The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
#117 Managing Dental Practice Risks Through Risk Assessments
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Resources:
- CDC Infection Prevention Checklist https://bit.ly/3DH9kly
- OSHA for Dentists https://www.osha.gov/dentistry
- HIPAA Security Risk Assessment https://bit.ly/45awmgr
- HR Risk Assessment https://www.aihr.com/blog/hr-risk-management/
Welcome. I'm Leslie Cannon. I'm Mary Gavoni.
SPEAKER_02I'm Linda Harvey. I'm Olivia Wan, and together we are the Compliance Divas. My name is Olivia Wann, and I'll be your moderator today for our podcast, How to Effectively Manage Risk Through Risk Assessments. Now, more than ever, it's so important to assess our risk to help insulate our practices against litigation and violations with regulatory authorities. As the compliance divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please subscribe to the compliance divas podcast through your favorite podcast channel, or you can visit our website, the compliancedivas.com. Resources we mentioned during this episode can be found on our website. Also, please submit questions to support at thecompliancedevas.com. It's all about the risk and conducting risk assessments to check our practices. To me, when we conduct a risk assessment, it's much like taking someone's temperature. The first thing we think of is someone running a fever. Could they be sick? How would we know if our dental practice is sick, so to speak? In this episode, we're going to talk to the divas about the different types of risk assessments that are available and how you can incorporate these tools into your practice to make sure that your dental practice remains healthy and safe and help immunize you against risk. I'd like to interview our diva, Linda Harvey. She's been a long-term member of ASHRM. My first question for Linda would be to tell us what ASHRM means and describe to us what an enterprise risk framework is.
SPEAKER_00Thank you, Olivia. I know that sounds so complex with a lot of acronyms and long terms and maybe confusing terms. Ashram stands for the American Society for Healthcare Risk Management. And I've been a longtime member because when I took my risk management training in Florida over 20 years ago, I just joined to stay current with different kinds of risk and different types of medical, dental, all healthcare settings. And one of the things they've talked about over the years is different types of risk assessments. And as you I really liked, as you said, your analogy of someone being sick as the office sick. How do we take the temperature? How do we know the health of the practice? How do we know about the safety of the patients? Those are all areas that can be risk for practice. And so with enterprise risk management, what it does is even though, say, a solo practice may not feel like it's an enterprise or a big corporate group compared to, say, a DSO or a hospital system or a medical system, every single practice is an enterprise because it's a corporation run by this by the doctor. They've got legal papers, you know, for their professional association or LLC or whatever framework they have. So they need to look at different types of risk to be sure their practice and their business is healthy in all areas. I would liken it, Olivia, to updating our patients' medical history. And we're looking for assessments there. We're assessing patients in that area to be sure that they're safe to work on, that there's no precautions we need to take or pre-procedure antibiotics that need to be prescribed, whatever the situation might be. But enterprise risk management has been around a long time in healthcare and it looks at a view of risk from a very comprehensive fashion. It looks all different areas, not just patient, uh just regulatory, but all different areas. And you can look at risk in six different categories or domains, if you will. And these are the legal regulatory, and Mary and Leslie are going to talk about some of those areas. We can talk about technology risk. You know, we can invest in a lot of expensive equipment, but are we using it properly? And is it being managed properly? We talked about operations as another area of risk. That includes patient care and sterilization. HR is another risk. And I think you'll talk about that in a little bit, Livia, but we want our employees to be our greatest asset, not our worst liability. And then finance and strategic risk are the other two areas to be looking at. And what's interesting about enterprise risk management, or ERM for short, is that these risks don't exist in isolation, Olivia. Whatever happens in one category or domain directly impacts all the other. So it's important that we don't have silos, whether we work in an organization or whether we work in a solo or group practice. Communication from the front to the back, back to the front, management, everybody is very important because that's how we minimize risk. Oftentimes there are areas of risk that the practice doesn't realize. You know, there's some low-grade symptoms that this kind of below the radar that we're not aware of, or we're too busy to pay attention to, or we keep saying, we'll get to that later, we'll get to that later. And later never comes because we're so busy with the next patient and the next patient and the next patient. But those latent errors are opportunities for some significant risk to happen. So by taking a risk assessment and looking at a particular checklist or assessment or making a list of things you think you're concerned about or that should go wrong, or talking to your carrier, your insurance carriers in different areas for different risk assessment tools. We have some that we'll publish on our this podcast, Olivia. But it's very important that you take the health of the practice and determine what risk exists. Are you as compliant as you need to be? Do you have all your HR documentation up to date? And when you're looking at these risks, you're also determining what risk do I think I can retain that I'm not too worried about? Or what risk is great enough that I need to have some resolution? Do I need to transfer the risk through insurance? Do I need to minimize the risk by stopping the behavior or stopping whatever the situation is? I'll give you a quick example. For years I have worked with dentists who have been in under disciplinary sanctions by the Board of Dentistry. And many times over, it's been a general dentist performing a specialty procedure. Maybe this doctor has a knack for, or so they think they have a knack for oral surgery and try to work with some pacted thermolars, and it turns into a board of dentistry and a legal complaint. So just looking at different risks, that's a risk, say, for example, that a practice could evaluate and determine yes, we know our oral surgery specialists are the best ones to handle that particular risk. So there's a lot of different areas that a practice can evaluate, Olivia. And it's important that everyone step back, particularly the doctor and the management team. But I think the whole team plays a role in this because everybody are the eyes and ears for safety and quality care in a dental practice.
SPEAKER_01That's great information, Linda.
SPEAKER_02And you know, over the years, I've recognized that what makes a dental practice susceptible to being sued is certainly lack of communication, whether they're not communicating with their team or they're not communicating with the patient. But what makes a dental practice lose a case is lack of documentation. And we can really start with those risk assessments to help us identify those areas where we need to be more efficient. But Linda, like anything else, if we do these risk assessments and we just fill out, oh yes, we're doing that, we're doing that, and it's not accurate information, then we're not going to achieve reliable results. So we have to take a very honest and accurate approach to these risk assessments and recognize that it's all about incorporating change. You know, how do we make those necessary changes in all these different areas that you spoke about, Linda, in order to be very effective? And so in conducting the risk assessments, we have to utilize that data that we're collecting. And it can be overwhelming when we do these risk assessments, like where do we start? How do we prioritize? And then how do we optimize our readiness? And I think you made a good point in talking about their dental licenses. These assessments help us protect those dental licenses. And I'd like to interview Mary about how to do the risk assessments and why, whether it's OSHA, infection control, and what tools are out there to help these dental practices, Mary.
SPEAKER_03Thanks, Olivia. And I'm so glad that you reinforce that whole point about moving beyond the risk assessment. So you can assess all the risk, but if you don't do anything about it, then why go through the exercise? And we've seen that in a number of cases. And I know Leslie's going to talk about this in a minute with HIPAA. People do their annual HIPAA risk assessment and identify the same risk year after year after year, and then they don't fix it. So, what about OSHA? And how do we go about that? Well, there are three areas that every practice should assess their risk in terms of OSHA. One is just general workplace safety, things like do you have trip and fall hazards? Do you have properly grounded electrical outlets in your sterilization area or a lab where there's water faucets and there's water around the electrical outlets? Do you have fire extinguishers? And we talked in a previous podcast about evacuation plans and those types of things. And OSHA's got some good resources, and we will put those in the resources section on the podcast notes and on our website. They have actually some high-level checklists for general workplace safety that you can go through that give you hints about what you should include in training and how that training should be conducted and so forth. And then we need to look at hazard communication. Do you have a chemical inventory, a list of all the products that you use in your office? Do you have your safety data sheets and are products out of the manufacturer's containers labeled? And there isn't a checklist that I have found specific to the hazard communication standard. And maybe any of the divas can certainly join in. But if you've purchased a manual from the American Dental Association, the Academy of General Dentistry, any of those entities that are specific to dentistry, you should have a checklist there. Certainly, we would advocate as consultants working with a consultant who can help you with a checklist of the things that you need to do to be in compliance. And then the last area that you need to go through, and probably the most critical one for your practice, is infection prevention and control. And we have a beautiful checklist provided to us by the Centers for Disease Control and Prevention. And you'll have the link to that. You can use either a paper version or the electronic version that's PDF fillable right on your computer. And you can type in your notes and things that you need to work on to be in compliance. And the CDC says that you should do this risk assessment once a year. OSHA also states in the Bloodborne Pathogen Standard and in the hazard communication standard that these safety plans that we have specific to those standards be reviewed and updated on an annual basis. So that is doing a risk assessment. And probably the best time to do it is to have it coincided with your annual training that you do and go through your checklists and make sure that you're on board with everything. So those tools are certainly available. Many people struggle with where do I go to find all this information? But it is available and it is accessible. So reach out, or first of all, look in your manual that you have. And if not, reach out to the compliance divas, reach out to a consultant if you're working with someone, and you should be able to access that information.
SPEAKER_01Great information, Mary.
SPEAKER_02And so important to conduct these assessments in this area to identify risk, not only risk for employee safety, but risk for patient safety. But now we can turn our attention to HIPAA. We all understand that we are required to do a HIPAA security risk assessment. But Leslie, what is that? What is a security risk assessment and how does cybersecurity tie into that?
SPEAKER_04Well, you know, Olivia, a lot of folks have uh really shied away from paying close attention to their HIPAA risk assessment. It's kind of an arduous job. It takes a while to go through, and initially it may be very confusing. But uh the bottom line is that according to Health and Human Services, a risk assessment helps an organization ensure that it's compliant with HIPAA's administrative, physical, and technical safeguards. And the beauty of going through a risk assessment is it helps health practice determine where they have gaps in areas that might affect uh patients' protective health information where you can be at risk. And so there's uh several different parts of a risk assessment. There's several steps, and there's some beautiful videos on the Health and Human Services website that explain what a risk assessment is, and there's some tools that an organization can use to actually download and conduct a risk assessment. And uh a lot of times we'll say, like, yeah, I don't people say I don't know where to even begin with how to conduct a risk assessment, and that's where these tools are very helpful. So, for example, one of the checklists says step one, determine what protective health information you have access to. Step two, assess your current security measures. Step three, identify where your organization is vulnerable and the likelihood of a threat. Step four, determine your level of risk. And then step five, which is probably something that we keep coming back to as being a very important piece of the risk analysis and risk assessment, is finalizing your documentation, actually showing that you have evaluated these various areas and what risk you've discovered, and what steps you're going to take to mitigate the risk, and maybe a due date or assign a person to actually be in charge of facilitating the risk assessment fixes, whatever it is that you find. And Mary hit the nail on the head when she said, Yeah, this is something that's annual. So while we may have gone through the long process of a risk assessment, whether we did it with a consultant or whether we did it on our own, or or we've used the guidance from the health and human services videos that are available. The thing is that we we need to look at it each year and see have we completed the steps that we where we found gaps in vulnerabilities? If not, why not? Can we study date to do that? Or are there new gaps in vulnerabilities that have come up? Now, something that scares me too is is a cybersecurity type of breach. I've always worried about not only for myself, but for my clients, that something's gonna happen inside your computer, they're gonna click on some kind of an attachment or download some malicious software and cause grave disruption to their patient data or perhaps have their patient data held for ransom. We hear stories over and over again about these unfortunate uh circumstances. So, again, on the Health and Human Services website, I found a great document that's multiple pages long that had 10 tips for cybersecurity in healthcare. And I'll just give you a replace the 10 tips, but I would encourage our listeners to take a look at each one of the full page of hyper information, sometimes more on each tip. So this is what it would look like to uh include a security rift assessment that includes cyber security. Number one, establish a security culture among your teams. Number two, protect mobile devices, number three, maintain good computer habits. Number four, use a firewall and of course maintain that even after date. Have a container plan. Plan for the anti-protective health information to only those individuals who are authorized to have access. Use change passwords and change them regularly. I kind of hate that one in the way that you know I hate having to change my password. But when you think about it, if I didn't change my password, let's say on my checking account, my password can be can be reached easily by some of the algorithms that are set up by these very sophisticated. So passwords are not a devil passage with phone number or the tree address or the word devil. So people in dentistry should be very wise when they use these passwords and then change them periodically. And uh that means including your guest and password or your for your internet access uh in your reception room. It shouldn't have access to your business information. So we make sure that our IT company has created strong separation between business and uh guest access. And then control physical access. That means that controlling physical access to any forms that are uh available in your practice, the the paper forms, but also control physical access to your computer systems. Remote access has been a big thing during COVID. Lots of people have uh enjoyed the pleasures of working from home. We need to be very careful as to what kind of access could allow malicious software or malicious intruders to access our data. Olivia?
SPEAKER_02Great information, Leslie. So it's critical that we conduct these HIPAA security risk assessments, and it's required. We have to do it. So you made some really good points there, and it reminds me of the newer information that we've been giving out to folks is that the Office of Civil Rights wants to make sure we have those recognized security practices in place. And don't be surprised if they ask you to demonstrate it. So when you're doing your risk assessment, you may want to gather whatever the question is asking to prove that you are demonstrating compliance with that area of risk. And you made another good point, Leslie, about the passwords. And I want to once mention once again that I use, as well as my staff and recommended clients, LastPass. And I have a paid version so that I can use it on my phone, my laptop, my desktop, and I because I can never remember all these passwords. And so it's a secure encrypted vault. So another area would be HR. That would be something that dental practices would benefit by conducting a risk assessment. And that risk assessment could be as simple as making sure we have the I-9, that there is a job application, that the employees have signed an acknowledgement of receipt of the employee handbook, that they've signed some kind of computer usage agreement, stating that they understand the work computers cannot be used for personal use, surfing the net, social media. Also, be sure we're conducting those background checks and that we verified that the dental license is current, keep up with PTO or time off absence, tardiness. Also, those performance reviews. We want to maintain documentation and any disciplinary action. And those are just a few things that I can think of offhand that would be beneficial to evaluate that we have those all in place, whether we maintain paper copies in a locked filing cabinet or we have scanned them and saved them to a password-protected file. So by doing these risk assessments and getting our team involved, one of the things that accomplishes is that we are taking a collaborative approach to assessing our practice environment and how well it's functioning in all these different areas that we're assessing. And the goal is to learn as well as achieve ongoing improvement. Because that is the goal, both for our dental teams, the dental business, and the patients that we're serving. We always want to improve and achieve high-quality services. Another area that we think about is violations. No one wants to pay an OSHA fine or a fine for HIPAA lack of compliance to the Office of Civil Rights or defend a malpractice suit. Week to week, I have dentists that reach out to me that they're concerned with a patient that's upset or dealing with situations that's very uncomfortable in today's society of people that are so quick to contact an attorney and see if they have a claim. So it boils down to risk, and we can effectively manage risk through these risk assessments. The risk assessments help us identify the needs for efficiency in our practices, but it doesn't really do us any good unless we incorporate those changes. As the divas have pointed out, we have to make the change for it to be worth the time we're putting into it. Because it's frustrating if we do a risk and then we repeat it the following year. And it's the same areas that we're pointing out that need to be addressed. So we have to close the gap of compliance and not become complacent with the areas that are not meeting those benchmarks. Does anyone else have anything they would like to share, Linda?
SPEAKER_00Livia, I would just like to remind our listeners that with these regulatory fines and sanctions that you mentioned, they're usually due in 30 days. There's not a payment plan with the federal government with these. So regardless of whether your fine is only 35,000 or whether it's 55,000, it's just important to think about the health of the practice as well as protecting the doctor's license, as you mentioned. So I just wanted to toss that little nugget out there.
SPEAKER_01Good point.
SPEAKER_02You know, OSHA fines, typically the dentist will write a check, but when they're HIPAA fines, it could be thousands of dollars or hundreds of thousands, or we look at some of these larger entities, millions of dollars. And that would be very difficult to simply write a check. And like you said, Linda, there's no payment plan. Mary, what can you share with us?
SPEAKER_03There's also very little room for negotiation with HIPAA, with the Department of Health and Human Services. What I've found through the years is that if an office is cited and they're assessed a fine for an OSHA violation, you can help reduce that, or they will reduce that fine for you if you immediately fix the problem, if you can argue successfully with them that what you're doing really doesn't pose a risk. And I've seen a bunch of those happen. So they'll reduce fines. And we got a good example of that during COVID, a practice in, I believe it was in Massachusetts, that it started out at somewhere around $54,000 or something in fines. And it was negotiated down to $9,500. I know the $9,500 is the for sure. I'm not sure about the upper end, but I know it was it was definitely five figures. And that was a result of negotiation with them. But I have not found the Department of Health and Human Services to negotiate at all. It's either their way or the highway.
SPEAKER_01Good point, Mary.
SPEAKER_02So the purpose of these risk assessments is that, as I mentioned, we want continuous improvement, but isn't it better to self-govern rather than having something held over us, making us do it? So don't wait for a violation to happen to make changes or have to meet these corrective actions that's been required of us. We want to self-govern ourselves through these risk assessments in order to identify areas that need to be improved and gather that data in order to prioritize our risk. You know, what needs to be done first, what is the highest risk, and then optimize our readiness with the goal to protect our dental practice as a business, also to protect the employees, and of course, to protect the patients that we're serving, which is key. So I've really enjoyed this episode discussing risk assessments and how we can incorporate them into our dental practices and also all the information that the divas have shared with our listeners. We hope that you have enjoyed it as well. As the compliance divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please submit your questions to support at thecompliancedeevas.com. And we will provide the resources that we've referred to in this episode in the show notes. Thanks again for joining us, and we'll see you next week.