Showing posts with label Internal Controls. Show all posts
Showing posts with label Internal Controls. Show all posts

INTEGRATING INTERNAL PREPARATIONS

Although integrated planning requires involvement of the external community in your facility plans, healthcare facilities must first be internally integrated. Without a seamless team response, the facility will be unable to assist the outside community.

Response requirements are not always predictable and smooth. Disasters may damage the physical structure of a healthcare facility, as has happened in previous earthquake and flooding events, and the damage must be addressed while staff are responding to the external community disaster (O’Toole, Mair, and Inglesby 2002). In addition, the healthcare facility may be compromised because of failures to the infrastructure, such as the loss of electrical power, water systems, and communication lines. A thorough internal disaster plan should address contingency “work arounds” for all possible damage to the facility.

Communications

Adequate disaster response requires instant and multifaceted communications networks that are reliable and flexible. However, a mere forecast of a disaster can overwhelm vital communication services, and in most disasters, the communication lines are the first to overload or fail. Redundant phone systems, broadcast fax capability, and the ability to increase the number of dedicated wireless phones within the healthcare system should rank high on the facility’s communication to-do list.

A hospital’s first alert or notification of an event may be via public television or radio broadcasts, requiring that hospitals mobilize for an event of which they have little knowledge. As with any community, warnings provide critical information that empowers people at risk to take action to save lives, reduce losses, and speed recovery. The extra time from an early warning allows improved preparedness and activation of services. Unfortunately, our national warning system—the Emergency Alert System—does not reach all people at risk, and the warning capability for many natural disasters is inadequate or may go unheeded.

Testing Capabilities

The U.S. GAO (2003a) reports that less than half of the hospitals surveyed for bioterrorism preparedness in early 2003 had conducted drills or exercises simulating a bioterrorism incident. Although staff training in biological agents was widespread, hospital participation in drills was less common.

The drills, training, and exercises that test plans and abilities and spearhead organizational improvement are among the most important aspects of disaster preparedness. The primary benefit of exercises is to reveal areas needing improvement. When disasters are not threatening, drills and exercises allow participants to make corrective actions to ensure all systems are ready when needed.

Mental Health Preparedness

For every one physical casualty caused by a terrorism incident, there are an estimated 4 to 20 psychological victims (Warwick 2002). In the aftermath of the 9/11 attacks, the psychiatric department at St. Vincent’s Catholic Medical Center—just one of the many healthcare facilities in the affected New York area—provided counseling and support to more than 7,000 people and received more than 10,000 calls to their help line during the first two weeks following the disaster (Rosuck 2002).

Hospitals and healthcare services should make provisions for accommodating and managing the substantial acute mental health needs of the community when a natural disaster or terrorist event occurs (JCAHO 2003). Psychological casualties often include those who are treating the physically affected—healthcare providers. For this reason, departments such as nursing, human resources, and social work as well as the chaplaincy, organizational development, and mission staff should be included in mental health planning sessions. Specifically, your organization plan should address the provision of nutritional, housing, spiritual, psychological, and other psychosocial needs and integrate these with the community plan. A triage system for behavioral health must consider the following people:

  • Survivors, those who lost a loved one, rescue workers, and people who witnessed the events

  • Those who lost a home, business, or job as a result of the event

  • Anyone else who was deeply affected

Benchmarking Organization Preparedness

Healthcare facilities can internally assess and broadly “eyeball” levels of preparedness based on assessment data, plans, human resources information, equipment, training, and performance during exercises and actual incidents. Self-assessments, exercises, and procedures for comparison with other facilities are important tools (IAEM 2003). To get accurate data, however, readiness must be evaluated by objective parties against prospectively established standards. A thorough assessment includes evidence of readiness maintained over time.

Readiness is not defined by the creation of a plan or by its periodic testing. To improve preparedness efforts, actions must be documented and efforts made to learn from mistakes and strengthen weaknesses. The current lack of standardized methodologies to compare the events of one facility to those of another, to compare activities among different types of disaster events, or to compare those taking place in different locations hampers the best assessment efforts.

Yet despite the lack of a standardized assessment tool, much is still to be learned from the experiences of hospitals that have implemented emergency management plans in real-world situations.

Automated Tools for Assistance

A plethora of new tools and models is emerging to assist communities in preparing their healthcare sector for response. Two such tools are listed below.

The National Guard Bureau’s Automated Exercise and Assessment System, a free software program, is easily deployed on personal computers and can be used to test community readiness for incidents involving weapons of mass destruction. Communities receive immediate feedback on command decisions, observe the consequences of those decisions, and receive response assessments on multiple levels. Using their actual resources, a participating community can survey and enter those resources into the software’s database and for the next 12 to 14 hours work through one of 11 different scenarios with up to 41 different roles for participants.


Auditing for the Masses

In summary terms, risk management identifies, prioritizes, and safeguards critical assets, while policies, procedures, and standards address employee conduct. Auditing is the process of assessing whether employees and business operations are in compliance with the organization's policies and procedures as well as applicable laws and regulations. Auditing is the investigation and measurement of employee behavior and business operations based on collected evidence. Counted together, risk management, policies and procedures, and auditing form the first three integrated steps in proactively addressing critical incident management.

Auditing is the compliance extension of your risk management program where operations, policies, and procedures are examined to determine whether operations are lawful, effective, efficient, and profitable. Auditing will determine that the organization's critical assets are accounted for, prioritized with adequate safeguards, and whether recovery and restoration procedures are implemented and tested. Fundamentally, auditing is also a comparison and analytical process comprised of collecting and evaluating evidence regarding management assertions and the actual state of the organization's operations. In fact, the most-critical part of auditing is the degree of separation between an organization's assertions and established system-addressed risk criteria. Any differences between assertions and the actual-state falls into a category called the "gap."

Information technology auditing is a carefully planned and executed business process involving the collection and evaluation of evidence to ascertain if a computer system safeguards critical assets and facilitates organizational goals being achieved.

Auditor Responsibilities
In the sense of their function, auditors must not have any direct responsibility or authority over any of the activities that they examine or could examine in the future. Operational assessments and employee performance appraisals do not, in any way, relieve employees of their professional responsibilities. Auditors must be authorized to have full and unrestricted access to relevant equipment and information including computer files, documents, records, property and employees. They must have a high degree of freedom in all audit-applicable business areas with the exception of specific restrictions imposed by law.

Internal Controls
Managing critical assets, their safeguards, controlling potential frauds and improving effectiveness and efficiency can best be achieved if senior managers establish a structure of internal controls. There really is not a great deal of universal details in this area as all organizations are different in their mission and function. Let's define internal controls here in the context of formal systems that prevent, detect, and correct policy violations, unlawful and abusive events. These are the three most important levels of general controls: prevention, detection, and correction.

General Controls
General controls are those internal controls having wide application to most areas of business operations. For the most part, they include but are not limited to specific system applications:

  • Planning and organization controls

  • Physical and logical access controls

  • Human resources

  • Risk management

  • Communications controls

  • System development controls


  • Specific Controls
    In broad terms these are controls with application to specific applications:

  • Access controls

  • Data input controls (these include all system data inputs)

  • Processing controls

  • Output controls


  • The overarching governing structure for specific and general controls is that of CIA, confidentiality, integrity, and availability. In current auditing views, there are many components where internal controls apply for example, separation of duties and least privilege, clear lines of authority and responsibility, adequate documentation, access control, management supervision, individual accountability, performance checks, and audit trails to name a few.

    Separation of Duties and Least Privilege
    Separation of duties basically means that separate employees should be responsible for initiating transactions, processing transactions, recording those transactions, and maintaining custody of critical assets. Least privilege means that employees have the knowledge and authority to perform their jobs and nothing more. For example, in a small organization an accounts payable clerk has the responsibility of preparing billing payments. She reviews the billing for its correctness and prepares wire transfer documents. By observing the concepts of separation of duties and least privilege, she does not have the authority or the ability to release funds. So, she prepares a voucher with the attached billing documentation and submits these materials to the finance vice-president who authorizes the transfer of funds. In the event the payment amounts are over $10,000, the organization's policies and procedures mandate that two vice-presidents approve the electronic wire transfer. Once the payment is approved, the transaction information flows to another employee that is responsible for posting the transaction to the organization's financial records.

    Authority and Responsibility
    Clear and well-defined lines of authority and responsibility are essential in controlling systems. In today's business environment, the distinctions between authority and responsibility may not be clear. It is frequently difficult as many resources are shared among many users. For example, database use is common among many users in a business organization. When several authorized users have simultaneous access and, through some unknown means, the data becomes corrupted, it is not always easy to fix responsibility.

    Documentation
    Documents and records are essential in providing an audit trail of activities within any system. Electronic and paper-based documents are used to support the initiation, execution, payment, and recording of transactions. Documentation is intended to provide an accurate record of events and acts. Documents should provide a tangible record in which events can be reconstructed from their content. In a well-designed system, audit trails document the actions and events occurring during business operations as well as those documents required to administratively run the business.

    Performance Checks and Accountability
    Checks of performance and accountability are done by auditors because employees are likely to forget policies and procedures, make genuine mistakes, become careless and negligent, or intentionally fail to follow procedures. Individual employee accountability is tied to performance and competence as well as continuing responsibility.

    Popular Posts