
MACRA MIPS Advancing Care Information
I started this article and previous seminars by referring to MACRA as Medicare’s new payment system. However, that concept is incorrect and an oversimplification of MACRA. MACRA stands for “Medicare Access and CHIP Reauthorization Act” and while the same will affect how Providers will get paid it is not necessarily a payment system. Medicare considers MACRA a Quality Program and refers to MACRA as their Quality Payment Program. At this point in time I feel comfortable writing that MACRA is a data collection initiative from Medicare that uses a bonus program as an incentive to get Providers to participate.
Using the data collection and bonus as a starting point is easy to visualize two separate possibilities for participation which Medicare refers to them as tracks. One of these tracks requires the participant to submit data and assume risks as it relates to patient’s behavior and outcomes. This first track is known as the Advanced Alternative Payment Model (APM). The other track is the Merit Based Incentive Payment System (MIPS) which is where most Providers will fall under.
MIPS is also divided into four additional categories, most of which resemble, a current program which these categories will be replacing. For example, Advancing Care Information is similar to the Electronic Health Record Incentive program with its corresponding Meaningful Use Measures and attestation requirements. For example, as part of MIPS and the Advancing Care Information category Providers are required to complete a HIPAA Security Risk Assessment (SRA).
This is where things start to get interesting as the guidance requires Providers that decide to participate to submit data for 90 consecutive days. Based on that simple statement, our experience with HITECH audits and discussions we have been having in the field we have come with a set of questions:
- Does the SRA needs to be conducted within the 90-day data collection period?
- Will a SRA outside of these parameters be considered acceptable?
- Conduct a Security Risk Assessment as soon as Possible
- Start data collection efforts prior to October 2, 2017
About Dr. Jose Delgado
Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.
Need help with healthcare compliance?
Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.
Schedule a consultation

