HIPAA Technical Review

When discussing document exchange the three areas of concern for HIPAA are document formats and communication protocols.

  • The ANSI X12N standards are the guidelines used for document format definitions.
  • HL7 standards govern electronic medical records.
  • EDI INT AS2 standards outline the protocol required by HIPAA for secure data transmission.

An example of a document exchanged is a submission of a claim to a payer. The Health Care Claim document format is the Transaction Set 837. The claim is transmitted by secure Internet. (The transmission is secure due to the exchange of certificates, encryption of the message, connection filtering and more.) As exchange occurs without manual intervention, the process must have extensive controls. Thus, EDI Integration is a combination of document format, data transmission, and process management.

A typical development scenario would include selecting three payers, as variation within the standard is permitted.

  1. From each payer, obtain specifications (documents expected, EDI and AS2 specifications, code lists, and the testing process).
  2. The project plan is drafted and reviewed with I.T. and A.R. staffs.
  3. The appropriate resources are identified and acquired and deliverables are set.

DCS’ implementation, planning and development experience shows the primary snags that arise during this type of project are:

  • Substantial delays or re-development occurs during testing with Trading Partners because of inaccurate or underdeveloped unit test plans during internal testing. This most often occurs because the looping structure of EDI documents is not understood by the person developing the translation.
  • Gap analysis is not completed, delaying a project because data required to be sent to the Trading Partners are not in the application tables or similarly no fields are available for data received.
  • Cross-reference data is not defined appropriately. This often occurs because the developer is not familiar with the actual business practices of your organization and makes incorrect assumptions.
  • Data transmission is halted because of network and Internet security. (Working with the firewall administrator is required).
  • Lack of knowledge transfer due to I.T. turnover.
  • Inadequate EDI support from application vendors.

You should also know that HIPAA required EDI data is also frequently sent to a database instead of a PMS. Several DCS customers have moved summary data into/out of Microsoft SQL ServerTM or Oracle 11gTM databases for subsequent processing such as reporting. DCS role is to help with data table design for EDI data and then map the data into a database. Frequently, DCS customers can save development cost by doing the business application and reporting themselves after DCS sets up programs to load the tables. Working jointly processes are swift and reliable.

Free Assessment

DCS is ready to discuss your EDI challenges and configuration. Contact us today and you'll be on your way to a smooth-running EDI system.

Get Your Assessment Now!

Business Tip

Planning for 2012?
Which EDI expenses should be paid by I.T. or by users such as customer service?

Learn More

Understanding EDI

understanding edi Electronic Data Interchange (EDI) is the computer-to-computer exchange of routine business documents such as Purchase Orders, Shipment Notices, Invoices, and Remittance Advices without human intervention. Data moves from your customer’s computer system – through the Internet securely – to your computer system.

Learn More

Find the Right IT Partner

Choosing an I.T. partner can be daunting. Get it right, and you can increase efficiency; get it wrong, and your business may suffer. DCS will work with you to develop and maintain the process automation that best meets the needs of your company.

Find a Partner