsoft Dynamics GP 2010
Workflows For Microsoft Dynamics GP 2010
Jeffrey Paulette
 
Help Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GPHelp Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GP
Jeffrey Paulette
 
Sage MAS 90 Year End Payroll Closing For 2010
Sage MAS 90 Year End Payroll Closing For 2010Sage MAS 90 Year End Payroll Closing For 2010
Sage MAS 90 Year End Payroll Closing For 2010
Jeffrey Paulette
 
Sage MAS 90 Year End Closing Procedures 2010
Sage MAS 90 Year End Closing Procedures 2010Sage MAS 90 Year End Closing Procedures 2010
Sage MAS 90 Year End Closing Procedures 2010
Jeffrey Paulette
 
What's New In Sage MAS 90
What's New In Sage MAS 90What's New In Sage MAS 90
What's New In Sage MAS 90
Jeffrey Paulette
 
Sage MAS 90 Tips & Tricks
Sage MAS 90 Tips & TricksSage MAS 90 Tips & Tricks
Sage MAS 90 Tips & Tricks
Jeffrey Paulette
 
Go Green While Saving Some Green
Go Green While Saving Some GreenGo Green While Saving Some Green
Go Green While Saving Some Green
Jeffrey Paulette
 

More from Jeffrey Paulette (16)

Business Activity Monitoring in MAS 90 With KnowledgeSync
Business Activity Monitoring in MAS 90 With KnowledgeSyncBusiness Activity Monitoring in MAS 90 With KnowledgeSync
Business Activity Monitoring in MAS 90 With KnowledgeSync
 
Sage MAS 500 Version 7.4 Sneak Peak
Sage MAS 500 Version 7.4 Sneak PeakSage MAS 500 Version 7.4 Sneak Peak
Sage MAS 500 Version 7.4 Sneak Peak
 
Sage MAS 90 with Doc-Link
Sage MAS 90 with Doc-LinkSage MAS 90 with Doc-Link
Sage MAS 90 with Doc-Link
 
Sage MAS Intelligence for MAS 90 & MAS 200
Sage MAS Intelligence for MAS 90 & MAS 200Sage MAS Intelligence for MAS 90 & MAS 200
Sage MAS Intelligence for MAS 90 & MAS 200
 
Business Portal for Dynamics GP
Business Portal for Dynamics GPBusiness Portal for Dynamics GP
Business Portal for Dynamics GP
 
Management Reporter for Dynamics GP
Management Reporter for Dynamics GPManagement Reporter for Dynamics GP
Management Reporter for Dynamics GP
 
Dynamics GP Year End Closing Procedures 2010
Dynamics GP Year End Closing Procedures 2010Dynamics GP Year End Closing Procedures 2010
Dynamics GP Year End Closing Procedures 2010
 
Microsoft Dynamics GP 2010 Sneak Peak
Microsoft Dynamics GP 2010 Sneak PeakMicrosoft Dynamics GP 2010 Sneak Peak
Microsoft Dynamics GP 2010 Sneak Peak
 
Workflows For Microsoft Dynamics GP 2010
Workflows For Microsoft Dynamics GP 2010Workflows For Microsoft Dynamics GP 2010
Workflows For Microsoft Dynamics GP 2010
 
Help Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GPHelp Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GP
 
Sage MAS 90 Year End Payroll Closing For 2010
Sage MAS 90 Year End Payroll Closing For 2010Sage MAS 90 Year End Payroll Closing For 2010
Sage MAS 90 Year End Payroll Closing For 2010
 
Sage MAS 90 Year End Closing Procedures 2010
Sage MAS 90 Year End Closing Procedures 2010Sage MAS 90 Year End Closing Procedures 2010
Sage MAS 90 Year End Closing Procedures 2010
 
What's New In Sage MAS 90
What's New In Sage MAS 90What's New In Sage MAS 90
What's New In Sage MAS 90
 
What's new in sage mas 90
What's new in sage mas 90What's new in sage mas 90
What's new in sage mas 90
 
Sage MAS 90 Tips & Tricks
Sage MAS 90 Tips & TricksSage MAS 90 Tips & Tricks
Sage MAS 90 Tips & Tricks
 
Go Green While Saving Some Green
Go Green While Saving Some GreenGo Green While Saving Some Green
Go Green While Saving Some Green
 

Recently uploaded

Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
Lviv Startup Club
 
Project File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdfProject File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdf
RajPriye
 
Recruiting in the Digital Age: A Social Media Masterclass
Recruiting in the Digital Age: A Social Media MasterclassRecruiting in the Digital Age: A Social Media Masterclass
Recruiting in the Digital Age: A Social Media Masterclass
LuanWise
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
fisherameliaisabella
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
creerey
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
Operational Excellence Consulting
 
Digital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and TemplatesDigital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and Templates
Aurelien Domont, MBA
 
Authentically Social Presented by Corey Perlman
Authentically Social Presented by Corey PerlmanAuthentically Social Presented by Corey Perlman
Authentically Social Presented by Corey Perlman
Corey Perlman, Social Media Speaker and Consultant
 
Kseniya Leshchenko: Shared development support service model as the way to ma...
Kseniya Leshchenko: Shared development support service model as the way to ma...Kseniya Leshchenko: Shared development support service model as the way to ma...
Kseniya Leshchenko: Shared development support service model as the way to ma...
Lviv Startup Club
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Arihant Webtech Pvt. Ltd
 
Company Valuation webinar series - Tuesday, 4 June 2024
Company Valuation webinar series - Tuesday, 4 June 2024Company Valuation webinar series - Tuesday, 4 June 2024
Company Valuation webinar series - Tuesday, 4 June 2024
FelixPerez547899
 
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Boris Ziegler
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
JeremyPeirce1
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
bosssp10
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
Nicola Wreford-Howard
 
The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
Adam Smith
 
Training my puppy and implementation in this story
Training my puppy and implementation in this storyTraining my puppy and implementation in this story
Training my puppy and implementation in this story
WilliamRodrigues148
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134
LR1709MUSIC
 
Mastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnapMastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnap
Norma Mushkat Gaffin
 
Observation Lab PowerPoint Assignment for TEM 431
Observation Lab PowerPoint Assignment for TEM 431Observation Lab PowerPoint Assignment for TEM 431
Observation Lab PowerPoint Assignment for TEM 431
ecamare2
 

Recently uploaded (20)

Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)Maksym Vyshnivetskyi: PMO Quality Management (UA)
Maksym Vyshnivetskyi: PMO Quality Management (UA)
 
Project File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdfProject File Report BBA 6th semester.pdf
Project File Report BBA 6th semester.pdf
 
Recruiting in the Digital Age: A Social Media Masterclass
Recruiting in the Digital Age: A Social Media MasterclassRecruiting in the Digital Age: A Social Media Masterclass
Recruiting in the Digital Age: A Social Media Masterclass
 
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdfModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
ModelingMarketingStrategiesMKS.CollumbiaUniversitypdf
 
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
 
Sustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & EconomySustainability: Balancing the Environment, Equity & Economy
Sustainability: Balancing the Environment, Equity & Economy
 
Digital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and TemplatesDigital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and Templates
 
Authentically Social Presented by Corey Perlman
Authentically Social Presented by Corey PerlmanAuthentically Social Presented by Corey Perlman
Authentically Social Presented by Corey Perlman
 
Kseniya Leshchenko: Shared development support service model as the way to ma...
Kseniya Leshchenko: Shared development support service model as the way to ma...Kseniya Leshchenko: Shared development support service model as the way to ma...
Kseniya Leshchenko: Shared development support service model as the way to ma...
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
 
Company Valuation webinar series - Tuesday, 4 June 2024
Company Valuation webinar series - Tuesday, 4 June 2024Company Valuation webinar series - Tuesday, 4 June 2024
Company Valuation webinar series - Tuesday, 4 June 2024
 
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
Agency Managed Advisory Board As a Solution To Career Path Defining Business ...
 
Top mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptxTop mailing list providers in the USA.pptx
Top mailing list providers in the USA.pptx
 
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
Call 8867766396 Satta Matka Dpboss Matka Guessing Satta batta Matka 420 Satta...
 
Exploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social DreamingExploring Patterns of Connection with Social Dreaming
Exploring Patterns of Connection with Social Dreaming
 
The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...The Influence of Marketing Strategy and Market Competition on Business Perfor...
The Influence of Marketing Strategy and Market Competition on Business Perfor...
 
Training my puppy and implementation in this story
Training my puppy and implementation in this storyTraining my puppy and implementation in this story
Training my puppy and implementation in this story
 
FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134FINAL PRESENTATION.pptx12143241324134134
FINAL PRESENTATION.pptx12143241324134134
 
Mastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnapMastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnap
 
Observation Lab PowerPoint Assignment for TEM 431
Observation Lab PowerPoint Assignment for TEM 431Observation Lab PowerPoint Assignment for TEM 431
Observation Lab PowerPoint Assignment for TEM 431
 

Modern Healthcare Information Technology

  • 1. Opportunity Knocks: Modern Healthcare Information Technology
  • 2. Agenda • HITECH/EHR Overview • HITECH/EHR Services & Solutions • Health Information Technology Risks • ANSI PHI Project
  • 3. HITECH/EHR Overview HITECH/EHR Overview HIPAA & PHI Data Breaches Enforcement Updates
  • 4. HITECH/EHR Overview • HC IT Project Drivers: Incentives  ARRA HITECH – ―EHR … by 2014‖  Nationwide HIT infrastructure  Meaningful Use HIPAA security requirements  Changing EHR MU Stage 2 & 3 requirements  Upcoming ACO requirements • HC IT Project Drivers: Sanctions  PHI breach notification  HIPAA enforcement
  • 5. HIPAA and PHI Data Breaches • Ponemon Institute: Data breaches cost hospitals nearly $6 billion/year1 • Medical-related data breaches listed in Privacy Rights Clearinghouse2  116 breaches listed in 2007-2008  229 breaches listed in 2009-2010 • 86% of large-hospital employees surveyed believe the number of data breaches discovered will increase under HITECH3 • The Department of Justice secured ―$2.5 billion in health care fraud recoveries—the largest in history,‖ for the fiscal year ending 9-30-20104 1- Source: Benchmark Study on Patient Privacy and Data Security, November 9, 2010, Ponemon Institute LLC. 2- Source: http://www.privacyrights.org/ 3- Source: 2009 HIMSS Analytics Report:―Taking a Pulse on HITECH, Are Hospitals and Business Associates Ready?‖ November 17, 2009. 4- Source: Department of Justice, November 22, 2010, http://www.justice.gov/opa/pr/2010/November/10-civ-1335.html 5
  • 6. Enforcement Updates HIPAA Sanctions • Periodic HHS CE & BA HIPAA Compliance Audits • Violations range from $100 to $1.5 million (willful neglect) • Extends criminal penalties to individual or employee of CE • State attorneys general can file civil suit on behalf of residents
  • 7. Enforcement Updates OCR Commitment to HIPAA Enforcement Program Increases • Regional Office Privacy Advisors (+$2.283 million) • Enforcement of the HIPAA Security Rule (+$1 million) • Investigation of the HITECH Breach Reports (+$1.335 million) • Compliance Review Program (+$1 million)
  • 8. Enforcement Updates HIPPA Enforcement Activities • Cignet Health, 2011: $4.3 million – Denying access to medical records & refusing to cooperate with OCR investigation http://www.hhs.gov/news/press/2011pres/02/20110222a.html • Massachusetts General Hospital Settles HIPAA Violations, 2011: $1 million – Documents left on subway by employee http://www.hhs.gov/news/press/2011pres/02/20110224b.html • Health Net, 2011: $55,000 + mandatory data-security audit 2 years – Lost portable drive & misrepresentation of risk http://www.healthdatamanagement.com/news/breach_hipaa_privacy_security_hitech_lawsuit-39645- 1.html • Rite Aid, 2010: $1 Million – Poor disposal practices http://www.hhs.gov/news/press/2010pres/07/20100727a.html
  • 9. HITECH/EHR Services & Solutions EHR Related Services BKD Provides
  • 10. HITECH/EHR Services & Solutions Outsourced Project Management • Assist management with development of project plan to manage all phases of EHR implementation project • Assist management with overseeing project milestones • Periodic project status & project risk reports EHR System Selection • Assist management with identifying & evaluating an EHR-compliant system • Demonstration scorecards—basis for purchase decisions • Total cost of ownership—three-year estimates that include software, equipment & implementation fees EHR Readiness Assessment • IT & infrastructure inventory • EHR current capabilities assessment • IT Governance & process maturity measurements • Security compliance assessment 10
  • 11. HITECH/EHR Services & Solutions ARRA Reimbursement Analysis • Develop reimbursement projections • Develop multi-year cash flow analysis mapping EHR project timeline with federal funding timeline projections EHR Meaningful Use Attestation Assistance • Review meaningful use objectives management has decided to report against • Develop audit procedures to determine if selected objectives are being met • Provide findings & recommendations based on executed audit procedures HIPAA Data Security & Privacy Assessment • Data-flow analysis • Risk & control identification • IT Governance & process maturity measurements • Control design & effectiveness testing 11
  • 12. Health Information Technology Risks Understanding HIT Data-flow Risk Associated with Clinical Systems Expanded Audit Procedures
  • 13. Health Information Technology Risks • Developing clinical system & sub-system inventory • Understanding flow of data in a healthcare system • Identifying risks & controls 13
  • 17. Health Information Technology Risks Expanded HIT Audit Procedures • Data-flow analysis • Computer Assisted Audit Techniques (CAAT) • Evaluating security at clinical system level • Evaluating intermediary data repositories & job scheduling/data integration systems 17
  • 18. ANSI/Shared Assessments PHI Project Report & tools valuing financial impact of unauthorized disclosure of protected health information (PHI)
  • 19. ANSI/Shared Assessments PHI Project http://www.ansi.org/standards_activities/standards_boards_panels/idsp/protected_health_information.aspx 19
  • 20. Thank You Matt Lathrom, CISM, CISA, MCP Managing Consultant BKD IT Risk Services mlathrom@bkd.com 816.221.6300