Monday, March 17, 2008

VoIP Billing Software

VoIP is an acronym for Voice over IP (Internet Protocol), or in more common terms, phone service over the Internet. Basically, it's a set of common Internet standards that allows a user's voice to be converted into small packs of digital data which can then be sent over computer networks. At the receiving end, VoIP computers reassemble the data packets back into a conventional audio signal that can be heard just as if on a regular telephone line. This is an online scheme that has been bubbling around the Internet community for the past few years. A major advantage of VoIP is that it avoids the tolls charged by ordinary telephone services.

There is VoIP billing software also that handles billing and other processes. This software can be used by all kinds of businesses. It helps in keeping track of customers, the bills to be sent to them and other such details through a protocol. This software has features like broadband phone, PC to phone, wholesale (termination), traffic exchange, international callback and prepaid calling cards that meet your VOIP business needs.

VoIP billing is tightly integrated with popular gateways, gatekeepers, proxies and soft switches from vendors like Quintum, Cisco, Sylantro, Veraz, Nextone, IPtel, Mera, and other compliant devices. Most telephony billing systems currently used today are based on non-IP standards, making them not equipped to handle or accurately bill for IP services; hence, VoIP billing rose to prominence. The reasons why most of the service providers and enterprises chose the VoIP billing software to expand their business is that it integrates the core functions like authentication, authorization, and accounting with vital functions that facilitate the effective management of all billing-related processes, like customers, services, finance, service distribution, reporting, traffic partners, and user rights.

VoIP billing software allows service providers and enterprises to expand their business by including cost-effective VoIP services in their offerings. It also enables the pre-paid or post-paid billing options for call usage and provides the ability to offer flexible call plans.

VoIP Billing Software provides detailed information on Billing Software, VoIP Billing Software, Chiropractic Billing Software, Free Billing Software and more. VoIP Billing Software is affiliated with HIPAA Complaint Medical Billing Software

Labels: , , , , ,

Friday, February 1, 2008

Electronic Medical Billing Software, HIPAA Compliance, and Role Based Access Control

HIPAA compliance requires special focus and effort as failure to comply carries significant risk of damage and penalties. A practice with multiple separate systems for patient scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. This article presents an integrated approach to HIPAA compliance and outlines key HIPAA terminology, principles, and requirements to help the practice owner to ensure HIPAA compliance by medical billing service and software vendors.

The last decade of the previous century witnessed accelerating proliferation of digital technology in health care, which, along with reduced costs and greater service quality, introduced new and greater risks for accidental disclosure of personal health information.

The Health insurance Portability and Accountability Act (HIPAA) was passed in 1996 by Congress to establish national standards for privacy and security of personal health data. The Privacy Rule, written by the US Department of Health and Human Services took effect on April 14, 2003.

Failure to comply with HIPAA risks accreditation and reputation damage, lawsuits by federal government, financial penalties, ranging from $100 to $250,000, and imprisonment, ranging from one year to ten years.

Protected Health Information (PHI)

The key term of HIPAA is Protected Health Information (PHI), which includes anything that can be used to identify an individual and any information shared with other health care providers or clearinghouses in any media (digital, verbal, recorded voice, faxed, printed, or written). Information that can be used to identify an individual includes:

  1. Name
  2. Dates (except year)
  3. Zip code of more than 3 digits, telephone and fax numbers, email
  4. Social security numbers
  5. Medical record numbers
  6. Health plan numbers
  7. License numbers
  8. Photographs

     

     

 

Information shared with other healthcare providers or clearinghouses

  1. Nursing and physician notes
  2. Billing and other treatment records

     

     

 

Principles of HIPAA

HIPAA intends to allow smooth flow of PHI for healthcare operations subject to patient's consent but prohibit any flow of unauthorized PHI for any other purposes. Healthcare operations include treatment, payment, care quality assessment, competence review training, accreditation, insurance rating, auditing, and legal procedures.

HIPAA promotes fair information practices and requires those with access to PHI to safeguard it. Fair information practices means that a subject must be allowed

  1. Access to PHI,
  2. Correction for errors and completeness, and
  3. Knowledge of others who use PHI

     

     

 

Safeguarding of PHI means that the persons that hold PHI must

  1. Be accountable for own use and disclosure
  2. Have a legal recourse to combat violations

     

     

 

HIPAA Implementation Process

HIPAA implementation begins upon making assumptions about PHI disclosure threat model. The implementation includes both pre-emptive and retroactive controls and involves process, technology, and personnel aspects.

A threat model helps understanding the purpose of HIPAA implementation process. It includes assumptions about

  1. Threat nature (Accidental disclosure by insiders? Access for profit? ),
  2. Source of threat (outsider or insider?),
  3. Means of potential threat (break in, physical intrusion, computer hack, virus?),
  4. Specific kind of data at risk (patient identification, financials, medical?), and
  5. Scale (how many patient records threatened?).

     

     

 

HIPAA process must include clearly stated policy, educational materials and events, clear enforcement means, a schedule for testing of HIPAA compliance, and means for continued transparency about HIPAA compliance. Stated policy typically includes a statement of least privilege data access to complete the job, definition of PHI and incident monitoring and reporting procedures. Educational materials may include case studies, control questions, and a schedule of review seminars for personnel.

Technology Requirements for HIPAA Compliance

Technology implementation of HIPAA proceeds in stages from logical data definition to physical data center to network.

 

     

     

  1. To assure physical data center security, the manager must
    1. Lock data center
    2. Manage access list
    3. Track data center access with closed circuit TV cameras to monitor both internal and external building activities
    4. Protect access to data center with 24 x 7 onsite security
    5. Protect backup data
    6. Test recovery procedure

     

     

  2. For network security, the data center must have special facilities for
    1. Secure networking - firewall protection, encrypted data transfer only
    2. Network access monitoring and report auditing

     

     

  3. For data security, the manager must have
    1. Individual authentication - individual logins and passwords
    2. Role Based Access Control (see below)
    3. Audit trails - all access to all data fields tracked and recorded
    4. Data discipline - Limited ability to download data

     

     

 

Role Based Access Control (RBAC)

RBAC improves convenience and flexibility of systems management. Greater convenience helps reducing the errors of commission and omission in granting access privileges to users. Greater flexibility helps implement the policy of least privilege, where the users are granted only as much privileges as required for completing their job.

RBAC promotes economies of scale, because the frequency of changes of role definition for a single user is higher than the frequency of changes of role definitions across entire organization. Thus, to make a massive change of privileges for a large number of users with same set of privileges, the administrator only makes changes to the role definition.

Hierarchical RBAC further promotes economies of scale and reduces the likelihood of errors. It allows redefining roles by inheriting privileges assigned to roles in the higher hierarchical level.

RBAC is based on establishing a set of user profiles or roles according to responsibilities. Each role has a predefined set of privileges. The user acquires privileges by receiving membership in the role or assignment of a profile by the administrator.

Every time when the definition of the role changes along with the set of privileges that is required to complete the job associated with the role, the administrator needs only to redefine the privileges of the role. The privileges of all of the users that have this role get redefined automatically.

Similarly, if the role of a single user is changed, the only operation that needs to be performed is the reassignment of the user profile, which will redefine user's access privileges automatically according to the new profile.

Summary

HIPAA compliance requires special practice management attention. A practice with multiple separate systems for scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. An integrated system reduces the complexity of HIPAA implementation. By outsourcing technology to a HIPAA-compliant vendor of vericle-like technology solution on an ASP or SaaS basis, HIPAA management overhead can be eliminated (see companion papers on ASP and SaaS for medical billing).

Yuval Lirov, PhD, author of Practicing Profitability - Network Effect for Revenue Cycle Control in Healthcare Clinic and Chiropractic Office: Scheduling, SOAP Notes, Care Plans, Coding, Billing, Collections, and Audit Risk (Affinity Billing) and Mission Critical Systems Management (Prentice Hall), inventor of patents in Artificial Intelligence and Computer Security, and CEO of Vericle.net - Distributed Billing and Practice Management Technologies. Yuval invites you to register to the next webinar on audit risk at BillingPrecision.com

Labels: , , , ,

Thursday, December 6, 2007

An Explanation of Medical Billing Software

Medical billing is an increasingly popular office or home-based small business opportunity that involves using skills and knowledge in medical terminology, insurance claims, and customer service to ensure that physicians and clinics receive payment from patients and insurance companies.

Whether working from home based small-businesses or at large hospitals, every medical biller utilizes medical billing software. Though still referred to as medical billing software, today’s electronic medical billing software is also more accurately called medical practice management software and covers many functions. Up-to-date medical billing software will generate a variety of reports based on data, manage appointments, as well as collect, transmit, and track billing information and payments. Current medical billing software will also make sure that records are kept in compliance with the Health Insurance Portability and Accountability Act security standards. When deciding on software to buy, compliance with this act is an important consideration and will help you steer clear of some of the software scam artists out there.

When considering software for a medical billing business, here are some things to ask yourself or potential suppliers:

• Does the software include the ability to manage several different accounts?
• Can the software handle multiple doctors or multiple offices?
• Does the software recognize current procedure and diagnosis codes and it is updatable for the future (very important!)

Many vendors will allow a trial use of their program to see if it fits your needs. You will also be able to address whether the supplier answers questions in a timely fashion and if the are helpful in a trouble-shooting situation. Remember that a good medical billing software suite will cost at least $500 so don’t be fooled by people trying to sell $50 products that don’t even function.

Though electronic billing is still mainstream, there is a movement towards online billing where a subscription is setup on the web allowing a paperless entry of patient information, claims, and more. This service will cost more than $200 per month so you have to research and weigh the benefits of a one time investment for electronic medical billing software that is local or the online web-based software that can be used from any web-connected computer or device.

Medical Billing Info provides comprehensive information about medical billing software, services, jobs and companies. Medical Billing Info is the sister site of Medical Billing Software Web.

Labels: , , ,