Call Us Today! 877-659-2467

MIPS, MACRA, and Risk Assessments

 

By Aris Medical Solutions

HIPAA Doctor EKG

MIPS (Merit-based Incentive Payment System) and MACRA (Medicare Access and CHIP Reauthorization Act) is designed to create better patient outcomes and reward those providers that accurately document the progress of their patients. This all sounds great but it takes additional time until this new workflow is established. This is very frustrating to providers who just want to take care of their patients. It is a “learned” function and can be dealt with accordingly if you keep your patience. I know what you are thinking…. and it is easier said than done.

So many practices think since “meaningful use” went away they no longer need to conduct a risk analysis. This is incorrect information. Part of the requirements are that you must still conduct a risk analysis or update the one you already have. When “updating” your risk analysis, be very careful. You are attesting that you have reviewed your vulnerabilities and mitigated those risks.

Conducting a thorough risk analysis is more than just checking a box. It is meant to assist the organization in identifying possible vulnerabilities so you have the opportunity to mitigate them to prevent data breaches. If you merely change the date on your risk analysis and later suffer a breach; that could come back to harm you. If you skip over this or do not take this seriously, you are literally putting your practice at risk.

The best way to tackle this elephant in the room is… one step at a time!

  1. Review your technology devices. Determine if anything has been or needs to be replaced and/or updated.
  2. Understand where and how data is created, accessed, and stored. This includes reviewing the workflow of everyone involved with PHI and ePHI.
  3. Conduct your risk analysis and update the risk management plan. If you choose to “update or review” your existing risk analysis, make sure you do not overlook anything.
  4. If you have not not done so already, create a Incident Response Team (IRT). Utilizing the Security Incident Report will help in determining whether the security incident should be treated as a data breach or not.
  5. When it comes to the actually MIPS documentation, there are organizations that will assist you at no cost to the practice. Don’t chance missing this opportunity to ensure your documentation is accurate.

For more information on how Aris Medical Solutions can help your organization with HIPAA Compliance and Protecting your Data call 877.659.2467 or click here to contact us.

“Protecting Organizations through Partnership, Education, and Support”

About Suze Shaffer

Suze Shaffer is the Owner and President of Aris Medical Solutions, a healthcare compliance company dedicated to simplifying HIPAA compliance. Through its online compliance solution, the HIPAA Keeper™, Aris Medical Solutions provides healthcare providers and business associates with the tools, documentation, training, and expert guidance needed to achieve and maintain HIPAA compliance.

Through the HIPAA Keeper™, Aris has assisted organizations nationwide with conducting risk analyses, developing risk management plans, implementing HIPAA Privacy and Security policies and procedures, and strengthening safeguards for protected health information. Aris Medical Solutions also considers applicable federal and state privacy and security requirements to help clients build a more comprehensive compliance program.

Suze is also a speaker and has presented at numerous conferences and professional events on HIPAA compliance, cybersecurity, risk management, and data breach prevention. Helping organizations understand their responsibilities and identify vulnerabilities before they result in a breach, audit, or investigation. She believes effective compliance begins with education. By helping organizations understand not only what they are required to do, but why those safeguards are important, organizations are better prepared to protect patient information and reduce their compliance risks.

At Aris Medical Solutions, the mission is simple: “Simplifying HIPAA” through education, expert guidance, and the HIPAA Keeper™, Aris Medical Solutions helps organizations turn complicated compliance requirements into a manageable, ongoing process.

The information provided reflects regulatory requirements and guidance available at the time of writing and is intended for educational purposes only. It should not be considered legal advice.

Share This HIPAA Blog

Why should I try to secure my data?

November 20, 2017

Two factor vs Two Step Authentications

January 20, 2018
©2026 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC