Integrated hipaa-compliant computer security system for permitting real-time access to individual budget and service plan data, and to monitor services and progress toward outcomes
Inventors
Brockie, Justin Mark • Ali, Md. Asif • Faruq, A. S. M. Omar • Kelly, James Michael • Rafique, Sazzad • Robbins, Richard Allen
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
Systems and methods for sharing billing information across at least two organizations in an integrated manner are described. A physical node may receive a request for authorization for a user in an organization to access an individual's information in another organization. The request may be logged. The physical node may determine whether the user is authorized to access the individual's information and, if it is, provide appropriate access. Also disclosed is an integrated web application and system which includes the core plan, budget, service authorizations, service documentation, claims, and communications of an individual under care and allows for calculated access and communication with external authorization and payment systems.
Core Innovation
The invention provides a HIPAA-compliant computer security method of real-time sharing of service, budget, and billing information associated with personal health information of one or more individuals among at least a first organization and a second organization in an integrated manner, while preventing unauthorized access to billing information. The first organization is associated with a first security domain and the second organization is associated with a second security domain, where the second organization has an access profile associated with the first security domain.
The method receives an authorization request from a user in the first organization to access service and budget information in the second organization, logs the authorization request in an activity log associated with at least the first organization or the second organization, and determines whether the user is authorized based on at least the access profile, one or more caseloads, one or more roles associated with the user, and the type of service and budget information pertaining to the one or more individuals. If authorized, the method transfers the service and budget information in compliance with HIPAA and logs the transferring in the activity log in compliance with HIPAA; if not authorized, the method prevents the requested access in compliance with HIPAA.
The method also receives information pertaining to services provided to the one or more individuals by the first organization and billing information generated by the first organization pertaining to the provided services. The information permits the user to monitor the services and the individual's progress toward outcomes, and the integrated approach further includes coordinating individual care plans by intake/eligibility to compute an Individual Budget Amount (IBA), creating a budget and Individual Service Plan, generating and routing service authorizations, capturing real-time attendance and attendance-derived billing data, and producing professional/institutional claims for submission to payors while providing real-time utilization and forecasting.
Claims Coverage
The document identifies two independent claims: a HIPAA-compliant computer security method and a HIPAA-compliant computer security system for real-time sharing of service, budget, and billing information across a first organization and a second organization. The independent claims center on authorization-request receipt, activity logging, authorization determination using access profile, roles, and caseloads, conditional HIPAA-compliant data transfer or denial, and receiving service and billing information to support monitoring of services and progress toward outcomes.
Hipaa-compliant real-time sharing across security domains
A HIPAA-compliant computer security method of real-time sharing of service, budget, and billing information associated with personal health information of one or more individuals among at least a first organization and a second organization in an integrated manner, while preventing unauthorized access to the billing information, where the first organization is associated with a first security domain, the second organization is associated with a second security domain, and the second organization has an access profile associated with the first security domain.
Authorization request logging and authorization determination
Logging, in an activity log associated with at least the first organization or the second organization, the user's request for authorization, and determining whether the user in the first organization is authorized to access service and budget information in the second organization based on at least the access profile, the one or more caseloads, the one or more roles associated with the user, and the type of service and budget information pertaining to the one or more individuals.
Conditional hipaa-compliant transfer with compliant logging or prevention
Responsive to determining that the user is authorized, transferring the service and budget information in the second organization in compliance with HIPAA and logging the transferring in compliance with HIPAA; responsive to determining that the user is not authorized, preventing the requested access in compliance with HIPAA.
Receiving service and billing information for monitoring outcomes
Receiving information pertaining to services provided to the one or more individuals by the first organization and billing information generated by the first organization pertaining to the provided services, wherein the information permits the user to monitor the services and the individual's progress toward outcomes.
Hipaa-compliant real-time sharing system with authorization controls
A HIPAA-compliant computer security system for real-time sharing of service, budget, and billing information associated with personal health information of one or more individuals among at least a first organization and a second organization in an integrated manner, while preventing unauthorized access to the billing information.
System means for authorization request logging and determining access
Means for receiving an authorization request by one or more physical nodes, means for logging the user's request in an activity log, and means for determining whether the user in the first organization is authorized based on at least the access profile, the one or more caseloads, the one or more roles associated with the user, and the type of service and budget information pertaining to the one or more individuals.
Means for transferring authorized information or preventing unauthorized access
Means for responding to a determination that the user is authorized comprising means for transferring, in compliance with HIPAA, the service and budget information to the user in the first organization and means for logging the transferring in compliance with HIPAA; and means for responding to a determination that the user is not authorized by preventing the requested access in compliance with HIPAA.
System means for receiving services and billing information for monitoring outcomes
Means for receiving, by one or more physical nodes, information pertaining to services provided to the one or more individuals by the first organization and billing information generated by the first organization pertaining to the provided services, wherein the information permits the user to monitor the services and the individual's progress toward outcomes.
Across the independent claims, the core coverage lies in HIPAA-compliant real-time sharing of service and budget information across security domains, activity logging and authorization decisions based on access profiles, roles, and caseloads associated with personal health information, conditional HIPAA-compliant transfer with compliant logging or prevention of access, and receiving service and billing information to allow monitoring of services and progress toward outcomes.
Stated Advantages
Prevents unauthorized access to the billing information while enabling real-time sharing of service and budget information.
Permits a user to monitor services and an individual's progress toward outcomes.
Documented Applications
Coordinating individual care plans by integrating service and budget information sharing, real-time attendance and attendance-derived billing data capture, generation and submission of professional/institutional claims to payors, and real-time utilization and forecasting for a state, an individual, a case manager, and a support circle.
Interested in licensing this patent?