Tuesday, March 6, 2018

Wicked Problems

They are called "wicked" problems.   In our world, there are many examples.   Inequality, illiteracy, terrorism, poverty, homelessness, famine and disease.  

The literature is filled with discussions, definitions, models and frameworks, of course, but in an effort to dissect this literature,  I recently used an online tool to test my ability to explain "wicked" problems in a new way.   The tool only allows you to use the Ten Hundred  most commonly used words in the Oxford English Dictionary (Note: the word "Thousand" isn't on the list.)  The process was developed by scientists who wanted to help people in better describing and understanding hard ideas.  

The links to some of the relevant literature, in addition to the online editor tool itself, are set out at the conclusion of this, my "top ten" wicked problem list, which still makes me smile today.  Enjoy.    


  1. A hard problem is a very large human problem.
  2. A hard problem can't be fixed for many reasons. First, a hard problem has deep and dark corners. Second, a hard problem is not easily understood because there are missing words and ever-changing meanings. Third, there are too many people who can't come together and agree on how to fix it.
  3. A type of hard problem is a world that can't grow food or find clean water. Another type is people who can't read or who always fight. Another type is people who have no money, no job or no home. Another type is people who are scared or sick.
  4. Every hard problem happens because of another hard problem.
  5. Different from hard problems, an easy problem can be understood and fixed. Even if not simple, an easy problem is like putting a human in a new place in the world or making children able to stop being sick.
  6. Trying to fix an easy problem either works or it doesn't. Trying to fix a hard problem is not the same -- things either get better or they get worse -- which is not always easy to see or like.
  7. Fixing a hard problem doesn't always last and it may cause or add to other hard problems, which makes most fixes hard to trust or accept, and easy to fight, for three reasons. First, humans often believe that the fix will only make the problem worse. Second, humans often believe that the fix is hard to do and it won't matter anyway. Third, humans often believe that the fix needs too much money and that we will lose more than we get in return.
  8. The real world of trying to fix hard problems is just that - hard. The problems always continue, change and grow, and the fixes never completely work, and the humans do not agree on anything.
  9. However, any human idea not to act or to try to fix a hard problem is also a big problem. 
  10.  All we can do is work together, and to try as best we can to try the fix the hard problems and to make our way forward in this crazy, yet amazing, world.



How good are you in explaining the many "hard ideas" in health care or otherwise?   Give this tool your best shot next time you're working on a fresh message that just might reach your audience.  

Links:

Gawande, Atul (2012). "Something Wicked This Way Comes," The New Yorker (June 28, 2012).
Hirschman, Albert O. The Rhetoric of Reaction: Perversity, Futility and Jeopardy. Belknap Press (2004).
Kolko, Jon, Wicked Problems, Problems Worth Solving. Austin Center for Design (2012).
https://www.wickedproblems.com/
RIttel, Horst W. J.; Webber, Melvin, M. (1973). "Dilemmas in a General Theory of Planning", Policy Sciences 4: 155-169.
Up-Goer Five Text Editor:  http://splasho.com/upgoer5/

Sunday, January 28, 2018

Recent OCR Resolution Agreement and HIPAA Corrective Action Plan ... Lessons Learned

During December 2017, the Health and Human Services' Office of Civil Rights ("OCR") entered into yet another Resolution Agreement after investigating a serious breach incident involving the electronic protected health information ("e-PHI") of over 2 million patients that was maintained by a Florida health care organization. https://www.hhs.gov/sites/default/files/21co-ra_cap.pdf   As with so many other past investigations, the OCR made findings that the organization lacked a thorough HIPAA security risk assessment or the necessary security measures and review procedures to safeguard the  e-PHI maintained on the organization's information system.  Lastly, the OCR determined that the organization had disclosed PHI to third party vendors, acting as business associates, without obtaining satisfactory assurances by way of written business associate agreements.

Under the terms of the Resolution Agreement, the organization was required to pay OCR $2,300,000 to settle the potential civil money penalties associated with the above violations.  Additionally, the Resolution Agreement required the organization to enter into a Corrective Action Plan ("CAP") for a two (2) year term that set forth the following terms and conditions:

  1. Compliance Representative.  Designation of an individual Compliance Representative ("CR") responsible for the direction and oversight of the organization's CAP implementation; 
  2. Security Risk Analysis/Risk Management Plan.  Completion of a thorough risk analysis and risk management plan and documentation of all security measures implemented to reduce all identified risks and vulnerabilities to a reasonable and appropriate level, all within 120 days of the CAP implementation date; 
  3. Policies and Procedures.   Review and revision of certain of the organization's HIPAA policies and procedures with copies submitted to OCR within 90 days, subject to OCR approval; 
  4. Distribution of Policies and Procedures to Workforce.  Adoption and distribution of OCR-approved policies and procedures to all existing and newly hired workforce who were subject to the requirements; 
  5. Ongoing Review and Update of Policies and Procedures.    Routine review and update of these policies and procedures to reflect any changes in applicable requirements, the organization's operations or other OCR guidance; 
  6. Business Associate Accounting/Agreements.  Completion of an accounting of all business associates, in addition to execution of all necessary business associate agreements, with copies submitted to the OCR within 120 days of the CAP implementation date; 
  7. Written Plan for Internal Monitoring of CAP Compliance.    Adoption of a written plan to internally monitor the organization's compliance with the CAP, a copy to be submitted to OCR within 60 days of the CAP implementation date, subject to OCR approval, all of which requires ongoing review and update to reflect any changes in applicable requirements, the organization's operations or other OCR guidance; 
  8. Assessor.    Selection and engagement of a duly qualified "assessor" within 60 days of the CAP implementation date, subject to OCR approval, who is responsible for implementing a written plan that complies with the "assessor's plan" requirements set out in the CAP, again subject to OCR approval, all of which shall result in ongoing assessor "reviews" that are submitted to OCR in regard to the organization's continuing compliance with the CAP; 
  9. Record Retention.   Record retention obligations on the part of the organization, the compliance representative and the assessor; 
  10. Validation Reviews. Agreement to permit OCR, in its discretion, to conduct any validation review necessary to confirm any assessor review or report; and
  11. Mandated Reporting Obligations.    Internal reporting obligations that require all workforce with access to the organization's e-PHI databases to report to the compliance representative any violation of the organization's HIPAA related policies and procedures that come to their attention, all of which shall be investigated and reported to both the assessor and OCR to the extent any investigation confirms a violation that qualifies as a reportable event.  
Much like the terms and conditions of a Corporate Integrity Agreement, entered into by health care entities and the Health and Human Services' Office of Inspector General ("OIG") , this CAP sets out a very stringent process by which the health care organization is required to implement, monitor and update its HIPAA compliance program under the direction of a designated "compliance representative" and subject to the ongoing review of the OCR and an external "assessor" process.  For any HIPAA covered entity or business associate that has endured a reportable breach incident, the prompt implementation of an internal corrective action plan that incorporates many of these interventions may be a very useful (and proactive) risk management tool, even before any OCR investigation or other involvement becomes necessary.   Lessons learned.  


Sunday, January 21, 2018

HIPAA Security ... Integrity Matters

The HIPAA Security Rule requires Covered Entities and their respective Business Associates to maintain certain Administrative, Physical and Technical safeguards to protect Electronic Protected Health Information ("e-PHI").  Specifically, these safeguards are designed to ensure the Confidentiality, Integrity and Availability of all e-PHI that is created, received, maintained or transmitted by the Covered Entity or its Business Associates.  45 CFR 306(a).

Whereas the Security Rule's Confidentiality requirements support those of the HIPAA Privacy Rule, the two additional goals  -- Integrity and Availability -- are also equally important.  According to the Security Rule, the term "Integrity" means that e-PHI is not altered or destroyed in an unauthorized manner.  The term "Availability" means that the e-PHI is accessible and usable on demand by an authorized person.  45 CFR 164.304.   

Beyond HIPAA, the term "integrity" hails from the Latin word "integer" and typically carries two definitions in most English dictionaries.  The first definition concerns a quality -- the quality of "being honest and having strong moral principles; moral uprightness."  The second definition concerns a state of being -- the state of "being whole or complete, undivided."   For purposes of this discussion, the second definition is most closely aligned with the Security Rule definition.  

HIPAA policies must specify the Administrative, Physical and Technical safeguards that have been adopted to safeguard the Integrity -- or the accuracy and completeness -- of a particular individual's e-PHI.  At a minimum, these policies should incorporate the following:  

  1. A glossary of defined and capitalized terms that incorporates the definitions arising under HIPAA and any other more stringent requirements that hail from state law (e.g., Designated Record Set ("DRS"), e-PHI, Electronic Media, etc.) plus any Covered Entity-specific definitions which typically address, for example, such things as the "legal health record" which is different from the DRS and represents the official business record of the entity for evidentiary purposes (*); 
  2. A provision that addresses the procedures for identifying and managing any erroneous or replaced e-PHI that has been relegated to an "obsolete" folder that technically remains a part of the legal health record;
  3. A provision that incorporates the most stringent record retention requirements adopted by the covered entity, whether under HIPAA, state law or at the direction of the entity's  legal counsel (e.g. legal hold) and/or professional liability carrier (e.g. litigation); and
  4. A provision that addresses the procedures for identifying and managing the destruction of any data following the expiration of all mandated record retention requirements.  
It remains my premise that the adoption of these and other HIPAA policies safeguards not only the state -- or the "big I" Integrity -- of the Covered Entity's information systems but also the quality -- or the "little i" integrity --  of those individuals who conduct patient care and related business operations on behalf of the Covered Entity, all in accordance with applicable requirements.  Truly a win-win in today's complex world.  


(*)  Note:  The DRS includes all PHI whereas the legal health record typically only includes the PHI used to make Treatment decisions.  For additional information, see AHIMA. "Fundamentals of the Legal Health Record and Designated Record Set." Journal of AHIMA 82, no.2 (February 2011): expanded online version.

Monday, January 1, 2018

That Tight Shoe

We brought in the New Year last eve, dining at one of our favorite little Italian restaurants, sitting at the bar eating probably the best Bucatini all’ Amatriciana in town.  We talked about the decision to look forward -- not back -- and to celebrate the many next generation(s) of family, friends, neighbors, students, colleagues, clients and others who continue to give meaning to our life. 
            
Trust me, it often requires intention (aka attitude) to celebrate the future and to shape our life experiences going forward.  To keep my momentum, I long ago posted a one-page chart from a well-worn book above my standing desk.  The chart lists numerous traits or symptoms that best describe both an “Open” and a “Contracted” life experience …

OPEN
CONTRACTED
Ease
Effort
Prevailing trust
Constant worry
Relaxed body
Congestion
“Can do” attitude”
“Can’t happen” attitude
Collaborative
Competitive
Curious, asking questions
Judgmental, defensive
Sees opportunities
Sees obstacles
Generous
Withholding
Willing to take risks
Hyper-cautious
Laughs easily at self
Takes self too seriously
Energized
Exhausted
Fighting FOR
Fighting AGAINST
Resilient
Resigned
Grateful
Keeping score
Releasing things easily
Hanging on
Makes clear requests and agreements
Unspoken or value expectations
Generative, accountable
Consumptive, “victim”
Wholehearted, courageous and bold
Conflicted, fearful and timid
Victoria Castle, The Trance of Scarcity (2007)

To celebrate the future is like taking off that tight shoe.  It is a choice that does not happen by itself -- it requires not only intention but also action, especially during these complex times.  For that, be bold and remember Mr. Wendell Berry’s words which always spur me on … “It may be that when we no longer know what to do, we have come to our real work and when we no longer know which way to go, we have begun our real journey.”   Happy New Year. 


Friday, January 13, 2017

HIPAA Business Associates ... How Do I Know Thee?

HIPAA, as amended by HITECH, imposes significant requirements on those persons or entities who qualify as a business associate (BA) as a result of their access to protected health information (PHI) in the performance of services on behalf of a covered entity (CE). 

For example, a BA could be a third party billing company, a shredding company, a law firm handling a Medicare audit appeal, a health care design consultant responsible for re-design of an emergency triage process, or even a third party responsible for storing PHI off-site. In each case, the drafting and negotiation of a business associate agreement (BAA) is an important step in confirming BA duties and obligations related to these service arrangements.   Some level of due diligence is also important before the BAA is executed and the CE is in a position to trust the BA with its PHI.  
To begin, the CE should confirm any and all names that have been used by the BA, whether now or in the past, so to confirm that none of these names are listed in the Office of Inspector General’s List of Excluded Individuals and Entities (OIG) or the General Services Administration’s System for Award Management (SAM), formerly known as the Excluded Parties List System.  
A review of the OIG Corporate Integrity Agreement database can also confirm any prior enforcement actions that may have involved a prospective BA. Additionally, if the BA maintains certain licenses, registrations or other credentials necessary to perform their services on behalf of the CE, these qualifications should be verified by the CE. Review of business references or a telephone interview with another CE may also be helpful.   
Proof of insurance coverage and some information about claims history should be requested. A general search for any public filings about the BA can provide additional information about their resources, business relationships and reputation. The BA may also be asked to disclose any outside business relationships which might represent a conflict of interest in doing business with the CE.   
Because the BA is subject to HIPAA, as a result of the HITECH amendments, the CE should inquire about the BA’s HIPAA compliance program, including but not limited to the recent completion of a HIPAA security risk assessment process, the adoption of HIPAA policies and procedures, and the extent to which the BA will engage the services of subcontractors to assist in the performance of services. Although not a HIPAA consideration, many CEs take additional steps to confirm the health status of the BA who will have any physical contact with the CE’s workforce or clients, including but not limited to up-to-date vaccination records and negative TB testing results.   
The CE can conduct its due diligence using a range of techniques. The BA could be asked to submit to a formal request for proposal process or the CE may ask the BA to complete and return a due diligence questionnaire. Selected HIPAA compliance documents may be requested as well. Depending on the nature of services to be performed, an in-person interview or a site visit may be in order.   

Once the BA arrangement has been finalized, pursuant to the terms and conditions of the BAA, the CE should adopt certain safeguards to verify, on a regular basis, the identification of any and all persons who perform services, whether in-person or remotely, so to prevent any risk of an unauthorized actor gaining access to CE PHI.  

For example, the CE contracts with a third party shredding vendor.  On a regular basis, the vendor comes on premises and removes secured documents to be shredded.  Without confirming the identification of any vendor employees before removing the documents, there is a serious risk that a "rogue actor" could represent themselves as a vendor employee and walk away with the CE documents, resulting in a serious HIPAA breach incident.  In the case of a remote or electronic arrangement, the CE and BA should also maintain an up-to-date list of those individuals who are authorized to access CE PHI on behalf of the BA, subject to the host of safeguards required under HIPAA security.  
In summary, the use of a well-drafted BAA, in addition to the use of an effective due diligence process, not only makes for a proper introduction to the BA but also serves another important purpose in allowing the CE to educate the BA and to communicate the importance of HIPAA compliance long before the parties sign on the bottom line.   Additionally, after the BAA has been executed, the CE should also institute safeguards to ensure that only authorized individuals perform the designated BA services for the duration of the business relationship.  
If you have any questions or require additional information regarding the establishment of a HIPAA-compliant CE-BA business relationship, please contact me through Integrity Health Strategies.

Tuesday, May 24, 2016

Amateurs

I recently visited the Herman Miller headquarters outside Grand Rapids, Michigan as part of a board retreat for the Nursing Institute for Healthcare Design (NIHD).    Herman Miller has been an innovator in the furniture business for over 80 years.    I left the retreat with a copy of the book, Leadership Jazz, which was written by Max DePree, the former chairman of Herman Miller's board.   An inspiring read, I finished the book before my flight landed in Minneapolis.  

I especially enjoyed the chapter about amateurs.  Frankly, I think we are all amateurs -- curious individuals who like nothing better than learning something new, often with unexpected results.   DePree calls it the "beneficial surprise" that celebrates the amateur's fresh point of view and which often produces a "stunningly elegant solution."    One of my NIHD colleagues likens amateurs to disruptive innovators, the roving leaders who defy definition.  She is spot on.

In addition to my work as a health care consultant and professor, I delight in my work as an amateur. Of course, there are my Wabi Creations that I design as an aspiring maker/artist.   I also enjoy several volunteer roles.  In most cases, the organizations have invited me to the table and welcomed my commitment, my curiosity, my talents.   On occasion, I need a quick "integrity check" when someone refers to me as a "self-taught" in contrast to their formally trained, "professional" status.  Stay the course, Susan.  Stay the course.

Indeed, let's celebrate amateurs of all types.  Let's also celebrate the wise leaders who know enough to seek out, welcome and empower amateurs in their organizations.  According to DePree, "leaders can make a college, a business or any organization hospitable to the person without the usual credentials.  The trick is simply to look at merit naked.  Learn to hear the tune despite the noise."

Thank you for the pep talk for us amateurs, Mr. DePree.  Leadership jazz, indeed.




Tuesday, May 17, 2016

The HIPAA Phase 2 Audits ... Here's the Skinny!

The Health and Human Services' Office of Civil Rights (OCR) has initiated Phase 2 of the HIPAA Privacy, Security and Breach Notification Audit Program (Program).  

If you are a HIPAA Covered Entity (CE) or Business Associate (BA, here's the skinny ... 

1.   AUDIT PROCESS.  The Program involves a multi-step process: (a) verification of CE and BA contact information; (b) pre-audit questionnaire and random sampling process to select CE and BA audit subjects; (c) notification letter and document request; (d) desk review; (e) on-site review of CE and BA selected from desk reviews and otherwise; (f) draft report; (g) CE (or BA) comment period; (h) final audit report.  

2.   AUDIT PROTOCOL.  The Program uses an Audit Protocol that is organized around the Privacy, Security and Breach Notification Rules.    http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/index.html  

3.   AUDIT GOAL.  The primary goal of the Audits is to review the policies and procedures for CE and BA compliance with selected Rules.  As with the Phase 1 Audits, the process is a primarily a compliance improvement activity, however OCR may initiate a follow up compliance review, as necessary.  

4.  COMPLIANCE REVIEWS.  A compliance review may be initiated by the OCR following receipt of a complaint, a breach notification, a media report, an audit report or otherwise, for "no reason." The compliance review is a multi-step process that includes (a) written notification and document request; (2) desk review: (3) on-site review that includes observations, interviews and additional document review that may extend over several days; (4) closing conference.  As necessary, OCR can also initiate subpoenas and other inquiries, as necessary, to complete the process.  Violations identified as a result of the compliance review may result in voluntary compliance, corrective action and/or resolution agreements that may impose multi-year monitoring and civil money penalties, among other requirements, all subject to a fair hearing procedure.  

5.   AUDIT RESULTS.  OCR will not post a listing of audited entities or the findings of an individual audit which clearly identifies the audited entity. However, under the Freedom of Information Act (FOIA), OCR may be required to release audit notification letters and other information about these audits upon request by the public, subject to FOIA regulations.  

6.   AUDIT READINESS.   How best to prepare for the Phase 2 Audits?  Assemble an in-house work group, print a copy of the Audit Protocol and begin your own self-study of the current policies and procedures and the related forms and documentation that evidence compliance with these policies and procedures.  

Questions or other Phase 2 Audit readiness follow up, please contact Susan Ziel at Integrity Health Strategies -- sziel@ihsconsultinggroup.com or (317) 819-7704.