HIPAA Workflow
 
Overview

HIPAA compliance involves a lot of processes in addition to setting up technical safeguards.
The costs generated by HIPAA compliance projects can be dramatically reduced by implementing the WorkflowGen workflow software. Instead of hiring new personnel to perform human based procedures or developing dozens of specific software applications, health care organizations can deploy fully compliant automated processes thanks to WorkflowGen.

The WorkflowGen BPM / Workflow software provides real time request follow-up, action tracking and audit trail functions as well as connectors to build gateways with legacy systems like HIS, databases, directories, ERPs.

Administrative safeguards require the implementation of several procedures which can be automated with WorkflowGen. The administrative safeguards comprise over half of HIPAA procedures and are grouped in the following standards:
- Security management process
- Assigned security responsibility
- Workforce security
- Information access management
- Security awareness and training
- Security incident procedures
- Contingency plan
- Evaluation
- Business associates contracts and other arrangements


Security management process

This standard requires organizations to: "Implement policies and procedures to prevent, detect, contain and correct security violation".
The following procedures defines in this standard can be successfully automated and optimized by using the WorkflowGen BPM / Workflow software:
- Risk analysis
- Risk management
- Sanction policy
- Information system activity review

Each WorkflowGen process includes the following features:
- e-Form to capture and control data input
- Workflow to orchestrate requests and actions
- Connectors to populate e-Forms fields or to perform import/export during the process execution
- If needed an agent can monitor logs to trigger automatic audit processes for example.


Workforce security

This standard requires covered entities to: "Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information..."
This standard is one of the biggest HIPAA challenge in term of change management.
IT departments must delegate access authorization responsibilities to department managers without compromising the security.
WorkflowGen provides a secure and lightweight solution to automate the following procedures:
- Authorization and/or supervision
- Workforce clearance procedures
- Termination procedures

By using WorkflowGen BPM / Workflow software to manage those processes you dramatically reduce  the costs generated by the management of an important amount of requests per month, moreover you comply with the traceability and audit HIPAA requirements.
WorkflowGen's integration features allow you to automatically import/export data to your HIS, HR system or directory.


Information access management
This standard requires covered entities to: "Implement policies and procedures for authorizing access to electronic health information..."

The following procedures can be automated with WorkflowGen:
- Access authorization
- Access establishment and modification

Security incident procedures
This standard requires covered entities to: "Implement policies and procedures to address security incidents."
Because the implementation of this standard is required for HIPAA compliance, healthcare organizations must have an efficient solution to manage security incidents.
The WorkflowGen BPM /Workflow software offers a fast and simple way to manage incident forms and associated workflows like "response and reporting" procedures.