Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
29
30
31
2
3
4
5
6
7
8
9
10
8:30 AM - HIMSS Europe
11
12
13
14
15
16
17
18
19
20
21
22
26
27
28
29
1
2
3
4
5
6
e-Health 2025 Conference and Tradeshow
2025-06-01 - 2025-06-03    
10:00 am - 5:00 pm
The 2025 e-Health Conference provides an exciting opportunity to hear from your peers and engage with MEDITECH.
HIMSS Europe
2025-06-10 - 2025-06-12    
8:30 am - 5:00 pm
Transforming Healthcare in Paris From June 10-12, 2025, the HIMSS European Health Conference & Exhibition will convene in Paris to bring together Europe’s foremost health [...]
38th World Congress on  Pharmacology
2025-06-23 - 2025-06-24    
11:00 am - 4:00 pm
About the Conference Conference Series cordially invites participants from around the world to attend the 38th World Congress on Pharmacology, scheduled for June 23-24, 2025 [...]
2025 Clinical Informatics Symposium
2025-06-24 - 2025-06-25    
11:00 am - 4:00 pm
Virtual Event June 24th - 25th Explore the agenda for MEDITECH's 2025 Clinical Informatics Symposium. Embrace the future of healthcare at MEDITECH’s 2025 Clinical Informatics [...]
International Healthcare Medical Device Exhibition
2025-06-25 - 2025-06-27    
8:30 am - 5:00 pm
Japan Health will gather over 400 innovative healthcare companies from Japan and overseas, offering a unique opportunity to experience cutting-edge solutions and connect directly with [...]
Electronic Medical Records Boot Camp
2025-06-30 - 2025-07-01    
10:30 am - 5:30 pm
The Electronic Medical Records Boot Camp is a two-day intensive boot camp of seminars and hands-on analytical sessions to provide an overview of electronic health [...]
Events on 2025-06-01
Events on 2025-06-10
HIMSS Europe
10 Jun 25
France
Events on 2025-06-23
38th World Congress on  Pharmacology
23 Jun 25
Paris, France
Events on 2025-06-24
Events on 2025-06-25
International Healthcare Medical Device Exhibition
25 Jun 25
Suminoe-Ku, Osaka 559-0034
Events on 2025-06-30
Articles

Apr 25: EHR Incentive Audits-Common Questions on Timelines and Risk Profile

ehr incentive audits

By Jim Tate, EMR Advocate and Meaningful Use Audit Expert
Twitter: @JimTate
eMail: audits@emradvocate.com
Website: www.meaningfuluseaudits.com

In recent conversations with Eligible Hospitals (EHs) two questions seem to be coming up more and more concerning CMS EHR incentive audits. Let’s take them on one at a time.

How long can my CMS EHR incentive attestation be subject to an audit?

CMS is pretty clear that documentation used in support of an attestation should be saved for 6 years. “Documentation to support attestation data for Stage 2 meaningful use objectives and clinical quality measures should be retained for six years post‐attestation. Documentation to support payment calculations (such as cost report data) should continue to follow the current documentation retention processes.” Sounds to me that you could possibly be audited for up to 6 years after an individual attestation. Case closed.

If an audit is failed, does that make me more likely to be audited again in future years?

Ah, this is a good one and gets into the shady area of “risk profile”. CMS, for obvious reasons, is keeping their cards close to their chest on what makes up the “risk profile”.  There is another angle to this that touches not on risk of audits for future attestations but also on past attestations. Case in point, I was contacted last week about such a “look back” audit situation. The initial audit was performed on a 2012 attestation and notification was received of a Negative Determination in August 2013 based on one measure. They were then the subject of an audit based on an earlier (2011) attestation and were notified of failure in March 2014 on the exact same measure. It only makes sense that during an audit if it becomes obvious that there is evidence of a “problematic” attestation the same issue might exist in earlier attestations. Now I have no insider info on what makes up the “risk profile” but I can usually do a little reading between the lines. If you went through an 2014 meaningful use audit, and didn’t have a Security Risk Assessment, I would think there would be a chance you couldn’t provide it for prior attestations either. I’m expecting we will see more and more of these “look back” audits based on what is revealed during an initial audit. Just make sense to me.

Side note: At HIMSS in February I spoke with Elizabeth Holland (director CMS’ Health IT Initiatives Group) and Robert Anthony (deputy director of CMS’ Health IT Initiatives Group) at HIMSS this year and here’s what they told me: The majority of failed audits occur either for lack of having documentation of the MU measures or the Security Risk Analysis.   To address this critical documentation issue, we’ve now added a review of the Security Risk Assessment to our Mock Audit Services.  If you are interested in learning more about conducting a mock audit for your organization, please contact me at audits@emradvocate.com.

Source