MSI Home Front Desk Health Records Billing Reporting ManageNet

HIPAA, the Health Insurance Portability and Accountability Act of 1996, was created to ensure the privacy, security and portability of health related information. Medical Systems has embraced both the spirit of these regulations and the specific rules by which a computer system should or must operate.


Transactions

Part of HIPAA’s mandate is protecting and establishing national standards for electronic healthcare transactions. This requires the industry to use one national standard electronic format and set of codes to exchange information.

Vision:CHC is fully compliant with the mandated formats for sending claims electronically (837 transaction set) and receiving remittances (835 transaction set).

Vision:CHC sends claims directly to payers and no clearinghouse is required. There is no additional charge for submitting claims with Vision:CHC.

All information required for submitting HIPAA-compliant claims are part of Vision:CHC. No additional software is required.


Privacy and Security

One of HIPAA's primary goals is to insure patient privacy with regards to their medical information. Several parts of Vision:CHC facilitate a community health center’s compliance with these aspects of HIPAA:

Role-based security: Vision:CHC allows a community health center to define "roles" with specific sets of authorized access to information with Vision:CHC. All functions of Vision:CHC can be included or excluded in these roles. Staff members are then assigned roles and passwords with which they individually log onto Vision:CHC. This method of security is mandated by the HIPAA Security Rule and highly suggested by the Privacy Rule. This method is very efficient for a community health center and yet provides a maximum amount of security by authorizing access only to those with a "need to know".

Accountability: All user actions within Vision:CHC are recorded and available for audit reports. A Patient Accountability report shows all access to a specific patient. And all audit reports show both what was changed and both the new and old values for each change.

Notice of Privacy Practices: Vision:CHC can record whether a patient has been given your Notice of Privacy Practices and if it has been signed. Automatic notices appear for those patients that have not yet signed their Notice of Privacy Practices. Several other fields either mandated by HIPAA or useful to a community health center’s operation are included such as Student Status, Release of Information, and others.

System Security: Medical Systems requires the server to be secure and to include a virus checker. Medical Systems will configure the server for maximum security and train the operators on the few functions they must perform which are, essentially, how to start and stop the server and check the backups. All communication to the server from outside the community health center is via a secure Virtual Private Network.