Medical Billing, HIPAA Compliance, and Role Based Access Control

HIPAA compliance requires special focus andtransparency about HIPAA compliance. Stated
effort as failure to comply carries significant riskpolicy typically includes a statement of least
of damage and penalties. A practice with multipleprivilege data access to complete the job,
separate systems for patient scheduling,definition of PHI and incident monitoring and
electronic medical records, and billing, requiresreporting procedures. Educational materials may
multiple separate HIPAA management efforts.include case studies, control questions, and a
This article presents an integrated approach toschedule of review seminars for
HIPAA compliance and outlines key HIPAApersonnel.Technology Requirements for HIPAA
terminology, principles, and requirements to helpCompliance Technology implementation of HIPAA
the practice owner to ensure HIPAA complianceproceeds in stages from logical data definition to
by medical billing service and softwarephysical data center to network. To assure
vendors.The last decade of the previous centuryphysical data center security, the manager must
witnessed accelerating proliferation of digitalLock data center
technology in health care, which, along withManage access list
reduced costs and greater service quality,Track data center access with closed circuit TV
introduced new and greater risks for accidentalcameras to monitor both internal and external
disclosure of personal health information.Thebuilding activities
Health insurance Portability and Accountability ActProtect access to data center with 24 x 7 onsite
(HIPAA) was passed in 1996 by Congress tosecurity
establish national standards for privacy andProtect backup data
security of personal health data. The Privacy Rule,Test recovery procedure
written by the US Department of Health and
Human Services took effect on April 14,For network security, the data center must
2003.Failure to comply with HIPAA riskshave special facilities for
accreditation and reputation damage, lawsuits bySecure networking - firewall protection,
federal government, financial penalties, rangingencrypted data transfer only
from $100 to $250,000, and imprisonment,Network access monitoring and report auditing
ranging from one year to ten years. Protected
Health Information (PHI) The key term of HIPAAFor data security, the manager must have
is Protected Health Information (PHI), whichIndividual authentication - individual logins and
includes anything that can be used to identify anpasswords
individual and any information shared with otherRole Based Access Control (see below)
health care providers or clearinghouses in anyAudit trails - all access to all data fields tracked
media (digital, verbal, recorded voice, faxed,and recorded
printed, or written). Information that can be usedData discipline - Limited ability to download data
to identify an individual includes:
Role Based Access Control (RBAC) RBAC
Nameimproves convenience and flexibility of systems
Dates (except year)management. Greater convenience helps reducing
Zip code of more than 3 digits, telephone andthe errors of commission and omission in granting
fax numbers, emailaccess privileges to users. Greater flexibility helps
Social security numbersimplement the policy of least privilege, where the
Medical record numbersusers are granted only as much privileges as
Health plan numbersrequired for completing their job.RBAC promotes
License numberseconomies of scale, because the frequency of
Photographs Information shared with otherchanges of role definition for a single user is higher
healthcare providers or clearinghousesthan the frequency of changes of role definitions
across entire organization. Thus, to make a
Nursing and physician notesmassive change of privileges for a large number
Billing and other treatment records Principles ofof users with same set of privileges, the
HIPAA HIPAA intends to allow smooth flow ofadministrator only makes changes to the role
PHI for healthcare operations subject to patient'sdefinition.Hierarchical RBAC further promotes
consent but prohibit any flow of unauthorized PHIeconomies of scale and reduces the likelihood of
for any other purposes. Healthcare operationserrors. It allows redefining roles by inheriting
include treatment, payment, care qualityprivileges assigned to roles in the higher
assessment, competence review training,hierarchical level.RBAC is based on establishing a
accreditation, insurance rating, auditing, and legalset of user profiles or roles according to
procedures.HIPAA promotes fair informationresponsibilities. Each role has a predefined set of
practices and requires those with access to PHIprivileges. The user acquires privileges by receiving
to safeguard it. Fair information practices meansmembership in the role or assignment of a profile
that a subject must be allowedby the administrator.Every time when the
definition of the role changes along with the set of
Access to PHI,privileges that is required to complete the job
Correction for errors and completeness, andassociated with the role, the administrator needs
Knowledge of others who use PHISafeguardingonly to redefine the privileges of the role. The
of PHI means that the persons that hold PHIprivileges of all of the users that have this role
mustget redefined automatically.Similarly, if the role of
a single user is changed, the only operation that
Be accountable for own use and disclosureneeds to be performed is the reassignment of
Have a legal recourse to combat violationsthe user profile, which will redefine user's access
HIPAA Implementation Process HIPAAprivileges automatically according to the new
implementation begins upon making assumptionsprofile. Summary HIPAA compliance requires
about PHI disclosure threat model. Thespecial practice management attention. A practice
implementation includes both pre-emptive andwith multiple separate systems for scheduling,
retroactive controls and involves process,electronic medical records, and billing, requires
technology, and personnel aspects.A threat modelmultiple separate HIPAA management efforts. An
helps understanding the purpose of HIPAAintegrated system reduces the complexity of
implementation process. It includes assumptionsHIPAA implementation. By outsourcing technology
aboutto a HIPAA-compliant vendor of vericle-like
technology solution on an ASP or SaaS basis,
Threat nature (Accidental disclosure by insiders?HIPAA management overhead can be eliminated
Access for profit? ),(see companion papers on ASP and SaaS for
Source of threat (outsider or insider?),medical billing).Yuval Lirov, PhD, author of "Mission
Means of potential threat (break in, physicalCritical Systems Management" (Prentice Hall,
intrusion, computer hack, virus?),1997), inventor of multiple patents in artificial
Specific kind of data at risk (patient identification,intelligence and computer security, and CEO of
financials, medical?), andBilling Technologies. Vericle delivers comprehensive
Scale (how many patient records threatened?).practice workflow engine that integrates patient
HIPAA process must include clearly stated policy,scheduling, electronic medical records (EMR), billing,
educational materials and events, cleartranscription, and compliance management. It
enforcement means, a schedule for testing ofimproves billing performance and reduces audit
HIPAA compliance, and means for continuedrisk.