Category: Editorial

Unwrapping the Potential of Patient Feedback

Evan Steele

By Evan Steele, founder and CEO, rater8.

As the year comes to a close, patients are racing against the calendar, not just to complete their holiday shopping, but also to schedule end-of-year medical appointments.

For many, meeting their annual deductible or taking advantage of flexible holiday schedules makes December the perfect time to prioritize healthcare.

For medical practices, this seasonal rush presents more than just full waiting rooms; it’s an opportunity to strengthen their online presence and gather meaningful patient feedback to carry into the new year.

Post-Care Surveys vs. Online Reviews

While related, post-care surveys and online reviews serve distinct purposes in the patient feedback ecosystem. Post-care surveys help practices capture real-time insights to improve operations, while online reviews are a public reflection of patient experiences that boost reputation and visibility. When used together, they can drive impactful changes, offer benchmarking against competitors, and build trust with both current and prospective patients.

Why Patient Feedback Matters During the Holidays

The end-of-year surge in patient engagement is the perfect time to prioritize both surveys and reviews. Here’s why:

  1. Patients are ready to engage: With healthcare top of mind, patients are more likely to provide meaningful feedback. Post-care surveys allow practices to gather input shortly after appointments, ensuring that responses are timely and relevant.
  2. Online reviews build momentum for the new year: A steady stream of patient reviews helps practices stand out online and reinforces trust with existing and prospective patients. Positive reviews improve a practice’s visibility and credibility online, creating a solid foundation for growth in the new year.
  3. Patient feedback drives meaningful change: While positive reviews enhance reputation, constructive criticism from surveys provides clear opportunities to refine operations, improve patient experience, and identify gaps in care delivery.

How to Boost Participation in Post-Care Surveys

Even in the hustle and bustle of the holiday season, you can inspire patients to participate in post-visit surveys with a few thoughtful strategies:

  1. Simplify the process: Send short surveys via text or email right after checkout with a direct link for easy access. A quick and seamless process is a win for busy patients.
  2. Communicate the value:  Be transparent about how their feedback helps improve care. When patients feel heard, they’re more likely to provide candid responses.
  3. Incentivize participation: Consider holiday-themed incentives, like a raffle entry or a personalized thank-you message, to encourage participation.

The Hidden Gift of Patient Feedback

It’s easy to focus on positive feedback: it feels good, boosts morale, and reinforces what you’re doing right. But the truth is, negative feedback can be just as valuable, if not more so. Honest criticism highlights areas where patients feel underserved and uncovers opportunities for meaningful improvement.

For instance, if several patients mention long wait times, it could be a sign to revisit scheduling processes or adjust staffing during peak hours. Or, perhaps feedback about confusing billing processes or difficulty reaching staff might indicate a need for better communication tools or additional training. These insights, while sometimes difficult to hear, are gifts in their own right, offering a clear path to better care. Moreover, gathering patient feedback and acting on it allows practices to benchmark themselves against competitors. By reviewing what other groups in your market are doing well or not so well, you can identify areas for improvement and differentiate yourself.

Continue Reading

Medical Devices are Attacked Every 20 Seconds: Here Is How to Protect Them

By Daniel Trivellato, vice president of healthcare and cyber risk solutions, Forescout.

A recent honeypot study revealed that every 20 seconds, somewhere in the world, a cybercriminal targets a medical imaging device. In the time it takes to check a patient’s vital signs, multiple attackers may be actively trying to breach the very systems designed to provide vital healthcare information and keep us alive.

While connected devices have become increasingly prevalent in healthcare, many healthcare organizations fail to adequately protect them. Recent research examining over 2 million devices across 45 healthcare organizations revealed that approximately half of all devices in healthcare networks are now Internet of Medical Things (IoMT), Internet of Things (IoT), operational technology (OT) or building automation devices. These are more than simply administrative systems, these devices play a direct role in influencing patient outcomes, including patient monitors, infusion pumps, and imaging systems.

Daniel Trivellato

Of the 306 medical device vendors observed, the research finds that medical devices are running on 110 different operating systems, making the complexity of securing these networks truly staggering.

While household names like Philips, GE Healthcare, and Baxter are major players in the space, these organizations only represent 40% of the vendor landscape. The remaining 60% is a fragmented maze of smaller providers, each with its own potential vulnerabilities.

Perhaps most alarming is the dramatic rise in exposed Digital Imaging and Communications in Medicine (DICOM) servers. Between August 2022 and May 2024, we’ve seen a 27.5% increase in exposed servers, with the majority of exposed devices located in the United States, India, Germany, Brazil, Iran, and China. Across all IoMT devices, our research uncovered 162 vulnerabilities, with half of the most critical flaws found in Windows-based systems.

Recent breaches have had real-world impact on both health systems and patients. In 2023, healthcare organizations experienced an average of 1.6 data breaches per day, with each incident affecting approximately 200,000 patients. This isn’t just about compromised data – it’s about real people whose private medical information is at stake.

When personal medical device data is stolen, patients can face serious personal risks, including identity theft, insurance fraud, and emotional distress. Many cybercriminals leverage stolen medical records to create sophisticated phishing schemes, impersonate patients to obtain prescription medications, or even blackmail individuals with sensitive health information. Patients may also experience emotional distress following a breach of personal information, feeling vulnerable knowing their most intimate health details have been exposed.

Continue Reading

Why’s Your Growth Game Stuck? Solutions for Health, Money & Tech Pros!

Today, where innovation and challenges collide daily, it can be hard to keep pace in industries that just won’t slow down. The healthcare, finance, and tech sectors feel these demands acutely.

Between patient loads, tech security threats, and funding crunches, professionals are balancing on a razor-thin edge. So, if your growth game feels stalled, you’re not alone! Let’s explore how a few strategic shifts can turbocharge your potential and make your operations more resilient than ever.

Are You Ready to Ride the Next Wave of Patient-Centric Care?

People today expect more from healthcare. Gone are the days when a quick consult would do the trick. Patients today want involvement, answers, and top-notch care on-demand. So, if your practice feels a bit behind, it’s time to rethink your approach.

Embracing a more patient-centered model is where the future lies. Think about virtual check-ins, real-time health data, or even AI-enhanced patient portals that empower patients while keeping them engaged. It’s about crafting an experience that feels less like an appointment and more like a personal health journey. Studies have shown that when patients feel more involved, they’re more likely to adhere to their health plans and experience better outcomes. For healthcare professionals, that’s a win-win.

A patient-centric approach also means thinking beyond individual visits. Regular check-ins, feedback surveys, and post-visit summaries can help build trust and loyalty. And in a time when patients can choose between thousands of providers, that loyalty can make a massive difference.

Is Your Tech Strategy Helping You Reduce Cyber Risks?

For finance and health pros, data security is non-negotiable. From patient records to financial details, these industries handle information that needs serious protection. But here’s the catch—security protocols are evolving rapidly, and hackers are even quicker to find new vulnerabilities. It’s a daily race to stay ahead.

So, what’s the key to keeping your data safe? First, a solid cybersecurity plan is a must. The old “it won’t happen to us” mindset has got to go. Regularly updating software, using multi-factor authentication, and educating your team on common threats are foundational steps. By proactively protecting your systems, you can reduce cyber risks and safeguard sensitive data.

Investing in advanced security tools might feel expensive initially, but think about the alternative. A single breach can lead to lawsuits, regulatory fines, and a massive hit to your reputation. In today’s tech-driven world, building robust security from day one is essential. Not only does it protect your clients, but it also shows you’re a trustworthy, reliable partner in their financial or health journey.

Continue Reading

How To Implement a Healthcare Cyber Resilience Plan

In healthcare, data breaches and cyber threats can disrupt patient care, compromise sensitive information, and even lead to financial losses.

A strong cyber resilience plan isn’t just about preventing attacks; it’s about preparing, responding, and recovering quickly if one occurs.

Here’s a step-by-step guide to building a cyber resilience plan tailored to the healthcare industry, ensuring your organization is well-prepared for cyber threats while maintaining patient trust.

1. Assess Your Current Cybersecurity Position

Begin by evaluating your cybersecurity strengths and weaknesses. Identify all digital assets linked to your network to uncover potential vulnerabilities. These include patient data systems and any third-party software, such as electronic health record (EHR) platforms. It’s also crucial to assess any digital health tools, like mobile apps or wearable tech integrations, that interact with patient data.

Once you’ve mapped out your assets, review defenses like firewalls, encryption, and system access policies to establish a baseline. This helps pinpoint gaps, providing a clearer picture of where to prioritize security improvements.

2. Set Clear Goals for Cyber Resilience

Define what “cyber resilience” means for your healthcare organization, focusing on maintaining essential services, protecting sensitive data, and reducing recovery time during an attack. These goals are critical in healthcare, where patient care depends on system availability.

Setting benchmarks, such as maximum allowable downtime or acceptable data loss, gives your team clear, measurable outcomes. This alignment ensures everyone understands the plan’s priorities and what success looks like.

3. Implement Cloud Security

Cloud technology is essential in healthcare for storing and sharing patient data, but it brings unique risks. Strengthening cloud security involves using multi-factor authentication (MFA) for system access and encrypting all data stored or transferred in the cloud.

Choose cloud providers who comply with healthcare regulations and conduct regular audits to ensure ongoing security. With robust healthcare cloud security measures, you protect patient data and enhance recovery options if a cyber incident occurs.

4. Develop Incident Response and Recovery Protocols

An effective resilience plan includes detailed incident response and recovery protocols. Your response plan should outline immediate steps for a breach, such as identifying the threat, containing it, and notifying affected parties under the Health Insurance Portability and Accountability Act (HIPAA) guidelines.

Disaster recovery protocols focus on restoring systems and retrieving data quickly, minimizing operational disruption. Automated backup tools help reduce downtime, and regular testing ensures readiness for real-world incidents.

5. Train Your Staff in Cybersecurity Awareness

Employee mistakes are a frequent cause of security incidents, often due to actions like clicking unsecured links, sharing passwords, or ignoring security alerts. Regular training equips your team to identify phishing emails, avoid unauthorized software downloads, and report unfamiliar devices connected to hospital equipment.

Additionally, encourage proactive security habits, such as locking screens when away, securing personal devices used for work, and updating passwords regularly. Hands-on activities, like unauthorized access scenarios or fake login prompts, help employees practice responses effectively. A culture of cybersecurity awareness empowers staff to safeguard data, fortifying your defense against potential breaches.

Continue Reading

Digital Health Adoption is Surging, But So Is Consumer Distrust

Dara St. Louis

By Dara St. Louis, executive vice president and a founding partner, Reach3 Insights

Many of us know exactly how many steps we’ve taken today. A quick glance at our phone or other fitness tracker makes quantifying certain aspects of our health a literal no-brainer. But while digital health is integrating snugly into everyday life for many Americans, there’s a catch: For every digital health evangelist, a similar number of Americans don’t trust big tech to use their health data responsibly.

In a study of 1,012 Americans 18 and older, we uncovered a tension between growing adoption and lingering trust issues that poses a unique challenge for companies in the healthcare tech space. Companies that can strike the right balance between innovation and trust could win over both sides of the trust spectrum, especially among younger, tech-savvier generations.

Digital Health Adoption Continues to Surge

Our latest digital health research suggests Americans are ready and willing to use technology to help them manage their health needs. Our latest digital health research reveals significant growth in the adoption of health-related technology among Americans:

— 66% of Americans now use health-related devices (up from 18% in 2021).
— 72% of Americans are using health-related apps, a sharp increase from 55% in 2021.
Fitness wearables and health apps have become mainstream, especially among younger generations:
— 29% of Gen Z and 23% of Millennials are particularly drawn to holistic wearables.
These users aren’t just downloading apps—they’re using them regularly. In fact:
— 88% of users actively engage with their health and wellness apps, especially for tracking: Fitness, nutrition, sleep, and mental health.

Mental health app usage is particularly notable among younger users, as 26% of Gen Z and 31% of Millennials use mental health apps. Many Americans say they’re open to AI playing a role in their health as well:

— 53% of respondents have positive or very positive feelings about AI in health and wellness.
— 17% specifically seek out applications that use AI.
— Over two-thirds might be interested in AI for digital health, especially for: Fitness, diagnosis, and screening applications.

The average American seems excited for digital health integration on the part of healthcare tech providers. There’s just one issue.

Americans Don’t Trust Big Tech with Their Health Data

The convenience is appealing, but when it comes to handing over sensitive health data, many are hitting pause. We saw this skepticism crop up several times in our research: The tech is promising, but Americans’ relationship with Big Tech is a stumbling block.

Fifty-seven percent of Americans believe tech companies could bring down the cost of healthcare, but 53% say they would never trust these companies with their personal health data. Over time, Americans have developed more reservations about Big Tech’s involvement in healthcare, with 44% expressing concerns in 2024 (up from 28% in 2022). Data privacy remains a key issue, as 49% of consumers are afraid it may be misused by the companies.

Continue Reading

Outsourcing In Drug Development: A Key Strategy for Sustainable Growth

The pharmaceutical industry is constantly evolving, driven by advances in science, technology, and patient needs. One of the most prominent trends shaping this industry is the outsourcing of various stages of drug development.

As companies aim to optimize costs and resources, outsourcing has become a strategic approach for pharmaceutical organizations looking to streamline operations, accelerate timelines, and maintain flexibility in a highly competitive market. By partnering with specialized organizations, companies can focus on their core competencies while leveraging the expertise and capabilities of external providers.

The Growing Importance of Outsourcing in Drug Development

Outsourcing is now a well-established strategy within the pharmaceutical industry. Particularly in the areas of research and development (R&D) and clinical trials, outsourcing offers significant advantages, from cost reduction to faster access to specialized skills. In an industry where time and quality are critical, outsourcing provides an opportunity for pharmaceutical companies to stay agile and meet regulatory requirements efficiently. Furthermore, outsourcing supports the global expansion of drug development, allowing firms to navigate regional regulations and access patient populations more effectively.

A recent report by Forbes underscores how pharmaceutical companies are increasingly relying on outsourcing partners to meet their R&D needs and manage costs. This trend is expected to grow as companies face rising pressure to bring innovative treatments to market quickly while balancing budget constraints. Outsourcing allows companies to meet these demands without compromising on quality or compliance, leading to faster and more efficient drug development processes.

The Role of Contract Research Organizations (CROs)

Contract Research Organizations (CROs) play a central role in the outsourcing landscape. These organizations provide a range of services, from preclinical studies to clinical trial management, ensuring that pharmaceutical companies have access to the resources and expertise required to conduct thorough, compliant research. CROs have the specialized knowledge needed to navigate complex regulatory requirements across different regions, which is particularly beneficial for pharmaceutical companies with global ambitions.

One notable example of specialized CROs is US clinical research organizations like Ergomed, which focus on supporting drug development through high-quality, regulated trials. These organizations bring expertise in protocol design, patient recruitment, data management, and reporting, enabling pharmaceutical companies to concentrate on advancing their therapeutic areas while CROs handle the operational complexities of clinical trials. By collaborating with reliable CROs, pharmaceutical companies can also benefit from enhanced data accuracy, regulatory compliance, and faster trial execution.

Continue Reading

HTI-2’s Sweeping Scope Means Unrealistic Timelines, Costly Compliance Requirements, and Concerning Changes

Stephanie Jamison

By Stephanie Jamison (Greenway Health) and Leigh Burchell (Altera Digital Health), Chair and Vice Chair, EHR Association Executive Committee, and Greg Thole (Oracle), Chair, EHR Association Certification Workgroup

In the lead-up to publication by the Assistant Secretary for Technology Policy (ASTP) of the Health Data, Technology, and Interoperability: Patient Engagement, Information Sharing, and Public Health Interoperability (HTI-2) proposed rule, health IT stakeholders braced for what was certain to be a massive policy proposal. Those fears were quickly realized when the overwhelming scope of proposed new and expanded software requirements in the 1067-page HTI-2 NPRM was revealed.

Leigh Burchell

Following an in-depth analysis of HTI-2 and the process of drafting comments (available here), the EHR Association has identified several overarching issues, as well as specific concerns related to Insights measures within the proposed rule.

Highlighting the Positives

Before we delve into the negatives, however, it is important to note that we are highly supportive of several of ASTP’s recommendations. One is the proposal to expand the Certification Program to include criteria focused on the adoption and use of certified health IT by both payers and public health agencies (PHAs) to supplement criteria for healthcare providers. Holding all parties to specific and consistent standards and procedures is critical to achieving real end-to-end interoperability.

Greg Thole

Another is the way ASTP has structured the numerous new proposed FHIR API-based required features (e.g., dynamic registration, SMART Health Cards, CDS Hooks, Subscriptions) in a manner that allows developers to re-use the same capability for multiple different use-case-focused criteria. This is a helpful format that allows developers to streamline and avoid duplicating work effort.

Finally, in the context of the Insights requirements, many of ASTP’s proposals demonstrate attentiveness to the questions and concerns raised by the Association and its member companies since the measures were originally finalized in HTI-1 rulemaking. Some of these tweaks to measurement specifications will reduce the burden and make for more consistent and valuable reporting data.

Overarching Concerns

While we do support many elements of HTI-2, there are also several areas of real concern. We’ve raised many of them previously in comments, but they have yet to be adequately addressed by ASTP and other regulatory agencies.

For example, a common refrain in the Association’s comment letters and RFI responses is that compliance timelines and the scope of work in ASTP regulations create significant burdens for all health IT developers, as well as our healthcare provider customers. We delivered this message related to HTI-1, and our members are now devoting extensive resources to compliance—sometimes at the cost of innovation clients have requested.

Yet, as evidenced by the extensive scope of the HTI-2 proposals, ASTP and CMS continue to ignore the significant and serious timeline concerns we’ve voiced for years. CMS programs, such as the Medicare Promoting Interoperability program and Merit-based Incentive Payment System (MIPS), require healthcare providers to use upgraded certified EHR technology effective essentially on the same deadlines set by ASTP for vendors to deliver those updates. This forces developers to deliver compliant solutions significantly earlier than the deadlines officially listed by ASTP and does not allow adequate runway after the deadline for healthcare providers to adopt the updates, potentially compromising a safe and effective implementation process.

Continue Reading

MDaudit’s 2024 Benchmark Report Reveals a Fivefold Increase in Dollars At-Risk from Payer Audits While Coding-Related Denials Surged by Over 125%

External audit volume more than doubled in 2024 over 2023-including higher rates of pre-payment audits-and total at-risk dollars increased fivefold to $11.2 million per MDaudit customer, impacting healthcare provider organizations’ cash flow and exposing them to higher potential denial rates.

Additionally, improvements in revenues and operating margins throughout 2024 were tempered by higher denial rates, including an increase in coding-related denials of more than 125% and in medical necessity-related denials of 75% for outpatient claims and 140% for inpatient claims. These trends highlight the pressing need to overhaul revenue cycle management (RCM) strategies in the coming year.

These were among the key findings of the 2024 MDaudit Annual Benchmark Report released today by MDaudit, an award-winning cloud-based continuous risk monitoring platform for RCM that enables the nation’s premier healthcare organizations to minimize billing risks and maximize revenues. Last year’s report forecast strong volumes for healthcare organizations, the impact of which was constrained by challenges related to controlling costs, improving margins, and seizing opportunities to generate new revenue streams-predictions that held true as operating margins improved by more than 4% against a surge in audits and denials.

Ritesh Ramesh

“Looking ahead to 2025, those same headwinds, along with new risks around timely reimbursement and cybersecurity costs, will impede continued progress toward financial stability,” said Ritesh Ramesh, CEO, MDaudit. “This backdrop of challenges elevates RCM transformation to a strategic imperative for health systems in 2025, with an emphasis on continuous monitoring of financial risk to enable proactive mitigation of issues before they impact operations.”

Payer Behavioral Shifts Send Audits Surging

An increase in external audit volume, coupled with an increase in the average denied amount per claim across professional (~4%), outpatient (~3%) and inpatient (7%) settings, exerted additional financial pressures on healthcare providers. This year also saw a trend in more pre-payment audits. Unlike traditional post-payment audits that can result in clawbacks, pre-payment audits increase denial risks and cause cash flow issues.

Payers also stepped up clinical documentation scrutiny, sending audits surging by 100% over 2023 levels and contributing to a 3-year increase in clinical denials of 51%. To counter this trend, providers must focus on high-value services and ensure that clinical documentation improvement (CDI), billing, coding, and RCM programs are tightly coupled to implement a closed feedback loop from the backend to the mid-cycle to drive efficiencies.

Additionally, the Centers for Medicare and Medicaid Services (CMS) has put Medicare Advantage (MA) plans under the microscope as it continues ferreting out fraud and abuse-efforts that led to a 72% rise in hierarchical condition category (HCC) and Risk Adjustment audits and a 51% increase in total denial amounts for MA plans.

This heightened scrutiny, coupled with more strident authorization requirements and higher denial rates, have many providers rethinking participation in MA plans. At minimum, billing compliance and coding teams should be focused on eliminating improper practices that will lead to heavy fines and penalties. This is particularly critical considering MDaudit findings that more than 25% of providers on average failed audits across both professional (33%) and hospital (23%) care settings.

Continue Reading