HEALTHCARE COMPLIANCE

Are you ready for an OIG Audit?

Hospitals, health systems, and physician groups are challenged to keep up with the complicated and ever changing healthcare regulatory environment. Every week new quitam lawsuits are unsealed, the Department of Justice announces recent False Claims Act/Stark law/Anti-kickback settlements, new governmental guideline are issued, and more. Further, the federal government and its enforcement agencies show no signs of scaling back their initiatives.

The Federal Sentencing Guidelines for healthcare organizations recommends that all organizations have a comprehensive compliance program in place.

In fact, over the past several years, leaders of organizations have been held personally accountable for not only their involvement in wrongdoing but allowing noncompliance to occur on their watch. However, one thing is clear–the existence of a compliance-driven “tone at the top” and an effective corporate compliance program that addresses the seven fundamental elements outlined in the Federal Sentencing Guidelines and made mandatory for healthcare organizations through the Affordable Care Act is both necessary and expected.

Our Healthcare Compliance Services Include:

  • Compliance Program Implementation
  • Compliance Program Effectiveness Assessments
  • Compliance Risk Assessment
  • HIPAA Compliance
  • HIPAA Security Risk Analysis
  • Cybersecurity Program Assessment
  • OSHA Compliance

We are prepared to work with you in various areas of expertise to help your organization respond to these compliance challenges.

Compliance Program Effectiveness Assessments

Is Your Compliance Program Effective? – We Can Help!

In 2018, the Office of Inspector General (OIG) unveiled its “Fraud Risk Indicator” that is used to ascertain the degree of risk an organization that declines to enter into a Corporate Integrity Agreement (CIA) poses to the federal healthcare programs. Although the existence of a compliance program does not affect the level of risk assigned, the failure to have in place a suitable compliance program designates the organization as “higher risk.”

 

 

Compliance programs are mandatory for hospitals, health systems, and physician groups, and the cost of noncompliance is high. It includes recoupment of overpayments, self-disclosures, fines, penalties, reputational harm, negative publicity, exclusion from Medicare/Medicaid, and potential individual liability. At WiseAnt Group, we can help your organization develop an individualized, meaningful compliance program and help to operationalize the program within your environment.

 


If you have an existing compliance program, we can evaluate it against the seven required elements from the OIG and offer recommendations to improve its effectiveness. We have the tools and resources to assist in implementing the proposals for improvement and are available for ongoing execution, support, and advisory services.

Compliance Risk Assessment Services

Regularly conducting a compliance risk assessment is foundational to an effective compliance program

Healthcare organizations are constantly facing new compliance risks and are challenged to keep up with the complicated and ever-changing healthcare regulatory environment. Today, now more than ever, it is vitally important that healthcare organizations maintain an effective compliance program. Regularly conducting a compliance risk assessment is foundational to an effective compliance program. It allows an organization to focus important resources on the greatest risks and those areas lacking adequate controls.

 

 

The WiseAnt Group’s compliance team has deep compliance industry knowledge and understands the day-to-day operational, regulatory, and compliance challenges healthcare organizations face. We can conduct an effective compliance risk assessment that will identify and evaluate compliance risks and provide recommendations to enable an organization to proactively prioritize its response and mitigation efforts toward the highest risks.

Key benefits of The WiseAnt Group’s Compliance Risk Assessment Services include:

Assessing compliance risk is critical to ensuring your compliance program is operating effectively. Allow our WiseAnt Team to do the heavy lifting that comes with performing a compliance risk assessment for your organization. A WiseAnt compliance risk assessment will provide the information your organization needs to ensure the highest areas of compliance risk are being evaluated and mitigated by your team.

HIPAA Compliance

Does Your Organization Have Proper Controls in Place to Ensure Compliance?

HIPAA compliance is ever evolving and, although it may seem complicated, your organization is responsible for the protection and security of Patient Health Information (PHI) and Electronic Patient Health Information (ePHI), even when it’s in the hands of others. The Health Insurance Portability and Accountability Act (HIPAA) of 1996 requires that patient information is stored securely, that access to their data is monitored and controlled, and that healthcare organizations have the proper protocols and systems in place to ensure compliance.

HIPAA rules change frequently, and the penalties for exposed patient records can range from $100 per record, if you’ve done everything possible to protect your network, to $10,000 per record, when the U.S. Department of Health and Human Services Office of Civil Rights (HHS/OCR) determines you’ve been negligent in your compliance responsibilities.

 

At WiseAnt Group, we offer a broad array of consulting solutions for healthcare organizations to meet regulatory HIPAA compliance requirements. Below are some of the key components of HIPAA Compliance that our experts can help with to achieve adherence to The Health Information Technology for Economic and Clinical Health (HITECH) Act and HIPAA security rulings:

>   Security risk assessments to discover potential risks within the organization’s network, web, mobile, cloud, virtual, and IT infrastructure.

 

>   Development or update of HIPAA Privacy Policy and Procedure Manual based on findings from our assessments.

 

>   Review of HIPAA documentation currently in place to ensure you are meeting requirements and to determine if all high-risk areas of compliance are being addressed.

 

>   HIPAA training for your organization.

 

>   Evaluate entire IT infrastructure security (servers, computers, laptops, firewalls, remote access, EHR/Practice Management systems, wireless access, etc.).

 

>   Vendor and business associate HIPAA evaluations to determine if safeguards are in place for your organization’s PHI and ePHI.

 

>   Breach investigation to discover the cause of the breach and remediation services to help your organization stay compliant.

 

>   Ongoing compliance monitoring and HIPAA advisory services that will offer continuous compliance with the HIPAA security, privacy, and data breach notification rules.

 

Waiting until you run into compliance violations to seek assistance can be expensive and time-consuming. Start eliminating compliance risks by contacting us now.

HIPAA Security Risk Analysis

Is Your Company in Compliance with HIPAA’s Administrative, Physical, and Technical Safeguards?

The Health Insurance Portability and Accountability Act (HIPAA) security rule requires that covered entities conduct an accurate and thorough assessment of risks and vulnerabilities to the confidentiality, integrity, and availability of electronic patient health information (ePHI).

 

A security risk analysis (SRA) helps to ensure an organization is compliant with HIPAA’s administrative, physical, and technical safeguards. An SRA also helps reveal areas where an organization’s ePHI could be at risk.

 

Completing an SRA and correcting any deficiencies are requirements for many incentive programs such as the Quality Payment Program and the Promoting Interoperability Program (formerly Meaningful Use). Additionally, in May of 2021, The Office of the Inspector General (OIG) announced it would audit the U.S. Department of Health and Human Services (HHS) to determine whether HHS’s Office of Civil Rights (OCR) has performed periodic audits of hospitals to assess compliance with HIPAA Security, Privacy, and Breach Notification rules and determine whether these audits effectively assessed ePHI protections.

Our Approach

>  Administrative, physical, and technical assessment

 

> Utilization of the guidelines in the National Institute of Standard and Technology (“NIST”) SP 800-30

 

>  Conduct an accurate and thorough analysis of the potential risks and vulnerabilities

 

>  A basic set of customizable security policies

 

>  Third party Vulnerability Scan of your systems

 

>   Vendor and business associate HIPAA evaluations to determine if safeguards are in place for your organization’s PHI and ePHI.

 

>  Phishing Campaign

 

>  Remediation list with recommendations

 

> Business Associate Agreement review and log

 

> Remediation assistance provided upon request

 

Not all breaches are preventable, but the best first step a facility can take is to take a deep dive into its security posture and self-identify where they are vulnerable before that vulnerability is exploited.

Contact us today to see how we can help.

Cybersecurity in Healthcare

What is Your Battle Plan to Fight Cybercrime?

Cybercrime, while impacting other industries over the past 20 years, has now attacked healthcare in a big way. Daily, we read about security breaches in small-, medium-, and large-scale healthcare organizations that often affect hundreds, thousands, or even millions of people and their private information. These violations occur for many reasons, including unidentified holes in technology infrastructure, lack of knowledge and financial resources to build and maintain a robust IT security program, non-existent policies and procedures governing information security, and untrained and unprepared users. One thing is certain, security compromises are a serious threat, and they will continue to occur along with security audits and six- and seven-figure penalty settlements.

 

Ransomware is just one example of cybercrime that hospitals, health systems, and physician groups must avoid. These attacks are threatening the very safety and well-being of our nation’s healthcare system.

“No healthcare organization is immune to the operational chaos, harrowing events, and potential financial ruin that can result from ransomware and other forms of online terrorism.”

Safety nets and other safeguards are available to minimize these risks, but many providers do not know how vulnerable their IT systems and networks are until it is too late.

Expectations from regulatory bodies:

  1. What is your organization doing to protect your vital data and financial assets from such attacks?
  2. Do you have a written plan that outlines strategies and tactics for preventing, detecting, and responding to these attacks?
  3. What governance structure do you have in place to oversee the accountability for implementing this security plan?
  4. How aware are your employees of the organizational and personal risks associated with cybercrime?
  5. Do you have an ongoing training program to increase this awareness?
  6. Do you have enough (or any) insurance that covers cybercrime events like ransomware?

The time has come for executives and boards to step up and work closely with healthcare technology leaders to develop a robust battle plan to fight cybercrime. With more personal, medical, financial, and other critical information now available in electronic form, these leaders must become much more proactive in protecting their organization’s data and information assets from known cybercriminals.

 

We have a team of experienced IT experts and third-party consultants who understand how to assess, design, build, and maintain robust IT infrastructures geared towards fighting cybercrime in various healthcare environments.

 

Contact us today to see how we can help.

OSHA Compliance

Your Employees Are Your Most Valuable Asset, Let Us Help You Keep Them Safe!

We will provide you with a comprehensive OSHA Safety program that meets all regulatory requirements to protect your employees and patients.

Our customizable OSHA Solutions include but are not limited to:

>  General Guidance on OSHA Requirements

 

>  Hazard Risk Assessment

 

>  Mock OSHA Inspections – Annually

 

>  OSHA Policies and Procedures

 

>  Safety Data Sheets (SDS)

 

> Updated OSHA Forms, Logs and Posters

 

Workforce Training on:

 

>  Blood-borne Pathogens Standard

 

> Hazard Communications Standard

 

> Regulated Waste Management (DOT)

 

> Fire & General Workplace Safety

 

We work with you and your organization through the entire process to ensure year-round compliance. Let us know how we can help. Our experts are ready to help.