- Home
- » e-Newsletters
PPV: Ensure that your remote coding program’s security is up to par with CMS guidance and HIPAA
EHR Connection, April 28, 2008
Devices and tools used to store and transmit electronic protected health information (ePHI), such as personal computers, flash drives, and remote access devices, are a source of growing concern at CMS. If your coders work remotely, now is the time to reexamine your security policies.
In December 2007, CMS announced a contract with PricewaterhouseCoopers for the company to conduct security audits that address CMS’ remote access guidelines released in 2006.
CMS expressed concerns about remote access in a recent security guidance and said:
In general, covered entities should be extremely cautious about allowing the offsite use of, or access to ePHI. There may be situations that warrant such offsite use or access, e.g., when it is clearly determined necessary through the entity’s business case(s), and then only where great rigor has been taken to ensure that policies, procedures, and workforce training have been effectively deployed, and access is provided consistent with the applicable requirements of the HIPAA Privacy Rule.
CMS has also said that covered entities should pay particular attention to three areas:
- Risk analysis and risk management strategies
- Policies and procedures for safeguarding ePHI
- Security awareness and training on the policies and procedures for safeguarding ePHI
Click here to learn how you can improve the security of your remote coding program.
The cost is $10. Medical Records Briefing subscribers can sign on for free access.
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- QA:Coding multiple initial infusions
- News and briefs: Oklahoma Osteopathic Association against residency bill change
- HIPAA Q&A: Level of encryption needed for email
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- ED-to-inpatient transfers are flawed with safety gaps
- Joint Commission Center announces handoff communication solutions
- Inside best practice: Reduce patient falls with a stoplight
- Identify modifiable risk factors to prevent patient falls
- Searched