Practice Management Alert

Practice Management:

Design Effective, Ongoing Healthcare Compliance Training, Part 1

Your onboarding and continuing education should be more than just checking a box.

Healthcare workers have all been there at some point during the start of their careers: They run the gamut of required training in HIPAA, acceptance of kickbacks, organization-specific policies, and other required training in healthcare compliance. They usually take these during their job’s onboarding process, then perhaps annually thereafter. But is there more that organizations can and should do to strengthen accountability? Could such trainings be made even more effective?

This is an important subject because healthcare is a heavily regulated industry and for good reason. You handle sensitive health information daily, and the public expects you to exercise care with the data entrusted to you. Many laws impact your work. Therefore, it is up to you to ensure that employees understand these laws to maintain a compliant organization and a safe space for patients. An effective compliance program should help employees recognize privacy, billing, referral, and business risks before these risks become patient care, financial, or legal problems.

For organizations handling protected health information (PHI), submitting claims, managing physician relationships, or participating in federal healthcare programs, onboarding and continuing education should address both legal requirements and the organization’s actual risk profile. Therefore, let’s discuss ways to create effective systems.

Start With What’s Required

HIPAA law contains clear workforce training expectations, though it does not prescribe one universal training schedule. Under the HIPAA Privacy Rule, an organization that’s a covered entity must train its employees and management on its policies and procedures according to what’s necessary and appropriate to perform the functions of their jobs. New employees are required to be trained within a reasonable timeframe after joining the company and when a material policy or procedure change affects the employee’s job function.

Medical team meeting in conference room

Though it would not be possible to list examples of all the changes that could occur, organizations would want to keep up with such things regularly. If a certain technology used by the organization is now considered no longer suitable for adhering to the Privacy Rule, the organization will want to make their members aware of this as soon as practicable, even if it’s before the next annual training update.

The HIPAA Security Rule, which establishes national standards for safeguarding electronic PHI (ePHI), requires covered entities and business associates to put in place security awareness training for employees and management. These training programs should include security reminders, login monitoring, password management, protection against malicious software, etc. A big goal of the Security Rule is protecting an individual’s ePHI while at the same time allowing covered entities to adopt technology that improves the quality and efficiency of healthcare. The Security Rule is designed to allow flexibility in allowing covered entities to enact policies, procedures, and technologies appropriate for their size, structure, and unique ePHI risks.

The principle here is clear: Training should be tied to each employee’s responsibilities. For example, a coder, biller, nurse, physician, patient access specialist, compliance officer, and executive all need HIPAA education. However, these jobs do not entail the same day-to-day risks. Training should address each unique risk.

Separate Law From Best Practice

Many in the healthcare field have the idea that annual HIPAA training is required. But a more accurate statement would be: “HIPAA requires an appropriate program of employee and management training and ongoing security awareness.” The regulations do not establish a single annual program deadline for all covered entities.

Nonetheless, annual training is a popular organizational practice, as it is a predictable, systematic pattern to reinforce policies. In addition to reinforcing policies, annual training also provides the opportunity to introduce annual regulatory changes and organizational changes while documenting completion. The U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) General Compliance Program Guidance is optional and nonbinding; however, it identifies compliance program infrastructure and risk management as fundamental subjects for healthcare organizations to ponder.

This distinction is important because it shows that organizations should not treat a once-a-year course as proof that all compliance risks have been addressed. Rather, annual training can serve as a starting point and be supplemented by role-specific training as new risks are identified. Policy changes, audit results, incidents, or changes in job duties should all be taken into account when deciding when additional training should be given. Therefore, training should be viewed as an ongoing process throughout the year, according to identified risk and not just to comply with the letter of the law.

Build Role-Based Onboarding Programs

Practical onboarding curricula begin with identifying what an employee will need to access, decide on, document, approve, bill, or oversee. This approach avoids overwhelming them with information unrelated to their work while ensuring that higher-risk roles receive more in-depth instruction.

All employees will need the core orientation that includes the HIPAA Privacy Rule and the HIPAA Security Rule, their organization’s code of conduct, reporting structures, non-retaliation clauses, and disciplinary standards. Staff working with claims, medical records, reimbursement, vendors, or physician agreements should be given additional training tailored to those job-specific areas.

For instance, coding and billing staff may need training specific to documentation integrity, accurate coding, denial management, and False Claims Act risk. These staff members will need to understand the specifics of how these elements and the law impact their daily work. Leadership, contracting, and physician personnel may need training more focused on financial relationships, referral arrangements, acceptance of gifts or incentives, and when Stark Law or anti-kickback statutes come into play. These members will need to know when and how to consult with compliance or legal counsel.

It should also be recognized when cross-training is appropriate across multiple lines of business. For example, practice leadership and physicians should have some awareness of coding- and billing-specific risks. Likewise, coders and billers should also have some knowledge of financial anti-kickback statutes. Key staff members should have training that leans heavily on the areas they deal with regularly and lightly on areas they may encounter only occasionally.

Check back next month for part 2, regarding specific steps you may consider to bolster your compliance training.

Alvin R. Cureton, Jr., CPC, COC, CPMA, AAPC Approved Instructor