Healthcare Workflow Management
Fine-tuning healthcare workflow management to make improvements in efficiency, productivity, and profitability can be a difficult task, but when successful, resources can be used more effectively, stress can be reduced, and patient throughput, patient satisfaction, and clinical outcomes can be significantly improved. The Importance of Healthcare Workflow Management The transition from files and charts to electronic medical record systems has helped ensure patient information is readily accessible at the point of care. EHRs are a central repository for all patient data and ensure accurate and up to date information is always available to inform healthcare decisions. EHRs have helped to improve productivity and efficiency, but EHRs alone are not the solution. Without effective healthcare workflow management and efficient and effective communications systems, it is difficult to unlock the full potential of EHRs. Healthcare workflow management to fine-tune hospital workflows is essential for removing redundancies that unnecessarily eat up hospital resources, delay the provision of...
Is PayPal HIPAA Compliant?
PayPal is HIPAA compliant for collecting payment from patients and plan members because HIPAA exempts entities that facilitate payments for healthcare or health plan premiums – however, PayPal is not exempted from HIPAA compliance for any other services it offers. Because PayPal will not enter into a Business Associate Agreement, covered entities should not disclose PHI when using these other services. In the text of the 1996 HIPAA Act, there is an administrative simplification provision relating to payment processing (§1179). This section states that the HIPAA Rules do not apply to banks and financial institutions when they are “authorizing, processing, clearing, settling, billing, transferring, reconciling, or collecting payments for health care or health plan premiums”. To eliminate questions about whether financial institutions qualify as business associates, the Department of Health and Human Services (HHS) later commented in the preamble to the Final Omnibus Rule that “the HIPAA Rules, including the business associate provisions, do not apply to financial institutions with...
Patient Workflow in a Hospital
A patient workflow in a hospital follows a patient through their entire hospital visit, from the point of admission to the point of discharge. During that healthcare journey a patient is likely to interact with many different healthcare professionals. It would not be unusual for a patient to interact with dozens of different employees in the hospital during a 7 day stay, including administration staff, nurses, physicians, and radiographers. Those healthcare professionals need to coordinate effectively throughout the patient journey in order to achieve goals for safety, quality, cost, and ensure a good patient experience. While strategies may have been adopted to ensure the smooth flow of a patient through the healthcare system, there are likely to be bottlenecks along the way that slow the patient’s journey. These bottlenecks slow down patient flow, which prevents hospitals from utilizing their resources effectively. One of the key problem areas is communication. Many hospitals are still heavily reliant on pagers and landlines to coordinate care and these outdated communication...
NY Attorney General Warns New Yorkers About Identity Theft Risk from PJ&A Data Breach
At least 4 million New Yorkers in New York City and Syracuse had their sensitive information stolen in a data breach at the Nevada medical transcription service provider Perry Johnson & Associates (PJ&A). The PJ&A data breach was announced earlier this month and has affected almost 9 million individuals across the United States. While the breach has recently been announced, hackers first gained access to PJ&A’s systems in May 2023. Hackers had access to data such as names, addresses, dates of birth, medical record numbers, hospital account numbers, admission diagnosis, dates/times of service, Social Security numbers, insurance information, and medical and clinical information. This week, New York Attorney General Letitia James issued a warning to all New Yorkers who have received a data breach notification from PJ&A to take steps to protect themselves against identity theft and fraud. New York healthcare providers affected include Northwell Health, the largest healthcare provider in New York, and Crouse Health in Syracuse. When a data breach occurs at a business...
BD Discloses Vulnerabilities in FACSChorus Software
Becton, Dickinson and Company (BD) has recently disclosed seven vulnerabilities in its FACSChorus software. The vulnerabilities are low- to medium-severity with CVSS scores ranging from 2.4 to 5.4. Successful exploitation of the vulnerabilities could allow an attacker to modify system configurations, access sensitive data, or access system components; however, in order to exploit the vulnerabilities an attacker would need to have physical access. The vulnerabilities, in order of severity, are: CVE-2023-29060 – Missing protection mechanism for alternate hardware interface – CVSS 5.4 Vulnerability is present in BD FACSChorus v5.0, v5.1, v3.0, and v3.1 – The workstation operating system does not restrict what devices can interact with its USB ports. The vulnerability could be exploited with physical access to gain access to system information and potentially exfiltrate data. CVE-2023-29061 – Missing authentication for critical function – CVSS 5.2 Vulnerability is present in BD FACSChorus v5.0, v5.1, v3.0, and v3.1. The workstation has no BIOS password....



