MIPS Highlights 2024 – Q3

With the kids back in school, it’s time to catch up on your MIPS homework! That means it’s time for the Security Risk Assessment (SRA)!

What is SRA?

The Security Risk Analysis (SRA) is a critical process for both MIPS and HIPAA. Under MIPS, it directly impacts a provider’s performance score in the Promoting Interoperability (PI) category, while under HIPAA, it is a legal requirement to ensure the protection of electronic Protected Health Information (ePHI).

MIPS (Merit-based Incentive Payment System): As part of the Promoting Interoperability (PI) category, healthcare providers are required to conduct or review a Security Risk Analysis (SRA) to protect electronic health information. This requirement ensures that practices have assessed the risks to the confidentiality, integrity, and availability of Protected Health Information (PHI) and have taken steps to mitigate those risks. The SRA is a measure that contributes to a provider’s overall MIPS score.

HIPAA (Health Insurance Portability and Accountability Act): HIPAA requires covered entities and their business associates to conduct a Security Risk Analysis as part of their compliance with the HIPAA Security Rule. The SRA is crucial for identifying potential risks and vulnerabilities to the electronic PHI (ePHI) that an organization holds. After identifying risks, organizations are expected to implement appropriate security measures to manage and mitigate those risks. Regular reviews and updates of the SRA are also necessary to ensure continued compliance.

How do I complete the SRA?

Many practices involve their IT to assist with completing the SRA. The SRA Tool Kit can be useful for practices trying to complete the SRA independently. However, while CMS provides these tools to aid self-evaluation, many industry leaders believe that relying on non-experts for your SRA could leave your organization vulnerable to attacks, potentially leading to reputational damage and financial penalties.

Compliance with the NIST Cybersecurity Framework 2.0 offers safe harbor protection in the event of a cybersecurity incident. Our security partner, PatientLock, provides enterprise-grade Security Risk Assessment services that are compliant with CSF 2.0.

How do I report or submit my SRA?

For MIPS PI reporting, you can submit your Security Risk Assessment (SRA) by providing a simple Yes/No attestation. It is essential to maintain a record of each SRA completed annually for potential MIPS audits. Ensure you keep multiple copies of these records off-site to safeguard against data breaches or corruption.

Share this Post:

Related Posts

MIPS Highlights 2025 – Q2

  Spring has sprung, which means it’s time to start your 2025 MIPS planning and monitoring. If you haven’t already scheduled an appointment with your Verana Practice Experience Manager, now is the time to do so. Additionally, this year Verana is requiring registration to verify practice details and select a service level. Please review details on Verana’s new service level selection and be sure to register by May 31, 2025.   2025 MIPS Deadlines January 1, 2025 – Start of the 2025 MIPS performance period for Quality and Cost May 2025* – Verana will update dashboards with 2025 Quality data May 31, 2025* – Deadline to Register with Verana for 2025 participation and select service level

Read More »

MIPS Highlights 2024 – Q4

As the Year Comes to a Close The team at EyeMD EMR Healthcare Systems would like to extend our heartfelt gratitude for your trust and partnership over the past year. We deeply appreciate your continued support and wish you great success and a joyful start to the New Year. Important MIPS Deadlines As we approach year-end, please keep the following key dates in mind for the MIPS attestation process: December 31, 2024: End of the 2024 MIPS attestation period December 31, 2024: Deadline for the MIPS Extreme & Uncontrollable Circumstances (EUC) Exception and the Promoting Interoperability Hardship application (closes at 8:00 PM ET) January 1,

Read More »
FTC logo

Federal Trade Commission Eyeglass Rule – Effective September 2024

The Federal Trade Commission (FTC) Eyeglass Rule, officially titled 16 CFR Part 456, is a regulation that mandates eyecare providers to provide patients with a copy of their eyeglass prescription immediately after an eye examination. This rule applies regardless of whether the patient requests the prescription, and even if the examination does not indicate a change in the prescription.   The FTC Eyeglass Rule will go into effect September 2024.   Rule Highlights: Automatic Release of Prescription: After completing an eye exam, you must provide the patient with a copy of their eyeglass prescription, even if they do not ask for it. No Conditions or

Read More »

Worldwide Cloud Outage Impact – Restored

Our support operations have been fully restored. Services for our credit card processing partner Nexio have also been fully restored. Eligibility checks for most carriers have been restored as well. A banner in the PM will provide status updates for the remaining carriers. We thank you for your patience and apologize for the inconvenience.

Read More »

Worldwide Cloud Outage Impact

 A software update from the cybersecurity company CrowdStrike has inadvertently disrupted IT systems globally. Although most of our systems were unaffected, our primary remote support tool (LogMeIn Rescue) is currently offline. Consequently, our remote support capabilities have been impacted. Our support team is unable to access customer systems using this tool. However, we can connect to remote systems using an alternative, customer-initiated tool. As a result, we are unable to perform certain remote tasks, which may lead to support delays and cancellations. Additionally, our credit card processing partner, Nexio, is currently unable to process credit card transactions, and certain eligibility checks are failing. We thank

Read More »

Welcome to NewCrop Rx v2- Exciting Updates and Enhanced Features!

We are excited to introduce NewCrop Rx v2!   Our development team has been collaborating closely with our ePrescribing vendor to bring you the latest version of NewCrop Rx. The new platform is designed to enhance usability and reliability, offering a host of new features including: A fresh, modern, and intuitive interface. Real-time benefits information (including alternative drug options). Customized SIG builders. New drop-down menus and much more! To ensure a seamless transition, please review the Migration Guide prior to your transition.   To assist you in mastering the ePrescribing process and optimizing your transition experience, the following resources are also available: Get Started Guide

Read More »

Worldwide Cloud Outage Impact

 A software update from the cybersecurity company CrowdStrike has inadvertently disrupted IT systems globally. Although most of our systems were unaffected, our primary remote support

Learn More »

EyeMD EMR Named 2024 Best In KLAS: Ambulatory Ophthalmology EMR


EyeMD EMR Named 2024 Best In KLAS: Ambulatory Ophthalmology EMR

More Information More Information
More Information More Information