Quality
Quality

Culture of Safety is based on Prevention, not Punishment

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS  

This article emphasizes the need of healthcare institutions to focus on building a culture of safety through Root Cause Analysis (RCA) to Manage Clinical Risk is an important management tool.  Read Part 1: Building a Culture of Patient Safety Starts with Reducing Staff Burnout posted December 3, 2024 and Part 2:  An Approach to Reduce Patient and Workforce Harm.

Introduction

Keeping patients safe requires an organizational culture of safety based on the commitment from Directors and C-Suite Executives.  Creating a patient safety environment includes complex interventions that involve the need for variations in individual work routines and healing processes as well as behavioral changes to be made on the part of the team or the individual for maximum acceptance from others.

Patient safety is a framework of organized activities that creates cultures, processes, procedures, behaviors, technologies and environments in health care that consistently and sustainably lower risks, reduce the occurrence of avoidable harm, make error less likely and reduce its impact when it does occur.

Every point in the process of care-giving contains a certain degree of inherent unsafety.

Clear policies, organizational leadership capacity, data to drive safety improvements, skilled health care professionals and effective involvement of patients and families in the care process, are all needed to ensure sustainable and significant improvements in the safety of health care.

Root Cause Analysis & Patient Safety

Most healthcare organizations use RCA as a tool to find out what happened, why it happened, and how to prevent it from happening again. The process is a tool for identifying prevention strategies. It is a process that is part of the effort to build a culture of safety and move beyond the culture of blame.

In a Root Cause Analysis Program, basic and contributing causes are discovered in a process similar to diagnosis of disease - with the goal always in mind of preventing recurrence.  The following information breaks this complex process down into basic bullet points and serves as an introduction to this topic only. 

What the RCA process is:

  • An inter-disciplinary, involving experts from the frontline services;
  • Successful when you involve those who are the most familiar with the situation;
  • A process which requires diligence - continually digging deeper by asking why, why, why at each level of cause and effect;
  • A process that requires your organization to identify changes that need to be made to systems; and
  • A process that must be performed with objectivity and as impartial as possible.

What RCA Should Encompass:

  • Determination of:
    • human and other factors;
    • Related processes and systems
    • potential improvement in processes or systems
  • Analysis of underlying cause and effect systems through a series of why questions
  • Identification of risks and their potential contributions

For Your Program to be Credible, an RCA must:

  • Adopt a top-down approach
    • Include participation by the leadership of the organization and those most closely involved in the processes and systems
  • Be internally consistent
  • Include consideration of relevant literature

The Safety Assessment Code (SAC)

The Safety Assessment Code (SAC) can be used to determine whether or not an RCA must be conducted, based on the severity of a specific incident and its probability of occurrence.  It is a method for determining whether any further definitive action is required concerning a particular incident based on the severity of the incident and its probability of occurrence.

A "SAC score" is also of value for incidents that did not result in an adverse event but may also lead to an RCA; i.e., a close call. Close calls occur far more frequently than adverse events and can provide an exceptional opportunity for learning. Close calls afford the chance to develop preventive strategies and actions before a patient may be harmed.

The SAC Matrix is a tool for combining severity and probability. While either the severity or probability of occurrence could be determined first, it is usually more productive to assess the severity first.

When you pair a severity category with a probability category for either an actual event or close call, you will get a ranked matrix score.  These ranks, or Safety Assessment Codes (SAC), can then be used for doing comparative analysis.  There are various SAC matrix tables available, the one below uses 3 severity and 4 probability categories. 

SAC Decision Making Matrix

While either the severity or probability of occurrence could be determined first, it is usually more productive to assess the severity first. This is true since until one has determined the severity of an incident it would be difficult if not impossible to assess an appropriate probability level.  Intersect the 2 categories to determine the SAC score.  For example, if the probability of the adverse event happening if frequent and it is determined by the team that it ranks a severity of “3”, then result would be mapped in the table below.

3 = highest risk

2 =  intermediate risk

1 =  lowest risk

probability severity

The utility of the SAC is at the start of the process so that resources are applied where they have the greatest opportunity to improve the level of safety from a systems perspective.

Root Cause Analysis (RCA) Versus Healthcare Failure Mode & Effects Analysis (HFMEA™)

HFMEA™ is a technique that is usually performed on a system to assess and prioritize the risks associated with that system in the hopes of reducing the risks through re-design as a proactive measure.  Both Root Cause Analysis (RCA) and Healthcare Failure Mode and Effects Analysis (HFMEA™) possess the following elements:

  • Both are non-statistical methods of analysis
  • The goal of both is to reduce patient harm
  • Both involve identifying conditions that lead to harm
  • Both are team activities

Many people confuse these terms and believe that they compete against each other when in fact neither of these two techniques can accomplish what the other can. They are complementary to each other.  A “root cause” is the most fundamental reason for a failure or situation where performance does not meet expectations.

  • Root cause analysis is routinely conducted reactively – to probe the reason for a poor or unexpected outcome or failure which has already occurred.
  • A recent use of root cause is to conduct such analysis as part of a proactive risk reduction effort using Healthcare Failure Mode and Effects Analysis (HFMEA™).

The table below provides a side-by-side comparison of these two analytical tools used in health care.



RCA

Required by Joint Commission after a sentinel event

HFMEA™

Proactive approach to prevent system-related failures

Similarities

  • Non-statistical methods of analysis;
  • Goal is to reduce possibility of harm to patients in the future;
  • Involves identifying conditions that lead to harm;
  • Requires experienced and trained quality managers to lead analysis efforts; and
  • Activity which requires people, time, materials and upper-level management support.

Differences

                            RCA                                                             HFMEA™

Reactive

Proactive

Focuses on an event

Focuses on entire process

Hindsight bias

Unbiased

Fear, resistance

Openness

Asks: “Why?”

Asks: “What if?”

Summary

Organizational culture refers to the shared beliefs, values, and behaviors within a healthcare organization. A lack of emphasis on patient safety in organizational culture can hinder initiatives that aim to ensure patient safety. It may manifest itself as a lack of commitment, inadequate support, or insufficient prioritization of safety measures by the hospital's leadership and staff. This can result in a higher likelihood of medical errors and adverse events occurring. A weak organizational culture can also discourage staff from reporting incidents or speaking out about potential safety concerns further compromising patient safety.

Building a culture of safety starts with educating your Board of Directors, a C-Suite Executives.  The Compliance Department should oversee internal audits that not only include typical compliance risks related to fraud, waste and abuse, but measuring compliance to safety standards as well.  Producing reports to present to high-level executives can help support the budget needed to mitigate patient risk of an adverse event.

To learn more about RCA, I recommend registering for the Certified Healthcare Auditor online certification training program which includes not only auditing, but using RCA for corrective action after the audit.  To learn more about training as a healthcare Compliance Officer, I highly recommend the online Corporate Compliance certification program. 

About the Author and AIHC

The author, Joanne Byron, shares her clinical, consulting, auditing and educational experience by serving as the Board Chair and overseeing the AIHC Volunteer Education Committee. She is also a volunteer hospice nurse, hospice hands-on-care volunteer and End of Life Doula.

The American Institute of Healthcare Compliance (AIHCR) is a non-profit healthcare training organization and a licensing/certification partner with CMS. Please visit our online store listing current training and certification offerings.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

You Play a Vital Role in Protecting the Integrity of the U.S. Healthcare System

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The U.S. health care system relies heavily on third-party payers to pay the majority of medical bills on behalf of patients. Health care insurance fraud is a pressing problem, causing substantial and increasing costs in medical insurance programs. To combat fraud and abuse, all levels within a medical practice, hospital or health care organization must know how to protect the organization from engaging in abusive practices and violations of civil or criminal laws.


If you are a health care provider, remember that payers trust you to provide medically necessary, cost-effective, quality care. You exert significant influence over what services your patients get. You control the documentation describing services they receive, and your documentation serves as the basis for claims you submit. Generally, the health care system pays claims based solely on your representations in the claims documents.


When the federal government covers items or services rendered to Medicare and Medicaid beneficiaries, the federal fraud and abuse laws apply. Many similar state fraud and abuse laws apply to your provision of care under state-financed programs and to private-pay patients. The most important federal fraud and abuse laws that apply to healthcare are the:

  1. False Claims Act (FCA);
  2. Anti-Kickback Statute (AKS);
  3. Physician Self-Referral Law (Stark Law);
  4. United States Criminal Code
  5. Exclusion Authorities; and
  6. Civil Monetary Penalties Law (CMPL).

Implementing a successful compliance program not only assists in protecting your organization but individuals within the organization. It is crucial for providers, coders and billers to understand these laws not only because following them is the right thing to do but also because violating them could result in criminal penalties, civil fines, exclusion from the federal health care programs or loss of your medical license from your state medical board.


Government programs, such as the Centers for Medicare & Medicaid Services (CMS), find the investment in their audit and monitoring programs are effective. CMS announced in the fall of 2021 that their aggressive corrective actions led to an estimated $20.72 billion reduction of Medicare Fee-for-Service (FFS) improper payments over seven years.


When you submit a claim for services provided to a Medicare beneficiary, you are filing a bill with the federal government and certifying you earned the payment requested and complied with the billing requirements. If you knew or should have known the submitted claim was false, then the attempt to collect payment is illegal.


When an organization fails to provide training and education to deter and detect fraud and/or abuse, it is likely to be detected by an outside investigative source via action such as:

  • Focused audit by the payer due to detection of suspect billing patterns when compared to your peers;
  • Routine audits conducted by the payer, such as Medicare’s Comprehensive Error Rate Testing (CERT); and
  • Internal whistleblower or qui tam action.

Internal auditing and monitoring programs are essential to keeping medical records and billing accurate. However, a routine internal billing and documentation review could turn into a more focused internal investigation. During that investigation, is it possible that an aberrant pattern of inappropriate billing is revealed? Do you know how to proceed if this happens?


First, remember that anyone can commit health care fraud. Fraud schemes range from solo ventures to widespread activities by an institution or group. Your organization should have a designated Compliance Officer. Audit professionals should have the authority to report potential fraud and abuse situations directly to the Compliance Officer for further investigation and resolution.


Problem areas brought to the attention of the Compliance Officer should also be included in corrective action training programs to avoid the continuation of the situation. One of the most important aspects of a compliance program is training and education at all levels of the organization.


Now, let’s talk more about qui tam action. There are five potential areas in which qui tam cases arise related to Medicare or Medicaid claims and the False Claims Act (“FCA”). Qui tam claims involving Medicaid/Medicare healthcare vary, depending on the level of care needed and provided. Categories often involve allegations of total neglect or no services, worthless services, inadequate and inferior services and products, and aggressive patient treatment. Other areas of fraud involve misrepresentation of credentials, upcoding of services, unbundling of services, and misrepresentation of patient data or populations.


Words of Advice


Maintain accurate and complete medical records and documentation of the services you provide.

  • Ensure your documentation supports the claims you submit for payment. Good documentation practices help to ensure your patients get appropriate care and allow other providers to rely on your records for patients’ medical histories.

Anytime a health care business offers you something for free or below fair market value, ask yourself, “Why?”

  • Remember, when a vendor or consultant provides coding and billing advice, the provider filing the claim is responsible for the accuracy of that claim. Be suspicious when you are told that a huge enhancement of revenue will be realized if you bill like this . . .

Get expert advice from a qualified source before investing or getting into a joint venture.

  • Some physicians who invest in health care business ventures with outside parties, such as imaging centers, laboratories, equipment vendors, or physical therapy clinics, may refer more patients for the services provided by those parties than physicians who do not invest. These business relationships may improperly influence or distort physician decision-making and result in the improper steering of patients to a therapy or service where a physician has a financial interest. Arrangements could be viewed as illegal.

Avoid illegal incentives to join a hospital’s community.

  • A hospital may pay you a fair market-value salary as an employee or pay you fair market value for specific services you render to the hospital as an independent contractor. However, the hospital may not offer you money, provide you free or below-market rent for your medical office, or engage in similar activities designed to influence your referral decisions.
  • Admit your patients to the hospital best suited to care for their medical conditions or to the hospital your patients select based on their preference or insurance coverage.

Don’t sell free product samples.

  • Many drug/biologic companies provide free product samples to physicians. It is legal to give these samples to your patients free of charge, but it is illegal to sell the samples.
  • The federal government has prosecuted physicians for billing Medicare for free samples.
  • If you choose to accept free samples, you need reliable systems in place to safely store the samples and ensure samples remain separate from your commercial stock.

Relationships with the pharmaceutical and medical device companies

  • As a practicing physician, you may have opportunities to work as a consultant or promotional speaker for the drug or device industry. For every financial relationship offered to you, evaluate the link between the services you can provide and the compensation you will get. Test the appropriateness of any proposed relationship by asking yourself the following questions and when in doubt, get legal advice: o Does the company really need your specific expertise or input? o Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services? o Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?

o  Does the company really need your specific expertise or input?

o  Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services?

o  Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?


Educate C-Suite and Compliance Officials in Your Company


An executive, top-down approach is required for a successful compliance program. The following seven components provide a solid basis for a compliance program:


1. Conduct internal monitoring and auditing

2. Implement compliance and practice standards

3. Designate a compliance officer or contact

4. Conduct appropriate training and education

5. Respond appropriately to detected offenses and develop corrective action

6. Develop open lines of communication with employees

7. Enforce disciplinary standards through well-publicized guidelines


Establishing and following a compliance program helps health care providers avoid fraudulent activities and submit accurate claims. However, implementing mechanisms to develop a culture of compliance requires educating high-level influencers within your organization. 


Suggest C-Suite executives take online training in healthcare Corporate Compliance.

Require your Compliance Officer, Chief Executive Officer and Chief Financial Officer to become certified not only in Compliance, but in Auditing for Compliance and Conducting Internal Investigations.


Joanne Byron is the Board Chair and Chief Executive Officer of the American Institute of Healthcare Compliance (AIHC) with more than 35 years of health care coding, documentation, billing and compliance experience as a consultant, health care executive and corporate trainer. Learn more about AIHC, a 501(c)(3) non-profit training organization, today.  

Read More