Policy Paper
87
Chapter 10
overseeing the iG Program
Maintaining the Information Governance (IG) program beyond an initial project effort is key to realizing continued and long-term benefits of IG. This means that the IG program must
be “evergreen” and become an everyday part of the organization’s operations and communica- tions. There is continuing work to do after an initial IG program push, shaping and prioritizing discrete projects to execute under the umbrella of the IG program. The idea is to embed IG con- siderations in everyday business processes so that they become routine.
Program Communications and training Since IG programs are fundamentally a change management effort, any successful IG program
must contain a well-developed communications and training component. The stakeholder audi- ence must be made aware of the new policies and practices that are to be followed, and how this new approach contributes toward the accomplishment of the organization’s goals and business objectives.
The first step in the communications plan is to identify and segment stakeholder audi- ences, and to customize or modify the message to the degree that is necessary to be effective. Communications to the Health Information Management (HIM) team should revolve around electronic health record (EHR) data quality and patient privacy aspects; communications with the Information Technology (IT) team should have a more technical slant; and communications to the Legal team should include some legal jargon and emphasize legal issues. The more forethought put into crafting the communications strategy, the more effective it will be.
That is not to say that all messages must have several versions: there are some core concepts and goals that should be emphasized in communications to all employees. Core messages include:
1. Mindfulness of information risks; 2. Emphasis on valuing information as an asset; 3. Information accuracy and quality are paramount; 4. Preserving the organization’s brand and reputation are essential, and stems from providing
superior patient care and guarding their PHI; 5. Stakeholder audiences must be consulted and informed as part of the IG program;
Information Governance for Healthcare Professionals Overseeing the IG Program
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-09-01 01:34:04.
C op
yr ig
ht ©
2 01
8. P
ro du
ct iv
ity P
re ss
. A ll
rig ht
s re
se rv
ed .
88 ◾ Information Governance for Healthcare Professionals
6. Information security and privacy are everyone’s job and all must be mindful when handling sensitive information;
7. IG programs require continuous improvement.
Training should take multiple avenues as well. Some can be classroom instruction, some online learning, and it is a good idea to create a series of training videos (which can be in the form of recorded webinars). Aim to make the training fun and engaging. The training effort must be consistent and ongoing to maintain high levels of IG effectiveness. Certainly, this means adding IG training to the onboarding process for new hires, and for employees joining or transferring to the organization.
Program Controls, Monitoring, Auditing, and enforcement The only way to measure the progress and success of an IG program is to develop metrics to
determine progress on training efforts, the level of employee compliance, its impact on key opera- tional areas, cost reductions, and progress made toward established business objectives.
Testing and auditing the program provides an opportunity to give feedback to employees on how well they are doing, and coach them and recommend changes they may make. But also, hav- ing objective feedback on key metrics will allow the executive sponsor to see where progress has been made, and also, where improvements need to focus.
Although the emphasis should be on continual improvement and feedback on metrics should be used to coach employees, clear penalties for policy violations must be communicated to employ- ees so they know the seriousness of the IG program. They must keep in mind how important it is in helping the organization pursue its business goals and accomplish stated business objectives. Penalties should be up to and including dismissal for severe violations.
Similar to a workplace safety program, ongoing training and communications are important to keep employees apprised of approved processes and behaviors which support IG. Also important is regular feedback based on established metrics to see how the IG program is progressing.
This requires vigilant and consistent monitoring and auditing to ensure that IG policies and processes are effective and consistently followed and enforced. If proper controls are in place this should become a regular part of the enterprise’s operations.
Monitoring and Accountability
Monitoring and accountability in the IG program demand a continuous tightening down and expansion of protections and the implementation of emerging, strategic technologies. IT develop- ments and innovations that can foster the effort must be steadily monitored and evaluated, and those technology subsets that can assist in providing security need to be incorporated into the mix. Some examples of newer IG-enabling technologies include advanced analytics, predictive cod- ing, file analysis, auto-classification, artificial intelligence, blockchain, and the Internet of Things (IoT). All these and more should be on the IG steering committee radar.
The IG policies themselves—for handling PHI and confidential information, e-mail, use of social media, cloud use and so forth—must be reviewed and updated periodically to accommo- date changes in the business environment, laws, regulations, and technology. Program gaps and failures must be addressed and the effort should continue to improve and adapt to new types of security threats.
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-09-01 01:34:04.
C op
yr ig
ht ©
2 01
8. P
ro du
ct iv
ity P
re ss
. A ll
rig ht
s re
se rv
ed .
Overseeing the IG Program ◾ 89
IG programs emphasize accountability. Maintaining an IG program requires that an indi- vidual (or small team) is accountable for continually monitoring and refining policies and train- ing approaches. Some individual must remain responsible for an IG policy’s administration and results.1
Perhaps the executive sponsor for the initial project becomes the chief information governance officer (CIGO) or IG “czar” of sorts; or the chief executive officer (CEO) continues ownership of the program and drives its active improvement. The organization may also decide to make the IG steering committee a permanent one, with ongoing responsibilities for monitoring, maintaining, and advancing the program.
However it takes shape, an IG program must be evergreen, dynamic, and aggressive in its execution—and in demonstrating benefits—in order to remain effective.
Staffing Continuity Plan
In today’s work environment, turnover is more frequent than in the past. People spend less time in a job before moving on to take new career opportunities outside of the organization, and also change jobs and move to other positions within an organization. So it is critical to have a staff- ing continuity plan for the IG steering committee so that the IG program does not have gaps or interruptions. Backup and supporting designates must be named and kept current on the admin- istration of the program. In addition to the role of executive sponsor, an organization may have a “supporting sponsor” or “deputy sponsor” so, should the need arise, the sponsorship function maintains continuity. And likewise, there should be other staffing redundancies built in to assure the smooth and continued operation of the IG program in the event of layoffs, terminations, or unplanned incidents that threaten it.
This may mean that when the formal IG program manager is unable to be there to execute their duties, an assistant or designated backup can carry out those duties.
It is also a good idea to cross-train employees within the IG team or steering committee. With this approach, the Legal team, for instance, will better understand the needs and requirements of the HIM and Records Management functions, and vice-versa. IT must better understand the Legal department’s needs. HIM should better understand Legal issues, and so forth. Cross- training improves collaboration and overall organization acceptance and understanding of the IG program, while building in safeguards to ensure it keeps running.
Continuous Process improvement Maintaining IG program effectiveness requires implementing principles of continuous pro‑
cess improvement (CPI). CPI is a “never-ending effort to discover and eliminate the main causes of problems.” It accomplishes this by using small-steps improvements, rather than implementing one huge improvement.
In Japan, the word kaizen reflects this gradual and constant process, as it is enacted through- out the organization, regardless of department, position, or level.2 To remain effective, the pro- gram must continue using CPI methods and techniques.
Maintaining and improving the program will require monitoring tools, periodic audits, and regular meetings for discussion and approval of changes to improve the program. It will—as emphasized in this book many times—require a cross-section of team leaders from IT, Legal, Records Management, Compliance, Internal Audit, and Risk Management, and also functional
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-09-01 01:34:04.
C op
yr ig
ht ©
2 01
8. P
ro du
ct iv
ity P
re ss
. A ll
rig ht
s re
se rv
ed .
90 ◾ Information Governance for Healthcare Professionals
business units participating actively and presenting ideas for improvements in information- handling procedures that can improve operational efficiency, while also citing possible threats and sources of information leakage.
Why Continuous Improvement Is Needed
While the specific drivers of change are always evolving, the reasons that organizations need to continuously improve their program for securing information assets are relatively constant, and include:
◾ Changing technology. New technology capabilities need to be monitored and considered with an eye to improving, streamlining, or reducing the cost of IG. The IG program needs to anticipate new types of opportunities and threats and also evaluate adding or replacing technologies to continue to improve it.
◾ Changing laws and regulations. Compliance with new or updated laws and regulations must be maintained.
◾ Internal information governance requirements. As the organization updates and improves its overall IG, the program elements that concern critical information assets must be kept aligned and synchronized.
◾ Changing business plans. As the healthcare enterprise develops new business strategies and enters new markets, it must reconsider and update its IG program. If, for instance, an organization moves from being a local entity to a regional, national, or global one, new laws and regulations will apply, such as greater privacy and data protection demands (e.g. the new European General Data Protection Regulation), as well as new information security threats. So new privacy and security strategies and policies must be formed.
◾ Evolving industry Best Practices. Best Practices change and new Best Practices arise with the introduction of each successive wave of technology, and with changes in the business environment. The program should consider and leverage new Best Practices.
◾ Fixing program shortcomings. Addressing flaws in the IG program that are discovered through monitoring, testing, and auditing; or addressing an actual breach of confidential information; or a legal sanction or fine imposed due to non-compliance are all reasons why a program must be revisited periodically and kept updated.3
Maintaining the IG program requires that a senior level officer of the enterprise, the execu- tive sponsor, continues to sponsor it and pushes for enforcement, improvement, and expansion. This requires leadership, as well as consistent and clear messaging to employees. IG and the security of information assets must be on the minds of all members of the enterprise; it must be something they are aware of and think about daily. Perhaps even IG-reinforcing messages are rotated on screen savers. Employees should be reminded to be on the lookout for ways to improve IG, and they should be rewarded for contributions made which improve program effectiveness.
Gaining this level of mindshare in employees’ heads will require follow-up messages in the form of personal speeches and presentations, newsletters, corporate announcements, e-mail mes- sages, and even posters placed at strategic points (e.g., near the shared printing station advising about secure procedures). Everyone must be reminded that keeping information assets secure is everyone’s job, and that to lose, misuse, or leak confidential information harms the organization over the long term and erodes its value.
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-09-01 01:34:04.
C op
yr ig
ht ©
2 01
8. P
ro du
ct iv
ity P
re ss
. A ll
rig ht
s re
se rv
ed .
Overseeing the IG Program ◾ 91
Chapter Summary: Key Points ◾ Maintaining and improving the IG program requires monitoring tools and regular
audits to continually improve it. ◾ Lines of authority, accountability, and responsibility must be clear for the IG program to
succeed long term. ◾ IG program communications should be consistent and clear, and customized for various
stakeholder groups. ◾ IG program testing and audits are an opportunity to improve training and compliance, not
to punish employees. ◾ An effective IG program requires vigilant and consistent monitoring and auditing to ensure
that IG policies are followed and enforced. ◾ Information technologies that can assist in advancing the program must be steadily moni-
tored, evaluated, and implemented. ◾ IG programs need built-in staffing redundancies to ensure their continued operation in the
event of employee turnover or transfer. ◾ Maintaining an IG program requires that an executive sponsor continues to push for enforce-
ment, improvement, and expansion of the program to secure and control information.
notes 1. Mark Woeppel, “Is Your Continuous Improvement Organization a Profit Center?” PEX Network,
June 3, 2009, www.processexcellencenetwork.com/process-management/articles/is-your-continuous- improvement-organization-a-prof.
2. Donald Clark, “Continuous Process Improvement,” Big Dog and Little Dog’s Performance Juxta- position, March 11, 2010, www.nwlink.com/~donclark/perform/process.html.
3. Randolph A. Kahn and Barclay T. Blair, Information Nation: Seven Keys to Information Management Compliance (AIIM International, 2004), pp. 242–243.
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-09-01 01:34:04.
C op
yr ig
ht ©
2 01
8. P
ro du
ct iv
ity P
re ss
. A ll
rig ht
s re
se rv
ed .
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-09-01 01:34:04.
C op
yr ig
ht ©
2 01
8. P
ro du
ct iv
ity P
re ss
. A ll
rig ht
s re
se rv
ed .