Compliance in Healthcare
Corporate Compliance

The Imperative of Documentation Integrity

Addressing the Healthcare Data Crisis 

Written by Joanne Byron, LPN, BS, CCA, CIFHA, CHA, COCAS, CORCM, CHCO, HPOC, OHCC, CMDP, ICDCT-CM/PCS 

The information in this article primarily applies to providers when recording patient encounters in their office or other places of service. Content is for educational purposes only and is not intended as consulting or legal advice.

Introduction

Clinical documentation represents the foundational pillar of modern healthcare, ensuring patient safety, care continuity, accurate reimbursement, and the ethical use of medical data for research. However, the healthcare industry is currently grappling with a severe data crisis driven by the proliferation of historical documentation errors.

  • The transition from paper-based charts to Electronic Health Records (EHRs), while designed to streamline operations and reduce medical errors, has inadvertently introduced systemic vulnerabilities that compromise the integrity of clinical data.

The modern healthcare data crisis is not simply a matter of lost or misplaced files; it is a systemic degradation of data quality caused by the cumulative effect of historical documentation errors. At the center of this crisis is the phenomenon known as "chart lore" or "note bloat," where inaccuracies and redundancies are perpetuated across multiple patient encounters.

Several structural and behavioral factors drive this crisis:

  • Overuse of Copy/Paste and Cloning: The implementation of EHRs introduced time-saving functionalities such as the "copy-forward" or copy/paste features. Studies have revealed that over 50% of the text in inpatient and outpatient notes is duplicated. This practice often results in carrying over outdated, irrelevant, or entirely incorrect clinical information (e.g., documenting an allergy that was proven false years prior), creating information overload and increasing the risk of adverse events.
  • Template and Drop-Down Menu Errors: The reliance on pre-populated templates and drop-down menus can lead to "mouse-click errors," where a provider accidentally selects a normal finding for an abnormal condition. These errors obscure the true "patient story" and result in contradictory or missing clinical context.
  • Patient Matching and Interoperability Failures: Poor data entry and fragmented system integration contribute to patient misidentification. Industry surveys indicate that up to 20% of patients may not be correctly matched to their records, leading to scenarios where providers make treatment decisions based on another individual’s medical history.
  • Defensive and Billing-Driven Documentation: Because healthcare systems rely on Evaluation and Management (E/M) codes and reimbursement structures, clinicians are often pressured to document excessively to satisfy complex billing requirements, rather than focusing purely on clinical utility. This return-on-investment approach distorts the clinical record and leads to defensive medicine.
    • In light of Evaluation & Management guidelines allowing time or medical decision-making for many codes, providers must remember, when time is used, the complexity of the visit must be reflected to support longer visit times (higher reimbursed codes). Payers will question when high levels of service are billed but the note does not reflect the amount of work to support reimbursement.

Artificial Intelligence and the Physician/Provider Burden

Ironically, the tools intended to make documentation easier, EHR systems, have become a leading driver of clinician stress and burnout. The "cognitive load" of navigating drop-down menus and templating systems detracts from face-to-face patient time. And now with Artificial Intelligence (ambient scribes) being integrated into clinical documentation, the burden can become overwhelming due to time to ensure there are no errors in the record. AI is being built of historical information that is peppered with errors, inaccuracy, and omissions.

Despite promised efficiency gains, a large multi-center study found that AI ambient scribes saved a relatively modest 16 minutes of documentation time per eight hours of care. Because physicians are ultimately responsible for the accuracy of their medical records, they are forced to shift cognitive effort from typing to auditing—carefully reviewing AI-generated text to ensure no critical data has been omitted or misstated

Integrating artificial intelligence (AI) as ambient scribes in clinical settings reduces documentation time but yields distinct error profiles. Studies from the National Library of Medicine indicate that up to 70% of AI-generated notes contain at least one error, with an average of 2 to 3 errors per note. Omissions are the most common mistake, accounting for 71% to 83% of all errors.

Breakdown of AI Errors

Research shows that the types and frequencies of errors vary widely by system:

  • Omissions: Occurring in roughly 70-80% of recorded mistakes, this happens when AI leaves out critical details. Studies note that over 40% of these omissions carry moderate to significant clinical importance (e.g., omitting comorbidities or medication side effects).
  • Additions: Representing 4% to 11% of errors, this occurs when the AI fabricates or inserts information that was never discussed.
  • Hallucinations & Wrong Outputs: Fabricated or severely misidentified medical terminology.
  • Misplacements: Occurring in 6% to 25% of errors, where the AI correctly transcribes the info but places it in the wrong section of the chart.

Documentation Integrity & Accuracy Metrics

While traditional self-documentation by doctors can also be fragmented, ambient AI drafts often capture a much higher volume of the spoken interaction. However, this can sometimes lead to an inverse problem of information overload for the physician reviewing notes for accuracy.

Patient Safety and Clinical Continuity

The primary purpose of any clinical note is to support continuous, high-quality patient care. Outpatient practices frequently treat patients across extended timelines and involve diverse clinical staff. Therefore, documentation integrity is critical for several interconnected reasons:

  • Preventing Diagnostic and Medication Errors: When previous providers fail to update active problem lists, or when notes contain contradictory information, the risk of adverse events skyrockets.
    • Accurate documentation ensures that allergy lists, historical diagnoses, and ongoing treatment regimens are clear, preventing medication interactions and duplicative testing.
  • Facilitating Coordinated Care: In an era of team-based care and interoperability, patient notes are often referenced by external specialists, primary care physicians, and allied health professionals.
    • Complete, up-to-date clinical notes give care teams a holistic view of a patient’s health journey, allowing them to make informed, data-driven decisions.

Financial Sustainability and Revenue Cycle

Documentation dictates reimbursement and an organization’s ability to support compliant billing and reimbursement. In outpatient settings, practices rely on Evaluation and Management (E/M) coding guidelines established by the Centers for Medicare & Medicaid Services (CMS) and the American Medical Association (AMA).

  • Reducing Claim Denials: Payers use automated systems to verify that documented services match the billed codes. Incomplete or vague documentation leads to high rates of claim denials, requiring expensive and time-consuming rework for billing staff.
  • Combating the "Cloning" Risk: EHRs offer time-saving features like "copy-and-paste," "carry-forward," and auto-fill. While efficient, these features frequently lead to documentation cloning, where notes contain outdated or clinically irrelevant information.
    • Payers increasingly view cloned notes as a compliance risk, which can lead to delayed payments or allegations of upcoding, leading to allegations of violating the False Claims Act.

The Clinical and Legal Repercussions

The accumulation of these errors across vast databases has severe, real-world consequences for patient safety and institutional liability. Regulatory bodies, including the Department of Health and Human Services (HHS) Office of Inspector General (OIG), heavily scrutinize outpatient billing. Ensuring documentation integrity limits the financial and reputational damage of audits:

  • Demonstrating Medical Necessity: Every medical service must be justified by documented medical necessity. Documentation must clearly demonstrate why a course of action was taken and what alternatives were considered. Without this, practices are vulnerable to recoupment during post-payment audits.
  • Combating Fraud, Waste, and Abuse: Accurate charting protects both the provider and the organization. Attempting to add missing information or diagnoses to a chart after an audit has been initiated is a serious legal violation that carries civil and criminal penalties. Maintaining real-time, tamper-evident documentation is the best legal defense for providers.
  • Patient Harm and Medication Errors: Data integrity issues directly impact diagnostic accuracy and treatment planning. Studies indicate that a significant percentage of EHR-related events—sometimes cited as over one-third of cases—have life-threatening potential. When providers are forced to skim through bloated records, critical changes in a patient's condition or medication history are frequently missed.
  • Artificial Intelligence and Big Data Limitations: The current push toward integrating artificial intelligence (AI) and machine learning (ML) into healthcare relies entirely on the premise of data accuracy. However, because a high percentage of EHR records contain documentation errors, predictive models are frequently built on flawed or "missing" data indicators, which compromises their clinical reliability and introduces unconscious biases into algorithmic decision-making.
  • Malpractice Liability: Legal teams increasingly scrutinize EHR meta-data and documentation errors during litigation. Many EHR-related malpractice liabilities stem directly from documentation errors and omission, making inaccurate record-keeping a major risk management concern.

Strategies for Restoring Documentation Integrity

Addressing the healthcare data crisis requires a fundamental shift in how documentation is viewed, created, and audited. Organizations must move beyond billing-centric metrics and prioritize true Clinical Documentation Integrity (CDI). We simply need more documentation professionals, specifically in the outpatient setting where most care is rendered.

Implement Continuous CDI Programs - Healthcare facilities must establish dedicated CDI teams that routinely review and audit charts for clarity, completeness, and clinical accuracy. However, it is important that auditors and those training providers in CDI have structured training themselves first. Not all coding and billing auditors are qualified to conduct a documentation integrity audit. By educating all those involved on best practices and modern documentation guidelines, organizations can ensure that the patient's medical history accurately reflects their current clinical state.

Engage with organizations for online CDI training to improve the basic understanding of a compliant medical record. Registering qualified staff and/or providers with an organization which is a Licensing/Certification partner with CMS is recommended, such as the American Institute of Healthcare Compliance which offers online training with option to Certify as a Medical Documentation Professional.

EHR Usability and Design Overhaul - Software vendors and IT departments must collaborate to redesign EHR interfaces. This includes implementing strict limits on copy-paste functionalities, utilizing anomaly detection tools to flag duplicated or contradictory text, and enhancing interoperability to reduce patient matching errors.

Structured Data Capture - Shifting from unstructured narrative notes to standardized, structured data formats allow for better data reuse, less error-prone information exchange, and more effective clinical decision support systems.

Patient Engagement as a Verification Tool - Opening up EHRs to patients—allowing them to access their own health records and actively report discrepancies—has proven to be an effective strategy for identifying and resolving embedded "EHRrors" before they cause harm.

Conclusion

The historical degradation of healthcare data integrity poses a significant public health threat, turning patient records from life-saving tools into repositories of perpetuated errors.

To mitigate this crisis, the healthcare ecosystem must prioritize actionable, systemic reforms. By investing in enhanced EHR design, responsible implementation of integrating AI, rigorous auditing and compliance, and a culture of clinical clarity, the industry can restore trust in medical data and safeguard patient lives.

Outpatient practices can no longer treat clinical documentation as a mere administrative byproduct. Documentation integrity is the structural backbone of patient safety, financial compliance, and legal protection. By actively investing in CDI processes, ongoing provider education, and optimized EHR workflows, outpatient practices can safeguard patient outcomes, reduce audit vulnerabilities, and restore clinician satisfaction.

About the Author

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS is an executive educator with the American Institute of Healthcare Compliance, a Licensing/Certification non-profit partner with CMS. She shares her experience of over 40 years as a nurse, consultant, auditor, and investigator in the healthcare field.

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

OCR Enforcement of HIPAA Right of Access and Release of Information (ROI)

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The article addresses the HIPAA Privacy Rule for Covered Entities regarding time limitations to respond to an individual’s request for access of protected health information or “PHI.” This article is not all inclusive and should not be used as legal or consulting advice. Scroll down for hyperlinks to free and low-cost training related to Right of Access & ROI.



What Is HIPAA Right of Access?


The HIPAA Privacy Rule generally provides individuals with a legal, enforceable right to see and receive copies, upon request, of the information in their medical and other health records maintained by their health care providers and health plans. This right is known as the HIPAA Right of Access.


HIPAA Right of Access policies have evolved over the years to ensure that patients have equitable access to their medical records. HIPAA requires covered entities to provide patients with access to their medical records. The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009, helped right of access policies evolve to reflect the growing use of EHR systems.


HIPAA Enforcement


HIPAA compliance it monitored by the Health & Human Services (HHS) enforcement agency, the Office for Civil Rights (OCR). The Office for Civil Rights is responsible for enforcing the Privacy and Security Rules. Enforcement of the Privacy Rule began April 14, 2003, for most HIPAA covered entities. Since 2003, OCR's enforcement activities have obtained significant results that have improved the privacy practices of covered entities. OCR also works in conjunction with the Department of Justice (DOJ) to refer possible criminal violations of HIPAA.


In 2019, the OCR launched the HIPAA Right of Access Initiative to advocate for individuals trying to obtain their health records in a timely manner at a reasonable cost as required by covered entities in the HIPAA Privacy Rule.


Complying With the HIPAA Privacy Right of Access Rule


If your organization is not responding timely to requests for medical records, a complaint to the Office for Civil Rights can trigger an investigation resulting in fines and other consequences, such as being posted on the OCR HIPAA website and a forced Corrective Action Plan.


A dedicated government webpage lists HIPAA News Releases & Bulletins listing OCR cases after investigating organizations which includes Right of Access settlements. Click Here to access this page. https://www.hhs.gov/hipaa/newsroom/index.html


The July 15, 2022, Health & Human Services (HHS) Press Release announces the resolution of eleven investigations and the enforcement actions taken with these eleven organizations related to violations of patient’s rights under HIPAA. In this press release the OCR Director Lisa J. Pino states:


“It should not take a federal investigation before a HIPAA covered entity provides patients, or their personal representatives, with access to their medical records. Health care organizations should take note that there are now 38 enforcement actions in our Right of Access Initiative and understand that OCR is serious about upholding the law and peoples’ fundamental right to timely access to their medical records.”

 

So, how timely must a covered entity be in responding to individuals’ requests for access to their PHI?


This is addressed under 45 CFR 164.524(b)(2) of the HIPAA Privacy Rule regarding access of individuals to protected health information (PHI). Under the HIPAA Privacy Rule, a covered entity must act on an individual’s request for access no later than 30 calendar days after receipt of the request.


If the covered entity is not able to act within this timeframe, the entity may have up to an additional 30 calendar days as long as it provides the individual, within that initial 30-day period, a written statement of the reasons for the delay and date when the entity will complete its action on the request. The 30-day timeline applies regardless of the following circumstances:

  • The PHI that is the subject of the request is maintained by the covered entity or by a business associate on behalf of the covered entity, or the covered entity uses a business associate to fulfill individual requests for access.

o The 30-day clock starts on the date that the covered entity receives a request for access, so any delay in obtaining the necessary information from a business associate or forwarding the request to the business associate for action “uses up” part of the allotted time.


o Alternatively, the 30-day clock starts when, instead of the covered entity, a business associate receives a request directly from an individual because the covered entity instructed the individual through its notice of privacy practices (or otherwise) to submit the access request directly to its business associate for processing. 

  • The covered entity negotiates with the individual on the format of the response. Covered entities that spend significant time before reaching agreement with individuals on format are depleting the 30 days allotted for the response by that amount of time.

  • The PHI that is the subject of the request is old, archived, and/or not otherwise readily accessible.

As noted by OCR, these timelines are outer limits. The government expects that covered entities should be able to respond to requests for access well before these outer limits are reached. However, in cases where a covered entity is aware that an access request may take close to these outer time limits to fulfill, the entity is encouraged to provide the requested information in pieces as it becomes available, if the individual indicates a desire to receive the information in this manner.


Resources to Comply With ROI and Right of Access


Learn more about 45 CFR § 164.524 - Access of individuals to protected health information. Free and reasonably priced training for you and your workforce is listed below:


Right of Access Specialist - Online Course

AIHC HIPAA Compliance Training Videos Free

Legal Information Institute (Cornell Law School) Free

HIPAA Online Privacy Course (Earn 12 AIHC and AHIMA CEUs)

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Addressing Revenue Cycle Labor Shortage With Technology and Outsourcing

Written by: Melvin Miller, COO




The labor shortage is currently one of the biggest issues across industries. Be it restaurants, hospitals, retail, hospitality, and manufacturing – take any sector and you will find that this is perhaps the #1 problem operations managers are facing.


In healthcare, the labor shortage is not limited to clinical roles but extends across administrative functions. Front-office staff, billers, coders, accounts receivable, denial management, and physician credentialing experts are in short supply.


If you look at the revenue cycle, lack of timely filing and follow-ups can increase denials and result in delayed cashflows. When your revenue cycle faces a staffing shortage for core functions, you tend to ignore the optimization functions such as quality assurance and underpayment reviews, which can unlock additional revenue opportunities.


The staffing shortage is aggravating problems for the hospitals, which were impacted already by the pandemic. Over the years, we have seen declining reimbursements necessitating revenue cycle operations to deliver the best financial outcomes, which requires deep healthcare and reimbursement process expertise.


With expert revenue cycle team members already in short supply and the mandate to get all employees vaccinated for COVID-19, hospitals and healthcare systems are losing employees due to resignations and terminations. Due to the shortage of clinical and non-clinical staff, many hospitals are on the verge of closing; in fact, many rural facilities have closed already. Further, the shortage has resulted in a fight for talent, which led to increased salaries and the cost of operations.


In this blog, we look at some of the strategies revenue cycle CFOs are deploying.

  • Cloud-based IT infrastructure

With the need to operate remotely, IT leaders are tasked with making mission-critical EHR and RCM platforms available anytime, anywhere. In most physician practices, the adoption of SaaS-based EMR/RCM solutions is increasing.

  • Process automation

Within both clinical and non-clinical revenue cycle solutions, the application of machine learning, AI, and RPA technologies are enabling revenue cycle leaders to combat the staffing shortage to some degree. Technology and automation can move routine, repeatable, labor-intensive tasks to the machines and reduce manual effort. For instance, claims status automation and the adoption of portals reduce call center workloads. When you free up people from mundane activities, they can focus on higher-value activities and have better job satisfaction.

  • Operational rigor

While all revenue cycle leaders talk about managing tighter operations, few have gone on to invest time and money in implementing workflow systems that help them measure, monitor, and manage the productivity of each employee. Transactional productivity improvements will, in the short term, lead to gains in financial outcomes.

  • Analytics for sustainable transformation

Usually, revenue cycle success boils down to strategic A/R management, i.e., understanding the patterns in denied claims, addressing root causes, strategic touches to claims in higher revenue brackets, and not allowing claims to fall into longer aging buckets. Revenue cycle analytics and adoption of industry-standard reporting can help RCM managers create the focus.

  • Outsourcing

Perhaps the #1 strategy that organizations are looking at is outsourcing, which gives them access to trained, certified labor across the nation. And with offshoring, you also get the benefits of cheaper cost structures. With the outsourcing and offshoring market now nearly two decades old, you can find service providers who have invested in process expertise and technology to help you get access to best-of-the-breed practices.

  • Optimizing costs to collect requires simultaneous implementation of pervasive change strategies

Across the revenue cycle operations, the questions that leaders need to ask are:


o What can you automate?


o What technologies do you need to invest in - workflow automation, analytics,
front-end tech?


o Where will you find the money to invest in new-age technology?


o Does this function need to be done onshore, or can you offshore it? 

  • Cash is king. Leaving revenue on the table is a crime.

Faster cash flow cycles are critical to the survival of healthcare organizations. Address the problems such as revenue leakage and front-end processes sustainably to streamline operations.

  • Change the job content for your employees

Accelerating the adoption of technology and outsourcing can shift the focus of your employees to strategic tasks. The change in job content makes them feel empowered to impact the organization’s revenue cycle outcome, which is more satisfying.

  • Don’t just outsource. Choose your vendor partner well.

Plan along with your vendors, transition and stabilize operations, and then move the goal post for the vendor every quarter.

While you can take the short-term to address your revenue cycle issues, it is time for revenue cycle leaders to implement sustainable solutions. The labor shortage is not going away quickly, and reimbursements will continue to decline. Technology, operational rigor, and outsourcing are the only options you have. Choose well, plan well, and execute in style.

Additional Resources:

  • Medical Billing Wholesalers - https://www.medicalbillingwholesalers.com

    _________________________________________________________

    Melvin Miller is an experienced Chief Operating Officer with a demonstrated history of working in the healthcare industry for over 15 years, Satish, a.k.a. Melvin, has experience in team building, business development, Healthcare Information Technology (HIT), revenue cycle process training, US. Health Insurance Portability and Accountability Act (HIPAA), and Healthcare Management.
Read More
Telehealth
HIPAA, Telehealth

Audio-Video Telehealth, Mobile Device Management & You

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS


This article addresses how to track telehealth policies while addressing HIPAA compliance and mobile device management as the United States enters into a post-pandemic era. The information is an overview and should not be used as legal or consulting advice. Health care providers need to look toward long-term telehealth policies, ensure compliance and realize there is remaining work to be done. 


Scroll to the end of this article for “Basic Telehealth Terminology” if you are new to telehealth or if you are a mobile device app developer!


Most Providers Utilize Audio-Only Telehealth


More than two-thirds of providers utilizing telehealth use audio-only, according to a recent Telehealth Survey conducted November 2021 through December 2021 by the American Medical Association (AMA). According to this survey, 85% of physician respondents indicate they currently use telehealth. Those reporting a decrease in use since first offering it, now indicate doing a mix of in-person and virtual care. Of physician’s using telehealth, the trend indicates 93% are conducting live, interactive video visits with patients and 69% are doing audio-only visits.  


Considering this survey and other reports on audio-video services, concerns seem to focus on potential overutilization, equity and quality of care. 


A concern expressed to AIHC, by our Compliance and HIPAA Officer members, surrounds mobile devices used by providers and practice managers and the organization’s responsibility to comply with applicable rules, regulations and mobile device policies.


So, how do policies apply? 

 

If your providers use a mobile device to access an organization’s internal network or system, the owner of that network or system’s policies and procedures apply to your use of the mobile device to gain such access. It is your organization’s responsibility to understand and follow the organization’s policies and procedures.


If an organization allows providers and professionals to use mobile devices for work, the organization should have reasonable and appropriate mobile device policies and procedures. The policies and procedures should describe any configuration requirements for mobile devices used by providers and professionals for work. It is your responsibility to understand and follow your organization’s mobile device policies and procedures. But, what about using personally owned mobile devices for work?

  • "Bring Your Own Device" or BYOD refers to using a personally owned mobile device for work. Providers should be reminded to let their organization know when they want to use a personally owned mobile device. Many organizations have centralized security management to make sure mobile devices accessing their internal networks or resources are compliant with their security policies. Centralized security management includes:

o Configuration requirements, such as installing remote disabling on all mobile devices; and


o Management practices, such as setting policy for individual users or a class of users on specific mobile devices.


It is the provider’s responsibility to understand and follow the organization’s mobile device policies and procedures. Registering the provider’s mobile device with the organization allows the organization to control who has access to its network or system and will keep unauthorized persons from accessing its network or systems.

  • Registering these mobile devices with your organization may also help the organization or law enforcement find your mobile device if it is lost or stolen. Providers should be directed to contact their organization’s Privacy Officer or Security Officer to register their mobile device.

Utilizing Step 4 from ONC’s 5-Step Process to Manage Mobile Devices Used by Health Care Providers & Professionals, the list of questions below is a way to take inventory of potential safeguards needed to address risk areas.


Mobile Device Management


 If your organization allows the use of mobile devices, what should the organization do about managing the use of mobile devices?


   o Has the organization identified all the mobile devices that are being used in the organization? How is the organization keeping track of them?


   o Has the organization assigned responsibility to check all mobile devices used for remote access, to find out if selected security/configuration settings are enabled?


   o Should there be a regular review and audit of the mobile devices? 


Misuse of Mobile Devices


 Does the organization have written procedures for addressing misuse of mobile devices?


   o If so, what are the consequences when a mobile device is misused and the incident poses risk of a data breach?


Should the Organization Allow BYOD?


 Is this a policy already in place, where providers are using their own devices?


   o Should the organization let providers and professionals use their personally owned mobile devices within the organization?


 Should providers and professionals be able to connect to the organization’s internal network or system with their personally owned mobile devices, either remotely or on site?


Restrictions on Mobile Device Use


 Does the organization restrict how providers and professionals can use mobile devices?


   o Can providers and professionals use mobile devices to access internal networks or systems, such as an EHR?


   o Are providers and professionals restricted from using mobile devices when they are away from the organization?


   o Can providers and professionals take their mobile devices home?


   o Should the organization allow texting or emailing of health information?


      Is there encryption allowing compliant texting and emailing from the mobile device?


Security/Configuration Settings for Mobile Devices


 Will the organization institute standard configuration and technical controls on all mobile devices used to access internal networks or systems, such as an EHR?


   o If so, is the organization's current mobile device configuration document, including connections to other systems/applications, inside and outside of the firewall.


Information Storage on Mobile Devices


 Are there restrictions on the type of information providers and professionals can store on mobile devices?


   o If so, where and for how long should the data be stored?


 Are providers and professionals allowed to download mobile applications to mobile devices? If so, what type(s) of applications are approved?


Recovery/Deactivation of Mobile Devices


 Does the organization have procedures to wipe or disable a mobile device that is lost or stolen?


 Does the organization have standard procedures to recover mobile devices from providers and professionals when their employment or association with the organization ends?


Mobile Device Training


Training is always a challenge, but if your organization cannot achieve effective training and compliance, you may need to reconsider how telehealth is delivered to your patient population.


 How is the organization training its workforce (management, doctors, nurses, and staff) on policies and procedures?


 How does the organization hold its workforce (management, doctors, nurses, and staff) accountable for non-compliance? 


What Additional Information Should I Know for Compliance?


Covered entities must comply with HIPAA Privacy and Security Rules to protect and secure health information, even when using mobile devices as described above. Taking it a step further, health care leaders are responsible to ensure that mobile device procedures and policies have been developed and properly implemented to protect the health information patients entrust to you.


Make Tracking Audio-Only Policy Easy


A great resource is utilizing the National Telehealth Policy Resource Center called “CCHP,” short for Center for Connected Health Policy. CCHP has been tracking audio-only policies across the country and offers access to state audio-only policies via CCHP’s Policy Finder Tool.


As AIHC advises, another resource is legal advice through your malpractice insurance company. At no additional charge, a risk attorney can be made available to help review which policies impact your type of practice and organization.


Free HIPAA Compliance Resources


Another reliable resource is found at HealthIT.gov, the official website of the Office of the National Coordinator for Health Information Technology, otherwise known as “ONC.” ONC offers basic guidance in these five steps 1) Decide; 2) Assess; 3) Identify; 4) Develop, Document and Implement; and 5) Train entitled “five steps organizations can take to manage mobile devices used by health care providers and professionals.”


Does Your Organization Have a Trained (Certified) HIPAA Privacy/Security Officer?


Your HIPAA Compliance Officer can serve as the best resource to help your organization navigate the telehealth and mobile device compliance issues facing your providers today. AIHC offers an online course covering both privacy and security with the option of certification (proctored and administered online).  The cost of certification is covered in the tuition price. Learn more.


It is highly recommended that mobile health app developers and Managed Service Providers (MSPs) have an in-house HIPAA Compliance Officer contributing input to ensure technology is compliant.


Are You a Mobile Health App Developer?


Integrating protections into your technology to create HIPAA compliant products is necessary for your company to succeed. Health care providers are subject to the HIPAA rules as covered entities to protect identifiable health information when it is created, received, maintained and/or transmitted. These protections are required under Federal and State Privacy, Security and Breach Notification Rules. A few basic resources to reference are:


The Office for Civil Rights (OCR) HIPAA website devotes a webpage under Special Topics entitled “Resources for Mobile Health Apps Developers.”


The Federal Trade Commission (FTC) offers a webpage entitled “Mobile Health Apps Interactive Tool” to help you locate federal laws to follow.


For Beginners - Basic Telehealth Concepts


Telehealth is also referred to as Telemedicine. It is the use of telecommunications technology to provide health care services to persons who are at some distance from the provider. This type of patient encounter involves a spectrum of technologies.


Coverage and payment for telehealth can include consultation, office visits, individual psychotherapy, pharmacologic management and other services delivered via an interactive audio and video telecommunications system.  

  • Providers are located at the distant site; and
  • Patients are located at the originating site.

Provider at the distant site - As stated above, providers are at the “distant site,” referring to where the provider is at time of service. The provider can communicate with the patient using an interactive audio and video telecommunication system that permits real-time communication with the beneficiary.


When telehealth is used, it is considered to be rendered at the physical location of the patient, and therefore a provider typically needs to be licensed in the patient’s state. During the COVID-19 public health emergency (PHE), many states waived this requirement or provided specific exceptions. Click Here for Cross-State Licensing information.


Medicaid programs often restrict the type of providers that can be reimbursed when delivering services via telehealth. During the COVID-19 PHE, the list of providers in Medicare and many state Medicaid programs expanded to include professionals such as occupational and physical therapists and speech-language pathologists. Federally Qualified Healthcare Centers (FQHCs) and Rural Health Clinics (RHCs) were also allowed to provide services in some cases. These policies are temporary and most will expire at the end of the PHE.


I also recommend utilizing the TELEHEALTH.HHS.GOV website for providers – “Getting Started with Telehealth.” This webpage provides many additional links to more resources your organization can use to navigate this complex topic.


Temporary telehealth policies during the PHE were implemented to provide improved access to health care during the COVID-19 pandemic. The federal government has been encouraging providers to use telehealth to conduct virtual appointments and has made the telehealth “rules” more flexible. For instance, audio-only delivery of care has rarely been reimbursed historically. But due to COVID and the PHE, temporary policies allow this modality to deliver some services.


The PHE is reviewed and potentially extended every 90 days. When the PHE ends, coverage for telehealth may change. Monitor these updates by using the CCPH website referenced earlier in this article found at https://www.cchpca.org/.

Read More
HIPAA Compliance
HIPAA

Is Sharing EHR Passwords a Problem?

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article addresses the importance of Electronic Health Record (EHR) security to help health care organizations, health plans, clearinghouses (Covered Entities) and their business associates avoid HIPAA violations under the Security Rule Standard § 164.312(a)(1). To obtain more information about mitigating the risk of a HIPAA violation, please consult with legal counsel or a HIPAA Security Consultant. 

 

What If . . .

 

What would happen if you shared your login and password to your online bank account? How about sharing the password to access your credit cards? How would you feel if you knew your doctor shared his/her password to your personal medical records with an unauthorized user? What if someone in medical billing shared his/her password to your account (containing your medical and financial identity) with someone not authorized to access your information?


What If EHR Passwords Are Shared . . .


Electronic health records (EHRs) incorporate a vast amount of patient information and diagnostic data, most of which is considered protected health information. With the advancement of technology, the emergence of advanced cyber threats has escalated, which hinders the privacy and security of health information systems such as EHRs.


As defined by the Center of Medicare and Medicaid Services (CMS), “An electronic health record (EHR) is an electronic version of a patient’s medical history, that is maintained by the provider over time, and may include all of the key administrative clinical data relevant to that person’s care under a particular provider, including demographics, progress notes, problems, medications, vital signs, past medical history, immunizations, laboratory data and radiology reports.”


Because this protected information and data can easily get into the wrong hands, individuals should not share passwords with anyone.  


Is This Really a Problem? Doesn’t Everyone Share Passwords?


Due to the sensitive nature of the information stored within EHRs, several security safeguards have been introduced through the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.


Prevalence of Sharing Access Credentials in Electronic Medical Records

To summarize an abstract published by PMC (Public Med Central) of the U.S. National Institutes of Health’s National Library of Medicine, it was found that to prevent data leakage, many countries have created regulations regarding medical data accessibility. These regulations require a unique user ID for each medical staff member, and this must be protected by a password, which should be kept undisclosed by all means. A survey was conducted with the following results:

  • A total of 299 surveys were gathered.
  • The responses showed that 220 (73.6%) participants reported that they had obtained the password of another medical staff member.
  • Only 171 (57.2%) estimated how many times it happened, with an average estimation of 4.75 episodes. All the residents that took part in the study (45, 15%) had obtained the password of another medical staff member, while 57.5% (38/66) of nurses reported this.

Their conclusion from this study: the use of passwords is doomed because medical staff members share their passwords with one another. Strict regulations requiring each staff member to have a unique user ID might lead to password sharing and to a decrease in data safety. Click Here to access the full study.


Remember to Comply With the 3 Pillars of Securing ePHI


The three pillars to securing protected health information outlined by HIPAA are administrative safeguards, physical safeguards, and technical safeguards. These three pillars are also known as the three security safeguard themes for healthcare. These themes range from techniques regarding the location of computers to the usage of firewall software to protect health information. A brief list of the HIPAA Security Safeguards:

  • Access control (technical safeguard) is a technique that prevents or limits access to an electronic resource. The intent behind access control techniques is to limit access to only authorized parties. The healthcare facility collects, stores, and secures patients’ data, which is very sensitive. This safeguard can take the form of role-based access control, attribute-based access control, and identity-based access control. Role-based refers to a person’s role in the healthcare facility. For instance, when a provider begins working at a healthcare facility, he/she has access to patient data, but only the patient data for his/her patients. If this provider also serves on a certain committee in the hospital, then another set of privileges is created to enable access to committee resources. When other data is accessed, a log is created that is periodically audited. When a front-desk clerk begins working in a facility, he/she has no reason to access clinical data, but may need access to the administrative data such as address and phone number, depending on the role that the person plays in the organization. Other names for this are media controls, entity authentication, encryption, firewall, audit trails, virus checking, and packet filtering.
  • Physical access control (physical safeguard) is a technique that prevents or limits physical access to resources. The intent of this control is similar to the technical safeguard: It limits access to only authorized parties. A patient in a facility will not have access to any clinic or ward except the one he/she is seen in. A front-desk clerk in the optometry clinic will not typically need access to the emergency room, so his/her access card will not open those doors. A provider in a facility will not typically need access to the server room, so his/her access card will not unlock those doors. Other names for this are physical security, (some) workstation security, assigned security responsibility, media controls (access cards), and physical access control.
  • Administrative safeguards are techniques that are not entirely technical or physical, but may contain a piece of each. These safeguards typically take the form of policies, practices, and procedures in the facility to regularly check for vulnerabilities and continually improve the security posture of the organization. Other names for this control are risk analysis and management, system security evaluation, personnel chosen for certain roles, contingency, business continuity, and disaster recovery planning.

When Someone Shares a Password – It Is a HIPAA Violation Under the HIPAA Security Rule – Technical Safeguard Related to Access Controls. 

 

The Security Rule defines access in § 164.304 as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subpart E of this part [the HIPAA Privacy Rule]).” Access controls provide users with rights and/or privileges to access and perform functions using information systems, applications, programs, or files. Access controls should enable authorized users to access the minimum necessary information needed to perform job functions. Rights and/or privileges should be granted to authorized users based on a set of access rules that the covered entity is required to implement as part of § 164.308(a)(4), the Information Access Management standard under the Administrative Safeguards section of the Rule.


Unique User Identification Requirement - § 164.312(a)(2)(i)

 

The Unique User Identification implementation specification states that a covered entity must: “Assign a unique name and/or number for identifying and tracking user identity.”


User identification is a way to identify a specific user of an information system, typically by name and/or number. A unique user identifier allows an entity to track specific user activity when that user is logged into an information system. It enables an entity to hold users accountable for functions performed on information systems with ePHI when logged into those systems using audit trails (addressed toward the end of this article).


Regardless of the technology or information system used, access controls should be appropriate for the role and/or function of the workforce member. For example, even workforce members responsible for monitoring and administering information systems with electronic protected health information or ePHI, such as administrators or super users, must only have access to ePHI as appropriate for their role and/or job function.


Sample questions for covered entities to consider:

  • Does each workforce member have a unique user identifier?
  • What is the current format used for unique user identification?
  • Can the unique user identifier be used to track user activity within information systems that contain ePHI?

So, What Can Happen If We Have Insufficient ePHI Access Controls?

Violating HIPAA law 104-191 can be costly. The HIPAA Security Rule requires covered entities and their business associates to limit access to ePHI to authorized individuals. The failure to implement appropriate ePHI access controls is also one of the most common HIPAA violations and one that has caused financial penalties. 


Financial penalties issued to covered entities for ePHI access control failures include:


Anthem Inc. – $16,000,000 penalty for access control failures and other serious HIPAA violations

OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations

OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations

University of California Los Angeles Health System – $865,500 penalty for the failure to restrict access to medical records

Colorado Medical Center – $111,400 penalty for the failure to terminate access to ePHI after an employee termination and a lack of a business associate agreement

Controlling Access to ePHI: For Whose Eyes Only?


The government HIPAA privacy/security enforcement agency is the Office for Civil Rights (OCR). OCR published the Summer 2021 Cybersecurity Newsletter on July 14, 2021, which states:


The rise in data breaches due to hacking as well as threats to ePHI by malicious insiders highlight the importance of establishing and implementing appropriate policies and procedures regarding these Security Rule requirements. Ensuring that workforce members are only authorized to access the ePHI necessary and that technical controls are in place to restrict access to ePHI can help limit potential unauthorized access to ePHI for both threats.


A recent report of security incidents and data breaches found that 61% of analyzed data breaches in the healthcare sector were perpetrated by external threat actors and 39% by insiders.


Without appropriate authorization policies and procedures and access controls, hackers, workforce members, or anyone with an Internet connection may have impermissible access to the health data, including protected health information (PHI), that HIPAA regulated entities hold. News stories and OCR investigations abound of hackers infiltrating information systems, workforce members impermissibly accessing patients’ health information, and electronic PHI (ePHI) being left on unsecured servers.


Information Access Management and Access Control are two HIPAA Security Rule standards that govern access to ePHI.


Download this newsletter:

Monitor Audit Trails


Audit trails automatically register and record where, when and who accessed the system. They also record what users do when they access the system. This tracks every change in patients’ information and documents it.


Since all the data is logged in the EHR system, it enables users to review the data at regular intervals and flag activities that seem suspicious. Regular reviews can also help correct mistakes caused by human error that could be flagged as a HIPAA violation. An audit trail answers the following:

  • Which patients’ data was accessed?
  • What time was it accessed?
  • Who retrieved the data?
  • Where was the data accessed from?

EHR software can also be set to send notifications to patients when their information is accessed. This way patients can report breaches as soon as they happen.


Conclusion


Create strong policies and procedures, then communicate these rules to your workforce. Enforce compliance through auditing and monitoring. Explain that when an individual allows another to use his/her password to access ePHI, that individual can alter and perform unauthorized functions and not be held accountable. The audit trail points back to the person who is assigned that password. 


Conduct on-going training of your workforce, which needs to include your C-Suite executives (who are not exempt from the rules). To gain the BEST results, conduct additional quarterly training with your front-line managers and supervisors.  Give them tools to incorporate HIPAA training at EVERY department meeting. If you think annual HIPAA training is sufficient, then you simply are not doing enough to protect your patient’s ePHI.


Additional Resources


Weekly HIPAA Podcasts (free) at:

OCR “The Security Rule” on the HHS website:

Train Online in HIPAA Privacy & Security:

Read More