THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.


Could you tell me a little bit about yourself and your roles and responsibilities as the director of medical compliance monitoring at University of Miami Health System? 
.
As the director of compliance program monitoring, my job is to make sure that all the various parts of the compliance program are working cohesively, efficiently, and effectively. I have worked in different types of compliance areas such as regulatory compliance, privacy compliance, and drug diversion. Bringing these competencies to my new job role allows me to take a holistic view of the department and ensure that the procedures used by each team are effective, while also meeting the compliance requirements.
As the ‘software guru’ for the internal compliance software leveraged by University of Miami Health System, I work with the different teams and help them ensure that all the data we are capturing from different sources is being tracked and is compliant with the regulations. All these workflows have to be quarterly reported to various committees, including the Executive Compliance Committee. I help the chief compliance officer create and deliver the relevant compliance report presentations at these meetings.
In the context of the COVID-19 pandemic and its after-effects, what are some of the underlying technology changes taking place in the healthcare space?
In my opinion, COVID-19 has only accelerated the ongoing changes in the industry, which otherwise would have taken years to reach the level of adoption that took place during the pandemic. Traditionally, patients had to go to healthcare providers to communicate with the practitioner. During COVID-19, however, it became imperative for many patients to communicate with their doctors remotely to enable patients to communicate with doctors from the safety and comfort of their homes. This was one of the reasons for the rapid growth of telemedicine in the last two years.
The post-pandemic world has also seen a rise in AIbased software, including advanced EMRs. AI-powered EMRs are streamlining much of the labor-intensive work for employees, enabling them to focus on delivering better patient experiences. AI-based software are enabling quick audits of every access to the system, while also facilitating proactive identification of incidents. With these emerging solutions, we are able to do much more than humanly possible to protect our patients, workforce, organization, and greater community from risk.
How has your organization pivoted according to the industry's newer needs or demands? Are there any new projects you have undertaken, which are accelerating the technology adoption at your organization?
The recent initiatives that come to mind is the consulting agreement reviews and fee-for-service arrangements. The University of Miami Health System is one of the first organizations I have worked with that allows our providers to perform external consulting for de-identification of health information within the bounds of the safe harbor provision granted by the Congress for compliance.
University of Miami Health System is also developing new software called UDisclose that enables quick and thorough review and management of conflicts throughout the institution. It requires all of our providers to submit their draft consulting agreements through that software, which allows us to verify data and streamline results. To augment our competencies in this aspect, we have made significant investment in the regulatory team and hired two new hires. They are solely responsible for creating a sub-team dedicated explicitly to handling UDisclose systems and examining those consulting agreements. In this regard, our ability to leverage new tools, commit resources and work together as a team puts us ahead of the curve with these consulting arrangements.
What advice would you like to impart to your peers seeking to venture along the same lines as yourself?
For an effective compliance program, the essential part is ensuring that responsibilities are clearly defined and everyone is aware of their contribution to the department as a whole and as an individual. I believe that communication is the most critical factor when it comes to compliance. Our department is unique, and a large portion of what we do involves handling personal information. We ensure that every team member understands the importance of handling this personal information safely and fits in the bigger picture of compliance.
As a compliance specialist, I have worked for numerous organizations. Many hospitals and health care settings fear compliance because of changing laws and regulations that can make it difficult for organizations to keep up with healthcare compliance. That is not the case with University of Miami Health System. We try to partner with each department's staff to ensure that they comply with all the rules and regulations, which ultimately improves patient outcomes. Providing high-quality patient care is crucial, as is ensuring that every member of your staff is not only involved, but also aware of their responsibilities and those of their coworkers, as well as how they fit into the more extensive process of compliance. We have the ability to quickly react to reports of HIPAA violations and reviews of consulting agreements, or whatever the current crisis is. I believe that having a solid compliance program requires going out there, being proactive, and raising regulatory awareness across each department.
What are some of the transformations or disruptions that you expect to take place in the industry in the coming years?
The 21st Century Cures Act's information-blocking and interoperability regulations are complex, unprecedented, and intertwined with the HIPAA rules. Regarding patient requests for data, the Cures Act prohibits providers, developers, and health information networks from engaging in practices that would inhibit patients from receiving their own data or methods that inhibit patient data from flowing where patients want it to go.
There is a significant increase in the amount of information that has to be delivered to patients in safe, simple, and quick methods so they have seamless access to their protected health information (PHI). The problem is in determining the exact data points that contribute to the record sets defined by the regulatory agencies. While industry groups have been working to define the relationships of the HIPAA designated record sets as used by the Cures Act as part of the PHI? definition, what makes up a designated record set outside of a HIPAA entity is unclear. I'm confident that over the next 18 months, the 21st Century Cures Act will give rise to some best practices and guidelines regarding what details will fall under the purview of the specified record set and what details might not necessarily require disclosure in this case.
I believe that consulting agreements will still be a crucial part of those health systems after the 21st Century Cures Act, allowing their providers to enter these kinds of partnerships. The Cures Act has increased the amount of information that is to me made available to the patients, which also increases the danger of a breach.
There will be a renewed emphasis on how hospitals and healthcare systems should manage their EMRs to ensure that staff and anyone with access to such information is utilizing their access correctly. In my opinion, the 21st Century Cures Act will lead to increased and renewed attention to the HIPAA privacy and security rules.