Tip: How to attack risks
Healthcare Auditing Weekly, July 22, 2008
Develop your risk-assessment processes based on your organization’s size and needs. Consider these eight strategies as you both assess your organization’s internal controls and identify risks.
- Shared risk language and measurements. Your organization must define risk-related terms (e.g., “serious risk) and use them consistently. The organization also needs a scale with which to rank and measure risks.
- Link enterprise risk management to corporate strategy and competitive advantage. Show the board and CEO how the risk assessment will help the organization reach its goals by explaining how it will benefit the bottom line.
- Get management buy-in. Make sure managers participate in the risk-assessment process and take responsibility for their departments’ risk areas.
- Link enterprise risk management to control self-assessments. Enterprise risk management looks at the organization’s overarching strategies, and control self-assessments focus on people’s interests at the department level.
- Share risk reports. Make sure managers are able to access risk reports when making decisions.
- Assess technology. Make sure your organization has consistent methods for storing and reporting on information-system risk areas.
- Responsibility and accountability. Integrate enterprise risk-management activities with other organizational activities, such as reviews and bonuses.
- Link the effect of risk identification to good corporate governance. Show how this process enables directors to meet their corporate-governance responsibilities.
This tip is adapted from The Healthcare Auditor’s Handbook. For more information about the book or to order your copy, visit HCMarketplace.
Comments
0 comments on “Tip: How to attack risks ”
Related Products
Most Popular
- Articles
-
- HIPAA Q&A: Level of encryption needed for email
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Identify potential Medicaid RAC target areas
- Capturing all necessary codes for IUD insertion and removal can be challenging
- Topic: CMS, OESS post new security compliance review information, checklist
- What does case-mix index mean to you?
- Q&A: Acute respiratory failure diagnosis does not require intubation
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- HIPAA Q&A: Level of encryption needed for email
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- CMS has reformulated payments for some bilateral procedures
- Oxygen Cylinder Storage Requirements
- Q&A: Follow CMS' coding guidelines when using modifier -25
- Understand the spine to code back procedures correctly
- What does case-mix index mean to you?
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Searched
