Page 6 - Your Practice Compliance
P. 6

Risk Management

"Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to
comply with [the General Requirements of the Security Rule]." HHS HIPAA Security Rule

To continue with the medical analogy, after the diagnosis or HIPAA security risk analysis, it is essential to create a
treatment plan. As you are aware, failure to have a treatment plan is ineffective action. A risk management plan is
an essential tool to compliance readiness and effective security of protected health information (PHI).

Two functions of Risk Management

     1. Evaluate and maintain security measures
     2. Implement processes of security measures

           Meaningful Use

The American Recovery and Reinvestment Act of 2009 authorize the Centers for Medicare & Medicaid Services
(CMS) to implement incentive programs for Meaningful Use of Electronic Health Record (EHR) systems. Meaningful
Use is a Medicare and Medicaid EHR Incentive Program, This program provides financial incentives for eligible
hospitals, practices, and professionals (physicians, dentists, etc.) to meaningfully use EHR technology.

To receive an EHR incentive payment, a covered entity and professionals alike must provide reports showing that
they are meaningfully using their EHRs and meeting certain objectives set by the CMS. If covered entity meet
objectives established for Meaningful Use, they can receive annual payments up to $44,000 for Medicare and
$63,750 for Medicaid. The program started in 2011, and payments will continue through 2016 to eligible covered
entities. After 2015, CMS will require eligible entities to meet Meaningful Use or be subjected to a financial penalty.

A Meaningful Use stipulation is to complete a thorough and accurate risk analysis of your practice’s EHR systems. A
risk analysis required for Meaningful Use can be completed in the same time frame as a HIPAA security risk
analysis is completed. These analysis are thorough review of all systems that interact with protected health
information (PHI), including your EHR systems. Your CMS website is available for more detailed Meaningful Use
information and its use.

Contact MedBill Compliance Group, Inc. today! Learn more about your practice HIPAA compliance, Security
Matrices, and Security/Privacy Rules to help your practice become compliant.

Copyright 2015: All rights reserved: Medbill Compliance Group, Inc  Page 5
   1   2   3   4   5   6   7