settingsMerit-Based Incentive Payment System (MIPS) and the SRA.
With two months left of 2021, time is running out to make sure you get you SRA done in time for MIPS submission. If your organization participates in MIPS, in addition to being federally required, a Security Risk Analysis (SRA) is an important chunk of your MIPS score, specifically the Promoting Interoperability (PI) measure. To attain a score on the PI measure, eligible organizations must attest yes to conducting or reviewing an SRA within the calendar year of the performance period. If you have not completed an SRA, you will receive a 0 for PI. This section makes up 25% of the entire MIPS score. MIPS participants must attain a 85% or higher to qualify for the exceptional performer bonus, and 65% to qualify for any incentive payments. If you score below 65% on MIPS, you can incur penalties.
What exactly is a Security Risk Analysis (SRA)?
The SRA is the first requirement in the HIPAA Security Rule. The HIPAA Security Rule establishes national standards to protect individuals’ electronic personal health information that is created, received, used, or maintained by a covered entity. The Security Rule requires appropriate administrative, physical and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information. An SRA helps you identify and implement safeguards that comply with and carry out the standards and implementation specifications in the Security Rule. Covered entities and business associates of ALL sizes are required to comply with HIPAA – and to perform a Security Risk Analysis. There is no exemption for small practices. If audited by the Office of Civil Rights (OCR), an up-to-date SRA is one of the first documents you’ll be asked for.
How can Medcurity help me?
Medcurity streamlines your Security Risk Analysis and creates a Risk Management Plan right sized for your organization. You have a team of experts supporting you throughout the year and a user-friendly dashboard to track your progress and reports, so you can confidently attest that you have met the SRA requirement. MediGroup members not only receive an exclusive discount on their Medcurity subscription, but also gain access to a library of educational resources focused on HIPAA and information security. Medcurity keeps subscribers informed on federal updates and advises you on any necessary changes so you can feel confident in your HIPAA compliance program. If you have questions or need resources on MIPS submission, you can reach out to Medcurity.