The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
#140 Year End Compliance Reminders
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
As we approach the end of the year and embark on the New Year, it's time to ensure we have accomplished key areas of compliance related to OSHA and HIPAA. In this episode, the Divas discuss the top 20 OSHA/HIPAA reminders to help you stay current in your dental practice.
Resources:
- CDC Infection Prevention Checklist https://www.cdc.gov/oralhealth/infectioncontrol/pdf/safe-care-checklist-a.pdf
- OSHA Top Ten Reminders Poster
- HIPAA Top Ten Reminders Poster
Welcome! I'm Leslie Cannon. I'm Mary Gavoni.
SPEAKER_02I'm Linda Harvey. I'm Olivia Juan and together we are the Compliance Divas. Welcome to the Compliance Divas podcast. My name is Olivia Waugh and I'll be your moderator. In today's episode, we're discussing year-in compliance reminders. As we approach the close of this year and we embark on the new year, the divas thought it would be very helpful to discuss 20 year-in reminder tips. The Divas have divided up these reminders, and we will zero in on the topics of HIPAA and OSHA. As the Compliance Divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please subscribe to the Compliance Divas podcast through your favorite podcast channel or on our website, the compliancedevas.com. Any resources we mentioned during the podcast can be found on the website. Please submit your questions to support at thecompliancedeevas.com. Also, please scroll down while you're on the podcast and leave us a review. So we're approaching the end of the year and the beginning of a new year. And as we look at our compliance programs in our practices, what are some of those top things that we need to focus on? So the divas have put together some very simple tips and reminders to make sure you close any gaps in your compliance program. We're going to start with our diva, Mary, for the first top five reminders, Mary.
SPEAKER_00Thanks, Olivia. And I think this is such a powerful tool talking about these as we approach the end of the year, when we want to get a fresh start for the new year and perhaps be more organized in the next year. So number one thing to remember to do is to make sure that you have either completed your OSHA training for this calendar year or that you have it, if you have, that you have it scheduled, time reserved in your schedule to do it in the coming year. Whether you need to block time in the schedule for no patients, or contact a trainer or the consultant that you work with to get on their schedule to come in and do the training for you. Make sure that you know you've got that taken care of. And make sure that you maintain your training roster. Remember that the four things that OSHA wants documented on your training documentation are the date of the training, the name of the employees who attended, and their position in the practice. Are they doctor, hygienist assistant, administrative team members, the topics that were discussed? So perhaps an outline of that training, and the name and the credentials of the trainer who presented. So it could be your infection control manager, could be your consultant that you work with from the outside, whoever does that training for you. And make sure that you have all those training records in place because that's very important if you have an OSHA inspection or an audit. Make sure that you review and update your exposure control plan. And a great way to do that is to complete the CDC checklist that you can find on the CDC website to see if there are any things that you're perhaps deficient in or not doing, and then go back and review your documentation to make sure that you have all those things included. And back in the day of so many paper manuals, that was a tough thing to do to update those plans. And so hopefully, whatever mechanism you use for keeping track of all your OSHA documentation that you either think about or have made it electronic so that you can easily go in and update and edit documents. Every year we need to evaluate safer medical devices. The OSHA Sharps injury prevention rule, that may not be the exact title for that particular standard that's a companion to bloodborne pathogens, requires that you do an annual review of whether or not you have had Sharps injuries and what types of injuries you've had in the practice during the past year, what types of personal protective equipment were worn or not worn when those injuries happened, if you took corrective measures and what were they to prevent it from happening again, and to evaluate whether safer medical devices might have helped to prevent that injury and research what is available. You don't have to utilize any new devices or every new device that comes into existence, but you at least have to evaluate, and there's a process for doing that to see if it makes sense in your practice. In particular, if the same injury keeps happening again. So a good example here would be a real common injury that happens in practices are the dental assistants or other team members who are cleaning instruments, getting them ready for sterilization. If the instruments are loose and they go into the ultrasonic loose, and then we have to package them, the propensity for puncture injuries is relatively high. So a corrective measure in that instance would be to use some kind of an instrument cassette or a container to have those instruments in while they're being cleaned, and they can be packaged inside that container as well. And if your state requires you to keep a sharps injury log, make sure that you have it updated so that you've recorded all those injuries in the sharps injury log. And remember that the sharps injury log is only about the incident that happened. You don't name the person that was involved in it. It's just the date and when and other required information. And if your practice has been notified by OSHA that you must use the OSHA injury reporting forms, then know that starting February 1st, you have to post that summary of injuries in your office for everybody to be able to see. But most dental practices are exempt from that.
SPEAKER_02Thank you, Mary, for summarizing those first five reminders as it relates to OSHA. So just a quick recap: training, training roster, update the exposure control plan, safer medical device evaluation, and Sharp's log if required, andor record keeping. Now for the next five reminders, let's talk with Linda and see what she has to say about those tips.
SPEAKER_01Olivia, my five tips also revolve around OSHA. First are the injury reports. Anytime someone has had an exposure incident with a contaminated needle or contaminated source throughout the year, we know that's documented on a particular injury report. So those reports need to be maintained confidential within the employee's OSHA medical record. So I'd like to refer our listeners to look through your OSHA binder and make sure none of those incident reports have gotten stuck inside the front cover or filed in the tab under the forms or some other place in the binder. They need to be with the doctor or the office manager, whoever manages that OSHA medical record file. So those are a must. They have to be there. Next, it revolves around the safety data sheet collection. Whether the office has an electronic binder or a paper binder, this needs to be reviewed and updated every year. So let's talk, let's talk about the paper binder first. And what that means is that you go through the sheets and you identify any items that you are not using, any products that you're not using in the practice, pull those out, save them in either a different binder, scan them into the server, or put them at the back of your current binder. But we have to keep those outdated SDS sheets for 30 years. So think about making sure that you go through that. Most of the time, I find Olivia offices that alphabetized their SDS binder. So even if a couple of team members can each take a few letters out of the alphabet, you can go through it quickly in about 10 or 15 minutes. Next is the chemical inventory list. This, just like the Safety Data sheet collection, are part of the hazard communication standard. The chemical inventory list is actually a list of the ingredients in all the products that you have in your practice. It's not a list of the products that you're buying from your favorite dental supplier, but it's the ingredients in each one of the surface disinfection products, profit-based, restorative materials, so forth. It's the ingredients in there. And that can be kept paper or electronic as well, as long as it's reviewed and updated annually. So I want to circle back to the electronic SDS binders really quickly. So if you have them living on your server, maybe your sales rep has sent them or you've downloaded it from the supply rep's website, that's all fine. If you're keeping them electronically, do you have them organized so you can go through and check to see which ones need to be updated? And by updating, I mean, Olivia, when you look at that SDS sheet and it's more than a couple of years old, go out and do a web search and see if the company has published an update. So there's a bit of work in keeping this part up. Fourth is just updating all your other OSHA and safety compliance policies, the fire safety plan, the emergency evacuation plan, your infection control plan, and so forth, and making sure that you have all those up to date. And just in the past couple of years, we've been creating a workplace violence and active shooter policy for our offices, because that's just a good thing to have in there and an abundance of caution because we never know what can happen in your practice. We have to be prepared for all kinds of events and emergencies. Lastly, review your task logs. Do you keep them in a binder? Do you keep them electronically? Um, hopefully, they're more than just a few sheets tacked to the wall or stuck in a drawer in sterilization. But the task logs cover everything from sterilization monitoring, monitoring of any, um if you're still using gold sterile, for example, but monitoring your ultrasonic, uh, fire safety checks with the fire extinguishers, monitoring the eye wash station, all the different areas that team members are creating, tasks and logs and checks, your amalgam separator, your pump, all kinds of areas, uh and all the equipment and so forth, there are task logs that you probably have created. Keep those up to date and make sure that all the proper maintenance is being done in a timely fashion. Because if not, then you may find out that one day either an inspector is coming in and you're looking for important records that are missing, or it may be that someone has not been keeping up maintenance with some of your important equipment and you get a equipment failure or something breaks down. So it does have good purposes, Olivia, preventive and required. So those are my five tips. Um, looking where your injury reports are filed, updating your SDS binder, making sure your chemical inventory list is up to date, and all the rest of your OSHA binder on the policies, and then lastly, your task logs.
SPEAKER_02Thanks, Linda, for those other five OSHA reminders. Our Diva Leslie could not be with us today. However, Mary is going to cover the first five reminders that relates to HIPAA compliance. Mary.
SPEAKER_00Thanks, Olivia. I want to go back first to one um thing that Linda emphasized that it's so important is that exposure incident reports and hepatitis B vaccine documentation are confidential medical records. And so if we're using paper records, it's pretty easy to keep them in like in a locked file cabinet. But a lot of people don't understand that if they're going to share them or not share them, store them electronically, that they can actually password protect those individual files or folders so that only certain people in the practice have access to them. So let's talk about HIPAA. Um HIPAA training is a certainly a requirement for a review of protocols for HIPAA on an annual basis, but we need to be adding in cybersecurity. And the what I recommend to the practices that I work with is that they talk to their technology support company that they work with that does all their security um and network um planning and setup for them, and that they do, as part of their services, a cyber training um session for them. And it could even be something that's recorded so that if there are new employees being onboarded, they can partake of that um training as well once it's past the training date. But as we're seeing so many breaches and so many fishing um attacks and all those kinds of things and practices, that is critically important. And one of the things that, as the divas we've discussed, is how really um sort of loosey-goosey practices have been in the past with computer security and doing shopping and all kinds of things. Um in fact, I had a practice that just opened a new facility, and the first day that they were open, Pandora caused a breach in their practice because they had their Pandora music set up on their office intranet. It got hacked. So be very careful. Just as with OSHA training, make sure you maintain a training roster, that you have documentation not only of your annual training, but new employee training if you've added to your staff. And if things change, there's new developments, you should do a maybe an abbreviated training session and also document that cyber training. Make sure that you review your security and privacy policies on an annual basis to make sure that you are following the most appropriate security practices, that you have a contingency plan in place in case something does happen, a breach, or and so forth. And make sure that you update even something as simple as designating who your privacy and security officer is in the practice. Review your business associate agreements, make sure that you have one for all of the companies that you work with that may need to have access to your patients' protected health information in order to provide services for you. And keep in mind that cleaning services are not covered by business associate agreements because they do not require access to protected health information to do their jobs. I have all of my practices I work with sign a confidentiality agreement with the cleaning services so that just in case there's an inadvertent piece of material that's that's left out that they may have seen that they agree that they will not share that with anyone. And then check with all of your IT support contracts, your practice management service support, your IT support company that you work with to make sure that all the services are in order, that um your backups have been checked for viability so that they could be restored from. Making sure that you're on the latest version of your operating system and your um updates are up to date, the Windows operating system and so forth, because we've had lots and lots of security patches recently. So those are my top five things on behalf of Leslie for today.
SPEAKER_02Those are great reminders that relate to HIPAA, which is so serious nowadays, especially. And just to bring this episode to a close, I wanted to add in the last five reminders, and these relate also to HIPAA, and that is to have the employees enter into confidentiality agreements if you haven't already done so. Make sure the hardware inventory is current, especially if you've uh have end of life on some of your equipment and purchase new hardware. Please make sure that your HIPAA security risk assessment has been conducted and that you have a corresponding work plan to address the issues that identified that there's a threat or vulnerability. And then please issue periodic reminders such as phishing emails. And the divas were speaking earlier about how we have an update from the US Department of Health and Human Services as of today that was published that relates to a phishing email that caused a lot of grief for a covered entity. So this is definitely timely information. So we appreciate our audience tuning in to the top 20 year-end reminder tips as the compliance divas. We bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please submit your questions to support at the compliancedevas.com. And we have provided the website links and resources for you in the show notes. We'll see you again with the next episode.