Time Is Running Out: Ensure You Meet 2024 MIPS EHR Security Requirements
The end of the year is quickly approaching, and if you haven’t completed your 2024 security requirements yet, now is the time to act. The Promoting Interoperability (PI) category of MIPS includes two required attestations intended to protect patient health information: the Security Risk Analysis (SRA) and the High Priority Practices Safety Assurance Factors for EHR Resilience (SAFER) Guide assessment. If you fail to attest to either of these requirements, you will not earn a score in PI.
In this post, we’ll provide an overview of each of these requirements so you can make sure to complete them before the year ends.
The Security Risk Analysis (SRA)
The SRA elements were established through the HIPAA Security Rule. This means that the SRA is not just a box to check for PI — your security practices must meet the necessary standards to ensure HIPAA compliance.
How Do I Meet the SRA Requirement?
To meet the SRA requirement, you must attest “yes” to conducting or reviewing your SRA, updating security measures where necessary, and addressing any security weaknesses you find.
Your SRA must:
- Document potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI) of the eligible clinician,
- Address the encryption/security of data stored in your Certified EHR Technology (CEHRT), and
- Be performed specifically for your system.
While you do not have to fix every identified issue during the performance year, you must show that you have a plan for correcting or mitigating deficiencies and that you are taking steps to implement that plan.
It’s important to note that assessing security risks and vulnerabilities goes beyond software. It includes all of the following factors:
- Physical Safeguards in your office environment. For example, do you have privacy screens on your computers?
- Administrative Safeguards, like workforce training.
- Technical Safeguards like having access restrictions on your EHR.
- Organizational Policies, Procedures, and Documentation Requirements: having written policies and documentation; having business associate agreements.
Take a look at the Department of Health and Human Services (HHS)’ guidance on the SRA for additional information on what constitutes a risk or vulnerability.
When Do I Need to Complete the SRA?
The SRA can be completed at any time during 2024. It does not have to coincide with your PI performance period. However, the analysis must be unique for each performance period, meaning that you cannot reuse your analysis from 2023 for 2024. If you have not completed the SRA yet, now is the time.
In addition to completing an SRA annually, you must conduct one anytime you install or upgrade to a new system.
For additional guidance on the SRA requirement, check out our recent webinar on this topic.
The High Priority SAFER Guide: Newly Required for 2024
A separate requirement, which is mandatory for the first time in 2024, is the High Priority Practices Safety Assurance Factors for EHR Resilience (SAFER) Guide attestation.
Why Is This Important?
The rate of cyberattacks has increased dramatically since 2018, with incidents like the Change Healthcare breach causing major disruptions to the U.S. health care system. The SAFER Guide requirement was implemented to help organizations take a proactive approach in preparing for cybersecurity breaches and attacks.
How Do I Meet the SAFER Guide requirement?
There are several SAFER Guides designed to help health care organizations optimize the safe use of EHRs. To satisfy the SAFER Guide attestation for the MIPS PI category, you only need to complete the self-assessment portion of the High Priority Practices SAFER Guide.
This guide includes a checklist of recommended practices and a worksheet for each practice, where you can take notes specific to your organization. You’ll assess your organization’s implementation of each practice using the following scale:
- Fully in all areas
- Partially in some areas
- Not implemented
You don’t need to implement each practice right away, and you won’t be scored based on how many practices are fully implemented. To meet the requirement, you must complete the checklist, evaluate your organization’s practices, and document any potential changes.
For more details on the High Priority SAFER Guide requirement, check out our previous blog on this topic.
Next Steps
- Share this information with your colleagues.
- Subscribe to our blog to get alerts on this and other important issues. You can subscribe using the field in our website footer below.
- If you are an Anatomy IT client, contact your MIPS Expert if you have any questions.
- If you are not an Anatomy IT client, contact us to learn more about our MIPS Success Plan and to reap the rewards of our combined decades of experience.
Let us know if you are interested in using Anatomy IT’s services to complete the SRA or the SAFER assessment.
Written By: Sarrah Hakim, MHSA
About the Author: Sarrah is a Manager of Health Policy at Anatomy IT.