36C24218R0567-007.pdf

PDF 543 KB Posted

Attached to
GLENS FALLS COMMUNITY BASED OUTPATIENT CLINIC Federal contract opportunity
Solicitation number
36C24218R0567
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 2

About this file

36C24218R0567 D.25 DOCUMENTATION AND CLINICAL RECORDS.pdf

View the file

Other files for this federal contract opportunity

Other files attached to GLENS FALLS COMMUNITY BASED OUTPATIENT CLINIC, newest first.
File Type Posted
36C24218R0567-0003000.docx DOCX document
36C24218R0567-0002000.docx DOCX document
36C24218R0567-0001000.docx DOCX document
36C24218R0567-012.pdf PDF
36C24218R0567-009.pdf PDF
36C24218R0567-003.pdf PDF
36C24218R0567-005.pdf PDF
36C24218R0567-010.pdf PDF
36C24218R0567-011.pdf PDF
36C24218R0567-006.pdf PDF
36C24218R0567-008.pdf PDF
36C24218R0567-004.pdf PDF
36C24218R0567-002.pdf PDF
36C24218R0567-001.docx DOCX document
36C24218R0567-000.docx DOCX document
Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

T-1

Department of Veterans Affairs Veterans Health Administration Washington, DC 20420

VHA HANDBOOK 1907.01

Transmittal Sheet

March 19, 2015

HEALTH INFORMATION MANAGEMENT AND HEALTH RECORDS

1. REASON FOR ISSUE: This Veterans Health Administration (VHA) Handbook provides basic health information procedures for managing the patient’s health record.

2. SUMMARY OF MAJOR CHANGES: Procedures have been revised to delineate new and additional specificity for health record documentation requirements, management of the health record, and management of health information.

3. RELATED ISSUES: VHA Handbooks 1907.03, 1907.04, and 1907.06.

4. RESPONSIBLE OFFICE: The Assistant Deputy Under Secretary for Health for Informatics and Analytics (10P2) is responsible for the content of this Handbook. Questions may be referred to 217-649-3691.

5. RESCISSIONS: VHA Handbook 1907.01, dated July 22, 2014, is rescinded.

6. RECERTIFICATION: This VHA Handbook is scheduled for recertification on or before the last working day of March, 2020.

Carolyn M. Clancy, MD Interim Under Secretary for Health

DISTRIBUTION: Emailed to the VHA Publications Distribution List on 03/23/2015.

D.25 DOCUMENTATION AND CLINICAL RECORDS

March 19, 2015 VHA HANDBOOK 1907.01 i

CONTENTS

HEALTH INFORMATION MANAGEMENT AND HEALTH RECORDS

PARAGRAPH PAGE

1. Purpose

2. Background

3. Scope

4. Definitions

5. Confidentiality of Information

6. Access to Health Records and Information

7. Information Security

8. Securing E-mail and Facsimile Transmissions

9. Employee Health Records

10. Compliance

11. Responsibilities

12. Management of Health Records

13. Authentication

14. Authorized Entries

15. Sensitive Health Records

16. Complete and Incomplete Records

17. Retention, Disposition, and Transfer of Records

18. Loaning Health Records

19. External Source Documents

20. Master Veteran Index (MVI)

21. Adverse and Sentinel Events and Close Call Reporting

22. Non-VA Medical Care

23. Research, Clinical Trials, and Experimentation

VHA HANDBOOK 1907.01 March 19, 2015 ii

CONTENTS Continued

PARAGRAPH PAGE

24. Disaster Recovery Plan

25. Electronic Health Record

26. Health Record Alterations and Modification

27. Comparison of: Update, Administrative Correction, Addenda, and Amendment Requests . 35

28. Documentation

29. Health Information Management (HIM)

30. Health Information Management Professional

31. Management of the Paper Health Record

32. Paper Health Record Maintenance

33. References

APPENDIX

A Definitions ............................................................................................................................. A-1

HEALTH INFORMATION MANAGEMENT AND HEALTH RECORDS

1. PURPOSE: This Veterans Health Administration (VHA) Handbook provides basic health information procedures for managing the patient health record. Procedures have been revised to delineate new and additional specificity for health record documentation requirements, management of the health record, and management of health information. AUTHORITY: 38 U.S.C. 305, 5723(d), 5727(9); 44 U.S.C. 3102(1).

2. BACKGROUND:

a. Under Title 44 United States Code (U.S.C.) 3102(1), VHA, by statute, must maintain complete, accurate, timely, clinically-pertinent, and readily-accessible patient health records, which contain sufficient recorded information to serve as a basis to plan patient care, support diagnoses, warrant treatment, measure outcomes, support education, research, and facilitate performance improvement processes and legal requirements.

b. The most current standards of The Joint Commission must also be followed, unless specifically otherwise stated.

c. The health record must be standardized with regard to content, creation, maintenance, management, processing, and expected quality measures. Electronic capture and storage of patient health information must be implemented to enhance access to patient data by health care practitioners and other authorized users. Electronically stored and printed patient information is subject to the same medical and legal requirements as handwritten information in the health record.

d. The privacy and security of patient information stored in any media must be protected in accordance with, but not limited to: the Privacy Act of 1974 (5 U.S.C. 552a), the Freedom of Information Act (5 U.S.C. 552); Federal Information Security Management Act (44 U.S.C.

3541); Office of Management and Budget (OMB) Circulars A-123 and A-130; VA Directive and Handbook 6500 Managing Information Security Risk: VA Information Security Program; Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules (Title 45 Code of Federal Regulations (CFR) 160, and 164); VHA Handbook 1605.1, Privacy and Release of Information; and The Joint Commission standards for privacy and security.

e. In accordance with Department of Veterans Affairs (VA) Handbook 6500, regarding the Information Security Program, local safeguards must be established concerning patient record security and confidentiality.

3. SCOPE: This Handbook provides guidance for managing health information and the health record.

4. DEFINITIONS: See Appendix A.

5. CONFIDENTIALITY OF INFORMATION:

a. All staff with access to patient information in the performance of their duties needs to know their responsibilities in maintaining the confidentiality of VA sensitive information, especially patient information, by completing the annual Cyber Security and Privacy training.

b. Under 5 U.S.C. 552a, patient health records are confidential regardless of medium. The privacy of patient information must be preserved and the information must not be accessible to, or discussed with, any unauthorized persons, nor is the information to be discussed in public areas.

c. Every VA employee with access to patient health records in any medium is responsible for the proper use, disclosure, and handling of the patient health records (see VHA Directive 1605, VHA Privacy Program, and VA Directive 6500, Managing Information Security Risk: VA Information Security Program). VA employees are also accountable for safeguarding patient confidentiality and privacy; failure to do so will result in administrative action, up to and including, termination or other legal adverse action.

d. VA employees must transport patient paper health records within the health care facility using a secure means, such as locked bags. Patient names and Social Security Numbers (SSN) located on the outside of the paper health record must be protected from incidental viewing by the public while in transport. Patient health records must be in control at all times by the VA employee and not left unattended in any public area. Where resources are not available, the patient may transport the patient’s own health record, as long as reasonable safeguards, approved by the Chief, Health Information Management (HIM), or facility Privacy Officer, are in place to ensure confidentiality and to maintain integrity of the health record. NOTE: VHA is minimizing the risk of identity theft and fraud by eliminating the unnecessary use of the SSN as an identifier, when possible.

6. ACCESS TO HEALTH RECORDS AND INFORMATION:

a. Access to health information is controlled, based upon specific criteria, to ensure integrity, minimize the risk of compromising confidentiality, and increase reliability. Only minimal access necessary to perform official job functions must be provided to employees.

b. Access to health records and health record file areas is limited to authorized personnel.

Only authorized personnel are allowed to print extractions from the patient’s electronic health record or to make copies from the paper chart.

c. Active or inactive health records must be readily accessible to authorized clinical and administrative staff.

7. INFORMATION SECURITY:

a. Security measures for authorizing access to the patients’ health record must be delineated in local policy. VA requires that all individuals requiring access to VA information and information systems complete VA’s approved VA Privacy and Information Security Awareness Rules of Behavior training before such individuals are authorized access to patients’ health record and complete the training annually thereafter (see VA Directive 6500 and Handbook 6500 Appendix D, Risk Management Framework for VA Information Systems - Tier 3: VA Information Security Program, Appendix D, Department of Veterans Affairs National Rules of Behavior Introduction).

b. As custodian of the health record, only the Chief, HIM, or designee, can approve the physical removal of original health records from the treating facility.

c. Health records in file areas and other areas where health records are temporarily stored (clinic or treatment areas, record review areas, quality assurance areas, release of information, etc.) must be locked when designated authorized personnel are not present to ensure the security of the area and to ensure health records are not accessible to unauthorized individuals.

Documents and health records show that the facility monitors physical access to information systems to detect and respond to incidents. VA requires that facilities control physical access to information systems by authenticating visitors before authorizing access to facilities or areas other than areas designated as publicly accessible (see VA Handbook 6500, Appendix D).

d. Precautions must be taken by VA staff to ensure that patient health records on computer screens cannot be seen by individuals who do not have a legitimate need-to-know.

e. All patient-identifiable waste paper, or discarded materials, from any department must be shredded or disposed of in accordance with approved disposal policies and procedures. Locked containers or shredders must be provided in employee work areas for disposal of sensitive patient information. NOTE: For more information refer to the VA Directive 6371, Destruction of Temporary Paper Records, which establishes VA policy to ensure that Personally Identifiable Information (PII) and other sensitive agency information contained in paper records is disposed of properly. Shredders that are compliant with this Handbook are specified in the National Security Agency (NSA) Central Security Service (CSS) Evaluated Products List for High Security Crosscut Paper Shredders EPL-02-01-AB at:

http://www.nsa.gov/ia/_files/Government/MDG/NSA_CSS_EPL_02_01_AB.pdf. Paper shredders can be used to destroy flexible media, such as diskettes, once the media are physically removed from their outer containers. The shred size of the refuse must be small enough that there is reasonable assurance in proportion to the data confidentiality that the data cannot be reconstructed (see National Institutes of Standards and Technology (NIST) 800-88, Guidelines for Media Sanitization, http://csrc.nist.gov/publications/nistpubs/800-88/NISTSP800-88_with errata.pdf).

f. A disaster plan for protecting and recovering health records damaged or destroyed by fire, flood, or by other means must be in place in accordance with VA Handbook 6500, Appendix D. This disaster plan must include provisions for recovering health care records on different types of storage media and emphasize that the goal is to prevent damage first, and then focus on recovery if health records are damaged or destroyed.

8. SECURING E-MAIL AND FACSIMILE TRANSMISSION:

a. E-mail.

(1) According to VA Handbook 6500, Appendix D, electronic mail must be used for authorized government purposes and contain only non-sensitive information, unless the information is appropriately encrypted. All encryption modules used to protect VA data must be validated by NIST to meet the currently applicable version of Federal Information Processing Standards (FIPS) 140-2.

(2) For Outlook or E-mail, both Public Key Infrastructure (PKI) certificates and Microsoft Rights Management Services (RMS) are FIPS 140-2 certified and VA approved for transfer of PII and protected health information (PHI). The Office of Information Technology (OIT) issues http://www.nsa.gov/ia/_files/Government/MDG/NSA_CSS_EPL_02_01_AB.pdf http://csrc.nist.gov/publications/nistpubs/800-88/NISTSP800-88_with-errata.pdf http://csrc.nist.gov/publications/nistpubs/800-88/NISTSP800-88_with-errata.pdf

PKI certificates to use when sending sensitive information; encryption ensures that the message and its attachments cannot be read or tampered during transmission.

(a) Personnel must follow the national PKI policies and procedures issued by OIT.

(b) Requests for PKI certificates are to be directed to the Local Registration Authority (LRA), who typically serves as the Facility Information Security Officer (ISO) at VHA facilities and program offices. A complete listing of Trusted Agents (including LRAs) can be accessed at:

https://vaww.portal.va.gov/sites/PKI/Lists/VA%20Trusted%20Agents2/AllItems.aspx. NOTE:

This is an internal VA Web site and is not available to the public.

(c) When the national deployment of the RMS product is complete, it can be used interchangeably with PKI to send sensitive information. NOTE: For details on the RMS rollout, contact the facility ISO.

(3) Auto-forwarding of email messages to addresses outside of the VA network is strictly prohibited.

b. Facsimile.

(1) Information received by facsimile (fax) is acceptable and may be included in the patient’s health record. Fax machine transmittals must not include information on drug, alcohol, Human Immunodeficiency Virus (HIV), or sickle cell anemia, unless the transmittal is directed to medical personnel, to the extent necessary, in a bona fide medical emergency.

(2) Fax machine transmittals may be used when no other means exists to provide the requested information in a reasonable manner or time frame and the fax machine is in a secure location and reasonable steps (i.e., verifying the fax number and notifying the individual prior to faxing) have been taken to ensure the fax transmission is sent to the appropriate destination.

(3) Fax machine transmittals may also be used for non-patient care (i.e. instructions for travel or to facility; meeting minutes); however, all established fax protocols must be strictly observed.

(4) A confidentiality statement must be attached to the cover page when transmitting individually-identifiable health information. For example, when transmitting outside VA: "This fax is intended only for the use of the person or office to which it is addressed and may contain information that is privileged, confidential, or protected by law. All others are hereby notified that the receipt of this fax does not waive any applicable privilege or exemption for disclosure and that any dissemination, distribution, or copying of this communication is prohibited. If you have received this fax in error, please notify this office immediately at the telephone number listed above." NOTE: See VHA Handbook 1605.1, Privacy and Release of Information, for more information.

9. EMPLOYEE HEALTH RECORDS:

a. The health records of employees are under the management of human resources and, if on paper, must be stored in a separate and secure location from Veteran health records, and access should be granted only to those designated individuals with a need-to-know. If documented electronically in the Computer Patient Record System (CPRS), they must be secured https://vaww.portal.va.gov/sites/PKI/Lists/VA%20Trusted%20Agents2/AllItems.aspx utilizing Authorization Subscription Utilities (ASU) and the Veterans Health Information and Technology Architecture (VistA) Sensitive Flag must be set to “sensitive” to ensure that access to these health records is limited. All employee health records in CPRS must be designated as “sensitive.” NOTE: For information on the Occupational Health Record-keeping System (OHRS), refer to the User’s Guide on the VA Documentation Library at:

http://www4.va.gov/vdl/application.asp?appid=186. This is an internal VA web site and is not available to the public.

b. The health records of employees who receive care as Veterans are under the auspices of HIM and are maintained with other Veteran health records. If on paper, these health records may be sequestered in a special location if directed by local policy. The electronic documentation of these health records must be secured by identifying them as “sensitive” health records in CPRS.

10. COMPLIANCE: There must be periodic review, or audit, of access to patient health records to ensure compliance with health record privacy and confidentiality standards. NOTE:

See VHA Handbook 1605.03, Privacy Compliance Assurance Program and Privacy Compliance Monitoring, for more information.

11. RESPONSIBILITIES:

a. Medical Facility Director. The medical facility Director, or designee, is responsible for establishing policies and processes in compliance with this Handbook, to include ensuring:

(1) The security and integrity of health record documentation through strict maintenance of ASU software applications.

(2) The health information professional (see paragraph 12.b.) is involved in all decisions, both technical and administrative, that impact, define, and control access and disclosure of patient health records.

(3) All relevant health information is assembled when a patient is admitted to inpatient or Community Living Centers (CLC) care, seen for a prescheduled or unscheduled ambulatory care visit, or presents for emergency services.

(4) Health information is available during scheduled and non-scheduled downtime of the computer systems.

(5) Authentication and authorization requirements are enforced (see paragraphs 13 and 14 of this Handbook).

(6) Health record completion and delinquency policies are consistent with accreditation standards, regulatory requirements, and medical staff guidelines (see paragraph 16 of this Handbook).

(7) Tracking and completing unauthenticated documentation.

(8) An adequate disaster recovery and contingency plan for health records according to VA Directive and Handbook 6500, Appendix D, and it must be reviewed at least annually, and staff http://www4.va.gov/vdl/application.asp?appid=186 must be oriented to the location of disaster manual materials (see paragraph 24 of this Handbook).

(9) The elimination or judicious use of the “copy and paste” electronic functionality.

(10) There are adequate security measures for identifying those users who can document in the health record with an electronic signature and for verifying the authenticity of user electronic signatures (see paragraph 25.f. of this Handbook).

(11) The proper procedure for correcting erroneous patient information is entered electronically or on paper (see paragraph 26 of this Handbook).

(12) Who has the authority to reassign an “erroneously entered progress note,” and under what circumstances these options are utilized (see paragraph 26.c.(2) of this Handbook).

(13) Who has the authority to change a patient note title, and under what circumstances these options can be utilized (see paragraph 26.c.(4) of this Handbook).

(14) That the Advance Directive is maintained in both the paper outpatient record and the paper inpatient record to accommodate patient movement from one setting to another, or from one facility to another (see paragraph 27.z.(2) of this Handbook).

(15) The maximum control of active and inactive patient paper record folders.

(16) The appropriate use of the health record charge-out system (see paragraph 30.d. of this Handbook).

(17) The proper annotation on the outside of the most current volume of the patient health record folder is labeled, “Do Not Resuscitate” or “Advance Directive,” when appropriate (see paragraph 31.a.(8) of this Handbook).

(18) Health information is filed in terminal digit sequence according to SSN.

(19) Access to health records and information (see paragraphs 6 and 12.j.) is controlled and limited to authorized staff.

(20) Information security (see paragraph 7).

(21) Confidentiality of records is maintained regardless of medium (see paragraph 5).

(22) That only authorized and identified individual’s document in the health record.

(23) Physical access to patient systems and records is controlled by authenticating visitors (see paragraphs 14 and 17.c.).

(24) MVI is maintained in the local VistA system (see paragraph 21).

(25) The proper retention, disposal, and transfer of patient health records (see paragraph 17).

(26) Non-VA medical care is documented.

(27) Adverse and sentinel events and close-calls are reported and documented (see paragraph 21).

(28) Research, clinical trials, and experimentation have appropriate approvals and documentation (see paragraph 23).

(29) Proper management and maintenance of the paper health record (see paragraphs 29 and 30).

(30) All documentation meets The Joint Commission standards.

(31) There is a policy in effect for correcting or rectifying health records.

(32) All electronic health care records are completed with confidentiality and integrity (see paragraph 25).

(33) Procedures are in place for the duplication, transfer, or loan of health records (see paragraph 28 and paragraph 29.f.).

b. Chief of the Clinical Service. The Chief of the clinical service, or designee, is responsible for the clinical management of health records, with each clinician and professional service contributing to the content of the patient health record.

c. Health Information Manager. The Chief of Health Information Manager (HIM) is responsible for the administrative management of health records, which includes planning, managing, advising, and directing the health information program in accordance with applicable Federal laws, facility by-laws, VHA policy, The Joint Commission standards, the Commission on Accreditation of Rehabilitation Facilities (CARF), and other regulatory and accrediting agencies. The Health Information Manager also creates and monitors systems to ensure accurate, timely, and complete health records, in accordance with VHA policy and The Joint Commission health information protocols. The HIM professional is responsible for:

(1) Managing Processes. The HIM professional:

(a) Organizes the HIM department according to the facility's needs and updates the HIM organizational chart as changes occur;

(b) Measures ongoing intradepartmental performance by establishing priorities, collecting data, monitoring and reporting outcomes, using valid and reliable techniques to analyze trends and variation, and taking appropriate action based on findings;

(c) Creates, maintains, and revises HIM staff position descriptions and functional statements as changes occur;

(d) Develops and maintains a historical guide to health record changes that have occurred over the life of the VA medical facility that would impact retrieval of health records;

(e) Ensures there is a VA medical facility-wide process in place to correct erroneous health information (see paragraph 26); and

(f) Ensures there is a VA medical facility-wide process in place to allow only authorized individuals to document in the health record (see paragraph 14).

(2) Reviewing and Monitoring Records. The HIM professional:

(a) Establishes and schedules performance monitoring and measuring activities to assess quality and timeliness of health information services in order to:

1. Identify variances from standards;

2. Ensure accuracy and consistency of information; and

3. Capture the results of care rendered to provide both patient and clinician the best possible information.

(b) Reviews the health record in order to assess presence, proper format, authentication, timeliness, and documentation supporting patient care, as reflected by the patient health record.

(c) Establishes criteria for reviews utilizing, at a minimum, current The Joint Commission standards and VHA initiatives, as appropriate, and must include all areas of patient care. With the ongoing implementation and improvement of the electronic health record, reviews must encompass new areas of risk that occur in an electronic health record system. NOTE: Where possible, reviews need to utilize technology to assist in identifying instances or patterns of documentation (or lack of) risk.

(3) Evaluating Processes. The HIM professional needs to evaluate the following topics:

(a) Quality of HIM Services.

1. Health record availability for ambulatory or outpatient care visits and inpatient scheduled admissions, if applicable. NOTE: This may include unscheduled downtime when CPRS is not available.

2. Health record completion reporting.

3. Timeliness, productivity, and quality of coding activities.

4. Timeliness, productivity, and quality of health record analysis.

5. Timeliness and productivity of release of information activities.

6. Quality and timeliness control of transcription services, this may include turnaround time, use of abbreviations, error rates, etc.

7. Timely productivity and quality of filing or scanning of reports.

(b) Data Validation.

1. Validation of the clinical and administrative information reported in the PTF, including the PTF Average Length of Stay (401) and PTF Disposition in Master File (419) reports;

2. Validation of the clinical and administrative information reported in the PCE data;

3. Inpatient and outpatient facility and professional services coding; and

4. Adequacy of billing processes and procedures, if applicable.

(c) Compliance with Health Record Privacy, Confidentiality, and Security Standards. This includes:

1. Access to patient health records to ensure compliance with health record privacy and confidentiality standards.

2. Access to the electronic health record, including those using the PDX, NHE, or Remote Data View.

3. Appropriateness of disclosures of facility patient information from telehealth operations, if applicable.

(d) Training. Training effectiveness of health information personnel.

(e) Contracts. Contracts or contract review, if applicable (i.e., coding, transcription, etc.).

(f) Reviews. Reviews and other activities pertinent to the delivery of quality health information services.

(4) Employee Orientation. The HIM professional participates in, or contributes to, orientation of all new staff expected to have contact with, or access to, health records. NOTE:

The HIM professional and the Clinical Applications Coordinator(s) need to work collaboratively with respect to the set-up, maintenance, access, and use of the CPRS system. Orientation and education must include, but is not limited to, the following:

(a) Confidentiality of health records (including VA disciplinary actions for violations of confidentiality) and the proper procedures for releasing information.

(b) The Joint Commission and VA requirements for clinical staff entries, including authentication, and other documentation requirements outlined in this Handbook.

(c) Set up and formulation of ASU consistent with facility by-laws, especially as they relate to the business rules for CPRS, to include documentation, authentication, security, access, and other business rules relating to health record documentation.

(d) Format of proper documentation.

(e) Time standards for documentation.

(f) Error correction or addenda to health records.

(g) Acceptable use of copy and paste.

(h) Required diagnostic information when ordering.

(i) Applicable medical necessity requirements.

(j) Chart deficiency protocols.

(k) Dictation and transcription protocols.

(l) Patient encounter form completion.

(m) Resident supervision requirements.

(n) HIM operational services, including hours and staff availability.

(o) Clearance procedures.

(5) Release of Information (ROI). The HIM Professional is responsible for the day-to-day activities of releasing health records in accordance with VHA Handbook 1605.1, Privacy and Release of Information, and working closely with the facility Privacy Officer, or in serving as the alternate Privacy Officer, in:

(a) Both safeguarding and disclosing, as appropriate, health information according to applicable VA standards:

1. 5 U.S.C. 552a, the Privacy Act of 1974;

2. 45 CFR parts 160 and 164, the HIPAA Privacy and Security Rules;

3. 5 U.S.C. 552, Freedom of Information Act (FOIA);

4. 38 U.S.C. 5701, which protects Veterans’ information in claims files, specifically names and addresses;

5. 38 U.S.C. 5705, which protects VA records and documents created by a VA health care facility’s medical quality assurance program activities; and

6. 38 U.S.C. 7332, which protects drug and alcohol abuse, Auto Immune Deficiency Syndrome (AIDS), Human Immuno Deficiency Virus (HIV), and Sickle Cell Anemia patient treatment records.

(b) Developing procedures relating to the duplication of medical, administrative, and perpetual medical records to ensure continuity of care and, when necessary, coordinate the prompt duplication of all medical data required; for example: records, slides, pacemaker records (including VHA Form 10-5548a, Pacemaker Surveillance), prosthetic records, and X-rays.

(c) Developing policies, processes, and procedures, designed to protect the privacy of patient health information and the confidentiality of health records maintained by VA; this includes monitors that both safeguard and appropriately disclose protected health information by ROI staff. HIM policies and procedures must adhere to the facility Privacy Policy to:

1. Address appropriate methods of disclosure.

2. Define those circumstances that require patient authorization prior to disclosure of patient data and health care information and when disclosure of patient health care information may be made without the patient’s consent.

3. Differentiate between mandatory disclosure (for example reporting of elder abuse) and permissive disclosure (for example access by health care staff).

4. Identify the circumstances that require inclusion of a re-disclosure notice with the release of patient-identifiable data and health care information.

5. Define circumstances when the transmission of patient-identifiable data and health care information can be appropriately forwarded by facsimile machine.

6. Provide for the prompt identification and indexing of incoming requests for Veteran individually-identifiable health information.

7. Conduct a comprehensive systematic review of the release of information activity within the VA health care facility not less frequently than once every 12 months.

8. Establish policies and procedures to make administrative updates and corrections to the patient health record.

9. Establish agreements for any HIM home-based employees that state that the employees are under the same requirements as regular employees for protecting confidentiality of all patient-identifiable data and health care information to which they have access.

10. Evaluate periodically factors such as workload, processing times, etc. to identify backlogs and expedite responses to requests for information.

11. Ensure that the confidentiality policies and procedures are part of new HIM employee orientation and are reviewed with the employee on an ongoing basis as part of each employee’s continuing education.

(6) Coding. The HIM professional is responsible for the coding functions, which includes:

(a) Oversight. The oversight responsibilities include:

1. Supervising or providing oversight for any diagnosis and procedure coding done outside the program in order to ensure the complete and accurate description of patient services.

2. Providing training and consultation to staff assigning or analyzing diagnoses or procedure codes outside of HIM.

3. Supporting and endorsing the AHIMA Standards of Ethical Coding, which are found in the following Web link:

(http://library.ahima.org/xpedio/groups/public/documents/ahima/bok2_001166.hcsp?dDocName =bok2_001166).

(b) Professional Staffing.

http://library.ahima.org/xpedio/groups/public/documents/ahima/bok2_001166.hcsp?dDocName=bok2_001166 http://library.ahima.org/xpedio/groups/public/documents/ahima/bok2_001166.hcsp?dDocName=bok2_001166

1. Coding requires specialized training, education, and skills. Specific guidelines and criteria must be followed to ensure proper code assignment, sequence, and reporting. While coding is performed for a variety of reasons, it is primarily done to permit the search and retrieval of information according to diagnosis or procedure associated with an assigned code number.

2. To ensure that coded data accurately reflects the diagnoses and the services provided to patients, it is essential to recruit, hire, and provide continuing education to retain competent, credentialed (RHIT, RHIA, Certified Coding Specialist (CCS), Certified Coding Specialist – Physician-based (CCS-P), Certified Professional Coder (CPC), Certified Professional Coder- Hospital (CPC-H)) coders.

(c) Contract coding services must be monitored for quality and timeliness.

12. MANAGEMENT OF HEALTH RECORDS:

a. Ownership. A health record and the health information within the health record are property of VA, as specified by 5 U.S.C. 552a(a)(4) and 44 U.S.C. 3301.

b. Health Record Creation. A separate, unique health record is created and maintained for every individual assessed or treated by VA, as well as those receiving community or ancillary care at VA expense. It is not required to print and file paper documents from electronic media for active health records.

(1) Patient health records must be maintained on the following individuals:

(a) The individual admitted to any level of inpatient care (medical facility, Mental Health Residential Rehabilitation Treatment Program (MH RRTP), CLC, etc.).

(b) The applicant who is found not to be in need of care or ineligible for care.

(c) The individual who is dead on arrival (authorized or unauthorized admission).

(d) The individual who is provided with ambulatory care for humanitarian reasons.

(e) The Veteran whose State Home or non-VA medical care or treatment is provided at VA expense.

(f) The Veteran whose community nursing home care is provided at VA expense.

(g) The Veteran examined for possible exposure to herbicides (includes Agent Orange), radiation, asbestos, and environmental contaminants.

(h) Veterans undergoing Compensation and Pension (C&P) or Persian Gulf examinations.

(i) The individual placed in pre-bed care, on ambulatory care or outpatient status, or on non- VA medical care status.

(j) The non-Veteran patient who is evaluated or treated in a VA medical facility under a sharing agreement (i.e., TRICARE, Civilian Health and Medical Program of VA (CHAMPVA)).

(k) A family member or significant other of a Veteran attending individual counseling.

(l) A Veteran who is being treated at a Community Based Outpatient Care (CBOC) under VA auspices or at a VA medical facility.

(m) Patients examined for Military Sexual Trauma (MST).

(2) The primary traits used to uniquely identify a patient within the Master Veteran Index (MVI) include, but are not limited to, the patient’s name, SSN, Date of Birth (DOB), and gender.

Secondary traits that may be used include, but are not limited to, the mother’s maiden name, address, and place of birth (city and state).

(a) The name entered into the patient’s electronic health record must be the complete legal proper name, and include a full middle name when available.

(b) In the event the identity of a patient is unknown, a pseudo SSN is assigned with 1900 entered for the DOB, and the name entered as UU-UNRESPONSIVE, PATIENT. Subsequent patient health records must be entered as UU-UNRESPONSIVE, PATIENT A, UU UNRESPONSIVE, PATIENT B, etc. The patient is then treated as a non-Veteran, humanitarian emergency, until the patient’s identity can be established. Health records must be completed with appropriate identity data elements once the patient has been identified (see VHA Directive 1906, Data Quality Requirements for Healthcare Identity Management and Master Veteran Index (MVI) Functions, for more information regarding requirements for identity management and MVI functions).

(c) If a patient is admitted under an incorrect name, once the name correction is made in VistA, all electronic documentation must be linked to the correct patient (see paragraph 25g(1) of this Handbook) including health information in packages other than Text Integration Utilities (TIU) and CPRS (i.e., laboratory, radiology). If assistance is required in ensuring that all unique identifiers are correct at the enterprise level, the national Healthcare Identity Management (HC IdM) Data Quality Team should be involved in the resolution process. All paper health information must also be corrected to reflect the correctly identified patient.

(d) Official name changes to the electronic health record must be coordinated with the local site’s MVI Point of Contact, Privacy Officer, and the national HC IdM Data Quality Team.

(e) Written requests for a name change, including removal of a middle name or middle initial from health records, are handled as a request for amendment of health records. Official documentation is required for all name change requests. NOTE: The required documentation varies based on the type of modification being requested (i.e. correction, change, removal).

Some requests are not granted.

(3) Health records must contain original signed documents, or electronically-authenticated documents.

(4) Health Record data within the electronic health record system will not be purged from the electronic system.

c. Legibility. Legibility refers to the quality of penmanship used when recording data, including a clear, written signature, as well as content and appearance of dictated, copied, or scanned information. Paper entries must be made in black ink to ensure permanent recording.

NOTE: Handwritten entries are limited to those documents that current technologies cannot yet support.

d. Symbols, Abbreviations, and Acronyms. While there is no requirement by The Joint Commission for a list of approved symbols, abbreviations, and acronyms, if they are used in the health record, there must be an explanatory legend or standardized list available to decipher their meaning. There must be a list of unapproved symbols, abbreviations, and acronyms which must be made available to all those who make entries in the health record and to others who use health records in the course of their official duties. Symbols, abbreviations, and acronyms are not to be used when documenting final diagnoses and procedures on patients released from inpatient, ambulatory or outpatient services. When included in information provided to patients (e.g., consent forms), abbreviations and acronyms must be explained in language that the patient can understand.

e. Language. All entries must be in English, and must conform to acceptable English grammar. Documents that provide information to patients (e.g., consent forms) may include Spanish translations, when appropriate, provided that both Spanish and English translations are included in the document.

f. Shadow Records. Shadow records (see Appendix A) must be limited or non-existent.

(1) To ensure compliance with The Joint Commission standard RC.01.01.01, there must be a process to track the location of all components of health records, including shadow records.

(2) Facility HIM Managers must be aware of any use of shadow records and, with the advice of the Facility Records Manager and the Medical Record Committee or equivalent, each site must determine the need to continue the use of any shadow health records and document such action in the committee minutes.

(3) Any use of shadow records must include a policy to address the privacy, security, and destruction of shadow records that may not be under the control of the HIM Manager.

g. Forms and Template Management.

(1) A local process for initiating, developing, and approving new electronic templates and overprinted paper health record documents must be established under the auspices of the health record review function.

(2) All internally-generated forms and shared templates that become part of the health record must receive prior approval. Requests for new forms and templates are to be limited to those that can be developed in an electronic format.

(3) As part of the health record review function, proposed templates must be reviewed for legal, policy, regulatory compliance, and ease of use. Requests must be approved via the facility approval process prior to implementation.

http:RC.01.01.01

(4) All components must reflect patient identifier information (full name and second unique identifier, such as Integration Control Number (ICN); when possible, the last four digits of the SSN are used instead of the full SSN), date of documentation, date of service, and facility name.

(5) VHA paper forms for specific components of the record are no longer mandated;

however, they are encouraged to be used as a guideline for developing electronic templates.

h. Health Record or Health Information Availability. A local policy and process must be established ensuring health information is always available, as needed (see paragraph 11.d. of this Handbook).

(1) For most cases where a patient is treated or seen at another VA medical facility, the Patient Data Exchange (PDX), Network Health Exchange (NHE) or Remote Data View (RDV), Remove Image View, VistA Web, or Register Once software must be used to expedite the transfer of needed health information between facilities. Scanned documents and images are only viewable through Remote Image View in VistA Imaging. Facilities must use the PDX encryption feature when transmitting data to other VHA facilities. If additional information is required, it may be copied and sent using overnight mail or secure fax machine when absolutely necessary.

(2) Previous inpatient and outpatient health records must be made available upon specific request for treatment purposes or as support for claims benefits. When there is evidence that a health record exists at another VA medical facility or, at the VA Records Center and Vault (RC&V), the record must be ordered upon specific request (see paragraph 17.b. of this Handbook).

i. Preparing Records for Litigation. Records for litigation that are unsigned, or with incomplete entries, must be presented for court exactly as they existed at the time the VA medical facility received the court order for the records. The same applies for records requested by Regional Counsel. If the VA medical facility needs to complete or sign the records in order to comply with VHA and facility policy, it needs to be done after providing the unsigned copy to the requestor. NOTE: Refer to HIM Practice Brief #4, “Guidelines for Defining a Legal Health Record,” for specific guidance on preparing a record for a Tort claim; it can be found at:

http://vaww.vhahim.va.gov/index.php?option=com_content&view=article&id=13&Itemid=572.

This is an internal VA Web site and is not available to the public.

13. AUTHENTICATION: Authentication demonstrates that the entry has not been altered.

Authentication includes the time, date, signature or initials, and the professional designation of the practitioner (credentials).

a. Standardized and current electronic signature blocks for all authorized users based on the person’s class taxonomy file must be maintained at each facility. This ensures non-repudiation and that appropriate billing occurs.

b. Authentication functionality must include the identity and credential or professional discipline of the author, the date signed, and the time signed, if required.

c. If the title block is used, it needs to accurately reflect the functional position of the user as defined by the service.

http://vaww.vhahim.va.gov/index.php?option=com_content&view=article&id=13&Itemid=572

d. As employees enter, leave, or transfer to a different position, the person class file and the title block must be edited to appropriately reflect job status.

e. Monitors to ensure person class files are correct must be established at each facility.

f. A method of identifying the author on paper must be established; i.e., stamps with the printed name and professional designation of the clinician, or a requirement of the clinician to print the clinician’s name to ensure legibility. Any initialed entries must be substantiated by at least one entry with the signature of the individual made during the episode of care. Signature stamps cannot be used.

g. All entries must be recorded and authenticated immediately after the care event or the observation has taken place to ensure that the proper documentation is available. This ensures quality patient care.

h. Controlled substance outpatient prescriptions in Schedules II, III, IV or V may be electronically prescribed using the prescriber’s PIV card to perform two-factor authentication using CPRS version 29 or later. This process will generate a digitally signed prescription that is compliant with Drug Enforcement Administration (DEA) rules found in the 21 CFR part 1311.

NOTE: Electronic signatures can be utilized for inpatient orders of controlled substance medications without two-factor authentication.

14. AUTHORIZED ENTRIES:

a. Policies, procedures, and ASU (see Appendix A) rules must be established at each VA medical facility to ensure only authorized individuals document in the health record and that the author(s) and any required cosigner(s) are identified.

b. ASU rules must be in concert with facility by-laws and facility policy.

c. Facility by-laws must be reviewed regularly and updated, if necessary, to depict who is authorized to make entries in the health record.

d. Caution must be exercised to ensure that any documentation included in the health record represents work that is appropriate within an individual’s scope; i.e., calls from patients that may include questions or comments that accompany the request for medication refills may be more appropriately documented by a nurse versus being captured by a clerk.

e. Only those individuals authorized by facility policy are allowed to make entries into the health record. This includes administrative documentation.

f. The practitioner who treats a patient is the individual responsible for documenting and authenticating the care provided. Interdisciplinary notes are used when multiple practitioners provide treatment during the same encounter.

g. All clinical staff authorized to document in a health record must record in CPRS, except for those instances where technology is not available for electronic entry.

h. The respective clinical staff, as defined by their scope of practice, must document every episode of clinical care.

i. Health record entries must be: completed, signed, and cosigned as necessary, transmitted, filed, or uploaded to ensure the information is available for patient care. Health care practitioners are responsible for completing their respective notes within prescribed timelines for patients under their care (see paragraph 28 of this Handbook).

j. A “Report of Contact” template can be used to document communications with patients.

This practice must be reviewed by the appropriate health record committee and approved to ensure that the health record only includes information that supports the patient’s treatment.

15. SENSITIVE HEALTH RECORDS:

a. Some specific health record types are deemed sensitive and may be maintained under direct supervision of the health information professional, or be flagged as “sensitive” in VistA or other facility computerized record repositories. These include, but are not limited to:

(1) VA Veteran employee patient health records;

(2) Regularly-scheduled Veteran volunteers;

(3) Individuals engaged in the presentation of claims before VA, including representatives of Veterans’ Service Organizations, or cooperating public or private agencies or Administrative Tort Claims; and

(4) Records involved in Administrative Tort Claim activities.

b. Specific medical or psychiatric diagnoses must not be the sole basis for flagging a patient record as “sensitive.” For example, records of patients should not be flagged “sensitive” solely because the patient is diagnosed as having HIV. NOTE: With the concurrence of the ISO, or designee, similar security measures may be applied to other patient records.

16. COMPLETE AND INCOMPLETE HEALTH RECORDS:

a. Record Completion. Patient health records must be timely, relevant, necessary, complete, and authenticated.

(1) Completeness implies that all required data is present and authenticated; all final diagnoses are recorded without use of abbreviations, and the transcription of any dictated information is completed, inserted, or uploaded into the health record.

(2) Health record completion and delinquency policies must be developed and must be consistent with accreditation standards, regulatory requirements, and medical staff guidelines.

These policies must:

(a) Specify time standards for content, authentication, and completion as required by The Joint Commission or VA medical facility policy.

(b) Describe procedures for ongoing monitoring and reporting of individual delinquent records, responsible clinicians, and re-occurring delinquency patterns to the appropriate staff and committees as outlined in the facility by-laws.

(c) Define when health record deficiency patterns become part of the individual’s (including residents) evaluation and placed in that clinician’s credentials file.

(d) Address whether or not students in teaching institutions can record in the official health record and the accuracy requirements for their entries.

(e) Define those entries in the health record that require countersignatures by supervising practitioners.

(f) Designate how the supervising practitioner records findings or pertinent observations that are not in agreement with the data already recorded; i.e., by an authenticated addendum or separate note.

(g) Ensure the presence and authentication of, at least, the following entries when appropriate:

1. History and physical (H&P) examinations;

2. Operative reports;

3. Diagnostic and therapeutic procedures;

4. Consultations; and

5. Discharge summaries.

(h) Ensure that the discharge summary and the operative reports are signed and co-signed, as necessary, by the supervising practitioner.

(i) Define when an inpatient health record becomes delinquent; however, in no case can the time period detailed in the medical staff rules and regulation exceed 30 calendar days.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.