<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hipaaaudit.com &#187; HIPAA Headlines</title>
	<atom:link href="http://hipaaaudit.com/category/hipaa-headlines/feed/" rel="self" type="application/rss+xml" />
	<link>http://hipaaaudit.com</link>
	<description>HIPAA Answers</description>
	<lastBuildDate>Wed, 01 Feb 2012 03:06:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Smart Phone Dumb Doc</title>
		<link>http://hipaaaudit.com/2012/01/03/smart-phone-dumb-doc/</link>
		<comments>http://hipaaaudit.com/2012/01/03/smart-phone-dumb-doc/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 17:09:23 +0000</pubDate>
		<dc:creator>HIPAA Admin</dc:creator>
				<category><![CDATA[HIPAA Headlines]]></category>
		<category><![CDATA[Company Policy]]></category>
		<category><![CDATA[HIPAA Audit]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HIPAA Policies]]></category>
		<category><![CDATA[HIPAA Risk Analysis]]></category>
		<category><![CDATA[Phone]]></category>
		<category><![CDATA[Smart]]></category>
		<category><![CDATA[Smart Phone]]></category>

		<guid isPermaLink="false">http://hipaaaudit.com/?p=1370</guid>
		<description><![CDATA[It wasn&#8217;t long ago that I was having a &#8220;discussion&#8221; with somebody about the use of smart phones by physicians. This discussion wasn&#8217;t that a smart phone is not a useful tool, but that in a medical office a smart phone is not a professional device. First the easy answer&#8230; You are out-and-about and get [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>It wasn&#8217;t long ago that I was having a &#8220;discussion&#8221; with somebody about the use of smart phones by physicians.</p>
<p>This discussion wasn&#8217;t that a smart phone is not a useful tool, but that in a medical office a smart phone is not a <em>professional</em> device.</p>
<h2>First the easy answer&#8230;</h2>
<p>You are out-and-about and get called on scene (away from your office/hospital) and need to look something up &#8211; smart phone to the rescue!</p>
<p>This is one of the perfect situations where a smart phone can help look up issues about drugs, or even pull up a patients records.</p>
<h2>Yet in the office&#8230;</h2>
<p>In the office it is a different situation entirely.</p>
<p>Yes, call me old fashioned, but to have my doc tapping away on a smartphone while I&#8217;m half dressed is not my idea of a quality visit.</p>
<ul>
<li>Is he texting?</li>
<li>Is he checking his stocks?</li>
<li>Is he checking the weather?</li>
<li>Is he checking sport scores?</li>
<li>Why is he smiling?</li>
</ul>
<p>If my 14 year-old is texting while I am speaking to him, things get ugly.</p>
<h2>&#8220;Oh Come On&#8230;</h2>
<p>It really isn&#8217;t that big of deal.&#8221;</p>
<p>Maybe not, but the AMA did just have <a href="http://www.ama-assn.org/amednews/2012/01/02/prl10102.htm" target="_blank">an article on this topic</a>.</p>
<p>&#8220;Besides, computers are a part of medical offices now.&#8221;</p>
<p>I get it.</p>
<p>Yet, to me, a smart phone <em>appears</em> unprofessional while a PC or Tablet does not come across this way.</p>
<h2>&#8220;This is Ridiculous&#8230;&#8221;</h2>
<p>Maybe it is.</p>
<p>Maybe I&#8217;m out of touch (I&#8217;m not).</p>
<p>Maybe you have a completely realistic reason to be tapping away on your phone in front of a patient.</p>
<p>This may all be perfectly legitimate.</p>
<p>BUT &#8211; turn the tables for a moment and see how it feels.</p>
<p>How do you react when your child is texting at the dinner table or while you are speaking?</p>
<h2>&#8220;But I have to Research&#8230;&#8221;</h2>
<p>Before computers where everywhere, you did your research out of the view of a patient.</p>
<p>Maybe&#8230;just maybe, that is where it should go again&#8230;behind the curtain.</p>
]]></content:encoded>
			<wfw:commentRss>http://hipaaaudit.com/2012/01/03/smart-phone-dumb-doc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stage 2 Delay</title>
		<link>http://hipaaaudit.com/2011/12/12/stage-2-delay/</link>
		<comments>http://hipaaaudit.com/2011/12/12/stage-2-delay/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 17:10:35 +0000</pubDate>
		<dc:creator>HIPAA Admin</dc:creator>
				<category><![CDATA[HIPAA Headlines]]></category>
		<category><![CDATA[attestation]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[HHS]]></category>
		<category><![CDATA[meaningful use]]></category>
		<category><![CDATA[Stage 1]]></category>
		<category><![CDATA[Stage 2]]></category>

		<guid isPermaLink="false">http://hipaaaudit.com/?p=1356</guid>
		<description><![CDATA[It comes as no surprise that the Health and Human Services (HHS) has announced a delay to the Meaningful Use (MU) Stage 2 requirements. At Stage 1 created loads of confusion, the delay of Stage 2 seemed&#8230;expected. Additionally, the HHS is clarifying that those who got their act together in 2011, wouldn&#8217;t be under a [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>It comes as no surprise that the Health and Human Services (HHS) has announced a delay to the Meaningful Use (MU) Stage 2 requirements.</p>
<p>At Stage 1 created loads of confusion, the delay of Stage 2 seemed&#8230;expected.</p>
<p>Additionally, the HHS is clarifying that those who got their act together in 2011, wouldn&#8217;t be under a different timeline than those who still have not attested.</p>
<p>This isn&#8217;t really any different, though before this announcement, as the rules were written, those who attested for Stage 1 in 2011, would have to meet Stage 2 in 2013.</p>
<p>Now everyone has until 2014 to meet Stage 2 requirements.</p>
<p>The American Medical Association (AMA) has apparently  urges the HHS to make the proposed requirements less rigorous and burdensome.</p>
<p>Stage 1 requirements are not all the rigorous.  Especially if your EHR is worthwhile.</p>
<p>Many EHRs approach MU in such a way that makes use of the EHR in a &#8220;meaningful way&#8221; cumbersome.</p>
<p>Additionally, reporting from many EHRs for MU stage 1 is weak.</p>
<p>When an EHR becomes Meaningful Use certified, part of that certification should require EASY pulling of data for attestation.</p>
<p>This is not the case for most EHRs.</p>
]]></content:encoded>
			<wfw:commentRss>http://hipaaaudit.com/2011/12/12/stage-2-delay/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sutter Breach Notes</title>
		<link>http://hipaaaudit.com/2011/11/21/sutter-breach-notes/</link>
		<comments>http://hipaaaudit.com/2011/11/21/sutter-breach-notes/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 17:16:37 +0000</pubDate>
		<dc:creator>HIPAA Admin</dc:creator>
				<category><![CDATA[HIPAA Headlines]]></category>
		<category><![CDATA[Company Policy]]></category>
		<category><![CDATA[Computer Policy]]></category>
		<category><![CDATA[Data Theft]]></category>
		<category><![CDATA[Hard Drive Encryption]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HIPAA Risk Analysis]]></category>
		<category><![CDATA[Laptop Encryption]]></category>
		<category><![CDATA[Stolen data]]></category>
		<category><![CDATA[thumb drive encryption]]></category>

		<guid isPermaLink="false">http://hipaaaudit.com/?p=1309</guid>
		<description><![CDATA[As I&#8217;ve preached before, if you are going to store PHI on a mobile device (laptop, external hard drive, etc), you better make sure that you encrypt the hard drive. Typically, I am less concerned about desktop PC&#8217;s and servers as, you should have proper physical security systems in place. The recent Sutter Medical Foundation [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>As I&#8217;ve preached before, if you are going to store PHI on a mobile device (laptop, external hard drive, etc), you better make sure that you <a href="http://hipaaaudit.com/hipaa-products/hard-drive-encryption/">encrypt the hard drive</a>.</p>
<p>Typically, I am less concerned about desktop PC&#8217;s and servers as, you should have proper physical security systems in place.</p>
<p>The recent Sutter Medical Foundation breach affected about 5 million patients&#8230;and brings to light the further need to encrypt desktop computers.</p>
<p>The device stolen was a desktop PC.</p>
<p>So, should that computer have been encrypted?</p>
<p>From the standpoint of minimizing risk, I would say that either:</p>
<ul>
<li>This computer should have been encrypted, or</li>
<li>The room that contained this computer should have a very high level of security.</li>
</ul>
<p>The basic assumption that is typically made with a desktop pc/server is they are in a secure area.</p>
<p>Well, that may need to be revisited.</p>
<p>Again, if you have upwards of 5 million patient records on a computer, I&#8217;d say the best practice would be to not only encrypt the device, but also have a very secure work area.</p>
<p>What about your practice?  You may &#8220;only&#8221; have a few thousand patient records in your EHR database.</p>
<p>Should your server be encrypted?</p>
<p>The knee-jerk reaction is, OF COURSE you should encrypt your server!</p>
<p>The more realistic answer is: encrypting your server may not be necessary if you have your server in a locked room.</p>
<p>Remember, it is not unusual to have many non-staff members roaming your office.<br />
The cleaning crew is my favorite example, as they are usually there after everyone else is gone.</p>
<p>If the device on which you store your PHI is not either in a locked room OR fully encrypted, you are in danger of having an ugly breach.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://hipaaaudit.com/2011/11/21/sutter-breach-notes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do as I say, not as I&#8230;Oops!</title>
		<link>http://hipaaaudit.com/2011/10/31/do-as-i-say-not-as-i-oops/</link>
		<comments>http://hipaaaudit.com/2011/10/31/do-as-i-say-not-as-i-oops/#comments</comments>
		<pubDate>Mon, 31 Oct 2011 18:17:29 +0000</pubDate>
		<dc:creator>HIPAA Admin</dc:creator>
				<category><![CDATA[HIPAA Headlines]]></category>
		<category><![CDATA[Company Policy]]></category>
		<category><![CDATA[Computer Policy]]></category>
		<category><![CDATA[Data Theft]]></category>
		<category><![CDATA[Hard Drive Encryption]]></category>
		<category><![CDATA[Healthcare]]></category>
		<category><![CDATA[HIPAA Audit]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HIPAA Risk Analysis]]></category>
		<category><![CDATA[HIPAA Violations]]></category>
		<category><![CDATA[Laptop Encryption]]></category>
		<category><![CDATA[Stolen data]]></category>
		<category><![CDATA[thumb drive encryption]]></category>

		<guid isPermaLink="false">http://hipaaaudit.com/?p=1272</guid>
		<description><![CDATA[Take a look at a list of PHI breaches and there are a few items that stand out: Many are at the hands of a contractor Most are portable storage device losses or theft (this includes tapes, laptops, etc) Lots are at big government entities One of the goals of HIPAA regulations is to give [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>Take a look at a list of PHI breaches and there are a few items that stand out:</p>
<ul>
<li>Many are at the hands of a contractor</li>
<li>Most are portable storage device losses or theft (this includes tapes, laptops, etc)</li>
<li>Lots are at big government entities</li>
</ul>
<p>One of the goals of HIPAA regulations is to give those that deal with PHI guidance on how to properly handle that PHI.</p>
<p>Specifically, follow the HIPAA regulations and you will greatly reduce the risk of a PHI breach.</p>
<p>The challenge of course, is the government can rarely explain anything clearly.</p>
<p>Add to that we are dealing with digital information &#8211; whether you use Windows, Macs, Linux or whatever operating system &#8211; managing your risk is a challenging.</p>
<p>Let me get back on topic&#8230;<br />
If anyone should be able to follow the rules, it would seem like our government could.</p>
<p>Well, the aren&#8217;t so good at it.</p>
<p>Here&#8217;s the deal, IF you store PHI on any portable device THEN you better encrypt it OR you are setting yourself up for failure.</p>
<p><a href="hhttp://hipaaaudit.com/hipaa-products/hard-drive-encryption/">Hard drive encryption</a> is not difficult nor expensive.</p>
<p>Additionally, IF you encrypt your PHI THEN you have safe harbor IF it is lost or stolen.</p>
<p>Believe me, you would rather deal with the prevention of a PHI breach that the after math of a PHI breach.</p>
]]></content:encoded>
			<wfw:commentRss>http://hipaaaudit.com/2011/10/31/do-as-i-say-not-as-i-oops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Centricity MU Reports Wrong</title>
		<link>http://hipaaaudit.com/2011/10/25/centricity-mu-reports-wrong/</link>
		<comments>http://hipaaaudit.com/2011/10/25/centricity-mu-reports-wrong/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 17:16:19 +0000</pubDate>
		<dc:creator>HIPAA Admin</dc:creator>
				<category><![CDATA[HIPAA Headlines]]></category>
		<category><![CDATA[Centricity]]></category>
		<category><![CDATA[GE]]></category>
		<category><![CDATA[meaningful use]]></category>

		<guid isPermaLink="false">http://hipaaaudit.com/?p=1262</guid>
		<description><![CDATA[If you are a Centricity user you should now have received the official bad news. The direct quote is: GE Healthcare recently became aware of inaccuracies with reports in Centricity Practice Solution and Centricity Electronic Medical Record (EMR) that may affect customers who have attested or are currently planning to attest for Meaningful Use through [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>If you are a Centricity user you should now have received the official bad news.</p>
<blockquote><p>The direct quote is:</p>
<p><em>GE Healthcare recently became aware of inaccuracies with reports in Centricity Practice Solution and Centricity Electronic Medical Record (EMR) that may affect customers who have attested or are currently planning to attest for Meaningful Use through the Medicare EHR Incentive Program.</em></p></blockquote>
<p>Not good.</p>
<p>They go on to clarify that if you have already Attested (I&#8217;d love to hear how many actually have) that you should re-run your reports, once GE has fixed them and:</p>
<blockquote><p><em>If your results are different from those used for attestation, you may need to evaluate if you have still cleared all applicable Meaningful Use thresholds for the original period or would meet the thresholds for all applicable measures</em>.</p></blockquote>
<p>Lovely.</p>
<p>A few things to note here:</p>
<ul>
<li>GE gives not expected date upon which those new reports should be ready</li>
<li>This in no way affects <a href="http://hipaaaudit.com/meaningful-use/core-objectives/">Core Object 15</a> which requires you: &#8220;Ensure adequate privacy and security protections for personal health information&#8221;, in other words, conduct a <a href="http://hipaaaudit.com/hipaa-products/meaningful-use-risk-kit/">HIPAA risk assessment</a>&#8230;so go ahead and get this out of the way.</li>
</ul>
<p>I&#8217;ve been dealing with a client on Centricity and we&#8217;ve raised many questions about the reports.</p>
<p>I&#8217;ve also been dealing with clients on other EHRs with similar report questions.</p>
<p>The over riding issue is this:</p>
<p>Your EHR may be <em>Meaningful Use Able</em> straight out of the box,<br />
but <span style="text-decoration: underline;">NOT </span><strong>Meaningful Use Ready</strong>.</p>
<p>Yes, you have the capability to use your MU certified EHR in a &#8220;meaningful way&#8221;, but unless you have it properly configured you won&#8217;t be tracking that fact.</p>
<p>And really, the ability to track meaningful use is what you want.</p>
<p>You can operate in a meaningful way all day long, but unless you know exactly which check-boxes to mark, or the 2 locations you must annotate the vitals&#8230;your EHR may not properly track your meaningful use.</p>
<p><strong>Note</strong>: <em>If you run your reports and a number seems funny, you better look further into it.</em></p>
<p>Those of you that blindly run MU reports, and see all green, be aware that is would be smart to scrutinize those numbers a bit.</p>
]]></content:encoded>
			<wfw:commentRss>http://hipaaaudit.com/2011/10/25/centricity-mu-reports-wrong/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

