Burnout, Boundaries, and Compliance
Leadership

Beyond Burnout

Workforce Ethics as Enterprise Risk and the Compliance Cost of Moral Injury 

Written by Bertholette Pardieu, MPH, CCEP, OHCC 

Introduction 

Workforce ethics, moral injury, and sustainability have emerged as critical compliance, governance, and patient safety concerns across the healthcare industry. Persistent staffing shortages, increased demand for services, and constrained resources have shifted workforce wellbeing from a human resources issue to an enterprise risk with direct implications for regulatory compliance, quality of care, and organizational stability.

For healthcare compliance and ethics leaders, understanding the relationship between workforce ethics and system performance is essential. Ethical strain within the workforce undermines reporting mechanisms, weakens compliance controls, and increases the likelihood of patient safety events. Addressing these challenges requires structured, organization-wide strategies that are deliberately integrated into governance, ethics, and risk management frameworks rather than addressed through isolated or informal efforts.

The Ongoing Workforce Crisis in Healthcare

Healthcare professionals across clinical and administrative roles continue to face escalating pressures. Chronic staffing shortages, burnout, high turnover, and increasing productivity expectations have become widespread across healthcare settings. These pressures are often accompanied by ethical conflicts that arise when professionals are unable to provide the level of care they believe patients require due to systemic constraints such as limited staffing, time pressures, or resource scarcity.

When healthcare workers repeatedly encounter situations where organizational limitations conflict with professional values, moral distress develops. If unaddressed, moral distress can progress into moral injury, which manifests as emotional exhaustion, disengagement, loss of trust in leadership, and withdrawal from organizational values. These outcomes directly affect workforce stability and compromise compliance processes, quality oversight, and patient safety initiatives.

Why Workforce Ethics Matters to Compliance and Risk

From a compliance and risk management perspective, workforce instability creates cascading organizational risk. Burnout and disengagement increase the likelihood of patient safety events, documentation errors, incomplete reporting, and breakdowns in adherence to policies and procedures. A workforce under sustained ethical strain is also less likely to participate meaningfully in compliance training, reporting mechanisms, and quality improvement activities.

Regulators and accrediting bodies increasingly assess organizational culture, leadership responsiveness, and staff engagement as part of broader evaluations of compliance effectiveness. As a result, compliance programs that fail to account for workforce ethics risk overlooking a key driver of regulatory exposure and patient harm.

To address this risk, compliance leaders should formally incorporate workforce ethics and moral injury into compliance risk assessments. Indicators such as turnover trends, vacancy duration, overtime utilization, safety event patterns, and ethics reporting activity provide valuable insight into ethical strain and emerging compliance vulnerabilities. Presenting these risks to executive leadership and boards alongside traditional compliance risks reinforces accountability and ensures appropriate mitigation strategies are implemented.

Workforce Sustainability as an Enterprise Risk

Workforce sustainability reflects an organization’s ability to maintain a stable, engaged, and ethically supported workforce over time. It extends beyond recruitment and retention efforts and encompasses leadership accountability, governance oversight, and organizational culture. Persistent workforce instability leads to diminished productivity, loss of institutional knowledge, increased reliance on temporary staffing, and escalating recruitment and onboarding costs. These challenges create financial strain and operational disruption, reinforcing the need to integrate workforce sustainability into enterprise risk management and governance structures.

Treating workforce ethics as an enterprise risk enables organizations to assign risk ownership, monitor trends over time, and implement corrective actions before issues escalate into regulatory or patient safety events.

Ethical Obligations and Moral Injury in Healthcare Compliance

Healthcare compliance programs are grounded in ethical principles that emphasize integrity, accountability, transparency, and patient-centered care. Moral injury represents a significant ethical risk because it undermines the ability of healthcare professionals to uphold these principles consistently. Compliance and ethics leaders have an obligation to recognize moral injury as an organizational issue rather than an individual failing. Ethical standards and regulatory expectations require healthcare organizations to foster environments where ethical concerns can be raised without fear of retaliation and where leadership responds meaningfully to those concerns. When ethical distress is ignored or minimized, trust in reporting mechanisms erodes, weakening compliance effectiveness and increasing organizational risk.

To strengthen ethical oversight, compliance leaders should establish clear ethics escalation pathways that are distinct from human resources or disciplinary processes. Providing staff with trusted avenues to raise ethical concerns outside of traditional human resources channels reinforces psychological safety and supports early identification of systemic issues that may impact compliance and patient care.

Ethical Support Structures That Strengthen Compliance

Healthcare organizations are increasingly implementing structured mechanisms to address workforce ethics and moral injury. When designed intentionally, these supports function as preventive and detective controls within compliance and quality frameworks. Moral distress rounds provide facilitated opportunities for staff to discuss ethically challenging situations in psychologically safe settings. When formalized through policy, documented appropriately, and reviewed at an aggregate level, these sessions help identify systemic challenges, promote consistent and ethical decision making, and inform leadership responses aligned with organizational values and regulatory expectations.

Ethics consultation services support staff and leadership in navigating complex ethical dilemmas related to patient care, resource allocation, or conflicting obligations. These services promote thoughtful decision making, consistent documentation, and alignment with ethical and regulatory standards. Wellbeing and resilience initiatives also contribute to workforce sustainability when they are integrated with ethics, compliance, and quality efforts. Effective programs address structural drivers of distress such as workload, staffing models, and leadership support rather than placing responsibility solely on individual coping strategies.

The Role of Compliance and Ethics Leadership

Compliance and ethics leaders play a critical role in elevating workforce ethics and moral injury from individual experiences to enterprise risk indicators. This includes integrating workforce ethics into compliance risk assessments, monitoring trends related to turnover, reporting activity, and safety events, and embedding ethical workforce considerations into auditing and monitoring activities. By doing so, compliance programs can identify early warning signs of ethical strain before they result in patient harm or regulatory exposure.

Leadership accountability is essential to sustaining ethical workforce support. Compliance leaders should partner closely with human resources, clinical leadership, quality, and safety teams to ensure workforce ethics risks are addressed through coordinated and sustainable interventions rather than isolated initiatives. This collaboration supports alignment between operational realities and ethical expectations.

In addition, compliance and ethics leaders should ensure workforce ethics risks are elevated through formal governance channels. Regular reporting to executive leadership and boards should include workforce-related risk trends, mitigation efforts, and outcomes. Providing leadership with clear, actionable data reinforces accountability and supports informed decision making. By reinforcing non-retaliation protections, promoting psychological safety, and modeling transparency, compliance leaders help sustain trust in reporting mechanisms and ensure workforce ethics remains an organizational priority.

Ethical Workforce Wellbeing and Safer Patient Care

Ethical workforce wellbeing is a critical driver of patient safety and compliance effectiveness. When healthcare professionals feel supported in navigating ethical challenges, they are more likely to report concerns, document accurately, and adhere to policies. Sustained ethical strain increases the risk of errors, underreporting, disengagement, and regulatory exposure.

Compliance leaders should treat ethical workforce wellbeing as an enterprise risk rather than an individual resilience issue.

Integrating workforce ethics indicators into compliance and patient safety monitoring allows organizations to identify systemic drivers of risk. Trusted reporting mechanisms, leadership accountability, and alignment of wellbeing initiatives with compliance and patient safety objectives ensure ethical workforce wellbeing functions as a protective control that supports safer patient care and long-term organizational sustainability.

Conclusion

Workforce ethics, moral injury, and sustainability represent one of the most significant risk areas facing healthcare organizations today. Staffing shortages, burnout, and ethical conflict threaten compliance effectiveness, patient safety, and financial performance. By integrating workforce ethics into compliance risk assessments, governance structures, and ethical support mechanisms, healthcare organizations can proactively address moral injury, support their workforce, protect patients, and strengthen long-term organizational resilience.

About the Author Bertholette Pardieu, MPH, CCEP, OHCC

Bertholette Pardieu, MPH, CCEP, OHCC is the Director of Risk Management and Corporate Compliance Officer at Broward Community and Family Health Centers, Inc., the largest Federally Qualified Health Center in Broward County. She has over a decade of experience leading enterprise-wide healthcare compliance, risk management, privacy, and governance programs across highly regulated environments, including FQHCs and Medicare and Medicaid systems. Her work focuses on integrating ethics, workforce sustainability, and patient safety into compliance and enterprise risk management frameworks. She regularly advises executive leadership and boards on regulatory strategy, organizational risk, and ethical governance. Bertholette earned her Office of Healthcare Compliance, Certified (OHCC) through the American Institute of Healthcare Compliance, a licensing/certification partner w/CMS.

References

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

From Findings to Action

Writing an Objective, Defensible Investigative Report 

Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

An internal investigative report represents the culmination of an internal forensic audit or compliance investigation conducted within your organization. It is the most critical deliverable in any inquiry, transforming data, interviews, and evidence into actionable conclusions. According to the Office of Inspector General’s (OIG) 2023 guidance, well-documented investigations not only demonstrate compliance program effectiveness but also protect organizations from regulatory exposure. This article provides tips to writing an objective and defensible investigative report.  For more information on how to conduct internal investigations and drafting your findings, consider registering and certifying as an Internal Forensic Healthcare Auditor (CIFHA) with the American Institute of Healthcare Compliance, a Licensing/Certification Partner w/CMS.

Introduction

In healthcare, the investigative report serves as both the historical record of an inquiry and the foundation for corrective action. Unlike informal summaries or audit notes, investigative reports must withstand scrutiny from regulators, accreditation bodies, and, in some cases, legal proceedings.

A report that is clear, factual, and defensible establishes credibility and demonstrates that the organization maintains a culture of compliance.

According to the U.S. Department of Justice’s 2024 Evaluation of Corporate Compliance Programs, documentation that reflects diligence, transparency, and follow-up is a decisive factor in evaluating the effectiveness of a compliance program. Similarly, the OIG, 2023 identifies timely reporting and accurate documentation as hallmarks of program integrity. Investigative reports thus become more than administrative records; they are compliance evidence.

The American Institute of Healthcare Compliance emphasizes that reporting is not merely a conclusion but an analytical phase requiring objectivity, ethical awareness, and technical precision.

Investigators are expected to synthesize complex data, maintain neutrality, and communicate findings in language that is factual and free from bias. When written properly, the investigative report transforms an incident into an opportunity for systemic improvement and risk reduction.

The Role of the Investigative Report

The investigative report is the official artifact that captures the who, what, when, where, why, and how of an inquiry. In many cases, the report becomes part of the audit trail reviewed by internal and external regulators.

A typical report lifecycle includes several stages—drafting, legal review, management approval, dissemination, and closure. During drafting, investigators must balance thoroughness with clarity. Legal counsel often reviews the document for privilege, tone, and factual accuracy, ensuring it aligns with both organizational policy and legal expectations. Once finalized, reports are stored in secure repositories, contributing to the organization’s compliance data archive.

Collaboration between departments is necessary. Compliance, Risk Management, Human Resources, and Legal must work together. The OIG’s 2024 Compliance Program Effectiveness Resource Guide notes that interdisciplinary collaboration ensures findings are contextualized, recommendations are actionable, and accountability is shared. Reports that integrate multiple perspectives are more defensible and effective.

Key Elements of a Defensible Investigative Report

1.  Clear Purpose and Scope

Every investigation should begin with a clearly defined purpose and scope. This section establishes the reason for the inquiry, outlines the questions to be answered, and defines the parameters of review. The scope should specify dates, departments, and records included. Ambiguity in this section can lead to confusion or accusations of overreach.

2.  Accurate Summary of Allegations

The summary should precisely capture the complaint or triggering event. Avoid loaded language or assumptions of intent. The investigator should record who made the allegation, what was alleged, and how the issue was reported, whether through a hotline, audit, or direct disclosure. The summary sets the foundation for factual neutrality.

3.  Methodology and Data Sources

Transparency in how evidence was collected and reviewed is vital for credibility. A strong methodology section identifies interviews conducted, documents examined, and systems accessed. According to Deloitte’s 2024 Internal Investigations Report, transparency in data collection fosters confidence among regulators and leadership.

4.  Chronological Narrative of Events

A chronological approach provides structure and logic. The Government Accountability Office’s (GAO) 2023 Fraud Risk Framework recommends organizing findings in sequence to demonstrate due diligence. Timelines clarify causation, highlight delays, and show that each step followed procedural fairness.

5.  Presentation of Evidence

Evidence must be presented clearly and factually. Data tables, summaries, and appendices can help. Use neutral phrasing such as “the documentation indicates” or “records show.” Avoid speculation or conclusions not supported by evidence.

6.  Analysis and Interpretation

This section bridges fact and meaning. Investigators should explain how findings relate to policies, procedures, or laws. The Association of Certified Fraud Examiners (ACFE, 2024) advises separating analysis from fact statements to maintain objectivity.

7.  Conclusions and Recommendations

A defensible conclusion synthesizes validated evidence and identifies corrective actions. Recommendations should be measurable and achievable, such as policy revisions, training, or audits. Avoid subjective commentary—focus on remediation, not blame.

8.  Documentation and Appendices

Supporting documentation should be referenced systematically. Attachments should include interview notes, data extracts, or relevant policies. Appendices demonstrate transparency and provide traceability for external reviewers.

Analytical Techniques for Investigative Reporting

Modern investigations increasingly rely on data analytics to support conclusions. According to PricewaterhouseCoopers (PwC’s) 2024 study on compliance analytics, quantitative analysis can identify outliers, correlations, and anomalies that qualitative methods may overlook. Tools such as data visualization dashboards, trend charts, and heat maps can make complex findings accessible to leadership and regulators.  For example, an investigator might analyze billing records to identify patterns of upcoding or duplicate claims. By visualizing data trends over time, the investigator can present evidence more persuasively.

The American Institute of Healthcare Compliance curriculum teaches participants how to interpret financial and operational data, integrating forensic accounting with compliance interpretation. The analytical phase also includes peer review and quality assurance.

According to the Society of Corporate Compliance and Ethics (SCCE, 2024), peer review provides an additional safeguard against bias or oversight. It ensures consistency across investigations and maintains trust in the process.

A Real-World Example: The Case of NorthView Behavioral Health

In 2024, NorthView Behavioral Health conducted an internal investigation after a report alleged improper overtime coding by nursing supervisors. The trained investigator used data analytics to compare scheduled shifts with payroll records, revealing discrepancies across three departments.

  • Interview transcripts and electronic timecard reviews confirmed manual overrides without documentation.
  • The investigator followed American Institute of Healthcare Compliance reporting principles, organizing the findings chronologically and using data tables to illustrate patterns of discrepancy.
  • The final report avoided subjective conclusions, instead focusing on systemic control gaps.

NorthView’s leadership responded by implementing automated shift validation, strengthening oversight protocols, and scheduling quarterly forensic audits. Because the report was objective, transparent, and data-driven, the organization self-disclosed to state regulators and avoided civil penalties. This case demonstrates how defensible reporting can convert a compliance issue into a model of organizational integrity.

Ethics, Language, and Professional Judgment

The ethics of reporting extend beyond accuracy to encompass tone and fairness. Investigators must avoid language that implies guilt or bias. According to the OIG’s 2023 Compliance Guidance, neutral phrasing and avoidance of adjectives that imply motive are essential to credibility. Investigative writing should mirror the impartiality of a court transcript, focusing on fact patterns rather than assumptions.

Professional judgment also plays a role in deciding what to include or omit. Transparency must be balanced with confidentiality and privilege. Collaboration with legal counsel helps determine which sections of a report may be privileged and how to handle sensitive information.

Turning Findings into Action

A defensible report achieves its true value only when findings lead to action. Compliance officers should ensure that recommendations translate into corrective and preventive actions (CAPAs). These may include revising policies, retraining employees, or enhancing data monitoring systems. The OIG (2024) recommends that compliance programs document each corrective action and assess its effectiveness through follow-up audits.

Action plans should be SMART—Specific, Measurable, Achievable, Relevant, and time-bound.

For example, if an investigation reveals inconsistent documentation practices, the CAPA may include targeted documentation training within 60 days and follow-up reviews within 90 days. By tying findings to measurable outcomes, organizations demonstrate accountability and compliance maturity.

Feedback loops are also critical. According to the GAO’s 2023 framework, integrating lessons learned into annual compliance reviews prevents recurrence of systemic issues. Trained investigators are equipped to design these loops, bridging the gap between investigative insight and continuous improvement.

Conclusion

The quality of an investigative report defines the credibility of the entire investigation. It is both a record and a reflection of an organization’s ethics. A defensible report is factual, impartial, and actionable, attributes that align with the standards set forth by OIG, Department of Justice (DOJ), and other oversight agencies. When written properly, the investigative report becomes a tool for learning rather than liability.

Certified Internal Forensic Healthcare Auditor-trained professionals are uniquely positioned to produce such reports. By combining forensic insight, analytical precision, and ethical clarity, they help organizations move from compliance response to proactive risk management. In a healthcare environment where accountability is paramount, the ability to write an objective, defensible report is both a compliance requirement and a professional hallmark of excellence.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • American Institute of Healthcare Compliance – 2025 Certified Internal Forensic Healthcare Auditor curriculum.
  • Office of Inspector General (OIG). (2023). General Compliance Program Guidance.
  • Office of Inspector General (OIG). (2024). Compliance Program Effectiveness Resource Guide.
  • U.S. Department of Justice (DOJ). Evaluation of Corporate Compliance Programs.
  • Association of Certified Fraud Examiners (ACFE). (2024). Report to the Nations on Occupational Fraud and Abuse.
  • Government Accountability Office (GAO). (2023). Fraud Risk Management Framework.
  • Deloitte. (2024). Internal Investigations and Reporting Trends in Healthcare.
  • PwC. (2024). Effective Documentation in Corporate Investigations.
  • Society of Corporate Compliance and Ethics (SCCE). (2024). Peer Review in Compliance Investigations.
  • Journal of Health Care Compliance. (2023). Ethics and Documentation Standards in Healthcare Audits.
  • Harvard Business Review. (2023). Transparency and Accountability in Organizational Reporting.
  • U.S. Department of Health and Human Services (HHS). (2024). Health Care Fraud and Abuse Control Program Annual Report.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Understanding Whistleblower Protections in Healthcare

Legal Obligations and Compliance Implications  


Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

The government’s new whistleblower complaint portal launched in April 2025 emphasizes the importance of complying with regulations related to qui tam suits, OCR investigations and protecting the rights of employees submitting a tip or complaint internally or to authorities. This article illustrates how certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation.

Introduction

Healthcare compliance professionals are often the first line of defense when systems break down. Understanding the interplay between legal protections and organizational ethics is vital—not only to ensure legal compliance, but also to foster environments where staff feel empowered and safe to report misconduct.

Whistleblowers are critical to protecting the integrity of healthcare delivery. When individuals report unsafe care, fraudulent billing, privacy violations, or ethical concerns, they help ensure accountability, uphold regulatory compliance, and safeguard patient welfare. For compliance professionals—particularly those working in environments regulated by Medicare, Medicaid, HIPAA, and federal contracts—it is essential to understand the scope and implications of whistleblower protections under current U.S. law.

This article explores the legal framework that underpins whistleblower protections, including the False Claims Act (FCA), HIPAA Privacy Rule exceptions, and National Defense Authorization Act (NDAA) provisions. It also highlights recent federal developments and compliance best practices to foster a culture of transparency and non-retaliation.

The False Claims Act and Qui Tam Provisions

For compliance departments, the implications of Qui Tam lawsuits extend far beyond financial penalties. They can lead to reputational harm, loss of patient trust, and stricter regulatory scrutiny. Therefore, proactive compliance programs must include regular audits, anonymous reporting options, and a culture that encourages early identification of potential violations.

The False Claims Act (31 U.S.C. §§ 3729–3733) is the federal government’s primary tool for combating fraud against public programs. Healthcare fraud accounts for a significant portion of FCA activity. Under its Qui Tam provision, private citizens—known as “relators”—can file lawsuits on behalf of the government when they have direct knowledge of fraudulent activities, such as billing for services not rendered or providing substandard care reimbursed by federal programs.

When the Department of Justice (DOJ) intervenes in these cases, whistleblowers may receive 15%–30% of recovered funds as a reward. In 2023 alone, the DOJ recovered over $1.8 billion from healthcare-related FCA cases, with whistleblower suits representing the vast majority of those recoveries.

Importantly, the FCA also prohibits retaliation. Section 3730(h) protects whistleblowers from termination, demotion, suspension, or harassment due to lawful acts in furtherance of a Qui Tam action or efforts to stop violations of the FCA.

HIPAA and Whistleblower Disclosures

Healthcare entities must train their workforce on the specific conditions under which PHI disclosures are permissible. Internal policies should not only comply with HIPAA but clarify what constitutes a 'good faith belief' and ensure disclosures are directed to appropriate oversight entities.

While the Health Insurance Portability and Accountability Act (HIPAA) is typically associated with patient privacy, it also contains important exceptions that protect whistleblowers. Under 45 CFR § 164.502(j), a workforce member may disclose protected health information (PHI) if:

  1. They believe in good faith that the covered entity has engaged in conduct that is unlawful or otherwise violates clinical standards; and
  2. The disclosure is made to a healthcare oversight agency, public health authority, law enforcement agency, attorney, or accreditation organization.

This clause is critical for compliance officers to understand, especially when investigating disclosures involving PHI. Any internal policy must clearly explain the scope of permissible disclosures and educate staff on when HIPAA permits these exceptions.

NDAA Protections and the Role of Contractors

The National Defense Authorization Act (NDAA) of 2013 (41 U.S.C. § 4712) expanded whistleblower protections to employees of federal contractors, grantees, and subcontractors, which includes many healthcare providers receiving federal funds. Under this statute, employees are protected from reprisal for reporting gross mismanagement, fraud, abuse of authority, or dangers to public health and safety.

Notably, these protections apply even if the employee discloses information outside of the organization, including to Congress, an Inspector General, or a federal employee responsible for contract oversight.

Compliance officers working with contractors should incorporate NDAA requirements into onboarding and ethics training materials. Additionally, contract language should affirm non-retaliation protections and clarify processes for raising concerns externally.

Recent Developments: HHS Whistleblower Portal and Enforcement

On April 14, 2025, the U.S. Department of Health and Human Services (HHS) launched a new whistleblower complaint portal specifically designed to receive reports of potential harm to children, including medically controversial treatments involving minors.

This new government portal signals increased federal oversight in how healthcare institutions respond to ethical and religious concerns raised by employees and demonstrates the government’s increased commitment to ensuring that providers and institutions uphold safety, informed consent, and respect for medical ethics.

This tool may also be used to identify systemic gaps in institutional policies around consent, safety, and staff protections.

In a notable case publicized by HHS, a hospital faced sanctions for terminating a nurse who refused to participate in a pediatric procedure due to her religious beliefs. HHS concluded that the hospital violated federal conscience protections, highlighting the intersection of whistleblower law, employment rights, and provider conscience protections.

Such scenarios highlight the importance of thorough documentation and timely response by compliance departments. Independent reviews of whistleblower complaints, performed by third-party investigators or ombudspersons, can enhance transparency and fairness in case handling.

Consider a hypothetical but realistic scenario

  • A behavioral health technician reports unsafe restraint practices involving minors in a residential facility.
  • Shortly after filing the internal report, the technician is placed on administrative leave and subsequently terminated.
  • The technician files a complaint under both the FCA and state labor law.
  • The investigation reveals that internal reports were not documented properly, retaliation safeguards were not in place, and training on non-retaliation was outdated.

This case underscores the need for compliance programs to ensure proactive risk mitigation, thorough documentation, and a robust culture of safety and transparency.

The Compliance Officer’s Role: Promoting a Speak-Up Culture

Organizations should periodically evaluate the effectiveness of their whistleblower protection efforts through anonymous staff surveys, incident response audits, and tracking the outcomes of reported concerns. This proactive approach signals to staff that leadership values integrity and transparency.

Certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation. Organizations must go beyond policy documents and invest in cultural and procedural safeguards:

- Establish and communicate clear non-retaliation policies.
- Train all employees and leadership on reporting rights and retaliation indicators.
- Maintain multiple confidential channels for reporting concerns.
- Ensure prompt and fair investigation of all complaints.
- Audit for compliance with whistleblower protection policies.

Conclusion

Ultimately, the goal of any whistleblower protection program is not merely compliance, but the cultivation of an ethical culture that consistently does what is right—even when it is inconvenient or uncomfortable. This requires leadership buy-in, staff empowerment, and a long-term commitment to transparency.

Whistleblower protections are more than legal requirements—they are pillars of ethical healthcare. Laws like the FCA, HIPAA, and NDAA empower individuals to report wrongdoing without fear. Compliance professionals must champion these safeguards, not only to avoid legal liability but to protect patient welfare, support employee integrity, and sustain organizational trust.

As regulatory enforcement intensifies and new federal protections emerge, healthcare organizations must remain vigilant, proactive, and transparent. The call to protect whistleblowers is not just a mandate—it is a moral and professional imperative.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance.  Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • U.S. Department of Health and Human Services (HHS). (2025). New Whistleblower Guidance and Complaint Portal. Retrieved from https://www.hhs.gov/protect-kids
  • 31 U.S.C. §§ 3729–3733, False Claims Act (FCA).
  • 31 U.S.C. § 3730(h), Anti-Retaliation Protections under the FCA.
  • 45 CFR § 164.502(j), Whistleblower Disclosures under the HIPAA Privacy Rule.
  • National Defense Authorization Act (NDAA) of 2013, 41 U.S.C. § 4712.
  • Office for Civil Rights (OCR), HHS. (2025). Press release on hospital investigation, April 14, 2025.
  • American Institute of Healthcare Compliance (AIHC). (2025). Newsblast: New Whistleblower Complaint Portal.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
General Compliance

The Legal and Ethical Imperative of Explicit Consent in Intimate Medical Procedures

Written by: Shelby Harriel-Hidlebaugh,  M.Ed. and BA  

The medical setting is expected to be a sanctuary of dignity and autonomy. However, sensitive exams and other intimate tasks conducted without consent can leave patients feeling violated. Informed consent is a cornerstone of ethical medical practice. It establishes a foundation of trust between patients and healthcare providers and protects patients’ autonomy over their own bodies. However, intimate medical exams and tasks performed without explicit consent continue to undermine these principles.

 
In order to address concerns about these unauthorized practices, an increasing number of states have passed laws protecting the bodily autonomy of patients. Additionally, the Centers for Medicare & Medicaid Services released revisions and clarifications to the Hospital Interpretive Guidelines for Informed Consent simultaneously with a letter by the Department of Health and Human Services to address medical professionals performing non-consensual intimate exams, particularly on patients under anesthesia.[1] Yet, as bioethicists and others have illustrated, these directives and laws are inadequate.[2]

 
To illustrate this point, a recent study published in October 2024 involving nearly 300 osteopathic medical students, 93.1% of them indicated that they were unaware of whether their state even has statutes regarding explicit consent for performing pelvic exams on anesthetized patients. Approximately 83.5% considered performing a non-consensual pelvic exam under anesthesia akin to sexual assault. Yet, out of those who acknowledged that they had performed pelvic exams, 74% of them either admitted that they did so without explicit consent or declined to answer the question. And this coming after 99.9% of them expressed a correct understanding of what constitutes informed consent.[3]

 
State statutes and institutional policies fail in fully protecting bodily privacy and rights for all patients in medical settings. While unauthorized sensitive exams have been garnering an increasing amount of attention from the media, legislators, bioethicists, and the medical community, far less focus has been placed on tasks such as urinary catheter insertions, gown and underwear removal, groin sanitization, pubic hair removal and other such intimately invasive functions conducted during prep for non-intimate elective surgical procedures.[4] These intimate encounters can result in the same psychological harm caused by non-consensual sensitive exams.[5]  And given that these tasks are performed under anesthesia and without prior disclosure, they raise significant ethical, legal, and institutional concerns. The reliance on patient incapacitation to perform such tasks does not absolve medical professionals of their ethical and legal responsibilities.


This article explores the legal framework surrounding these practices, emphasizing case law, Federal law, and institutional policies while calling for systemic reform to secure equal protection for all patients from all unwanted and non-consensual intimate encounters before, during, and after elective medical procedures. 


Relevant Case Law: Protecting Bodily Privacy


Foundations of Bodily Privacy
According to the American Medical Association’s (AMA) code of ethics, physical privacy is one aspect of patient privacy that medical personnel must protect in all settings as “an expression of respect for patient autonomy and a prerequisite of trust.”[6]


Bodily privacy extends beyond the focus of medical associations and institutions. It is also a fundamental legal principle upheld by multiple judicial rulings. In York v. Story (9th Circuit Court), the court emphasized that the right to privacy over one’s naked body is integral to self-respect and dignity. The decision underscored that any unauthorized exposure or intrusion violates an individual’s constitutional protections.[7]

 
The right to bodily privacy extends into medical settings, as established in Local 567 American Fed. v. Michigan Council 25 (E.D. Mich. 1986). Here, the court affirmed that hospitalization does not negate a person’s right to bodily privacy when it noted that, “It would be a strange doctrine … that would decree that the sanctity of the right of privacy…fully respected in a public restroom, is forfeited by the fact of falling ill and becoming hospitalized.” It further stated that privacy violation—whether by a healthcare provider or another individual—remains significant regardless of gender.[8]

In Backus v. Baptist Medical Center, the court upheld a hospital’s decision to prevent male nurses from being assigned to labor and delivery units. The ruling recognized that intimately invasive tasks such as intimate hair removal performed by unselected individuals could violate patients’ constitutional right to privacy. The judgment further affirmed that such violations are not mitigated by the healthcare professional’s intent or qualifications, placing the patient’s perception, comfort, autonomy, and well-being at the forefront.[9]


Institutional and Judicial Recognition of Psychological Harm in Medical Settings
The Federation of State Medical Boards (FSMB) defines patient harm as “inclusive of physical and emotional harm, resulting distrust in the medical system and avoidance of future medical treatment, and other related effects of trauma.”[10] Further, the National Council of State Boards of Nursing (NCSBN) states that “Sexual boundary violations result in significant and enduring harm to patients.”[11]


Courts have also acknowledged the psychological harm that results from unauthorized intimate medical contact. The ruling in Backus v. Baptist Medical Center highlighted the emotional and psychological toll of privacy violations, underscoring the need for healthcare providers to prioritize patients’ perceptions of dignity and autonomy over institutional convenience or routine practices.[12]


The potential to inflict lifelong psychological harm underscores the importance of consent.


Consent

Standards of Consent
Federal law provides a clear framework for understanding consent as a "freely given agreement to the conduct at issue by a competent person." Importantly, it stipulates that unconscious, incapacitated, or unaware individuals cannot provide valid consent.[13]  Beyond Federal law, state laws and Title IX policies that govern teaching hospitals at associated universities address consent. For example, the University of Iowa’s sexual misconduct policy defines consent as “knowing, voluntary, and clear permission by word or unambiguous action.” This provides a straightforward definition of consent as it applies specifically to intimate areas of the body defined by the policy as “breasts, buttock, groin, or genitals.”[14] The failure to secure explicit consent for intimate tasks—such as gown or underwear removal, pubic hair removal, groin sanitization, or urinary catheterization—contradicts these policies, placing patients at risk of harm and retraumatization.

Implied Consent – A Flawed Justification
Healthcare providers often justify failing to disclose intimate medical tasks by invoking the concept of implied consent, assuming that patients understand and agree to all preparatory procedures associated with a surgery or treatment. However, the invasiveness of manipulating private body parts not directly involved in the procedure renders it unique to the intrusiveness of general procedure. Thus, the implied consent approach undermines the ethical principle of informed consent by creating a significant gap in the important communication process. Patients cannot consent to procedures they are unaware of, and withholding information about intimate tasks denies them the opportunity to make an informed decision with regards to access of their private areas. Without such agreement, intimate functions performed prior to, during, or after non-intimate, elective procedures would theoretically constitute unauthorized and offensive touching regardless of their medical necessity. Legal and institutional definitions of consent for sexual contact directly challenges the medical practice of relying on implied consent for intimate tasks performed without explicit patient knowledge.

 
While the medical community asserts that it is their professional duty to safeguard their patients’ dignity and bodily privacy, assuming that patients have implicitly consented to intimate preparatory tasks for a non-intimate procedure not only denies them the right refuse treatment but also to safeguard their bodily sanctity themselves while simultaneously forcing patients to adhere to the provider’s concept of dignity, rather than allowing patients to assert their own values. Ultimately, when medical personnel subject patients to intimate procedures and tasks to which they have not truly consented, they deny the autonomy and humanity of their patients, which is a core ethical principle of the medical profession.

 
The principle is clear: patients must be fully informed and explicitly agree to visual or physical access of the private areas of their bodies outside a medical emergency.

Sexual Misconduct Concerns and Intimate Procedures and Tasks

The absence of explicit consent for intimate medical tasks parallels behaviors classified as sexual misconduct in other contexts. Under Federal law, non-consensual sexual contact—including contact with genitals, breasts, or other intimate areas—either directly or through clothing is classified as sexual misconduct.[15]

 
State law and universities model their statutes and policies after sexual misconduct Federal laws. So, too, do medical organizations and associations who also address sexual boundary violations. For example, the NCSBN notes that “Clear sexual boundaries are crucial to patient safety” and specifically classifies “Removing a patient’s … clothing, gown or draping without consent, [or] emergent medical necessity” as sexual misconduct.[16] The FSMB bans physical intimate contact “without…explanation of its necessity, and without obtaining informed consent.”[17]

 
FSNB and NCSBN policies also state that sexual misconduct includes behavior that “can have the effect of embarrassing, shaming, humiliating or demeaning the patient.”[18]


Accommodating Vulnerable Populations

Americans with Disabilities Act (ADA)
The ADA extends additional protections to individuals with PTSD and other disabilities, requiring accommodations to prevent retraumatization.[19]  Medical tasks and procedures involving intimate areas without explicit consent can exacerbate psychological harm, particularly for individuals with histories of sexual trauma. Providers – including universities overseeing associated hospitals – who fail to obtain explicit consent for such actions as intimate preparatory tasks denies these patients the opportunity to assert their boundaries, further marginalizing their needs. Thus, they inadvertently violate these legal protections. Comprehensive consent policies that prioritize patient awareness and agreement are essential to fulfilling these obligations.

Recommendations for Reform

Legislative Action

1.  Mandating Explicit Consent

  • Federal and state governments should enact laws requiring explicit consent for all intimate medical tasks, including preparatory steps like gown removal, pubic hair clipping, groin sanitation, urinary catheter insertion and other such procedures.
  • These laws should mandate detailed discussions of these tasks during the informed consent process and require written documentation of patient agreement.

2.  Enforcing Accountability

  • Oversight mechanisms should be strengthened to ensure compliance with consent standards. Medical boards, institutions, facilities, and universities must be held accountable for violations, with penalties such as fines, suspensions, or revocation of licenses.

Institutional Reforms

1.  Revamping Consent Practices

  • Universities and hospitals should revise their informed consent processes to include detailed explanations of intimate preparatory tasks. Patients must be informed of all key aspects of their care and given the opportunity to agree or refuse.

2.  Promoting Transparency in Medical Education

  • Teaching hospitals must disclose the involvement of medical students or residents in procedures – especially those of an intimate nature – and secure explicit patient consent. Transparency is critical to maintaining trust and ethical standards in medical training.

Cultural and Ethical Shift

1.  Prioritizing Patient Autonomy

  • The medical community must prioritize patients’ perceptions of dignity and autonomy, recognizing that intimate medical tasks are not trivial to those being treated.

2. Educating Providers

  • Training programs should emphasize the importance of explicit consent and the ethical implications of intimate medical tasks. Providers must understand the psychological and legal consequences of failing to secure patient agreement

Conclusion

Given the fact that Federal and state law acknowledges and protects the special status attached to individuals’ intimate spaces, medical professionals should comply with these regulations because “patients do not think of their intimate regions in a detached or neutral way.”[20] Case law, Federal law, medical associations, and university and institutional policies converge on the necessity of respecting bodily autonomy and securing explicit consent for medical procedures. Despite these established frameworks, systemic failures in enforcement and the reliance on implied consent perpetuate harmful practices that violate patient rights and erode trust in healthcare institutions. Legislative reforms, institutional accountability, and a cultural shift toward prioritizing the patient’s– rather than the provider’s – notion of dignity are essential to restoring trust, preventing harm, and aligning medical practices with ethical and legal standards.

About the Author

Shelby Harriel-Hidlebaugh has an M.Ed. and BA from the University of Southern Mississippi.  She is a mathematics instructor at Pearl River Community College.  She has a published article on this topic in Voices in Bioethics, November 2023. https://journals.library.columbia.edu/index.php/bioethics/article/view/11927

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved 


[1] CMS Revisions and Clarifications to Hospital Interpretive Guidelines for Informed Consent. April 1, 2024. Retrieved from https://www.cms.gov/files/document/qso-24-10-hospitals.pdf; HHS Letter to the nation’s teaching hospitals and medical schools. April 1, 2024. https://www.hhs.gov/about/news/2024/04/01/letter-to-the-nations-teaching-hospitals-and-medical-schools.html

[2] Neff G. Comply with Privacy Rights to Avoid Unconsented Intimate Exams. American Institute of Healthcare Compliance. November 12, 2024. https://dev-main.aihc-assn.org/comply-with-privacy-rights-to-avoid-unconsented-intimate-exams/; Bruce L. A Pot Ignored Boils On: Sustained Calls for Explicit Consent of Intimate Medical Exams. HEC Forum. 2020 Jun;32(2):125-145. doi: 10.1007/s10730-020-09399-4. PMID: 32152870; PMCID: PMC7223770; Friesen P, Wilson RF, Kim S, Goedken J. Consent for Intimate Exams on Unconscious Patients: Sharpening Legislative Efforts. Hastings Cent Rep. 2022 Jan;52(1):28-31. doi: 10.1002/hast.1337. PMID: 35143067

[3] Rachel Cutting, Varsha Reddy, Sneha Polam, Nicole Neiman, and David Manna (2024). Prevalence of pelvic examinations on anesthetized patients without informed consent. Journal of Osteopathic Medicine. DOI: https://doi.org/10.1515/jom-2024-0058

[4] Harriel - Hidlebaugh, S. (2023). Not Just Non-Consensual Pelvic Exams: The Need for Expressed Consent for All Intimate Tasks for Elective Procedures. Voices in Bioethics, 9. https://doi.org/10.52214/vib.v9i.11927

[5] For patient narratives of bodily privacy violations and their effects, see Medical Patient Modesty, www.patientmodesty.org/modesty.aspx

[6] American Medical Association, “Privacy in Health Care,” Chapter 3.1.1; https://code-medical-ethics.ama-assn.org/ethics-opinions/privacy-health-care

[7] York v. Story, https://casetext.com/case/york-v-story

[8] Local 567 American Fed. v. Michigan Council 25, 635 F. Supp. 1010 (E.D. Mich. 1986). https://law.justia.com/cases/federal/district-courts/FSupp/635/1010/1438741/

[9] Backus v. Baptist Medical Ct., https://casetext.com/case/backus-v-baptist-medical-ctr

[10] Federation of State Medical Boards, “Physician Sexual Misconduct”

[11] National Council of State Boards of Nursing, “Practical Guidelines for Boards of Nursing on Sexual Misconduct Cases,”https://ncsbn.org/public-files/Sexual_Misconduct_Book_web.pdf

[12] Backus v. Baptist Medical Ct., https://casetext.com/case/backus-v-baptist-medical-ctr

[13] https://www.law.cornell.edu/uscode/text/10/920

[14] https://opsmanual.uiowa.edu/community-policies/sexual-harassment-and-sexual-misconduct/prohibited-conduct

[15] Department of Justice, https://uscode.house.gov/view.xhtml?req=(title:18%20section:2246%20edition:prelim)

[16] National Council of State Boards of Nursing, “Practical Guidelines for Boards of Nursing on Sexual Misconduct Cases,” https://ncsbn.org/public-files/Sexual_Misconduct_Book_web.pdf

[17] Federation of State Medical Board, “Physician Sexual Misconduct,” https://www.fsmb.org/siteassets/advocacy/policies/report-of-workgroup-on-sexual-misconduct-adopted-version.pdf

[18] Federation of State Medical Boards, “Physician Sexual Misconduct”; the NCSBN uses very similar language stating that sexual misconduct includes “contact which may reasonably be interpreted as demeaning, humiliating, embarrassing, threatening, or harming a patient.”

[19]  Introduction to the Americans with Disabilities Act, https://www.ada.gov/topics/intro-to-ada/

[20] Bruce L. “A Pot Ignored Boils On”

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Part 3:  AI & Risk to Empathy, Compassion and Trust in Healthcare

Impact of Artificial Intelligence (AI) on Patient-Centered Care


Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article follows Part 1 - Basics of Artificial Intelligence (AI) and Healthcare Compliance published by AIHC on June 6, 2023 and Part 2 – Who Regulates Healthcare AI?.  AI is advancing rapidly, so we encourage you to reference the new Artificial Intelligence article category for the latest published by AIHC.  The COVID pandemic has proven that patients like telehealth and means other than face-to-face encounters for routine health needs.  But can AI replace the empathy, compassion and trust instilled during a personal encounter with a health care professional?  This article explores recent research on the topic of AI and patient-centered outcomes research.


As AI is integrated into patient care and medical coding, billing and accounts receivable management, will we risk the human connection of empathy and compassion which builds trust in the physician-patient relationship?  I embarked on a short research project to explore this topic and share my findings with AIHC members and affiliates.


Empathy, compassion and trust are fundamental values of a patient-centered, relational model of health care.  As Artificial Intelligence (AI) is advancing the delivery of health care and improving the diagnosis and treatment of our patients, is this promising technology providing greater efficiency and more free time for health-care professionals to focus on the human side of care, including fostering trust relationships and engaging with patients with empathy and compassion?  Or is it freeing time to see more patients to increase the revenue stream?


A June 2023 abstract was posted to the National Institutes of Health (NIH) National Library of Medicine, entitled “Artificial Intelligence in Health: Enhancing a Return to Patient-Centered Communication.”  The authors emphasize concerns around AI in the delivery of health care; concerns related to ethics, privacy, data representation and the potential of eliminating physicians. 


The article states “However, AI cannot replicate a physician's knowledge and understanding of the patient as a person and the conditions in which he or she lives. Therefore, provider-patient communication will be paramount in providing safe and effective health care.”


In April 2023, the NIH posted “The impact of artificial intelligence on the person-centered, doctor-patient relationship: some problems and solutions”.  The authors agree AI is a solution to freeing up of time for doctors and facilitating person-centered doctor-patient relationships. However, “… there is very little concrete evidence on their impact on the doctor-patient relationship or on how to ensure that they are implemented in a way which is beneficial for person-centered care.” 

  • Patient-centered outcomes research (PCOR) compares the impact of two or more preventive, diagnostic, treatment, or health care delivery approaches on health outcomes, including those that are meaningful to patients. 

In light of the given the importance of empathy and compassion in the practice of person-centered care, they conducted a literature review and found that besides empathy and compassion, shared decision-making, and trust relationships emerged as key values.


Using AI tools can have a positive impact on person-centered doctor-patient relationships, according to the article, when:

  1. using AI tools in an assistive role; and
  2. adapting medical education.

“Artificial intelligence and the doctor-patient relationship expanding the paradigm of shared decision making” is a June 2023 NIH article emphasizes how AI based clinical decision support systems (CDSS) are rapidly becoming more prevalent in healthcare, playing an important role in diagnostic and treatment processes. For this reason, AI-based CDSS has an impact on the doctor-patient relationship, shaping their decisions with its suggestions.


The article poses that we may be on the verge of a paradigm shift, where the doctor-patient relationship is no longer a dual relationship, but a triad. AI implementations may instead foster the inappropriate paradigm of paternalism. Understanding how AI relates to doctors and influences doctor-patient communication is essential to promote more ethical medical practice. Both doctors' and patients' autonomy need to be considered in the light of AI.


A successful AI case related to patient-centered outcomes was located on HealthIT.gov, the website for the Office of the National Coordinator for Health Information Technology (ONC).   ONC completed a project in September 2021 “Training Data for Machine Learning to Enhance Patient-Centered Outcomes Research Data Infrastructure.” 


Through this project, ONC in partnership with NIH and the National Institute of Diabetes and Digestive and Kidney Diseases (NIDDK), advanced the application of AI/ML in patient-centered outcomes research (PCOR) by generating high quality training datasets for a chronic kidney disease (CKD) use case – predicting mortality within the first 90 days of dialysis. This case was selected because mortality in the first 90 days of dialysis initiation in ESKD/ESRD patients remains notably high and included joint clinician-patient informed decision making. PCOR researchers can build off the foundational work completed through this project and extend the application of these methods to a wider array of use cases and advance the application of ML to enhance PCOR infrastructure.


Conclusion


Working in health care requires adapting to constant change as technology and software advancements force not only providers, but IT professionals and health care administrators to stay ahead of what is coming.


It is important to be fiscally responsible, however, do we want to live in a world where we can only speak to a machine regarding questions about our medical bills, or discuss our concerns regarding a treatment plan?  Where is the humanity in that?


We must move forward with integrating AI into our lives.  But, moving forward, it is important to re-evaluate whether and how empathy, compassion and trust could be incorporated and practiced within a health-care system where artificial intelligence is increasingly used. Most importantly, society needs to re-examine what kind of health care it ought to promote.


AIHC will continue to post articles related to artificial intelligence with regards to healthcare compliance.  Click Here for additional articles on various HIPAA topics.  Click Here for articles relating to Artificial Intelligence. Visit the AIHC Certifications page with online compliance learning opportunities.

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Provider Credentialing Verifies Expertise

Written by Angela Chorny, MA, President and CEO of Emerge and See, LLC




Payor Enrollment – An Understated and Overlooked Process


Oh, the all-important question of credentialing! Why do we need to be credentialed and what is it?

Credentialing is the anchor between billing and being PAID. It is one of the most important aspects to healthcare, AND, in many cases, it is REQUIRED!


So, what is credentialing? Credentialing is the process of verifying that a provider’s expertise and qualifications to render care to patients are real and valid, this process is also called Primary Source Verification, or PSV… simply stated.


Many facilities and groups who are accredited by an entity, such as JCAHO, AAAHC, AAAASF (just to name a few), are REQUIRED to complete this process for every provider who is rendering services within the group or facility, especially active, licensed, independent practitioners, or LIPs. The accreditation agency will provide their own list of requirements, but a group or facility may include additional requirements of their own in order to privilege a provider.


The buck doesn’t stop there, though, that’s only about half of the credentialing process. Payor enrollment is an understated and overlooked process. This is where the provider is enrolled into the health plans that they would like to accept from their patients. If the provider is not enrolled in the plan, you will not be able to bill for services rendered, ESPECIALLY with Medicare and Medicaid.


In addition, once the provider is enrolled with the payor/insurance health plan, they are added to the roster of available care in their area… built in marketing! When a patient calls and requests a list of providers that accept their health plan in the area requested, the enrolled provider and/or practice will be on that list provided to the potential new client.


So Why Is Credentialing So Important?


  1. Protecting Patients and Ethics.

    Credentialing is undertaken to determine whether a practice or healthcare professional is fully qualified to treat patients. Patient care has always been the core purpose of medical credentialing. The process itself is rather tedious and involves verifying a practitioner’s credentials against various relevant data points.

    For instance, a provider is continuously monitored against major publications like the Death Master File, Sex Offender Registries, National Abuse Registry, OFAC, and many other sources. A provider can be denied credentialing if their name shows up in any of the above data points.

    Credentialing also monitors sanctions on a provider’s license via the Office of Inspector General (OIG) as well as any possible lawsuits and their outcomes via the National Provider Data Bank, or NPDB. These tools have been put in place and are required to be utilized to help the practice make a determination as to whether the provider should be privileged or employed by the entity. Credentialing can also be denied based on a provider’s license having expired or having defaulted on their student loans.

    Credentialing instills confidence among patients and provides added comfort that the organization wants to provide professional and ethical services to a patient. For example, it would be nice to know that a particular provider in charge of providing treatment to a child is not a registered sex offender or that a psychologist has the qualifications necessary to provide you with sound advice.

    Competency and performance reviews are a fundamental part of the credentialing process. Organizations who implement this process leave no stone unturned in determining whether a practice or healthcare professional is worthy of being credentialed. As a result, patients can feel safe going for treatment to clinics and hospitals whose staff are all credentialed.
  2. Prevents Lost Revenue.

    Insurance carriers do not reimburse for services rendered if the provider and/or entity is not credentialed, or enrolled, with them. It is important to note here, that being enrolled with a payor and being “in network” are two different things. Once the provider is enrolled with the payor, services rendered may then be billed. Becoming “in network” means that the provider now has a contract with the payor and rates are set as per the agreement and cannot be negotiated until the agreement term has expired.

    Furthermore, it is illegal for the payor to reimburse anyone prior to having completed their own Primary Source Verification process. Therefore, at all times, a payor will advise you NOT to see their patients until the provider or organization is credentialed with them.

    Once enrolled with a payor, you are ready to bill for services rendered and will be reimbursed according to the agreed upon fee schedule. You just opened the door to an entirely new set of patients, thereby increasing your revenue!

    In addition, as previously mentioned, the provider will also be added to the roster and registry for patients who call in to request a particular type of provider in their area. So, the payor, is driving more patients through your door.
  3. Mitigate and manage risk.

    With the latest increase in lawsuits over lack of appropriate credentialing on behalf of an entity, it’s one of the most basic parts of your practice that you want to protect. As immunity began to lose ground as a viable legal argument, the 1957 case Bing v. Thunig firmly established that hospitals have an ethical responsibility for the medical care received by patients.

    A few years later, the 1965 case of Darling v Charleston Community Memorial Hospital—in which a staff provider so severely erred in the setting of a broken leg that it eventually had to be amputated—set the legal precedent that a hospital could be held negligent for failing to assess or monitor the competency of their medical staff.

    To limit liability in the aftermath of these cases, hospitals implemented more   rigorous credentialing and privileging protocols. Unfortunately, this led to another problem… Providers being denied appointment or privileges by a hospital’s governing body turned to the Sherman Act and state antitrust laws to claim that the practice of credentialing amounted to anti-competitive collusion. Providers claiming injury under the Sherman Act must demonstrate that the denial or revocation decision negatively impedes the availability of medical services within the community.

    Stuck between a rock and a hard spot of this legal minefield, hospital and medical staff leadership, in particular those assigned with peer review responsibilities, were reluctant to deny medical staff appointment or privileges. The Health Care Quality Improvement Act (HCQIA) of 1986 provided those physicians involved in peer review activities a layer of protection against lawsuits filed by the physician under review in retaliation for a negative decision by their peers. Improperly used, HCQIA can be seen as a shield inviting abuse by those in a peer review position for decisions that benefit themselves directly or indirectly. As a result, antitrust claims continue.

    Over the years, hospitals have recognized that strong and transparent credentialing and privileging processes provide the greatest guarantee of qualified and competent medical staff and the best defense against legal risks. CFR regulations (U.S. Code of Federal Regulations (CFR)  have, as a result, become the best standard for due diligence.

Know the Law


As healthcare credentialing becomes increasingly more important, be sure that you know your way around. Hospitals generally follow a basic credentialing and privileging framework established within the section of the U.S. Code of Federal Regulations (CFR) comprising the Public Health Service Act. However, these CFR Title 42 regulations (Conditions of Participation—CoPs) only specify credentialing and privileging requirements for hospitals to gain or maintain accreditation to participate in Medicare and Medicaid.


Even though Title 42 CoPs do not directly affect hospitals outside of Centers for Medicaid and Medicare Services (CMS) jurisdiction, they are still important to an unregulated health sector operating in a patchwork of federal, state, and civil legal landscape.


Create a Credentialing Process


Be clear on what you expect your providers to present to you for all background checks and scans as well as for payor enrollment purposes. That way, you will be able to streamline. Be sure to assign a person to the task. It can be a very tedious and time-consuming process, so it’s usually best if you have help that can handle all tracking of enrollment applications as well as any expirables that may be coming up.


Don’t miss the reappointment dates! If reappointment dates are missed you are back to square one in the credentialing process of payor enrollment, and if you miss any within your organization, you are no longer in compliance with your accrediting agency and neither is the provider!


If you choose to outsource, which is becoming exceedingly more popular now, be sure to choose a reputable organization. Many organizations are popping up nowadays, so it is definitely important that your Credentials Verification Processor (CVO) knows what they’re doing as regulations absolutely need to be followed.


About My Company


There are also enrollment companies and one stop shops available, such as Emerge and See, LLC where we handle the entire process for you. Emerge and See is based on a solid foundation of seasoned Credentialing Specialists. We become your full-service Credentialing Department while saving you an enormous amount of money on payroll. Please feel free to visit our website at www.emergeandsee.com, it would be our pleasure to be at your service!


As we say in the credentialing world… Happy Credentialing!

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Compliance & Internal Investigations

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




Are you an internal auditor conducting “routine” reviews? Have you ever uncovered erroneous or potentially fraudulent evidence? Once your suspicions have been reported to the Compliance Officer, were you asked to partake in evidence gathering during the investigation? The content of this article is for educational purposes and not intended as consulting or legal advice.


For those of you more experienced auditors, additional training in how to handle evidence during an internal investigation not only advances your career but helps secure evidence that can be used if an actual crime has been committed. I also recommend reading When Healthcare White-Collar Crimes Turn Red, an AIHC blog article from 2021.


Do you need to convince executives that crime is a potential problem for your organization? The Department of Justice (DOJ) posts “News & Noteworthy” cases here. 


What Comes to Mind When You Hear the Word “Forensic”?

 

Most of us think about investigations as seen on television programs, such as “CSI” or “Bones.” Forensic science is a critical element of the criminal justice system – “Forensic scientists examine and analyze evidence from crime scenes and elsewhere to develop objective findings that can assist in the investigation and prosecution of perpetrators of crime or absolve an innocent person from suspicion.”


According to the Merriam-Webster dictionary, the word forensic is defined as the following:

  • Belonging to, used in, or suitable to courts of judicature or to public discussion and debate
  • Relating to or dealing with the application of scientific knowledge to legal problems

Your auditing and compliance skills become valuable to professional law enforcement, but you need to know what, when and how to handle a situation which could potentially turn into criminal charges against someone within your organization. First, let’s start with prevention.


Is It an Internal or External Investigation?


Internal Investigations are conducted by skilled employees (or a consultant under contract working for the organization) trained to perform specialized audits to gather evidence when there is suspected fraud, abuse or crime. These investigations are typically conducted to gather information sufficient for legal counsel to determine whether an external investigation is warranted by the appropriate authorities.  These employees are often referred to as Internal Forensic Auditors or Internal Investigators. For the purpose of this course, we will refer to this position as an Internal Forensic Auditor.


Internal Forensic Auditors report to a Board of Directors, Compliance Officer and/or Audit Committee of the health care organization and typically work under the direction of the organization’s legal counsel.


External Forensic Auditors are independent of the organization they are auditing. They are experts working as an investigator for an accounting or consulting firm, CMS, a police department, the FBI or another agency as described above.


The process of conducting a forensic investigation is, in many ways, similar to the process of conducting an audit, but with some additional considerations. The various stages are briefly described below. 


Step 1: Accepting the Investigation


Review information regarding the matter and consider whether you (and your team) have the necessary skills and experience to accept the work.

  • Forensic investigations are specialized in nature, and the work requires detailed knowledge of fraud investigation techniques and the legal framework.
  • Investigators must also have received training in interview and interrogation techniques and in how to maintain the safe custody of evidence gathered.
  • Investigators must be able to address potential conflicts of interest or bias and achieve objectivity.

Step 2: Planning the Investigation


The investigating team must carefully consider what they have been asked to achieve and plan their work accordingly. The objectives of the investigation will include:

  • Recognize if there is sufficient evidence to warrant a forensic investigation. If so, then anticipate planning required to achieve the following:

      o Identify the type of fraud that has been operating, how long it has been operating for,
    and how the fraud has been concealed;

           Determine deadlines and timeframes to complete the investigation which may
    be driven by regulatory factors;

      o Identify the fraudster(s) involved;

      o Quantify the financial loss suffered by the organization;

      o Gather evidence for potential use in court proceedings;

           Identify the type of report format required and record evidence appropriately; and

      o Provide advice to prevent the reoccurrence of the fraud. 

The investigators should also consider the best way to gather evidence. They may choose the use of computer assisted audit techniques or other various methods appropriate for the situation.


Step 3:  Gathering Evidence – Fact Finding


In order to gather detailed evidence, the investigator must understand the specific type of fraud that is suspected. The evidence should be sufficient to ultimately prove the identity of the fraudster(s), the mechanics of the fraud scheme, and the amount of damage or loss suffered by the organization.


It is important that the investigating team is skilled in collecting evidence that can be used in a court case and in keeping a clear and secure chain of custody until the evidence is presented in court. If any evidence is inconclusive, or there are gaps in the chain of custody, then the evidence may be challenged in court or even become inadmissible. Investigators must be alert to documents being falsified, damaged or destroyed by the suspect(s). 


“Chain of custody” is defined by Dictionary.com as “the order in which a piece of criminal evidence should be handled by persons investigating a case, specifically, the unbroken trail of accountability that ensures the physical security of samples, data and records in a criminal investigation.” To prove the chain of custody, and ultimately show that the evidence has remained intact, prosecutors generally need internal investigators who can testify:

  • That the evidence offered in court is the same evidence they collected or received.
  • To the time and date the evidence was received or transferred to another provider.
  • That there was no tampering with the item while it was in custody.

Evidence can be gathered using various techniques, including: 

  • Testing controls to gather evidence which identifies the weaknesses which allowed the fraud to be perpetrated;
  • Using analytical procedures to compare trends over time or to provide comparatives between different segments of the business;
  • Applying computer assisted audit techniques which may help to identify the timing and location of relevant details being altered in the computer system;
  • Discussions and interviews with employees;
  • Substantive techniques such as: reconciliations, cash counts and reviews of documentation.

Step 4: Analyzing Data


After evidence and facts have been gathered and recorded, it is time to analyze all the data. The goal of data analysis is to determine if there is a relationship between the independent and dependent variables and to look for patterns within the data. 


Recording and organizing data may take different forms depending on the kind of information being collected. The way you collect your data should relate to how you’re planning to analyze and use it. Regardless of what method you decide to use, recording should be done concurrently with data collection if possible, or soon afterwards, so that nothing gets lost and memory doesn’t fade. Some of the things to do with the information collected can include:

  • Gather together information from all sources and observations;
  • Make photocopies of all recording forms, records, audio or video recordings, and any other collected materials to guard against loss, accidental erasure, or other problems;
  • Enter narratives, numbers, and other information into a computer program where they can be arranged and/or worked on in various ways;
  • Perform any mathematical or similar operations needed to get quantitative information ready for analysis;
      o These could include entering numerical observations into a chart, table, or spreadsheet, or figuring the mean (average), median (midpoint), and/or mode (most frequently occurring) of a set of numbers.
  • Transcribe (making an exact, word-for-word text version of) the contents of audio or video
    recordings;
  • Code data (translating data), particularly qualitative data that isn’t expressed in numbers, into a form that allows it to be processed by a specific software program or subjected to statistical analysis; and
  • Organize data in ways that make it easier to work with. This will depend on your research design and your evaluation questions.
      o Consider grouping observations by the dependent variable (indicator of success) they
    relate to, by individuals or groups of participants, by time, by activity, etc.
      o You might also want to group observations in several different ways so that you can study interactions among different variables. 

There are two kinds of data you’re apt to be working with. However, not all evaluations will necessarily include both.

  • Quantitative data refers to the information that is collected as, or can be translated into, numbers which can then be displayed and analyzed mathematically.
  • Qualitative data can be collected as descriptions, anecdotes, opinions, quotes, interpretations, etc. They are generally not able to be reduced to numbers and/or are considered more valuable or informative if left as narratives.

As you might expect, quantitative and qualitative information need to be analyzed differently. The investigation is likely to lead to legal proceedings against one or several suspects. Therefore, members of the investigative team must be comfortable with appearing in court to explain how the investigation was conducted and how the evidence was gathered.


Step 5: Report Your Findings


Draft the report in an objective manner. Do not draw conclusions, just report the facts. The checklist below summarizes what a typical report should contain:

  • Provide a Summary of the Investigation or Case
  • Describe the Investigation Plan
  • Case Notes – Keep an Investigator Diary
  • Information Interview Summaries
  • Interview Reports
  • Analysis of Investigation
  • Conclusion
  • Recommendations and Additional Action(s) Required With This Case
  • Exhibit Listing - attachments and evidence related to the case

Conclusion


An Ounce of Prevention Is Worth a Pound of Cure – So Learn More About Health Care Crime


A little precaution before a crisis occurs is preferable to a lot of legal complications, “bad press” and huge potential losses afterward. Preventing fraud in your organization starts with not hiring criminals! That might sound ridiculous, but are we really doing everything we should during the hiring phase of employees and contractors?


Most organizations are using the LEIE on the OIG website to screen new hires and conduct monthly verifications. But is this enough?


Unverified employees can put your organization at risk with a dramatic impact on your company’s brand reputation, performance and finances. Screening employees at hire, and periodically during employment, is a must for creating a safe workplace.


Below is a “short list” of screening tactics to consider before extending an offer to a candidate for hire. Be sure to review your procedure with legal counsel or a human resources expert to avoid any potential legal consequences with the U.S. Equal Employment Opportunity Commission (EEOC) related to changing your current hiring practices.

  • Criminal background check
  • Office of Inspector General (OIG) Exclusions Database check
  • Education – verify graduation, degree
  • Professional Certifications (check all certifications with the certifying agency – do not accept certificates from the potential employee as proof)

The EEOC has a webpage dedicated to help employers that addresses “Background Checks – What Employers Need to Know.” The information on this page is a joint publication between the EEOC and the Federal Trade Commission or FTC.


When making personnel decisions, which include hiring, retention, promotion, and reassignment, the EEOC states that employers should consider the background of applicants and employees. For example, the EEOC states you may want to consider verifying:

Except for certain restrictions related to medical and genetic information (per HIPAA, addressed further on the EEOC website), it's not illegal for an employer to ask questions about an applicant's or employee's background or to require a background check.


AIHC offers training – a “how to” participate in or conduct an internal investigation. The course is offered online with the option to certify (with a professional proctor online). The program is entitled Internal Forensic Auditor. If this course seems too intense, you may want to begin with the Auditing for Compliance online program.

Read More
HIPAA Compliance
HIPAA

How to Handle Passwords Like a Boss!

Written by: J. David Sims, CHITSP, CHMSP, Managing Partner at Security First IT, LLC; Board Member with the American Institute of Healthcare Compliance; Podcaster, Speaker, & HIPAA Instructor; Help Me with HIPAA Podcast Contributor and Federal HICP 405(d) Task Group & HIC-TCR Task Group




Cybersecurity starts with the basics, such as appropriately managing passwords within your organization. The Health Insurance Portability & Accountability Act (HIPAA) requires access controls and password management, which requires a top-down approach within your organization. Whether you are a Covered Entity or Business Associate, handle it like a boss!

In a recent article by Joanne Byron, she discussed one of the biggest challenges with proper password management… password sharing! In this article, I’m going to introduce you to some ways that you can overcome this challenge in your organization.

First, let’s start by setting three ground rules that I use for cybersecurity:

Rule #1 – Security is not convenient

Rule #2 – Security is not optional

Rule #3 – Security should not unnecessarily hinder the user

Understand that by design, security is there to hinder or stop an action. Think of your house for a minute. I have a sign in my yard advertising that I have monitored security in my home. I also have an alarm system, a deadbolt, a dog, and a shotgun. All these things represent different levels of security and incident response. They all cost me money and they are all inconvenient in some way. To protect my family, my most precious assets, is not optional. However, I can’t make this level of security so inconvenient that it doesn’t work. Therefore, I’ve ensured that these levels of security do not hinder my family’s ability to quickly enter and exit the home.

Security is there to deter the bad guys and to keep out those who should not be in my home (like the in-laws).

Passwords are just one layer of security for your electronic Protected Health Information and other digital assets. It is also a layer of security that is heavily dependent on the user… the human. The human must follow your password policy so that proper passwords are created and used in the correct manner. However, like a flowing river, humans will often find the path of least resistance (or create one) to get their job done.

Therefore, it is so important to train employees on your password policy, why passwords matter, what can happen when passwords are shared, and so on. Equally important is that the organization should take reasonable measures to make using passwords not a huge hinderance. Let’s take a look at some solutions to help your team be password ninjas!

Password Managers

Password managers are a fantastic tool for… you guessed it… managing passwords! I could not do without a password manager. At last check, I had over 1700 unique passwords stored in my password manager.

Password managers offer an array of other benefits and services but at its core, a password manager allows you to store all your passwords in a single, secure place. Instead of having to remember dozens or hundreds of passwords, the user only has to remember the one password that opens their password manager. Think of it as a vault for your passwords.

Another feature of most password managers that I love is the ability for me to share a password with someone without giving them the password. There are a few ways this can be used. I can set up a user account for someone and program their password into the password manager so that they can login to the application using their own credentials, and they never see the password. This ensures that a user can’t use their credentials outside of the office to access anything business related.

This is also very helpful for those websites that do not allow for multiple user accounts, but you still need multiple users to access it and use it. I see this often in practices where a business website only gives the practice a single account to use. The practice uses the same username and password for every employee that needs access to that website. Even worse, when employees leave the practice the credentials are not changed, which allows the separated employee to assess the site from anywhere.

There are several additional benefits of a good password manager application, so investigate one for your organization. They are well worth the small investment.

Creating Passwords

Whether you use a password manager or not, you still must deal with creating secure, unique passwords. Remember, you do not want to have the same password used more than once. Using the same password for everything is like having one key for your house, your car, your office, as well as all your past houses, cars, and offices. Oh, and the key has your name and address on it. Can you see how important it is to use different passwords everywhere?

Before we continue, it is important for you to understand that the bad guys aren’t trying to login to your online accounts typing in one password at a time hoping to get lucky. The bad guys use software automation and databases of passwords to throw at your accounts. This is called a brute force attack.

They know that most people are lazy and use terrible passwords. The most common password is 123456. You may laugh, but this password has been exposed in breaches more than 23 million times. It seems that no matter how terrible of a password it is, people still use it. For these people convenience is a higher priority than security. I wonder if these same people leave their car and homes unlocked… because, yeah… fumbling for a key is not convenient either.

Just a few months ago, the cybersecurity world learned of a leaked list of passwords called RockYou2021. This massive list of breached passwords and passwords from other sources comprises an impressive list of 8.4 billion unique passwords. 8.4 billion!!! Is there a chance that a password you use will show up on a list that size? Yeah, most likely. Unless you are one of the smart ones that use good password creation practices.

Since I’ve already mentioned password managers, it is worth noting that most password managers come with a password generator built-in that allows you to select a few criteria for your password and presto, it creates a password for you to use. Whether you’re using a password manager or not, here are some criteria to consider for your secure password:

Size Matters

Length is more important than complexity. Forever and a day we’ve heard that password complexity is necessary. Well, after years of research, we’re finding that all that complexity lends itself to creating other problems.

Many users fulfill this complexity requirement the same way by simply capitalizing the first letter of the password and adding a 1 or ! to the end. If I just guessed 25% of your password, you should be relegated to using a manual typewriter for the next month. Your password should be at least 8 characters (I prefer 12 to 16) minimum. The longer the password, the harder it is for software to crack it.

Change Is Good, or Is It?

Consider eliminating or reducing periodic password resets. We are also finding out that having people change their passwords too often means that they can’t remember them. I can often tell how many times someone has changed their password by how many exclamations they have at the end. Every time there was a password change, they simply added an exclamation.

If you are using secure passwords, there is no need to change them unless they become compromised in any way. However, knowing if they are compromised becomes super important and your organization should subscribe to services that monitor your accounts for compromised credentials. This brings us to the next point.

You Made the List! That Sucks.

Every password should be checked against known “blacklists” that include dictionary words, repetitive or sequential strings, passwords taken in prior security breaches, variations on the site name, commonly used passphrases, or other words and patterns that cybercriminals are likely to guess. Using a password that is on a Blacklist makes the password almost useless. Imagine if your home had one of those digital keypads for keyless entry. Now, imagine that there was a list floating around your town that had your home’s key code. How would it make you feel that thousands of strangers can easily walk right into your home if they desire? Using a compromised password is much the same.

Lie… Seriously!

You know those password hints you had to create to set up your bank account? Chances are, those answers are fairly easy to get by just paying attention to your social media accounts and what you share online. Heck, the answers may even be able to be socially engineered out of you.

When presented with these password hints and security questions… lie like crazy! What’s my mother’s maiden name? NunYoBitNess!

Get creative and have fun with it but remember you may need to use these answers at some point to recover or reset your real password, so you need to keep this information. I hate to keep coming back to password managers, but most of them also allow you to keep secure notes in your vault (it’s not just for passwords).

What Do You Have? What Do You Know?

Multi-factor (MFA) or Two-factor (2FA) authentication requires users to authenticate themselves using something they know and something they have.

2FA has been around for a very long time. If you’ve ever used an ATM machine to get cash, you’ve used 2FA. You used your card (something you have) and your PIN (something you know).

Using 2FA will likely require that you use an “Authenticator” app. There are many available but stick with the known companies like Google, Microsoft, Authy, etc.

I highly recommend using 2FA everywhere it is available. Even if someone has your username and password, it will be difficult for them to get past your additional authentication methods.

Wrapping It Up

Now that you know how to create secure passwords, how to store them safely, and how to manage them properly, you are ready to go out into the world and show everyone in your organization how they too can handle passwords like a boss!

Want More Information on HIPAA Compliance?

Help Me With HIPAA is the most popular, longest running podcast of its kind. Patient care starts from the moment a person entrusts you with their personal information. Join Donna and David each week as they deliver HIPAA and humor in a way you've never experienced. Who says learning can't be fun? Not us!


Train Online in HIPAA Privacy & Security Compliance – Click Here for more information.


Only need short refresher courses or targeted training? Check out the AIHC HIPAA short courses.

Read More
HIPAA Compliance
HIPAA

Is Sharing EHR Passwords a Problem?

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article addresses the importance of Electronic Health Record (EHR) security to help health care organizations, health plans, clearinghouses (Covered Entities) and their business associates avoid HIPAA violations under the Security Rule Standard § 164.312(a)(1). To obtain more information about mitigating the risk of a HIPAA violation, please consult with legal counsel or a HIPAA Security Consultant. 

 

What If . . .

 

What would happen if you shared your login and password to your online bank account? How about sharing the password to access your credit cards? How would you feel if you knew your doctor shared his/her password to your personal medical records with an unauthorized user? What if someone in medical billing shared his/her password to your account (containing your medical and financial identity) with someone not authorized to access your information?


What If EHR Passwords Are Shared . . .


Electronic health records (EHRs) incorporate a vast amount of patient information and diagnostic data, most of which is considered protected health information. With the advancement of technology, the emergence of advanced cyber threats has escalated, which hinders the privacy and security of health information systems such as EHRs.


As defined by the Center of Medicare and Medicaid Services (CMS), “An electronic health record (EHR) is an electronic version of a patient’s medical history, that is maintained by the provider over time, and may include all of the key administrative clinical data relevant to that person’s care under a particular provider, including demographics, progress notes, problems, medications, vital signs, past medical history, immunizations, laboratory data and radiology reports.”


Because this protected information and data can easily get into the wrong hands, individuals should not share passwords with anyone.  


Is This Really a Problem? Doesn’t Everyone Share Passwords?


Due to the sensitive nature of the information stored within EHRs, several security safeguards have been introduced through the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.


Prevalence of Sharing Access Credentials in Electronic Medical Records

To summarize an abstract published by PMC (Public Med Central) of the U.S. National Institutes of Health’s National Library of Medicine, it was found that to prevent data leakage, many countries have created regulations regarding medical data accessibility. These regulations require a unique user ID for each medical staff member, and this must be protected by a password, which should be kept undisclosed by all means. A survey was conducted with the following results:

  • A total of 299 surveys were gathered.
  • The responses showed that 220 (73.6%) participants reported that they had obtained the password of another medical staff member.
  • Only 171 (57.2%) estimated how many times it happened, with an average estimation of 4.75 episodes. All the residents that took part in the study (45, 15%) had obtained the password of another medical staff member, while 57.5% (38/66) of nurses reported this.

Their conclusion from this study: the use of passwords is doomed because medical staff members share their passwords with one another. Strict regulations requiring each staff member to have a unique user ID might lead to password sharing and to a decrease in data safety. Click Here to access the full study.


Remember to Comply With the 3 Pillars of Securing ePHI


The three pillars to securing protected health information outlined by HIPAA are administrative safeguards, physical safeguards, and technical safeguards. These three pillars are also known as the three security safeguard themes for healthcare. These themes range from techniques regarding the location of computers to the usage of firewall software to protect health information. A brief list of the HIPAA Security Safeguards:

  • Access control (technical safeguard) is a technique that prevents or limits access to an electronic resource. The intent behind access control techniques is to limit access to only authorized parties. The healthcare facility collects, stores, and secures patients’ data, which is very sensitive. This safeguard can take the form of role-based access control, attribute-based access control, and identity-based access control. Role-based refers to a person’s role in the healthcare facility. For instance, when a provider begins working at a healthcare facility, he/she has access to patient data, but only the patient data for his/her patients. If this provider also serves on a certain committee in the hospital, then another set of privileges is created to enable access to committee resources. When other data is accessed, a log is created that is periodically audited. When a front-desk clerk begins working in a facility, he/she has no reason to access clinical data, but may need access to the administrative data such as address and phone number, depending on the role that the person plays in the organization. Other names for this are media controls, entity authentication, encryption, firewall, audit trails, virus checking, and packet filtering.
  • Physical access control (physical safeguard) is a technique that prevents or limits physical access to resources. The intent of this control is similar to the technical safeguard: It limits access to only authorized parties. A patient in a facility will not have access to any clinic or ward except the one he/she is seen in. A front-desk clerk in the optometry clinic will not typically need access to the emergency room, so his/her access card will not open those doors. A provider in a facility will not typically need access to the server room, so his/her access card will not unlock those doors. Other names for this are physical security, (some) workstation security, assigned security responsibility, media controls (access cards), and physical access control.
  • Administrative safeguards are techniques that are not entirely technical or physical, but may contain a piece of each. These safeguards typically take the form of policies, practices, and procedures in the facility to regularly check for vulnerabilities and continually improve the security posture of the organization. Other names for this control are risk analysis and management, system security evaluation, personnel chosen for certain roles, contingency, business continuity, and disaster recovery planning.

When Someone Shares a Password – It Is a HIPAA Violation Under the HIPAA Security Rule – Technical Safeguard Related to Access Controls. 

 

The Security Rule defines access in § 164.304 as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subpart E of this part [the HIPAA Privacy Rule]).” Access controls provide users with rights and/or privileges to access and perform functions using information systems, applications, programs, or files. Access controls should enable authorized users to access the minimum necessary information needed to perform job functions. Rights and/or privileges should be granted to authorized users based on a set of access rules that the covered entity is required to implement as part of § 164.308(a)(4), the Information Access Management standard under the Administrative Safeguards section of the Rule.


Unique User Identification Requirement - § 164.312(a)(2)(i)

 

The Unique User Identification implementation specification states that a covered entity must: “Assign a unique name and/or number for identifying and tracking user identity.”


User identification is a way to identify a specific user of an information system, typically by name and/or number. A unique user identifier allows an entity to track specific user activity when that user is logged into an information system. It enables an entity to hold users accountable for functions performed on information systems with ePHI when logged into those systems using audit trails (addressed toward the end of this article).


Regardless of the technology or information system used, access controls should be appropriate for the role and/or function of the workforce member. For example, even workforce members responsible for monitoring and administering information systems with electronic protected health information or ePHI, such as administrators or super users, must only have access to ePHI as appropriate for their role and/or job function.


Sample questions for covered entities to consider:

  • Does each workforce member have a unique user identifier?
  • What is the current format used for unique user identification?
  • Can the unique user identifier be used to track user activity within information systems that contain ePHI?

So, What Can Happen If We Have Insufficient ePHI Access Controls?

Violating HIPAA law 104-191 can be costly. The HIPAA Security Rule requires covered entities and their business associates to limit access to ePHI to authorized individuals. The failure to implement appropriate ePHI access controls is also one of the most common HIPAA violations and one that has caused financial penalties. 


Financial penalties issued to covered entities for ePHI access control failures include:


Anthem Inc. – $16,000,000 penalty for access control failures and other serious HIPAA violations

OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations

OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations

University of California Los Angeles Health System – $865,500 penalty for the failure to restrict access to medical records

Colorado Medical Center – $111,400 penalty for the failure to terminate access to ePHI after an employee termination and a lack of a business associate agreement

Controlling Access to ePHI: For Whose Eyes Only?


The government HIPAA privacy/security enforcement agency is the Office for Civil Rights (OCR). OCR published the Summer 2021 Cybersecurity Newsletter on July 14, 2021, which states:


The rise in data breaches due to hacking as well as threats to ePHI by malicious insiders highlight the importance of establishing and implementing appropriate policies and procedures regarding these Security Rule requirements. Ensuring that workforce members are only authorized to access the ePHI necessary and that technical controls are in place to restrict access to ePHI can help limit potential unauthorized access to ePHI for both threats.


A recent report of security incidents and data breaches found that 61% of analyzed data breaches in the healthcare sector were perpetrated by external threat actors and 39% by insiders.


Without appropriate authorization policies and procedures and access controls, hackers, workforce members, or anyone with an Internet connection may have impermissible access to the health data, including protected health information (PHI), that HIPAA regulated entities hold. News stories and OCR investigations abound of hackers infiltrating information systems, workforce members impermissibly accessing patients’ health information, and electronic PHI (ePHI) being left on unsecured servers.


Information Access Management and Access Control are two HIPAA Security Rule standards that govern access to ePHI.


Download this newsletter:

Monitor Audit Trails


Audit trails automatically register and record where, when and who accessed the system. They also record what users do when they access the system. This tracks every change in patients’ information and documents it.


Since all the data is logged in the EHR system, it enables users to review the data at regular intervals and flag activities that seem suspicious. Regular reviews can also help correct mistakes caused by human error that could be flagged as a HIPAA violation. An audit trail answers the following:

  • Which patients’ data was accessed?
  • What time was it accessed?
  • Who retrieved the data?
  • Where was the data accessed from?

EHR software can also be set to send notifications to patients when their information is accessed. This way patients can report breaches as soon as they happen.


Conclusion


Create strong policies and procedures, then communicate these rules to your workforce. Enforce compliance through auditing and monitoring. Explain that when an individual allows another to use his/her password to access ePHI, that individual can alter and perform unauthorized functions and not be held accountable. The audit trail points back to the person who is assigned that password. 


Conduct on-going training of your workforce, which needs to include your C-Suite executives (who are not exempt from the rules). To gain the BEST results, conduct additional quarterly training with your front-line managers and supervisors.  Give them tools to incorporate HIPAA training at EVERY department meeting. If you think annual HIPAA training is sufficient, then you simply are not doing enough to protect your patient’s ePHI.


Additional Resources


Weekly HIPAA Podcasts (free) at:

OCR “The Security Rule” on the HHS website:

Train Online in HIPAA Privacy & Security:

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

Basic Audit Principles & Code of Conduct

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




When tasked with performing an audit or review, it is important to understand your part in the process, comply with the basic audit principles and perform your duties with the highest level of professionalism. Respect is earned, not automatically “given,” after achieving a credential such as “Certified Healthcare Auditor” which has been offered by the American Institute of Healthcare Compliance since 2004.


Follow the Basic Audit Principles


The principles listed below are taken from ASQ (American Society for Quality).  The twenty principles are divided into four categories:

  1. Auditor Conduct
  2. Preparing
  3. Performing
  4. Reporting

AUDITOR CONDUCT

  • Do not disclose auditee proprietary information to others.
  • Be honest and impartial by avoiding conflicts of interest.
  • When an unethical activity is observed, verify it, record it, and report it.
  • Protect auditee property entrusted to you.
  • Use knowledge and skills for the advancement of public welfare.

PREPARING

  • Ensure that sufficient resources are available to accomplish the purpose of the audit.
  • Verify that there is an established system/process to audit before the audit.
  • Assigned auditors must be competent/qualified.
  • Communicate agreed-upon information to the auditee, such as audit times, purpose, areas to be audited, and standards to be audited against.

PERFORMING

  • Verify conformance to agreed-upon requirements (the rules). Auditors don’t determine auditee requirements.
  • Ensure that sufficient samples (records, product, processes, interviews, and so on) are taken to match the purpose and scope of the audit.
  • Stay within the agreed-upon scope unless the degree of risk necessitates other actions.
  • Samples must be random and representative unless specified objectives require otherwise.
  • Conformance and nonconformance must be verifiable and traceable.
  • Comply with auditee rules (safety, environmental, health, restricted areas, and so on).
  • Keep auditee informed of audit progress.

REPORTING

  • Report the results of the investigation truthfully and in a clear, correct, concise, and complete manner.
  • Communicate the importance of findings/nonconformities.
  • Ensure that results are traceable to requirements.
  • Do not take ownership of problems found.

Pearls of Wisdom From the Late General Colin Powell


General Colin Powell’s 13 Principles of Leadership


General Powel passed away on October 18, 2021. He is one of our great U.S. military leaders. This list of Principles of Leadership is simple, brief and worthy of remembering:

  1. It ain’t as bad as you think. It will look better in the morning.
  2. Get mad, then get over it.
  3. Avoid having your ego so close to your position that when your position falls, your ego goes with it.
  4. It can be done!
  5. Be careful what you choose.
  6. Don’t let adverse facts stand in the way of a good decision.
  7. You can’t make someone else’s choices.
  8. Check small things.
  9. Share credit.
  10. Remain calm. Be kind.
  11. Have a vision. Be demanding.
  12. Don’t take counsel of your fears or naysayers.
  13. Perpetual optimism is a force multiplier.

Abide by the Code of Ethics and/or Code of Conduct


If you haven’t reviewed your organization’s expectation of professional conduct, then it is time to locate such information and read it carefully. Are you a credentialed member of the American Institute of Healthcare Compliance (AIHC)? If so, you are also expected to abide by our organization’s Code of Conduct, described below and located here on our website:  https://dev-main.aihc-assn.org/code-of-conduct/


This Code is a guide to the ethical conduct expected of students and certified professionals of the American Institute of Healthcare Compliance, Inc. (AIHC). The Code also aims at informing the public of the principles to which health care compliance professionals are committed.


The health care industry operates in a heavily regulated environment with a variety of identifiable risk areas. In addition to the challenges associated with patient care, health care providers are subject to voluminous and at times complex sets of rules governing administrative operations. Over the last decade, risk associated with non-compliance has grown dramatically. Those serving in a position of compliance in a health care organization have assumed great responsibility and should be concerned with the manner in which they carry out their duty as a compliance professional.


Students and those certified through AIHC are viewed by employers and the public as compliance professionals. The very word professional implies that you are an expert. The following competencies are expected:

  1. Take action to satisfy the mission and vision of your organization.
  2. Influence others to do the right thing; you are serving as a role model.
  3. Work to achieve the highest standards of quality while being fiscally responsible.
  4. Become an expert in the skills and tools necessary to do your job.
  5. Always perform to the best of your abilities.
  6. Appreciate and support those you work with.
  7. Practice good manners and use proper etiquette at all times.
  8. Demonstrate high ethical and moral standards.
  9. Be honest and fair in all of your dealings with others.
  10. Respect and acknowledge the talents of your peers.
  11. Professionals are humble and generous in their praise of others.
  12. Professionals are pleasant even during trying times.
  13. Recognize any shortcomings you might have and begin working on your professional image.
  14. Obey the law.
  15. Keep your knowledge up to date through self-teaching and maintaining continuing education efforts.

In Conclusion, Remember –

 

Good leaders see excellence wherever and whenever it happens. Excellent leaders make certain all subordinates know the important roles they play. Look for everyday examples that occur under ordinary circumstances. Good leaders know that each person on the team is contributing in a small but important way to the business. A leader who sets a standard of “zero defects, no mistakes” is also saying, “Don’t take any chances. Don’t try anything you can’t already do perfectly, and for heaven’s sake, don’t try anything new.” Be the leader you know you can be. Empower subordinates to take initiative and be the subordinate leader who stands up and makes a difference.


Learn more about becoming a Lead Auditor by taking the online, (on-demand) Auditing for Compliance training program today!

Read More