Meeting Compliance with Secured Patient Information Access
Healthcare Tech Outlook

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.

.

Meeting Compliance with Secured Patient Information Access

.

Could you tell me a little bit about yourself and your roles and responsibilities as the  director of medical compliance monitoring at the University of Miami Health System?

I work at the University of Miami Health System as the director of compliance program  monitoring. During my career, I have worked in several healthcare compliance areas such as  regulatory compliance, privacy compliance, and drug diversion prevention. Bringing these  competencies to my role at the University of Miami Health System allows me to take a holistic  view of the compliance department and ensure that the procedures used by each compliance

team are effective while also meeting the regulatory requirements. I ensure that all aspects  of the compliance program work cohesively, efficiently, and effectively.

I am also a ‘software guru’ for the internal compliance software leveraged by the University  of Miami Health System. I work with the different compliance department teams and help  them ensure that all the data we are capturing from different sources are tracked and  compliant with the healthcare regulations. All of these compliance related workflows have to  be reported quarterly to various committees, including the executive compliance committee.  I help the Chief Compliance Officer create and deliver the relevant compliance reports and  presentations at these meetings.

In the context of the COVID-19 pandemic and its after-effects, what are some of the  underlying technology changes taking place in the healthcare space?

In my opinion, COVID-19 has only accelerated the ongoing changes in the industry, which  otherwise would have taken years to reach the level of adoption that took place during the  pandemic. Traditionally, patients had to go to healthcare providers to communicate with the  practitioner. During COVID-19, however, it became imperative for many patients to  communicate with their doctors remotely from the safety and comfort of their homes. This  was one of the reasons for the rapid growth of telemedicine in the last two years.

“We try to partner with each department's staff to ensure that they comply with all  the rules and regulations, which ultimately improves patient outcomes.”

The post-pandemic world has also seen a rise in AI-based software, including advanced EMR  monitoring software. AI-powered software’s are streamlining much of the labor-intensive  work for audit and compliance employees, resulting in less manual work when auditing access  to the EMR. They facilitate quick audits of every access to the system while also allowing  accurate identification of incidents. With these emerging solutions, we are able to do much  more to protect our patients, workforce, organization, and greater community from risk.

How has your organization pivoted according to the industry’s newer needs or demands?  Are there any new projects you have undertaken that are accelerating the technology  adoption at your organization?

As an organization, we are constantly looking to incorporate new technology into our  processes to meet the increasing demands of the industry. Some initiatives include reviewing  new information security tools like multifactor authentication, exploring the expansion of

telehealth and making it a mainstay in our organization, performing Cybersecurity incident  response tabletop exercises, and deploying several new firewalls and enabling AI (Artificial  Intelligence) active threat blocking to protect against cyberattacks.  

It’s clear that cybersecurity is a high priority item today and it’s reasonable to assume that  this will only become a greater priority item as time goes on due to the rapid development of  network services and technologies. As a result, it’s essential to have a robust information  security team who has the responsibility to monitor for and address cybersecurity incidents  as well as exploring proactive options to further secure proprietary and patient information. 

What advice would you like to impart to your peers seeking to venture along the same lines  as yourself?

I believe that communication is the most critical factor when it comes to compliance. The  essential part of an effective compliance program is ensuring that responsibilities are clearly  defined, and everyone is aware of their contribution to the department as a whole. Our  department works with confidential information regularly. We ensure that every team  member understands the importance of handling this confidential information safely and how  their role fits in the bigger picture of compliance.

I have worked for numerous organizations as a compliance professional. Many hospitals and  healthcare settings fear compliance because of changing laws and regulations that can make  it difficult for organizations to meet their strategic goals. That is not the case with the  University of Miami Health System. We try to partner with each department to ensure that  the organization’s strategic goals are successfully implemented while also in compliance with  the applicable rules and regulations, which ultimately improves patient outcomes. Providing  high-quality patient care is crucial, as is ensuring that every member of your staff is aware of  their responsibilities and those of their coworkers in the compliance paradigm.

At the University of Miami Health System, due to our collaborative culture the Compliance  Department has the ability to quickly react to reports of HIPAA violations and reviews of  consulting agreements, or whatever the current crisis is. The collaborative culture is a critical  component to the success of the compliance program. Employees need to trust that they can  proactively reach out to Compliance when they encounter an issue to ensure initiatives are  implemented in a compliant manner on the front end instead of waiting until the concern  raises to an issue that has to be addressed.

What are some of the transformations or disruptions that you expect to take place in the  industry in the coming years?

The 21st Century Cures Act’s information blocking and interoperability regulations are  complex, unprecedented, and intertwined with the HIPAA rules. Regarding patient requests  for data, the Cures Act prohibits providers, developers, and health information networks from  engaging in practices that would inhibit patients from receiving their own data or methods  that inhibit patient data from flowing where patients want it to go.

There is a significant increase in the amount of information that has to be delivered to  patients in safe, simple, and quick methods, so they have seamless access to their protected  health information (PHI). While industry groups have been working to define the relationships  of the HIPAA-designated record sets used by the Cures Act as part of the PHI definition, what

makes up a designated record set is left open to interpretation by each organization. The  problem is determining the exact data points contributing to the record sets defined by the regulatory agencies. I’m confident that over the next 18 months, the 21st Century Cures Act  will give rise to some best practices and guidelines regarding what details will fall under the  purview of the designated record set and what details might not necessarily require disclosure  in this case.

I believe that advanced monitoring software will still be a crucial part of those health systems  after the 21st Century Cures Act. The Cures Act has increased the amount of information to  be made available to the patients, which also increases the danger of a breach.

There will be a renewed emphasis on how hospitals and healthcare systems should manage  their EMRs to ensure that the staff and anyone with access to such information is utilizing  their access appropriately. In my opinion, the 21st Century Cures Act will lead to increased  and renewed attention to HIPAA privacy and security rules in the future.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief