decisionhealth Newsletters, Part B News - 2012 Issue 6 (June)
Secure your EHR bonus with practice-tested security risk analysis techniques
Subscribe or sign in to view the full article.
Article Overview
This article explains how security risk analysis fits into HIPAA compliance and the EHR incentive program, and why practices needed to pay close attention to documentation, safeguards, and audit risk. It is aimed at providers, practice administrators, and health IT staff who help assess electronic patient-data security and prepare for incentive-program reviews. The discussion covers common implementation pitfalls, practice-based approaches to completing an SRA, and general areas of security emphasis noted by the OIG.
Why This Topic Matters
Practices that attest to EHR incentive requirements could face audit scrutiny and financial exposure if security risk analysis activities are incomplete or poorly documented. The article helps readers understand the operational and compliance issues surrounding electronic health information security.
Article Sections
-
Compliance
Introduces the compliance context for security risk analysis in relation to HIPAA and the EHR incentive program. It frames the operational and audit concerns for provider practices.
-
Avoid common pitfalls when conducting SRAs
Summarizes practical planning approaches that practices use when organizing and documenting a security risk analysis. It focuses on workflow, staffing, and preparedness considerations.
-
OIG’s unofficial audit targets for patient data security
Describes broad security areas the OIG identified as points of interest for audit review. It also notes that the list is unofficial and tied to program oversight activity.
What You Will Learn
- How security risk analysis relates to EHR incentive program compliance
- What kinds of practice-level planning support a completed security risk analysis
- Which broad patient-data security areas have been highlighted for audit attention
- How provider organizations can organize internal teams and resources around security review
- Why documentation and preparation matter for incentive-program attestation
Who Should Read This
- Physicians and group practices
- Practice administrators
- Health information management professionals
- Health IT and EHR support staff
- Compliance and revenue cycle teams
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com