วันอาทิตย์ที่ 27 ธันวาคม พ.ศ. 2552

Electronic Medical Billing Software, HIPAA Compliance, and Role Based Access Control


Image : http://www.flickr.com


HIPAA requires a special effort to concentrate and lead a non-significant risk of harm and penalties. A practice with multiple separate systems for planning the patient requires medical records and electronic billing, HIPAA separated more management effort. This paper presents an integrated approach to HIPAA and HIPAA are described to help ensure the most important concepts, principles and standards of practice owners HIPAA billing for medical servicesand software.

The last decade has witnessed the last century, accelerating the spread of digital technology in the health sector that have lower costs and better service quality, new and greater risks for inadvertent disclosure of personal health information.

The Health Insurance Portability and Accountability Act (HIPAA) was adopted in 1996 by Congress to create national standards for privacy and security of personal health data. The rule on privacy,the U.S. Department of Health and Human Services was written April 14, 2003.

Violations of HIPAA, accreditation and reputational risks satisfy claims of the federal government, fines ranging from $ 100 to $ 250,000, and imprisonment from one to ten years.

Protected Health Information (PHI)

The key concept of HIPAA is Protected Health Information (PHI), all using what can an individual identify and understand allInformation with other health professionals or clearing in all media, in print (common digital, verbal, recorded voice, fax, or in writing). Information that can be used to identify a person includes:

Name
Dates (except years)
CAP more than 3 digits, telephone and fax numbers, e-mail
Social Security Number
Medical Record Numbers
Health Plan Issues
The license numbers
Photos

Information with other health professionals orClearing
Nursing and medical notes
Billing and other documentation of treatment

Principles of HIPAA

Ensure a HIPAA PHI for healthcare operations, with the consent of the patient, but prevent the unlawful ban PHI for other purposes. Healthcare operations include treatment, payment, assessment of quality of care, review of skills training, accreditation, evaluation assurance, monitoring and legal procedures.

HIPAA promotes fair informationProcess and requires access to PHI protection. Fair treatment of data means that a person is allowed
Access to PHI
The correction of errors and completeness and
Knowledge of others who use PHI

Safeguarding of PHI means that people who need to keep PHI
Responsible for their use and disclosure
You have a legal recourse to combat violations

HIPAA implementation process

HIPAA Implementation begins with the assumptions PHIDisclosure of the threat. The implementation includes both pre-and post-clearance audits and includes processes, technology, personnel and aspects.

A threat model for helping the process of implementing HIPAA. It contains assumptions about
Threat to nature (the accidental disclosure of inside? Access for profit?)
Source of threat (outsider or insider?)
The resources of the potential threat (pause, physical intrusion, computer hack, virus?)
Some types of data onRisk (patient identification, finance, medicine?) E
Scale (such as patient data, many threatened?).

HIPAA process must be clearly stated policy, planning, teaching and events, as applied in a clear meaning, a timetable for testing of HIPAA, and tools for greater transparency on HIPAA. Declared policy usually includes a statement of least privilege access to job data, the definition of accident PHI and complete procedures for monitoring and reporting.The material can be case studies, problems of control, and a calendar of seminars for staff review.

Requirements for HIPAA compliance technology

Networking Technology to implement the HIPAA proceeds in several stages from the logical data defining the physical center of data.

In order to ensure the safety of the physical data center, the operator must
Lock Computer Center
List Manage access
Track to track access data center with closed circuit cameras, bothbuild internal and external activities
Protect access to the data center with 24 x 7 on site security
Protect your data backup
Test procedure recovery

For network security, data center facilities for details
Secure Networking - firewall protection, encrypted data transfer only
Monitoring network access and Audit Report
Need of data security, transmission
Individual authentication - individual login and password
Role-Based Access Control (see below)
AuditThe trails and paths - all access to all data fields and records
The discipline of data - the limited ability to download data

Role-Based Access Control (RBAC)

RBAC improves the convenience and flexibility of the management system. Greater comfort to isolate the error and omissions in the granting of access rights for users. Greater flexibility contributes to the implementation of the policy of least privilege, where there are users, as well as the rights are necessary for the completion of theirWork.

RBAC supports the economies of scale, because the frequency of changes in the role definition for a single user exceeds the frequency of changes in role definitions across the organization. How to make a big change permissions for a large number of users with the same set of privileges that the sole administrator to change the definition of role.

Hierarchical RBAC supports further economies of scale and reduces the likelihood of errors. Allows the redefinition of rolesinherits the privileges for the roles assigned to hierarchical level.

RBAC is a set of user profiles or roles based in accordance with the responsibilities. Each role has created a default set of privileges. The user gets the privileges that membership of the role or assignment of a profile by the administrator.

Each time the definition of the role changes with the number of privileges is necessary for the job with the role that the member complete the 'Administrator privileges only need to redefine the role. The rights of all users who receive the role automatically redefined.

Although the role of a single user is changed, it is the only process that needs to be done for the redistribution of the user profile, user access permissions will be set automatically according to the new profile.

Abstract

HIPAA requires special attention to management practices. Practice withseveral separate systems for planning, requires health records and electronic billing, HIPAA separated more management effort. An integrated system reduces the complexity of implementing HIPAA. By outsourcing the technology supplier to provide a HIPAA compliant vericle technology as a solution on an ASP or SaaS-based, HIPAA administrative burden can be eliminated (see companion documents of ASP and SaaS) for medical billing.

ไม่มีความคิดเห็น:

แสดงความคิดเห็น