Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
27
28
30
1
2
3
4
5
6
7
8
9
11
12
13
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Forbes Healthcare Summit
2017-11-29 - 2017-11-30    
All Day
ForbesLive leverages unique access to the world’s most influential leaders, policy-makers, entrepreneurs, and artists—uniting these global forces to harness their collective knowledge, address today’s critical [...]
29th Annual National Forum on Quality Improvement in Health Care
2017-12-10 - 2017-12-13    
All Day
PROGRAM OVERVIEW The IHI National Forum on December 10–13​, 2017, will bring more than 5,000 brilliant minds in health care to Orla​​ndo, Florida, to find meaningful connections [...]
Dallas Health IT Summit
2017-12-14 - 2017-12-15    
All Day
About Health IT Summits U.S. healthcare is at an inflection point right now, as policy mandates and internal healthcare system reform begin to take hold, [...]
Events on 2017-11-29
Forbes Healthcare Summit
29 Nov 17
New York
Events on 2017-12-14
Dallas Health IT Summit
14 Dec 17
Dallas
Articles

Dec 11: Limit EHR copy-paste to reduce fraud risk

regenstrief institute and indiana university

Hospitals are employing safeguards to prevent electronic health record fraud and abuse to varying degrees, but must do more, according to a new report from the U.S. Department of Health & Human Services Office of Inspector General.

HHS contracted with RTI International (RTI) to develop recommendations to enhance data protection. The report looks at the extent to which hospitals are following those recommendations.

It found that efforts to protect data were aimed more at ensuring privacy rather than detecting fraud and abuse. The authors were especially concerned that too little is done to limit the use of EHRs’ copy-paste functions.

“Although the copy-paste feature in EHRs can enhance efficiency of data entry, it may also facilitate attempts to inflate, duplicate, or create fraudulent health care claims,” the report’s authors say.

EHR vendors reported that the copy-paste function in their technology cannot be customized or disabled. Hospitals complained that this limits their ability to restrict it to authorized users.

The report found:

  • Only 24 percent of hospitals had policies in place regarding use of copy-paste
  • 44 percent of hospital audit logs reported the method (copy-paste, direct text entry, speech recognition) of data entered into the EHR, as recommended
  • 61 percent shifted responsibility to the user to confirm that copy-pasted data was accurate
  • 22 percent advised EHR users to avoid “indiscriminately copy-pasting”
  • 21 percent of policies required EHR users to cite the original source of the copy-pasted data

In addition, the report found that:

  • Although nearly all hospitals with EHR technology had recommended audit functions in place, they may not be using them to their full extent
  • All hospitals employed a variety of RTI-recommended user authorization and access controls
  • Nearly all hospitals were using RTI-recommended data transfer safeguards
  • Almost half of hospitals had begun implementing RTI-recommended tools to include patient involvement in anti-fraud efforts

It recommended that the Office of the National Coordinator for Health IT and the Centers for Medicare & Medicaid Services strengthen their collaborative efforts to develop a comprehensive plan to address fraud vulnerabilities in EHRs and that CMS develop guidance on the use of the copy-paste feature in EHR technology.

A California radiologist was fined more than $7 million for fraudulent radiology reports in which untrained staff cut and pasted the signatures of board-certified radiologists without their knowledge or permission, then submitted the reports for billing.