SlideShare a Scribd company logo
1 of 20
Download to read offline
Opportunity Knocks:
   Modern Healthcare
Information Technology
Agenda


• HITECH/EHR Overview
• HITECH/EHR Services & Solutions

• Health Information Technology Risks
• ANSI PHI Project
HITECH/EHR Overview

     HITECH/EHR Overview
   HIPAA & PHI Data Breaches
      Enforcement Updates
HITECH/EHR Overview

• HC IT Project Drivers: Incentives
   ARRA HITECH – ―EHR … by 2014‖
     Nationwide HIT infrastructure
     Meaningful Use HIPAA security requirements
     Changing EHR MU Stage 2 & 3 requirements
     Upcoming ACO requirements
• HC IT Project Drivers: Sanctions
   PHI breach notification
   HIPAA enforcement
HIPAA and PHI Data Breaches

• Ponemon Institute: Data breaches cost hospitals nearly $6
  billion/year1
• Medical-related data breaches listed in Privacy Rights
  Clearinghouse2
        116 breaches listed in 2007-2008
        229 breaches listed in 2009-2010
• 86% of large-hospital employees surveyed believe the number of
  data breaches discovered will increase under HITECH3
• The Department of Justice secured ―$2.5 billion in health care
  fraud recoveries—the largest in history,‖ for the fiscal year
  ending 9-30-20104
     1- Source: Benchmark Study on Patient Privacy and Data Security, November 9, 2010, Ponemon Institute LLC.
     2- Source: http://www.privacyrights.org/
     3- Source: 2009 HIMSS Analytics Report:―Taking a Pulse on HITECH, Are Hospitals and Business Associates Ready?‖ November 17, 2009.
     4- Source: Department of Justice, November 22, 2010, http://www.justice.gov/opa/pr/2010/November/10-civ-1335.html


 5
Enforcement Updates

HIPAA Sanctions
• Periodic HHS CE & BA HIPAA Compliance Audits
• Violations range from $100 to $1.5 million (willful
  neglect)
• Extends criminal penalties to individual or employee of
  CE
• State attorneys general can file civil suit on behalf of
  residents
Enforcement Updates

OCR Commitment to HIPAA Enforcement
Program Increases
•   Regional Office Privacy Advisors (+$2.283 million)
•   Enforcement of the HIPAA Security Rule (+$1 million)
•   Investigation of the HITECH Breach Reports (+$1.335 million)
•   Compliance Review Program (+$1 million)
Enforcement Updates

HIPPA Enforcement Activities
• Cignet Health, 2011: $4.3 million – Denying access to
  medical records & refusing to cooperate with OCR
  investigation
   http://www.hhs.gov/news/press/2011pres/02/20110222a.html

• Massachusetts General Hospital Settles HIPAA Violations,
  2011: $1 million – Documents left on subway by employee
   http://www.hhs.gov/news/press/2011pres/02/20110224b.html

• Health Net, 2011: $55,000 + mandatory data-security audit 2
  years – Lost portable drive & misrepresentation of risk
   http://www.healthdatamanagement.com/news/breach_hipaa_privacy_security_hitech_lawsuit-39645-
       1.html

• Rite Aid, 2010: $1 Million – Poor disposal practices
   http://www.hhs.gov/news/press/2010pres/07/20100727a.html
HITECH/EHR Services &
      Solutions

  EHR Related Services BKD Provides
HITECH/EHR Services & Solutions

Outsourced Project Management
•     Assist management with development of project plan to manage all phases of EHR
      implementation project
•     Assist management with overseeing project milestones
•     Periodic project status & project risk reports
    EHR System Selection
•     Assist management with identifying & evaluating an EHR-compliant system
•     Demonstration scorecards—basis for purchase decisions
•     Total cost of ownership—three-year estimates that include software, equipment &
      implementation fees
EHR Readiness Assessment
•     IT & infrastructure inventory
•     EHR current capabilities assessment
•     IT Governance & process maturity measurements
•     Security compliance assessment

10
HITECH/EHR Services & Solutions

ARRA Reimbursement Analysis
•    Develop reimbursement projections
•    Develop multi-year cash flow analysis mapping EHR project timeline with federal
     funding timeline projections
EHR Meaningful Use Attestation Assistance
•    Review meaningful use objectives management has decided to report against
•    Develop audit procedures to determine if selected objectives are being met
•    Provide findings & recommendations based on executed audit procedures
HIPAA Data Security & Privacy Assessment
•    Data-flow analysis
•    Risk & control identification
•    IT Governance & process maturity measurements
•    Control design & effectiveness testing



11
Health Information
Technology Risks

    Understanding HIT Data-flow
Risk Associated with Clinical Systems
    Expanded Audit Procedures
Health Information Technology
Risks

• Developing clinical system & sub-system
  inventory
• Understanding flow of data in a healthcare
  system
• Identifying risks & controls




13
Health Information Technology
Risks




14
Health Information Technology
Risks




15
Health Information Technology
Risks




16
Health Information Technology
Risks

Expanded HIT Audit Procedures
• Data-flow analysis
• Computer Assisted Audit Techniques (CAAT)

• Evaluating security at clinical system level

• Evaluating intermediary data repositories &
  job scheduling/data integration systems


17
ANSI/Shared Assessments
       PHI Project

 Report & tools valuing financial impact
 of unauthorized disclosure of protected
        health information (PHI)
ANSI/Shared Assessments PHI
Project




 http://www.ansi.org/standards_activities/standards_boards_panels/idsp/protected_health_information.aspx


19
Thank You



Matt Lathrom, CISM, CISA, MCP
    Managing Consultant
     BKD IT Risk Services
    mlathrom@bkd.com
       816.221.6300

More Related Content

What's hot

Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KCTell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KCKevin Perry
 
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...Brussels Briefings (brusselsbriefings.net)
 
Top 3 Changes in Technological Advances influencing Healthcare version 2
Top 3 Changes in Technological Advances influencing Healthcare version 2Top 3 Changes in Technological Advances influencing Healthcare version 2
Top 3 Changes in Technological Advances influencing Healthcare version 2Chris Dawson
 
Meaningful Use and Security Risk Analysis
Meaningful Use and Security Risk AnalysisMeaningful Use and Security Risk Analysis
Meaningful Use and Security Risk AnalysisEvan Francen
 
HIPAA Workloads on AWS - Pop-up Loft Tel Aviv
HIPAA Workloads on AWS - Pop-up Loft Tel AvivHIPAA Workloads on AWS - Pop-up Loft Tel Aviv
HIPAA Workloads on AWS - Pop-up Loft Tel AvivAmazon Web Services
 
BlueButton on FHIR @HXRconf
BlueButton on FHIR @HXRconf BlueButton on FHIR @HXRconf
BlueButton on FHIR @HXRconf Mark Scrimshire
 
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...Mark Scrimshire
 
Brisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage FrameworkBrisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage FrameworkARDC
 
How Best Are Medical Practices Prepared to Address HIPAA Breaches?
How Best Are Medical Practices Prepared to Address HIPAA Breaches? How Best Are Medical Practices Prepared to Address HIPAA Breaches?
How Best Are Medical Practices Prepared to Address HIPAA Breaches? Medical Billers and Coders
 
How Safe are mHealth Apps?
How Safe are mHealth Apps?How Safe are mHealth Apps?
How Safe are mHealth Apps?Maria Wolters
 
Dennis Kehoe - ECO 15: Digital connectivity in healthcare
Dennis Kehoe - ECO 15: Digital connectivity in healthcareDennis Kehoe - ECO 15: Digital connectivity in healthcare
Dennis Kehoe - ECO 15: Digital connectivity in healthcareInnovation Agency
 
Health IT Programmes - lifting performance across the sector
Health IT Programmes - lifting performance across the sectorHealth IT Programmes - lifting performance across the sector
Health IT Programmes - lifting performance across the sectorHealth Informatics New Zealand
 
Medicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcareMedicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcareInnovation Agency
 
Data Preparation and Visualization for Monitoring NCDs Mortality
Data Preparation and Visualization for Monitoring NCDs MortalityData Preparation and Visualization for Monitoring NCDs Mortality
Data Preparation and Visualization for Monitoring NCDs MortalityRamon Martinez
 

What's hot (20)

Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KCTell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
Tell, Joseph, Tellevate, Resources for EHS Regulatory Information, 2015 MECC-KC
 
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
Brussels Briefing n. 55: Erik Árokszállási "Blockchain applications in food s...
 
Innovative project1
Innovative project1Innovative project1
Innovative project1
 
Top 3 Changes in Technological Advances influencing Healthcare version 2
Top 3 Changes in Technological Advances influencing Healthcare version 2Top 3 Changes in Technological Advances influencing Healthcare version 2
Top 3 Changes in Technological Advances influencing Healthcare version 2
 
Meaningful Use and Security Risk Analysis
Meaningful Use and Security Risk AnalysisMeaningful Use and Security Risk Analysis
Meaningful Use and Security Risk Analysis
 
HIPAA Workloads on AWS - Pop-up Loft Tel Aviv
HIPAA Workloads on AWS - Pop-up Loft Tel AvivHIPAA Workloads on AWS - Pop-up Loft Tel Aviv
HIPAA Workloads on AWS - Pop-up Loft Tel Aviv
 
BlueButton on FHIR @HXRconf
BlueButton on FHIR @HXRconf BlueButton on FHIR @HXRconf
BlueButton on FHIR @HXRconf
 
HSCIC: NHS Pathways - Intelligent Data Toolkit
HSCIC: NHS Pathways - Intelligent Data ToolkitHSCIC: NHS Pathways - Intelligent Data Toolkit
HSCIC: NHS Pathways - Intelligent Data Toolkit
 
The Path to Wellness through Big Data
The Path to Wellness through Big DataThe Path to Wellness through Big Data
The Path to Wellness through Big Data
 
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
Aneesh Chopra - HealthCa.mp/dev Keynote. 2016: the Year to participate in the...
 
Brisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage FrameworkBrisbane Health-y Data: Queensland Data Linkage Framework
Brisbane Health-y Data: Queensland Data Linkage Framework
 
How Best Are Medical Practices Prepared to Address HIPAA Breaches?
How Best Are Medical Practices Prepared to Address HIPAA Breaches? How Best Are Medical Practices Prepared to Address HIPAA Breaches?
How Best Are Medical Practices Prepared to Address HIPAA Breaches?
 
#soteSlush: Antti Tuomi-Nikula
#soteSlush: Antti Tuomi-Nikula#soteSlush: Antti Tuomi-Nikula
#soteSlush: Antti Tuomi-Nikula
 
How Safe are mHealth Apps?
How Safe are mHealth Apps?How Safe are mHealth Apps?
How Safe are mHealth Apps?
 
Dennis Kehoe - ECO 15: Digital connectivity in healthcare
Dennis Kehoe - ECO 15: Digital connectivity in healthcareDennis Kehoe - ECO 15: Digital connectivity in healthcare
Dennis Kehoe - ECO 15: Digital connectivity in healthcare
 
Paul McGinness - ECO 21
Paul McGinness - ECO 21Paul McGinness - ECO 21
Paul McGinness - ECO 21
 
#soteSlush - Teemupekka Virtanen
#soteSlush - Teemupekka Virtanen#soteSlush - Teemupekka Virtanen
#soteSlush - Teemupekka Virtanen
 
Health IT Programmes - lifting performance across the sector
Health IT Programmes - lifting performance across the sectorHealth IT Programmes - lifting performance across the sector
Health IT Programmes - lifting performance across the sector
 
Medicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcareMedicalchain - ECO 15: Digital connectivity in healthcare
Medicalchain - ECO 15: Digital connectivity in healthcare
 
Data Preparation and Visualization for Monitoring NCDs Mortality
Data Preparation and Visualization for Monitoring NCDs MortalityData Preparation and Visualization for Monitoring NCDs Mortality
Data Preparation and Visualization for Monitoring NCDs Mortality
 

Viewers also liked

Sage MAS 90 Payment Solutions
Sage MAS 90 Payment SolutionsSage MAS 90 Payment Solutions
Sage MAS 90 Payment SolutionsJeffrey Paulette
 
Sage MAS Intelligence vs. Biz Insights
Sage MAS Intelligence vs. Biz InsightsSage MAS Intelligence vs. Biz Insights
Sage MAS Intelligence vs. Biz InsightsJeffrey Paulette
 
Financial Reporting Tools for Dynamics GP Shootout
Financial Reporting Tools for Dynamics GP ShootoutFinancial Reporting Tools for Dynamics GP Shootout
Financial Reporting Tools for Dynamics GP ShootoutJeffrey Paulette
 
SSAE 16 Transitions Overview
SSAE 16 Transitions OverviewSSAE 16 Transitions Overview
SSAE 16 Transitions OverviewJeffrey Paulette
 
Internal Controls Over Information Systems
Internal Controls Over Information Systems Internal Controls Over Information Systems
Internal Controls Over Information Systems Jeffrey Paulette
 
Basic tutorial how to use google calendar
Basic tutorial how to use google calendarBasic tutorial how to use google calendar
Basic tutorial how to use google calendarCherrylin Ramos
 

Viewers also liked (7)

Sage MAS 90 Payment Solutions
Sage MAS 90 Payment SolutionsSage MAS 90 Payment Solutions
Sage MAS 90 Payment Solutions
 
Sage MAS Intelligence vs. Biz Insights
Sage MAS Intelligence vs. Biz InsightsSage MAS Intelligence vs. Biz Insights
Sage MAS Intelligence vs. Biz Insights
 
Financial Reporting Tools for Dynamics GP Shootout
Financial Reporting Tools for Dynamics GP ShootoutFinancial Reporting Tools for Dynamics GP Shootout
Financial Reporting Tools for Dynamics GP Shootout
 
SSAE 16 Transitions Overview
SSAE 16 Transitions OverviewSSAE 16 Transitions Overview
SSAE 16 Transitions Overview
 
Internal Controls Over Information Systems
Internal Controls Over Information Systems Internal Controls Over Information Systems
Internal Controls Over Information Systems
 
How To Use Google Calendar
How To Use Google CalendarHow To Use Google Calendar
How To Use Google Calendar
 
Basic tutorial how to use google calendar
Basic tutorial how to use google calendarBasic tutorial how to use google calendar
Basic tutorial how to use google calendar
 

Similar to Modern Healthcare Information Technology

What Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sWhat Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sIatric Systems
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture ECMDLearning
 
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT SecurityRedspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT SecurityRedspin, Inc.
 
Panel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITPanel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITmihinpr
 
Blockchain2[1].pptx
Blockchain2[1].pptxBlockchain2[1].pptx
Blockchain2[1].pptxkoretamirat
 
HITRUST CSF Meaningful use risk assessment
HITRUST CSF Meaningful use risk assessmentHITRUST CSF Meaningful use risk assessment
HITRUST CSF Meaningful use risk assessmentVinit Thakur
 
Regulatory Intelligence
Regulatory IntelligenceRegulatory Intelligence
Regulatory IntelligenceArmin Torres
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Kimberly Simon MBA
 
data for Nursing.pptx
data for Nursing.pptxdata for Nursing.pptx
data for Nursing.pptxcalich88
 
Comp8 unit6a lecture_slides
Comp8 unit6a lecture_slidesComp8 unit6a lecture_slides
Comp8 unit6a lecture_slidesCMDLMS
 
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...Polsinelli PC
 
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...Michigan Primary Care Association
 
Direct Boot Camp 2 0 Federal Agency requirements for exchange via direct
Direct Boot Camp 2 0 Federal Agency requirements for exchange via directDirect Boot Camp 2 0 Federal Agency requirements for exchange via direct
Direct Boot Camp 2 0 Federal Agency requirements for exchange via directBrian Ahier
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTKimberly Simon MBA
 
E Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep PpE Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep Pphunterberney
 
Trust and Governance in Health and Social Care
Trust and Governance in Health and Social Care Trust and Governance in Health and Social Care
Trust and Governance in Health and Social Care Napier University
 
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...eringold
 
Health Information Exchange Workgroup 110310
Health Information Exchange Workgroup 110310Health Information Exchange Workgroup 110310
Health Information Exchange Workgroup 110310Brian Ahier
 

Similar to Modern Healthcare Information Technology (20)

What Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sWhat Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​s
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture E
 
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT SecurityRedspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
 
Panel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITPanel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HIT
 
Blockchain2[1].pptx
Blockchain2[1].pptxBlockchain2[1].pptx
Blockchain2[1].pptx
 
HITRUST CSF Meaningful use risk assessment
HITRUST CSF Meaningful use risk assessmentHITRUST CSF Meaningful use risk assessment
HITRUST CSF Meaningful use risk assessment
 
Regulatory Intelligence
Regulatory IntelligenceRegulatory Intelligence
Regulatory Intelligence
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
data for Nursing.pptx
data for Nursing.pptxdata for Nursing.pptx
data for Nursing.pptx
 
Comp8 unit6a lecture_slides
Comp8 unit6a lecture_slidesComp8 unit6a lecture_slides
Comp8 unit6a lecture_slides
 
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
 
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
 
Direct Boot Camp 2 0 Federal Agency requirements for exchange via direct
Direct Boot Camp 2 0 Federal Agency requirements for exchange via directDirect Boot Camp 2 0 Federal Agency requirements for exchange via direct
Direct Boot Camp 2 0 Federal Agency requirements for exchange via direct
 
HIPAA
HIPAAHIPAA
HIPAA
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
 
E Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep PpE Healthcare Systems Hb Emr Prep Pp
E Healthcare Systems Hb Emr Prep Pp
 
Hb Emr
Hb EmrHb Emr
Hb Emr
 
Trust and Governance in Health and Social Care
Trust and Governance in Health and Social Care Trust and Governance in Health and Social Care
Trust and Governance in Health and Social Care
 
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
 
Health Information Exchange Workgroup 110310
Health Information Exchange Workgroup 110310Health Information Exchange Workgroup 110310
Health Information Exchange Workgroup 110310
 

More from Jeffrey Paulette

Business Activity Monitoring in MAS 90 With KnowledgeSync
Business Activity Monitoring in MAS 90 With KnowledgeSyncBusiness Activity Monitoring in MAS 90 With KnowledgeSync
Business Activity Monitoring in MAS 90 With KnowledgeSyncJeffrey Paulette
 
Sage MAS 500 Version 7.4 Sneak Peak
Sage MAS 500 Version 7.4 Sneak PeakSage MAS 500 Version 7.4 Sneak Peak
Sage MAS 500 Version 7.4 Sneak PeakJeffrey Paulette
 
Sage MAS Intelligence for MAS 90 & MAS 200
Sage MAS Intelligence for MAS 90 & MAS 200Sage MAS Intelligence for MAS 90 & MAS 200
Sage MAS Intelligence for MAS 90 & MAS 200Jeffrey Paulette
 
Business Portal for Dynamics GP
Business Portal for Dynamics GPBusiness Portal for Dynamics GP
Business Portal for Dynamics GPJeffrey Paulette
 
Management Reporter for Dynamics GP
Management Reporter for Dynamics GPManagement Reporter for Dynamics GP
Management Reporter for Dynamics GPJeffrey Paulette
 
Dynamics GP Year End Closing Procedures 2010
Dynamics GP Year End Closing Procedures 2010Dynamics GP Year End Closing Procedures 2010
Dynamics GP Year End Closing Procedures 2010Jeffrey Paulette
 
Microsoft Dynamics GP 2010 Sneak Peak
Microsoft Dynamics GP 2010 Sneak PeakMicrosoft Dynamics GP 2010 Sneak Peak
Microsoft Dynamics GP 2010 Sneak PeakJeffrey Paulette
 
Workflows For Microsoft Dynamics GP 2010
Workflows For Microsoft Dynamics GP 2010Workflows For Microsoft Dynamics GP 2010
Workflows For Microsoft Dynamics GP 2010Jeffrey Paulette
 
Help Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GPHelp Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GPJeffrey Paulette
 
Sage MAS 90 Year End Payroll Closing For 2010
Sage MAS 90 Year End Payroll Closing For 2010Sage MAS 90 Year End Payroll Closing For 2010
Sage MAS 90 Year End Payroll Closing For 2010Jeffrey Paulette
 
Sage MAS 90 Year End Closing Procedures 2010
Sage MAS 90 Year End Closing Procedures 2010Sage MAS 90 Year End Closing Procedures 2010
Sage MAS 90 Year End Closing Procedures 2010Jeffrey Paulette
 
Go Green While Saving Some Green
Go Green While Saving Some GreenGo Green While Saving Some Green
Go Green While Saving Some GreenJeffrey Paulette
 

More from Jeffrey Paulette (16)

Business Activity Monitoring in MAS 90 With KnowledgeSync
Business Activity Monitoring in MAS 90 With KnowledgeSyncBusiness Activity Monitoring in MAS 90 With KnowledgeSync
Business Activity Monitoring in MAS 90 With KnowledgeSync
 
Sage MAS 500 Version 7.4 Sneak Peak
Sage MAS 500 Version 7.4 Sneak PeakSage MAS 500 Version 7.4 Sneak Peak
Sage MAS 500 Version 7.4 Sneak Peak
 
Sage MAS 90 with Doc-Link
Sage MAS 90 with Doc-LinkSage MAS 90 with Doc-Link
Sage MAS 90 with Doc-Link
 
Sage MAS Intelligence for MAS 90 & MAS 200
Sage MAS Intelligence for MAS 90 & MAS 200Sage MAS Intelligence for MAS 90 & MAS 200
Sage MAS Intelligence for MAS 90 & MAS 200
 
Business Portal for Dynamics GP
Business Portal for Dynamics GPBusiness Portal for Dynamics GP
Business Portal for Dynamics GP
 
Management Reporter for Dynamics GP
Management Reporter for Dynamics GPManagement Reporter for Dynamics GP
Management Reporter for Dynamics GP
 
Dynamics GP Year End Closing Procedures 2010
Dynamics GP Year End Closing Procedures 2010Dynamics GP Year End Closing Procedures 2010
Dynamics GP Year End Closing Procedures 2010
 
Microsoft Dynamics GP 2010 Sneak Peak
Microsoft Dynamics GP 2010 Sneak PeakMicrosoft Dynamics GP 2010 Sneak Peak
Microsoft Dynamics GP 2010 Sneak Peak
 
Workflows For Microsoft Dynamics GP 2010
Workflows For Microsoft Dynamics GP 2010Workflows For Microsoft Dynamics GP 2010
Workflows For Microsoft Dynamics GP 2010
 
Help Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GPHelp Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GP
 
Sage MAS 90 Year End Payroll Closing For 2010
Sage MAS 90 Year End Payroll Closing For 2010Sage MAS 90 Year End Payroll Closing For 2010
Sage MAS 90 Year End Payroll Closing For 2010
 
Sage MAS 90 Year End Closing Procedures 2010
Sage MAS 90 Year End Closing Procedures 2010Sage MAS 90 Year End Closing Procedures 2010
Sage MAS 90 Year End Closing Procedures 2010
 
What's New In Sage MAS 90
What's New In Sage MAS 90What's New In Sage MAS 90
What's New In Sage MAS 90
 
What's new in sage mas 90
What's new in sage mas 90What's new in sage mas 90
What's new in sage mas 90
 
Sage MAS 90 Tips & Tricks
Sage MAS 90 Tips & TricksSage MAS 90 Tips & Tricks
Sage MAS 90 Tips & Tricks
 
Go Green While Saving Some Green
Go Green While Saving Some GreenGo Green While Saving Some Green
Go Green While Saving Some Green
 

Recently uploaded

Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportFuture of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportDubai Multi Commodity Centre
 
Exploring-Pipe-Flanges-Applications-Types-and-Benefits.pptx
Exploring-Pipe-Flanges-Applications-Types-and-Benefits.pptxExploring-Pipe-Flanges-Applications-Types-and-Benefits.pptx
Exploring-Pipe-Flanges-Applications-Types-and-Benefits.pptxTexas Flange
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdfAgusHalim9
 
tekAura | Desktop Procedure Template (2016)
tekAura | Desktop Procedure Template (2016)tekAura | Desktop Procedure Template (2016)
tekAura | Desktop Procedure Template (2016)Norah Medlin
 
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdfInnomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdfInnomantra
 
LinkedIn Masterclass Techweek 2024 v4.1.pptx
LinkedIn Masterclass Techweek 2024 v4.1.pptxLinkedIn Masterclass Techweek 2024 v4.1.pptx
LinkedIn Masterclass Techweek 2024 v4.1.pptxSymbio Agency Ltd
 
stock price prediction using machine learning
stock price prediction using machine learningstock price prediction using machine learning
stock price prediction using machine learninggauravwankar27
 
Hyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings releaseHyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings releaseirhcs
 
wagamamaLab presentation @MIT 20240509 IRODORI
wagamamaLab presentation @MIT 20240509 IRODORIwagamamaLab presentation @MIT 20240509 IRODORI
wagamamaLab presentation @MIT 20240509 IRODORIIRODORI inc.
 
Series A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by AccionSeries A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by AccionAlejandro Cremades
 
How to Maintain Healthy Life style.pptx
How to Maintain  Healthy Life style.pptxHow to Maintain  Healthy Life style.pptx
How to Maintain Healthy Life style.pptxrdishurana
 
A Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettA Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettJacobBadgett
 
How Do Venture Capitalists Make Decisions?
How Do Venture Capitalists Make Decisions?How Do Venture Capitalists Make Decisions?
How Do Venture Capitalists Make Decisions?Alejandro Cremades
 
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptxBlinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptxSaksham Gupta
 
RATINGS OF EACH VIDEO FOR UNI PROJECT IWDSFODF
RATINGS OF EACH VIDEO FOR UNI PROJECT IWDSFODFRATINGS OF EACH VIDEO FOR UNI PROJECT IWDSFODF
RATINGS OF EACH VIDEO FOR UNI PROJECT IWDSFODFCaitlinCummins3
 
Copyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowCopyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowMiriam Robeson
 
NewBase 17 May 2024 Energy News issue - 1725 by Khaled Al Awadi_compresse...
NewBase   17 May  2024  Energy News issue - 1725 by Khaled Al Awadi_compresse...NewBase   17 May  2024  Energy News issue - 1725 by Khaled Al Awadi_compresse...
NewBase 17 May 2024 Energy News issue - 1725 by Khaled Al Awadi_compresse...Khaled Al Awadi
 
Aptar Closures segment - Corporate Overview-India.pdf
Aptar Closures segment - Corporate Overview-India.pdfAptar Closures segment - Corporate Overview-India.pdf
Aptar Closures segment - Corporate Overview-India.pdfprchbhandari
 
Creative Ideas for Interactive Team Presentations
Creative Ideas for Interactive Team PresentationsCreative Ideas for Interactive Team Presentations
Creative Ideas for Interactive Team PresentationsSlidesAI
 
Constitution of Company Article of Association
Constitution of Company Article of AssociationConstitution of Company Article of Association
Constitution of Company Article of Associationseri bangash
 

Recently uploaded (20)

Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportFuture of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
 
Exploring-Pipe-Flanges-Applications-Types-and-Benefits.pptx
Exploring-Pipe-Flanges-Applications-Types-and-Benefits.pptxExploring-Pipe-Flanges-Applications-Types-and-Benefits.pptx
Exploring-Pipe-Flanges-Applications-Types-and-Benefits.pptx
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
 
tekAura | Desktop Procedure Template (2016)
tekAura | Desktop Procedure Template (2016)tekAura | Desktop Procedure Template (2016)
tekAura | Desktop Procedure Template (2016)
 
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdfInnomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
Innomantra Viewpoint - Building Moonshots : May-Jun 2024.pdf
 
LinkedIn Masterclass Techweek 2024 v4.1.pptx
LinkedIn Masterclass Techweek 2024 v4.1.pptxLinkedIn Masterclass Techweek 2024 v4.1.pptx
LinkedIn Masterclass Techweek 2024 v4.1.pptx
 
stock price prediction using machine learning
stock price prediction using machine learningstock price prediction using machine learning
stock price prediction using machine learning
 
Hyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings releaseHyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings release
 
wagamamaLab presentation @MIT 20240509 IRODORI
wagamamaLab presentation @MIT 20240509 IRODORIwagamamaLab presentation @MIT 20240509 IRODORI
wagamamaLab presentation @MIT 20240509 IRODORI
 
Series A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by AccionSeries A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by Accion
 
How to Maintain Healthy Life style.pptx
How to Maintain  Healthy Life style.pptxHow to Maintain  Healthy Life style.pptx
How to Maintain Healthy Life style.pptx
 
A Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettA Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob Badgett
 
How Do Venture Capitalists Make Decisions?
How Do Venture Capitalists Make Decisions?How Do Venture Capitalists Make Decisions?
How Do Venture Capitalists Make Decisions?
 
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptxBlinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
 
RATINGS OF EACH VIDEO FOR UNI PROJECT IWDSFODF
RATINGS OF EACH VIDEO FOR UNI PROJECT IWDSFODFRATINGS OF EACH VIDEO FOR UNI PROJECT IWDSFODF
RATINGS OF EACH VIDEO FOR UNI PROJECT IWDSFODF
 
Copyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowCopyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to Know
 
NewBase 17 May 2024 Energy News issue - 1725 by Khaled Al Awadi_compresse...
NewBase   17 May  2024  Energy News issue - 1725 by Khaled Al Awadi_compresse...NewBase   17 May  2024  Energy News issue - 1725 by Khaled Al Awadi_compresse...
NewBase 17 May 2024 Energy News issue - 1725 by Khaled Al Awadi_compresse...
 
Aptar Closures segment - Corporate Overview-India.pdf
Aptar Closures segment - Corporate Overview-India.pdfAptar Closures segment - Corporate Overview-India.pdf
Aptar Closures segment - Corporate Overview-India.pdf
 
Creative Ideas for Interactive Team Presentations
Creative Ideas for Interactive Team PresentationsCreative Ideas for Interactive Team Presentations
Creative Ideas for Interactive Team Presentations
 
Constitution of Company Article of Association
Constitution of Company Article of AssociationConstitution of Company Article of Association
Constitution of Company Article of Association
 

Modern Healthcare Information Technology

  • 1. Opportunity Knocks: Modern Healthcare Information Technology
  • 2. Agenda • HITECH/EHR Overview • HITECH/EHR Services & Solutions • Health Information Technology Risks • ANSI PHI Project
  • 3. HITECH/EHR Overview HITECH/EHR Overview HIPAA & PHI Data Breaches Enforcement Updates
  • 4. HITECH/EHR Overview • HC IT Project Drivers: Incentives  ARRA HITECH – ―EHR … by 2014‖  Nationwide HIT infrastructure  Meaningful Use HIPAA security requirements  Changing EHR MU Stage 2 & 3 requirements  Upcoming ACO requirements • HC IT Project Drivers: Sanctions  PHI breach notification  HIPAA enforcement
  • 5. HIPAA and PHI Data Breaches • Ponemon Institute: Data breaches cost hospitals nearly $6 billion/year1 • Medical-related data breaches listed in Privacy Rights Clearinghouse2  116 breaches listed in 2007-2008  229 breaches listed in 2009-2010 • 86% of large-hospital employees surveyed believe the number of data breaches discovered will increase under HITECH3 • The Department of Justice secured ―$2.5 billion in health care fraud recoveries—the largest in history,‖ for the fiscal year ending 9-30-20104 1- Source: Benchmark Study on Patient Privacy and Data Security, November 9, 2010, Ponemon Institute LLC. 2- Source: http://www.privacyrights.org/ 3- Source: 2009 HIMSS Analytics Report:―Taking a Pulse on HITECH, Are Hospitals and Business Associates Ready?‖ November 17, 2009. 4- Source: Department of Justice, November 22, 2010, http://www.justice.gov/opa/pr/2010/November/10-civ-1335.html 5
  • 6. Enforcement Updates HIPAA Sanctions • Periodic HHS CE & BA HIPAA Compliance Audits • Violations range from $100 to $1.5 million (willful neglect) • Extends criminal penalties to individual or employee of CE • State attorneys general can file civil suit on behalf of residents
  • 7. Enforcement Updates OCR Commitment to HIPAA Enforcement Program Increases • Regional Office Privacy Advisors (+$2.283 million) • Enforcement of the HIPAA Security Rule (+$1 million) • Investigation of the HITECH Breach Reports (+$1.335 million) • Compliance Review Program (+$1 million)
  • 8. Enforcement Updates HIPPA Enforcement Activities • Cignet Health, 2011: $4.3 million – Denying access to medical records & refusing to cooperate with OCR investigation http://www.hhs.gov/news/press/2011pres/02/20110222a.html • Massachusetts General Hospital Settles HIPAA Violations, 2011: $1 million – Documents left on subway by employee http://www.hhs.gov/news/press/2011pres/02/20110224b.html • Health Net, 2011: $55,000 + mandatory data-security audit 2 years – Lost portable drive & misrepresentation of risk http://www.healthdatamanagement.com/news/breach_hipaa_privacy_security_hitech_lawsuit-39645- 1.html • Rite Aid, 2010: $1 Million – Poor disposal practices http://www.hhs.gov/news/press/2010pres/07/20100727a.html
  • 9. HITECH/EHR Services & Solutions EHR Related Services BKD Provides
  • 10. HITECH/EHR Services & Solutions Outsourced Project Management • Assist management with development of project plan to manage all phases of EHR implementation project • Assist management with overseeing project milestones • Periodic project status & project risk reports EHR System Selection • Assist management with identifying & evaluating an EHR-compliant system • Demonstration scorecards—basis for purchase decisions • Total cost of ownership—three-year estimates that include software, equipment & implementation fees EHR Readiness Assessment • IT & infrastructure inventory • EHR current capabilities assessment • IT Governance & process maturity measurements • Security compliance assessment 10
  • 11. HITECH/EHR Services & Solutions ARRA Reimbursement Analysis • Develop reimbursement projections • Develop multi-year cash flow analysis mapping EHR project timeline with federal funding timeline projections EHR Meaningful Use Attestation Assistance • Review meaningful use objectives management has decided to report against • Develop audit procedures to determine if selected objectives are being met • Provide findings & recommendations based on executed audit procedures HIPAA Data Security & Privacy Assessment • Data-flow analysis • Risk & control identification • IT Governance & process maturity measurements • Control design & effectiveness testing 11
  • 12. Health Information Technology Risks Understanding HIT Data-flow Risk Associated with Clinical Systems Expanded Audit Procedures
  • 13. Health Information Technology Risks • Developing clinical system & sub-system inventory • Understanding flow of data in a healthcare system • Identifying risks & controls 13
  • 17. Health Information Technology Risks Expanded HIT Audit Procedures • Data-flow analysis • Computer Assisted Audit Techniques (CAAT) • Evaluating security at clinical system level • Evaluating intermediary data repositories & job scheduling/data integration systems 17
  • 18. ANSI/Shared Assessments PHI Project Report & tools valuing financial impact of unauthorized disclosure of protected health information (PHI)
  • 19. ANSI/Shared Assessments PHI Project http://www.ansi.org/standards_activities/standards_boards_panels/idsp/protected_health_information.aspx 19
  • 20. Thank You Matt Lathrom, CISM, CISA, MCP Managing Consultant BKD IT Risk Services mlathrom@bkd.com 816.221.6300