Workflow and EMR: How do you do it?

During the past two weeks, I have spent several hours creating process diagrams or flow charts for a customer. After using our billing software and a custom attendance/reporting module we created for them in 2003 but maintaining paper clinical records, they are now implementing a custom Forms module and preparing to implement our behavioral health electronic medical record (EMR) product.

Clearly, understanding their current work flow is essential to assure that the steps we follow to implement the electronic record will cause minimal disruption of their productivity and maintain their confidence in their billing and cash flow. The goal of the CEO and CFO is to seamlessly provide and document services so payment audits do not result in lowered funding; the goal of the clinical staff is to help addicted people recover from their addictions and become productive citizens; and the goal of the billing staff is to assure that services are accurately reported and billed so the agency is paid for services provided.

The end point we plan to reach is that billing will not occur until documentation of the treatment is in place, but getting to this point will be a gradual process. Helping clinical and business office staff understand the job responsibilities, work flow and the anxieties of their colleagues will allow them to work more effectively as part of a team. The team, of course, shares the goals of providing the best clinical services as efficiently as possible and assuring that payment is obtained for those services so they all can continue doing their respective jobs.

While this flow charting was a time-consuming process, it was most instructive. One thing we have learned in almost 25 years in business is that our customers rarely use our products in the way we designed them. . . .and each organization does things differently. This customer was no exception. For us to make assumptions about how the counselors and business specialists in this or any of our customer organizations do their work would be foolish, at best.

A couple of months ago, our business development manager indicated that she gets frequent questions from prospective users wondering how they will integrate an EMR into their current work flow. Should they enter the progress note into the program while the consumer is in their office? If they wait until the client leaves, won’t it take too much time? Trish suggested that we write a blog article on how clinicians utilize our EMR in the course of their work. We decided to ask a couple of our customers to describe their work process so we could get a more accurate idea of how they work.

The answers to our inquiry were very interesting, and different from one another. As could be expected, the work flow of a psychiatrist/psychopharmacologist and that of a psychologist/psychotherapist were quite different. We are grateful to Scott P. Hoopes, M.D. of Meridian, ID and Scott Gale, Ed.D. of Franklin, TN for their input.

We were interested to find that neither Dr. Hoopes nor Dr. Gale enter a progress note while the patient is in the room; that happens after the patient has left. We also learned that neither provider relies upon a staff assistant to enter clinical information; they are both comfortable with a keyboard and prefer typing their own note to the more involved process of dictating, reviewing and correcting transcription, copying the note to the patient file and signing it. Dr. Hoopes does manage prescriptions while the patient is present, including reviewing, creating and sending the prescription to the pharmacy.

We learned that Dr. Gale, in spite of his use of our electronic clinical record since 1992, still scribbles notes and thoughts on paper while the patient is in his office. He scans these notes into electronic storage and shreds the paper. (As a solo provider without support staff, he does everything in his practice.) While he could attach these scanned documents to the patient’s file in the EMR, it is my impression that he considers this brief process note to be his work product. . .the psychotherapy note that HIPAA allows a psychotherapist to keep and store separately and not to release to an insurer. His note in the EMR is the formal record of the service provided. While some recommend against maintaining a separate set of psychotherapy notes, we have found that many of our customers do so. For some, this is the main reason not to move to an EMR. . .they are not sure how they would continue to maintain these psychotherapy notes while also using an electronic record.

Dr. Hoopes’ work flow was developed after time working in a community mental health setting where he was expected to see five patients in an hour. In 1995, not very long after starting his private practice and struggling for a while with paper records, he started using our software for billing, electronic claims filing and clinical records. Eventually, he also added scheduling.

His current work flow allows him to see his schedule at all times. Prior to the arrival of his patient, he brings their record onto the screen and makes a quick review. He duplicates the last progress note into one with today’s date for editing after the patient leaves. In the fifteen minutes he spends with each patient for a medication check, he is able to be engaged with them to determine their progress or lack thereof. Based on the information obtained, he decides to continue or alter their current medication, making any needed adjustments and sending the prescriptions to the pharmacy. He walks the patient out to the receptionist, who electronically schedules their next appointment. He returns to his desk, edits the progress note with today’s status, signs the note, and calls up the record of the next scheduled patient, repeating the process between 20 and 32 times a day.

My guess is that other users of our EMR product and of other products in the marketplace follow both very similar and very different work processes in their organizations. After all, while most of our customers provide behavioral health services, each is different, with varying clinical and business cultures. In every case, to most effectively implement a behavioral health EMR, it is essential to have a clear picture of your pre-EMR work flow and your goal for use of an EMR. Both of these will make it easier to choose and to implement the EMR of your choice.

Please share your experiences with the work flow in your business. Is work flow analysis something you have ever done? If so, what was your motivation? We would also love for you to share your work process experiences with implementing an EMR, if you have done so. What changes were necessary in your work flow to fully utilize the EMR? How successful have you been in that process?

If you would like to enter a comment, just click on the title of this article and enter your comment in the box at the bottom of the page. Please let us know your thoughts.

Get Out of HIPAA Jail Free

Consider a couple of nightmares that might easily come true:

1. Your laptop, with a variety of documents and files containing confidential, protected health information on its hard drive, is stolen from your car, hotel, or disappears while you are traveling.

2. Your office is burglarized and all the desktop computers, as well as a server containing your patient database, are stolen.

I ran across the following set of statistics, or very similar ones, repeatedly, most often on web sites of security companies:

  • Every 53 seconds another laptop is stolen in the USA.
  • At least 600,000 laptops are stolen each year in the USA. 
  • Hardly any (3%) stolen laptops are ever recovered. 
  • Laptop computer theft trails only identity theft as the most common crime. 
  • Almost half of all data leaks and breaches are the result of lost or stolen portable computers, according to a study by The Identity Theft Resource Center .
  • Laptops are the number-one item stolen in San Francisco – San Francisco Police Department.
  • The Identity Theft Resouce Center’s recent list of 397 significant data breaches so far for the year of 2009 includes 51 healthcare breaches that compromised almost 9 million records.

Most of the sources of these data are trying to sell a security solution of one sort or another, but the vulnerability of laptops, especially in transit, is obvious. I don’t have any statistics for burglaries of computer systems from offices, but I’ll wager that most of you either know of a victim of such a crime, or have been a victim yourself.

Long before HIPAA, health professionals – especially mental health professionals – had a professional responsibility to safeguard the privacy of their patients/clients and the confidentiality of the personal and clinical information in their custody. HIPAA came along and increased our awareness of the special risks of electronic records and communications, defining Protected Health Information (PHI) at a federal level and providing some rules and guidelines for securing PHI stored or transmitted in electronic form. Now the Health Information Technology for Economic and Clinical Health Act (HITECH) has arrived and adds some pretty sharp teeth to HIPAA’s privacy and security rules.

If you need a push to get you to take privacy and security compliance seriously, consider the following from Section 13402 – Notification In The Case Of Breach. (This section is from HITECH/HIPAA: Notification in the case of breach at lawtechtv.com (a site I would strongly recommend that you visit). The bold italics are mine:

If PHI is secured as per the guidance then providers have a “safe harbor” and the notification requirements are not triggered in case of a breach. Despite the safe harbor, other federal and state PHI laws remain in full force and effect. Any PHI not secured as per the guidance is considered to be unsecured PHI whose breach will trigger the notification requirements. 13402(a): Covered Entities (CE’s) must notify individuals. 
13402(b): Business Associate’s must notify CE’s. 
13402(d): Notification must be no later than 60 days after discovery. 
13402(e): Specific notification methods are required depending on the number of individuals whose PHI was breached. 
13402(f): the notification must contain specific content.
13402(h): unsecured PHI* means PHI that is not secured through: 1) encryption; and/or 2) destruction—as provided by HHS guidance. Methods must render PHI “unusable, unreadable, or indecipherable” to unauthorized individuals (see HIPAA Security Rule  & NIST standards).

If PHI is secured as per the guidance then providers have a “safe harbor” and the notification requirements are not triggered in case of a breach. Despite the safe harbor, other federal and state PHI laws remain in full force and effect. Any PHI not secured as per the guidance is considered to be unsecured PHI whose breach will trigger the notification requirements.

If over 500 individuals’ PHI has been compromised then the media must be notified and the Secretary of HHS as well.

Breach: “the unauthorized acquisition, access, use or disclosure of PHI which compromises the security or privacy of such information, except where an authorized person to whom such information is disclosed would not be able to retain such information.”

Do you really want to have to choose between:

  1. Significant civil penalties (between $100 and $50,000 per violation, up to $1.5 million maximum per incident) and …
  2. Publishing in the local media a notice of your failure to protect your patients’ private information?

Of course not! Why not take advantage of the explicitly defined safe harbor? If the hard drive of that missing laptop has been encrypted, using appropriate technology, then there is no notification requirement at all! The same technology can be applied to every hard drive in your organization, especially the servers on which the bulk of the PHI resides. There are numerous commercial disk encryption approaches available, as well as free, open-source solutions such as TrueCrypt, that would provide you with the protection you want and owe to your patients, all penalties aside.

My previous post regarding encryption resulted in no reader response whatsoever. Does this information about your notification responsibilities make it more likely that you will move forward with data encryption? If not, why not?

The Devil and Database Encryption

Most every week I have a call from my credit card company’s security department to see if the recent activity on our account is actually ours. We used to get these calls maybe a couple of times a year, but now it is literally weekly.

A while back our credit card processor for SOS transactions notified us of new, stricter, security measures that we must follow or face the possibility of very substantial penalties. As a result, our customer credit card transactions now live in an encrypted database on a standalone computer that is not connected to our network or the Internet, and authorizes charges through a quaint dial-up modem connection directly to the processor’s system.

Arguably, financial data is a more tempting target for bad guys than most healthcare information, but there is little question that any data stored and moved around via electronic means is vulnerable. HIPAA requires that covered entities, and soon, business associates, take steps to determine the potential risk to the data that is in their systems, and to address the risk through a variety of security measures. These measures run the gamut from locked doors, user access passwords and workstation timeouts, through military-grade data encryption.

I have been thinking a good bit about the last of these: encryption. From CMS’s summary in HIPAA Security Series, Security Standards – Technical Safeguards (page 6-7):

4. ENCRYTION AND DECRYPTION (A) – § 164.312(a)(2)(iv)
Where this implementation specification is a reasonable and appropriate safeguard for a covered entity, the covered entity must:
“Implement a mechanism to encrypt and decrypt electronic protected health information.” (EPHI)

Encryption is a method of converting an original message of regular text into encoded text. The text is encrypted by means of an algorithm (i.e., type of procedure or formula). If information is encrypted, there would be a low probability that anyone other than the receiving party who has the key to the code or access to another confidential process would be able to decrypt (i.e., translate) the text and convert it into plain, comprehensible text.

There are many different encryption methods and technologies to protect  data from being accessed and viewed by unauthorized users.

  • Sample questions for covered entities to consider:
    Which EPHI should be encrypted and decrypted to prevent access by persons or software programs that have not been granted access rights?
  • What encryption and decryption mechanisms are reasonable and  appropriate to implement to prevent access to EPHI by persons or software programs that have not been granted access rights?

Generally, the safeguards you are expected to implement scale proportionately to the risk and the size of your organization. Thinking about the data stored in your billing and EMR systems, you would have to judge the risk to your data as very high if you have the database installed on a notebook computer that is routinely carried around by a staff member. Likewise, data moved across a network over a wi-fi connection would have to be considered as high risk. Even a solo practitioner or two person practice in either of these scenarios would probably be seen as negligent if the data were not protected by available encryption technology.

In the case of the notebook computer, I would think that whole-disk encryption should be in force, as there are likely to be letters, emails, and other sensitive data on the system that would not be protected if just your practice management/EMR database were encrypted.  Microsoft includes its BitLocker encryption system in Windows Server 2008 and the high-end versions of Windows Vista and Windows 7, but there also are many third party disk encryption products that one could use.

Wi-Fi protection means that you should use the best possible wi-fi encryption technology, at this moment, WPA2, coupled with a truly random password. Doing so would prevent virtually anyone “eavesdropping” on your wireless traffic from extracting meaningful information.

The correct path is not so obvious when it comes to encryption of primary databases, especially in the offices of small providers without dedicated IT personnel. Encryption is seeded by a string of characters, similar to a password or passphrase, called an encryption key. It is analogous to the key to your home or office, except that you can’t just break a window or call a locksmith if you lose the key. Good encryption is, for all practical purposes, impossible to crack. So, although the conscientious provider or practice owner’s first impulse probably would be to strongly encrypt, the risk analysis should include the risk of losing the encryption key, and therefore access to all the data stored in the database! The end result would be the same as a catastrophic hard drive failure with no backup — complete data loss and a very serious HIPAA violation.

Database encryption is only workable, therefore, in the presence of a formal, well-considered, bullet-proof procedure for encryption key management. Google that last phrase (“encryption key management”) and you will see that there are government documents several hundred pages in length that describe the procedures that must be followed to assure that  keys are both secure, and also readily available to those who need them.

To encrypt or not to encrypt? Devil or deep blue sea? What do you think? There are simple, keyless encryption schemes that are not terribly secure. Do you use something like that? Do you have a proven procedure for key management that you would be willing to share? You could lock your server in a bank rated vault, but then what if you forget the combination? We are back where we started! Anyone have any answers? Please click the title of this entry and leave us your comments.

Personal vs. Professional: Social Networking Sites

I checked my email on Sunday night to find two new requests for “friend” status on my Facebook page…one was from a customer, the other was from my mother-in-law. The juxtaposition of requests brought directly home the conflict and confusion that some folks are having about use of the social media sites. Is your use personal or professional? Is it acceptable to mix the two? Would you and your contacts be better served if you have two separate online identities, a personal one and a professional one?

I am a firm believer in synchronicity. I think of Carl Jung and his notion of synchronicity (an acausal connection of events in time) often as I experience the unexpected confluence of events. This weekend was no exception.

  1. On Friday, I had time (for the first time in weeks) to tune in to HubSpot TV, a podcast done by staff members of the Internet Marketing firm whose products and services I use. They mentioned this issue of social media utilization and the possible need to keep one’s “identities” separate. One of their blogs addressed the issue on Friday and the author lays out some considerations.
  2. On Friday evening, my partner, Seth Krieger, suggested that I write a blog on social media and professional vs. personal concerns.
  3. On Sunday I got the Friend requests I mentioned above.
  4. This morning I looked at two print newspapers I receive: The New England Psychologist ran an article featuring input from Thierry Guedj, Ph.D., “Psychologists navigate use of online social networking sites“; and The National Psychologist included John Grohol, Psy.D.’s article “How ‘tweet’ it is: Social networking using Twitter”. Both of these psychologists explore some of the concerns unique to providers in the behavioral health community.

This confluence of events was impossible for me to ignore. I have found myself thinking about these issues often over the past several months. Since I began use of social networking as a way to spread our business presence more broadly on the Internet, the differences between personal and professional presence have been playing around the periphery of my mind.

While I have not seen clients for the last 16 years, I was trained as a psychologist and saw patients in a private practice and in a CD program setting from 1978 to 1993. I am well aware that boundary issues are confronted regularly by psychotherapists charged with providing a safe space in which consumers of their services can deal with issues ranging from relatively minor personal problems to serious chronic mental health issues. Protecting that ‘space’ is part of building trust and of maintaining the privacy of the client.

The sanctity of that space is challenged regularly, sometimes by the spill-over of the therapist’s life into the therapy. Personal illness and family deaths are regular intruders, but many others exist. I hosted a live, call-in television show on psychology topics from 1981 to 1983. Some of my clients were proud of the public education work I was doing; others felt that they lost a part of me that they owned and were not happy to share me with the public. As a feminist psychologist treating lots of women, it was not unusual to cross paths with a client in the ‘real’ world. Prior agreements about how or whether to greet in public aside, face-to-face interaction outside the therapy space was often a cause for discomfort for me and for the client.

Those challenges to privacy are part of the physical community in which we live. Now we add the complication of a virtual world in which massive quantities of information, both personal and professional, are available to anyone who bothers to Google us. Factor into that the fact that we have no idea which information the client has. Each form of social media provides different challenges.

1. blog: A weblog, or blog, can be an excellent way for you to provide useful information to your own clients and to many others who see your blog articles. But if you go out there into the blogosphere and take a look at the material available, you will find that the writing styles are much less formal than other published documents, especially journal articles. Because of that informality, there can be a tendency to slip into personal revelation.

Potential benefits:
Great way to become more known in your community, to educate and share valuable information with your clients, and to provide a community service through public education.
Potential risks: Informal style of blogs can lead you to share more personal information than you would usually do in journals or in direct contact with your clients.

2. Facebook: When I started to use Facebook, I intended that use to be purely personal. My nephew’s wife invited me to join first. I resisted. When an age-mate with whom I share a book club and a social sphere invited me, I joined. Facebook has been great fun! I have connected with classmates, friends and family members. As with many people in my age group, my postings are rather tame. They do reveal personal relationships and history. I was a little conflicted when business associates asked for ‘friend’ status, but decided that I do not live a wild and crazy life and there is little about me on Facebook that I am not comfortable sharing with customers and other business associates.

Potential benefits:Facebook is a great way to keep up with new family photos and to stay in more frequent contact with friends and family members who are far away.
Potential risks: If you do live a wild and crazy life and do not want your clients to know that, do not give ‘friend’ status to those clients.

3. LinkedIn: LinkedIn is the only one of the social networking sites I use that is designed for professional purposes. It is professional networking, par excellence. If you want to connect with other colleagues, this is the place to do it. If you are looking for a job, this is certainly the place I would start. There are headhunters who frequent the site looking for the most qualified individuals for their position postings. You can join groups that meet your interests and connect there with other folks who have like concerns. 

Potential benefits: LinkedIn is a great place to network with other professionals. It is designed for peer-to-peer connections.
Potential risks: If your clients/patients are other professionals, you might run into them here and need to make some decisions about who your network should include or exclude.

4. Twitter: Twitter is something else. I am still not sure about Twitter. I use it in a purely professional way. In fact, the name under which I tweet is @SOS_Software. The people I follow are other professionals who have similar interests. Those other folks are great sources of information. The tweets I find most useful are about articles, blogs and news that is relevant to my professional world. Most of the people who follow me are also interested in healthcare and software. Sometimes, I get a follow from someone who seems totally unrelated to anything in which I am interested. I blocked the clearly pornographic Follow that appeared last week.
     The way I use Twitter is totally contrary to the way most young people use it. To folks who are used to text messaging for everything, Twitter is a way to disperse text messages much more broadly. You can let everyone in your network know your status all at one time. To me, this is useless. To many others it is an essential part of staying connected.

Potential benefits: This is an excellent way to disperse a communication to a large group of people at one time. You could use Twitter to communicate educational information to all of your clients at once.
Potential risks: Twitter is like Facebook. Everybody who follows you sees everything. If you intersperse personal messages with your professional ones, everybody who follows you still sees all of it.

What do you think about these social networking sites? Do you use them? Does your organization use them to keep in touch with consumers? What do you see as the potential benefits or glaring weaknesses of being connected 24/7?

One last word of advice: If you decide to jump into the sphere of social networking, decide whether you are going to do so as a professional or for your personal needs. Once you decide, choose your networking sites accordingly. If you want to do both, you might be best served by having two different social networking identities.

Data Security, Backup, and the HITECH Law

A question on one of the psychology listservs I follow got me thinking, yet again, about data security…and backup. The writer asked about the proper procedures to follow when patient psychotherapy treatment records are permanently lost. The question pertained to how the counselor in question should respond to the loss of all of their patient data from a mental health clinical record software program. Since we provide one such program, my attention was immediately attracted.

The other listserv members addressed three issues: recovery of the data from the hard drive, backup of the data, and re-creation of the records from scratch. Because of our experience with customers losing data due to computer failure, I focused yet again on data backup and database recovery. Added to my thoughts this time are the HIPAA requirements for securing protected health information (PHI) and the increased penalties in the HITECH portion of the stimulus bill (ARRA) for breach of privacy and security of PHI.

It is likely that you all remember that HIPAA requires healthcare providers (including psychiatrists, psychologists, social workers, mental health counselors, and community behavioral health organizations) to have in place procedures for securing the PHI of their patients. Most mental health workers with whom I am familiar focus on the privacy aspect of this protection; they see it as their responsibility to assure that the consumer’s information remains private. HIPAA also mandates that providers and their organizations have in place plans to protect the security of their physical data.

The National Institute of Standards and Technology (NIST) has produced Special Publication 800-66-Revision 1, “An Introductory Resource Guide for Implementing the HIPAA Security Rule.” A quick search of this document finds that the words “loss of data” are mentioned on pages 38, 77 and 98. The first mention is in a table describing the necessary contents of the Contingency Plan for data security, including a Data Backup Plan. The sections of this document that focus on the Contingency Plan and the Disaster Recovery Plan are the ones most concerned with electronic data storage.

If your organization, including your private practice of psychology or psychiatry, does not have a Contingency Plan and a Disaster Recovery Plan, however brief, you are living dangerously. And, of course, you must implement your plan to secure your PHI, not just have a plan.

How does this pertain to you? Let’s start with your data backup plan. What is it? Who in your organization is responsible to implement it? What are the consequences if it is not implemented?

One of our customers,   W. E. (Bill) Benet, Ph.D., Psy.D., Clinical Psychologist, Gainesville, FL  WEBenet.com | Assessment Psychology.com describes his experience and current backup strategy.

“I mentioned Eco Data Recovery in my previous note because I had to use their service a number of years ago after the hard drive on my main office PC mechanically failed and became inaccessible while backing up to a tape drive, corrupting the data on the tape. Fortunately, Eco was able to recover all of the data from the hard drive, by disassembling it in a ‘clean room’ and scanning the data off the individual platters. Luckily, the data on the hard drive hadn’t been corrupted, but it very easily could have been, and I would have lost years of billing records and reports.”

“But what about data that has become insidiously corrupted without being immediately obvious?”

“Today, I employ a simulated RAID backup strategy involving nightly network backups to two external USB drives, as well as from one PC to the other, AND continuous 24/7 incremental offsite backups, using Carbonite. Hopefully, if corrupted files are discovered days or weeks later, those incremental backups will save the day, at least for a while.”

Here at SOS Software, we all too often run into an organization where the principals thought they had an excellent data security plan, only to find out that their plan had not been effective or had not been implemented by the person(s) who were responsible to do so.

One of the obstacles we run into is the common belief that “it can’t happen to us.” We all know this is magical thinking; of course, it can and does.

Another often-believed myth is “I don’t really need to worry about data on my PC; data can always be recovered from a hard drive if there is a problem.” While this belief is sometimes true, it often is not. If the files lost when a computer crashes are in a complex, proprietary relational database, they sometimes are totally irretrievable. They are not text files where parts can be grabbed and some sense made of the data.

Our product uses Sybase ASA as its engine because that database creates a transaction log that can allow us to completely recreate every keystroke the user made…if the log file is intact. In fact, we use Sybase because of this capability to completely recreate the database if it is necessary to do so. As long as we have a usable starting point, we can restore the entire database from the log file…if we have an intact log file.

Two problems can intervene. 1. With our products as with many others, if the backup is done while the database is running, certain of the files are not backed up because they cannot be accessed completely. Some backup software products will tell you they can back up even when the program is running. That is not true with SOS products. 2. Hard drives often fail gradually becoming literally “flaky” over time. If key sectors of the log file are lost, it is impossible to recreate the database from the log, even if there has been no overwriting of the database.

Also, sadly, even folks who believe they responsibly make backups, never test those backups to assure they can be restored properly, and they often use the same backup medium overwriting old backups. If the hard drive has been gradually failing, destroying parts of the files as it goes, then backups of those bad files become bad too…all of this over time with no noticeable degradation of performance of the database.

Then the catastrophe occurs…a power surge or some other event causes a crash of the hard drive and the database will not restart when the computer is rebooted!

As indicated by comments on my post of November 19, 2008, The Indispensable Data Backup, among my readers are many folks who are sophisticated computer users who are responsible enough to use multiple methods of backing up their patient data. Using a rotating system of backing up with permanent, non-incremental backups created periodically and stored off-site, is crucial. The strategy we recommend is in document 125 on our main web site.

If you have never tried restoring from one of your backups, you have not completed the process. Unverified backups are useless backups. Useless backups equal insecure PHI. How big a risk taker are you?

Please add your comments by clicking on the title of this article and typing in the box at the bottom of the page.