Background Research
31
Chapter 4
Who Should Be Part of an information Governance team?
IG programs require cross-functional collaboration; however, IG teams or steering committees from each individual healthcare organization will have a slightly different makeup depending on program focus and objectives, organizational IG maturity, staffing, budget resources, competi- tive posture, and other factors.
A formal IG Program Charter must be drafted and signed off on by the executive sponsor. The program charter lays out the purpose and scope of the program, goals and objectives, report- ing structure of the IG steering committee, SMEs and sub-committees, frequency of meeting, and other key guidelines.
Selection of the executive sponsor is a critical starting point. The executive sponsor must make the business case for the IG program and make IG steering committee selections along with the IG Lead. It is advisable that a deputy or associate executive sponsor also be named to build in durability and continuity to the IG program, in the event that the executive sponsor leaves or is terminated. This is also true of the IG Lead.
iG is an Umbrella Program
IG can be thought of as an overall umbrella program that manages or “governs” information access, risk, quality, protection, privacy, and the information lifecycle across the enterprise. IG is a
Information Governance for Healthcare Professionals Who Should Be Part of an Information Governance Team?
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
32 ◾ Information Governance for Healthcare Professionals
broad policy framework for enforcing information compliance and accountability, with progress mea- sured by agreed-upon metrics. These metrics must be developed with the input of stakeholders so that they are not only relevant and meaningful, but also accepted by the end users and IG team members.
Having better quality and more trusted information helps improve decision-making and com- pliance capabilities while reducing information risk. Formally embedding an IG program ensures that resources, including budget and management time, are spent to maximize information value while minimizing information risks and costs.
Leveraging Models and Frameworks There are several IG models and frameworks that can help to inform the selection and develop-
ment of an IG steering committee.
the iG Reference Model The core IG steering committee group must include Legal, IT, HIM and RIM, Cyber-security, and
Privacy, at a minimum, provided the organization has these basic functions represented in the organizational structure. (And if these functions are not represented in an organization of today, they should be).
There is precedent for this foundational structure, when looking at the Information Governance Reference Model (IGRM). The IGRM is a simple graphic tool developed by EDRM.net, ARMA International, and the Compliance, Governance, & Oversight Council (CGOC) in consultation with thousands of end users. The IGRM graphically displays the key impact areas of IG programs, shows unified governance and process transparency, and depicts the relationship between infor- mation assets, duty, and value, which can help to educate IG program stakeholders early on and to spur discussion of IG’s cross-functional nature.1
Business pro�t
Value
Create, use
Asset
Privacy and security
risk
Duty Legal risk
RIM risk
Duty: Legal obligation for speci�c information
Asset: Speci�c container of information
Value: Utility or business purpose of speci�c information
Information Governance Reference Model (IGRM) Linking duty + value to information asset = e�cient, e�ective management
IT e�ciency
Dispose
Store, secure
Retain archive
Hold, discover
Policy integration
Uni�e d governance
Process transpar enc
y
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
Who Should Be Part of an Information Governance Team? ◾ 33
Take note that there is one more group depicted, which is “Business” or business units. The key business unit(s) included in the IG program may reflect a focus on data governance, EHR governance, patient privacy, or reducing legal costs, and will vary based on a particular healthcare organization’s structure, business objectives, and business scenario. Business units provide critical input in IG policy development efforts.
HIM and the governance of EHR information are fundamental to reducing medical mistakes, improving patient outcomes, improving patient satisfaction and retention, reducing litigation and associated costs, and improving overall population health. There may be other business units that are high priority, such as the Business Office function, where improvements in operational effi- ciency can yield significant economic benefits. Beyond that, business units with the highest litiga- tion costs or most difficulty with finding information for everyday tasks, litigation requests, or compliance audits are good places to look for high priority pilot projects under the umbrella of the overall lG program.
Some additional key departments that should be represented on the next tier of the IG steering committee, (depending on the organizational structure and business scenario), may be:
◾ Finance/CFO. Often overlooked is the idea that poor IG can lead to major data breaches and dramatic losses in patient/customer confidence, revenues, and market value of the orga- nization. The case can be made that the CFO shares a fiduciary responsibility to ensure that proper IG controls are in place to help safeguard the organization’s information assets. Also, the CFO will know the status of budgets and can possibly make adjustments or transfers to invest in needed IG program steps. And once IG controls are in place, Infonomics principles may be applied to gain new value or even monetize information.
◾ Chief Data Officer (CDO)/Data governance. As quality clinical data is critical for deliver- ing value and improving patient outcomes and overall population health, this is a key role. All other downstream reports and analytics depend on having clean, accurate, non-duplicate data, so it is critical to have a data governance effort that focuses on capturing accurate data at the source. This can be challenging in healthcare, with the variety of proprietary clinical and laboratory devices that do not always adhere to industry standard data formats.
◾ Risk management. Managing information risk is core to IG efforts. You can see “Risk” noted as a focus in the IGRM graphic under “Legal,” “Privacy & Security,” and “RIM.” If the organization has a formal risk management department, their involvement in the IG program will be valuable. Some organizations may wish to use the ISO 31000 Risk Management standard to guide efforts.
◾ Compliance. HIPAA compliance is critical and HIPAA audits can result in major fines. Compliance efforts focus both externally, regarding regulations and statutory requirements, and internally, to ensure employees follow company policies and procedures, as well as exter- nally imposed requirements.
◾ Human resources. Since IG programs are change management (CM) efforts, HR is central to the communications and training strategy to help embed IG considerations like pri- vacy and security into routine business processes. Emphasizing compliance with IG policies and procedures in employee performance reviews will involve working with HR to develop meaningful metrics. Training should be conducted regularly and consistently, using mul- tiple modalities.
◾ Change management. If the organization has a formal CM function, this group can play a key role, as all IG programs are fundamentally CM efforts. Often an external consultant can assist in developing the CM plan to complement IG efforts.
.
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
34 ◾ Information Governance for Healthcare Professionals
◾ Analytics. Applying advanced analytics to clean, accurate data can yield a variety of benefits in healthcare, namely the improvement of clinical outcomes and financial performance. Additional advances can be made in improving patient satisfaction and perhaps even some new insights and innovations in patient care. Further, there may be new ways to improve operational efficiency, and beyond that, monetize and leverage aggregated or anonymized data with suppliers or business partners. “Harnessing the value of information is one of the foundational purposes of IG, but an IG program also must balance the goals of analytics against information risks and retention requirements.”2
◾ Audit. The Audit department can play a key role in measuring IG program progress based on meaningful, pre-established metrics which have been developed and approved by the IG team. Metrics provide management feedback for continual improvement and program fine- tuning. Audit findings can provide crucial input for decision-making within an IG program.
introducing the information Governance Adoption Model™ for Healthcare
In February, 2016, AHIMA launched healthcare’s first Information Governance Adoption Model™ (IGAM) via IGHealthRate™, an assessment tool.3 The IGAM is an extension and expan- sion of the IG Reference Model, although it does not go so far as to diagram inter-relationships and reflect the roles of risk (specifically, information risk) and change management, which are key components of IG programs.
The IG Adoption Model™ can help spur discussion in the beginning stages of IG program planning, and can also assist in highlighting key areas for representation in the IG Program Steering Committee.
According to AHIMA, the 10 IG organizational competencies depicted in the model can be assessed based on key markers on a scale of IGAM Level 1™ (lowest, least mature) to IGAM Level 5™ (highest), to determine maturity levels and to conduct a gap analysis to determine the tasks needed to move the organization up the maturity scale to the desired level of improvement.
Awareness and adherence
Enterprise info mgnt.
IG performance
Analytics
IT governance
Data governance
Legal and regulatory
AHIMA’s Information Governance Adoption Model
(IGAM) competencies
IG structure
Strategic alignment
Privacy and security
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
Who Should Be Part of an Information Governance Team? ◾ 35
Analyzing the iGAM™ for iG team Staffing In the IGAM™ we can see that, as with the IG Reference Model, Privacy and Security are
represented, as is Legal & Regulatory. Also, Data Governance and Analytics are represented, furthering the argument to include representation of these functions on the IG steering commit- tee. IT governance, that is, leveraging frameworks (e.g. CoBIT5) in the IT department to make it more efficient and accountable, while getting results that contribute to organizational business objectives, is also represented. The employee in charge of IT governance, likely the CIO, should be considered a major stakeholder. The CIO is also accountable for enterprise information manage- ment (EIM), a major aspect of IG.
IG structure and strategic alignment are mostly responsibilities of the executive sponsor and IG Lead, with input from the entire committee. IG performance could be measured quantitatively by the CFO or an internal audit professional, and monitored by the Executive Sponsor.
IG awareness is largely the job of the Executive Sponsor and IG Lead, with assistance from HR or the training department. IG Adherence and IG Performance should be monitored by the Executive Sponsor using established metrics, perhaps audited by the CFO or an internal auditor.
In Summary
It is abundantly clear that implementing IG programs requires a cross-functional approach to facilitate sharing and leveraging information. IG has a wide reach and effective IG brings together stakeholders from across the organization and builds on their synergies to better govern and opti- mize information.
Information governance programs are heavily focused on information quality, security, and privacy. As a cross-functional discipline, it is challenging to muster and manage scarce resources to address enterprise issues that do not belong clearly to established functional groups like IT or Legal. Managing and prioritizing these information asset challenges requires the same type of planning and control used historically for deploying and managing capital assets. Managing and leveraging information assets means that new opportunities and value may be found that can provide a sustainable competitive advantage to the organization.4
Major executive Sponsor Role Throughout this book, one key fact is emphasized repeatedly: Securing a sponsor at the execu-
tive management level is critical—it is the most important factor for IG success. In fact, it is so important it may be advisable to name a separate deputy executive sponsor, or to have the IG steering committee chair also serve as a deputy or co-executive sponsor.
Strong executive sponsorship is a key IG Best Practice. Program failure is a great risk with- out an active and engaged executive sponsor. Such a program likely will fade or fizzle out or be relegated to the back burner. Without strong high-level leadership, when things go awry, finger pointing and political games may take over, impeding progress and cooperation.
According to studies, the two most common IG executive sponsors are General Counsel and the CIO. Sometimes IG programs are led by an organization’s General Counsel, and they may be well-versed in privacy law, but they may not have the technology competencies to understand exactly how to apply complex new IG-enabling technologies, and they may have a basic under- standing of retention schedules but are not well-versed in HIM Best Practices. Sometimes IG
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
36 ◾ Information Governance for Healthcare Professionals
programs are led by the CIO, who may be well-versed in security and aware of privacy issues, but often CIOs and HIM managers don’t speak the same language: a “record” means something totally different to a CIO than to a HIM manager; also, legal research is not the CIO’s job and the general counsel will always have to make those decisions anyway.
Executives must be on board and a primary executive sponsor driving the IG effort is needed in order to garner the necessary resources to develop and execute the strategic IG plan. That execu- tive must be held accountable for the development and execution of the plan.
Resources are needed—time, human capital, budget money, new technologies. The first is a critical element: It is not possible to require managers to take time out of their other duties to participate in a project if there is no executive edict and consistent follow-up, support, and com- munication. In fact, IG program progress should be measured in performance reviews of key players on the IG steering committee and for stakeholder groups.
The executive sponsor serves at least six key purposes in an IG program:
1. Budget. The executive sponsor ensures an adequate financial commitment is made to see that project milestones are met and lobbies for additional expenditures when change orders are made or cost overruns occur.
2. Planning and control. The executive sponsor sets direction and tracks accomplishment of specific, measurable business objectives.
3. Decision‑making. The executive sponsor makes or approves crucial decisions and resolves issues that are escalated for resolution.
4. Expectation management. The executive sponsor must manage expectation, since success is quite often a stakeholder perception.
5. Anticipation. Every project that is competing for resources can run into unforeseen block- ages and objections. Executive sponsors run interference and provide political might for the IG Lead or program manager (PM) to lead the project to completion, through a series of milestones.
6. Approvals. The executive sponsor signs off when milestones and objectives have been met and signs contracts for the acquisition of new information technologies and services.
The higher level the executive sponsor is in the organization, the better. The CEO wields the most authority, and some IG programs are sponsored by the CEO, particularly where there has been a major breach, costly litigation, or major regulatory fines. With CEO sponsorship come many of the key elements needed to complete any successful project, including allocated manage- ment time, management priority, and budget money.
Critical and Sometimes Fickle Executive Sponsor Role
There may be a clear executive sponsor at some point early on but when that person realizes they will be held accountable for the performance of groups outside their direct control (and com- petitors at their corporate level can then sabotage progress), they might look for cover and find a way to postpone, de-prioritize, or kill the IG program. Focusing efforts on clearly established business objectives will largely reduce this inherent problem of conflicting agendas. (Having a deputy executive sponsor will also shore up the executive sponsor role).
Sometimes all an unenthusiastic executive sponsor has to do is wait for the natural inertia of the over-sized and lethargic IG steering committee to weigh things down, and soon other projects and programs that are more routine and cost-justifiable in the short term take resources from the
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
Who Should Be Part of an Information Governance Team? ◾ 37
IG effort. It then may fade into the background until there is a new litigation disaster, major com- pliance failure, massive security breach, or other such negative IG drivers.
According to surveys and research, the implementation of an IG program is more and more often being driven by the Legal department, General Counsel or Assistant General Counsel, or the chief information officer (CIO). Other IG programs may be led by the chief risk officer, chief information security officer (CISO), or, ideally, as the Sedona Conference has recommended, a Chief IG Officer (CIGO).
The CIGO must have the mandate and authority to drive the program forward and should have overlapping skillsets that include expertise in e-discovery, cyber-security, information pri- vacy, data governance, health information management (HIM) and general records management, IT, and business operations.
the emerging Role of the CiGo A key challenge is that because of the interdisciplinary requirements for implementing IG, no
one seems to want to own IG. It touches on parts of the strengths of a CIO or General Counsel or HIM Manager or Information Security Manager or Chief Compliance Officer, but it also requires that they go out of their comfort zone into new areas.
So where should IG reside? Who should be in charge of an IG program? There is a need for a new job title to pull all these disciplines together into a cohesive IG pro-
gram: CIGO. This has been promoted by the Sedona Conference® and other organizations. The CIGO should be a highly competent manager who has broad operations experience and
competencies: near-expert not only in IT, but also legal and compliance issues, data governance tools and methods, HIM issues, privacy issues, information security tools and techniques, and business issues. They must also have outstanding communications and management skills. That is a challenging job description.
A CIGO can act in a coordinating function, but lacking authority, their efforts will likely be met with resistance. Because of its requirements, the organization can leverage the authority of the executive sponsor, or even consider granting the CIGO authority over the CIO, chief infor- mation security officer (CISO), chief privacy officer (CPO), and even CFO. The CIGO could be very nearly a chief operations officer (COO), and that is an option for whom the CIGO reports to, if not the EVP of Risk—or even the Administrator or CEO. It is a crucial job that mostly is not being filled. However, there is a great need for it, and it due to its focus, a well-prepared CIGO could lead the IG effort and produce consistent, tangible results.
Assigning team Roles and Responsibilities The executive sponsor must designate an IG Lead or program manager—perhaps even a Chief
IG Officer—and depending on the focus of the IG effort, that person could come from one of several areas including legal, infosec, risk management, HIM/records management, or IT.
When assigning the roles and responsibilities of the remainder of the IG team, the easy deci- sion is to have IG team representatives take responsibility for the functional areas of their exper- tise. Nevertheless, there will be overlap, and it is best to have some pairs or small workgroups teamed up to gain the broadest amount of input and optimum results.
This will also facilitate cross-training. For instance, inside legal counsel may be responsible for rendering the final legal opinions, but not being an expert in HIM or document management or risk
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
38 ◾ Information Governance for Healthcare Professionals
management means they could benefit from input of others in specialized functional areas, which will inform them and help narrow and focus their legal research. So when performing the basic research as to which regulations and laws apply to the organization regarding security, retention, and preservation of patient records and PII, the initial research could be conducted by the HIM or records manage- ment head, in consultation with the corporate archivist and CIO, with the results of their findings and recommendations drafted and sent to the legal counsel. The draft report may offer up several alterna- tive approaches that need legal input and decisions. Then the legal department can conduct their own, focused research, and make final recommendations with consideration given to the organization’s legal strategy, business objectives, financial position, and applicable laws and regulations.
The result of the research, consultation, and collaboration of the IG team should be a final draft of the IG strategic plan (see Chapter 9 for more detail). It will still need more input and development to align the plan with business objectives, an analysis of internal and external driv- ers, applicable Best Practices, competitive analysis, applicable information technology trends, an analysis and inclusion of the organization’s culture, and other factors.
Caveat: the importance of a tiered iG Steering Committee for expediency
When reviewing research and anecdotal observations on IG programs it is clear that often IG efforts are slow to start, can get delayed or put on hold, and then re-start, and that sometimes the IG effort is abandoned, put on a shelf. Then later, executives realize that the “IG problem” (e.g. deaths and injury from medical mistakes, non-compliance fines, risks of colossal information breaches, soaring litigation costs, failure to capitalize on emerging opportunities by leveraging analytics) is not going away—so the IG program re-starts again.
One of the root causes of sluggish IG efforts is the basic failure to structure the IG steering commit- tee properly, and to consider the realities of group dynamics, corporate politics, scheduling, and program management.
Since IG efforts are by nature cross-functional and require the involvement of key stakeholder groups, IG steering committees can become large and unwieldy. Also, the politics can become crippling, causing progress to slow and threatening the continuation of the IG program.
In practice, there have been IG steering committees of 15, 18, even 20 or more individuals representing the various functional groups in a large organization. Managing the needs and inputs of this broad swath of stakeholders is inherently challenging.
Due to the expanse of an IG program, the IG program team or steering committee should be set up with a tiered structure. The core departments driving the IG program, or “top tier” should be:5
◾ Legal. Because legal considerations are paramount, the legal department must be deeply involved and perhaps lead the IG program. Legal is best represented at a high level by the General Counsel, Assistant GC, or a senior legal officer. Legal costs and liabilities can soar with poor IG, further underscoring the importance of efficient legal functions. Further, Legal must implement “litigation response protocols” and drive e-discovery efforts—which inherently involve IT and records management policies, two other core stakeholders in IG programs. The legal department also must provide guidance on privacy breach response protocols and render opinions on privacy matters to ensure compliance.
◾ Information technology. IT is key to IG efforts, as IG requires IT for data and IT gov- ernance, and for tracking sensitive information, applying automated controls, auditing,
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
Who Should Be Part of an Information Governance Team? ◾ 39
implementing business process redesign, and more. Organizations must leverage IT to improve efficiencies and monitor the effectiveness of the IG program. Also, IT must work with Legal, HIM, and RIM to preserve the organization’s electronically stored information (ESI) in legal matters.
◾ Health Information Management (HIM) and Records and Information Management (RIM). The HIM department is responsible for managing patient health records in accor- dance with privacy laws and retention regulations. Safeguarding these records is mission- critical and a key factor in maintaining patient trust. RIM is responsible for maintaining corporate business records to ensure compliance with applicable statutory and regulatory requirements. HIM and RIM must also work with Legal to execute e-discovery functions.
◾ Information Security. “InfoSec” or “cyber-security” is responsible for keeping the organiza- tion’s databases and confidential information secure, and providing policy input, techniques, and IT to prevent the loss of intellectual property (IP). InfoSec has played an increasingly greater role in IG programs due to colossal data breaches, privacy concerns, and reputational risk;
◾ Privacy. The Privacy group must conduct research and provide policy guidance for the handling of protected health information (PHI), personally identifiable information (PII), credit card information (PCI), and other sensitive patient and employee information. The goal is to have privacy considerations “baked in” to everyday business processes, so that, “privacy by design” may be achieved.6 This is a key aim of IG programs.
The tiered strategy can be employed to make these IG planning teams more effective, agile, and accountable: A tiered IG steering committee with staggered meeting requirements will bring in only those needed to a meeting, while not wasting everyone else’s time.
Otherwise, the IG program initiative will follow the same predictable and sluggish cycle it did before, only with a slightly different set of players.
Below are some guidelines for structuring an IG steering committee for better results:
1. Recruit a strong executive sponsor (and perhaps a deputy executive sponsor). A clear leader who has authority can help focus IG efforts and deliver results in the form of early wins to keep feeding and growing the IG program. The executive sponsor should be apprised of progress and should sign off on milestones and major policy decisions as they are presented to them by a small subset of leaders from the IG steering committee. Due to the importance of the executive sponsor, and the fact that turnover does occur and can hinder program prog- ress, it is advisable to consider naming a “deputy” executive sponsor as a backup support.
2. Form a high‑level “decision committee.” This can be a group of three, four, or at the most, five leaders from the functional areas most involved in IG efforts. They are the ones who are to be held accountable for delivering results and keeping the IG program on track. They should meet regularly, probably weekly, to drive the IG program forward. Their focus should be on focus, that is, directing the efforts of the IG steering committee and delegating spe- cific tasks to ensure tangible results are delivered from small early wins and the IG program expands in a logical way that focuses on meeting business objectives.
3. Form subject matter expert (SME) teams using cross-functional team members. In a sort of matrix organizational structure, create teams to center effort on key areas of IG impact, and to cross-train each other. For instance, the e-discovery readiness team should include members from Legal staff, but also (depending on the business scenario) HIM, Records Management, IT, and perhaps the business unit that is most involved or embroiled in litiga- tion. The Data Governance (DG) SME team must include the DG lead, but also members
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
40 ◾ Information Governance for Healthcare Professionals
from Privacy, Security, IT, and key business units. Recommendations from the SME teams should be made to the decision committee for final deliberation, and then presented to the executive sponsor for sign-off and approval (or rejection to re-work the approach).
4. Keep all members of the IG steering committee updated. Committee members should be regularly updated on program status, progress, and decisions. Do not waste committee members’ time with a meeting when an e-mail or update to the intranet or collaborative site will do.
5. Convene the entire IG steering group only when necessary—perhaps every two weeks in the initial phases of the IG program, and then at least monthly following the IG program launch. The meeting of the entire group should be scheduled so that it does not conflict with IG steering committee members’ schedules to the extent possible.
Additional tips: For those who cannot attend a formal IG program meeting, provide a video conference or at least a conference call link, and for those who cannot attend even remotely, a recording of the meeting. Do not allow excuses for non-participation. Also, ensure that tasks and progress of the IG program effort are tied directly to stated business objectives.
Stay focused and do not waste IG steering committee members’ time. Lay out a reporting and meeting schedule that makes sense and structure the IG team into more agile, accountable units which can meet on their own and not waste others’ time.
Chapter Summary: Key Points ◾ Implementing IG programs requires a cross‑functional approach. ◾ The IG Reference Model provides a starting point for IG steering committee staffing. ◾ The IG Adoption Model™ from AHIMA can assist in IG steering committee staffing deci-
sions, and also in planning and IG maturity assessments. ◾ The top tier of an IG steering committee should include: Legal, IT, HIM/RIM, Information
Security, and Privacy. ◾ A tiered IG steering committee keeps it more nimble and able to make decisions. ◾ Due to the interdisciplinary requirements for implementing IG, no one wants to own IG. ◾ IG programs require a strong executive sponsor. ◾ Chief IG Officer (CIGO) is a new title for a person heading up IG programs. ◾ The CIGO must be proficient in legal issues, cyber-security, HIM, privacy, and more.
notes 1. “Information Governance Reference Model,” EDRM.net, https://www.edrm.net/frameworks-and-
standards/information-governance-reference-model. 2. Jason R. Baron and Amy R. Marcos, “Information Governance: Establishing a Program and Executing
Initial Projects,” Practical Law, October/November 2015, 24–33 (pp. 27–28). 3. “Information Governance Offers a Strategic Approach for Healthcare (Updated),” Practice Brief,
Journal of AHIMA 86, no. 11 (November 2015): 56–59. 4. Ibid. 5. Jason R. Baron and Amy R. Marcos, “Information Governance: Establishing a Program and Executing
Initial Projects,” Practical Law, October/November 2015, 24–33 (p. 26). 6. Ann Cavoukian, “The 7 Foundational Principles,” PrivacyByDesign.ca, January 2011, https://www.
ipc.on.ca/wp-content/uploads/Resources/7foundationalprinciples.pdf.
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
41
Chapter 5
Building an iG Framework
Information Governance is complex and has many “moving parts” due to its cross-functional, col-laborative nature. To direct and manage an IG program properly, an Information Governance Framework (IGF) must be formally established to provide the guardrails to guide decisions.
An IGF includes, at a minimum:
Business objectives
Executive sponsor(s)
IG Steering Committee
IG Lead
Relevant standards and Best Practices
An evaluation of external and internal business considerations
IG reference models or frameworks
Program metrics and auditing
IG communications and training plan
It is essential that the IGF is customized for each individual healthcare organization and its business needs. The focus of an IG program may vary, and so the structure of the IGF will also vary to reflect that focus.
Building an iG Framework Once the executive sponsor is in place, (and perhaps a deputy executive sponsor, for good mea-
sure), you must build an IGF, which is the foundation of the IG program. Without it, the result will be a weak and unstable, aimless program that will likely fail, as many have.
Each IG framework will look a little different but there are commonalities that appear in suc- cessful ones. An IGF needs to be modified according to the business and economic environment, competitive scenario, budget, and internal human resources and skillsets.
Below are the key components of an IG Framework that serve as the construct, the foundation for any successful IG program:
Information Governance for Healthcare Professionals Building an IG Framework
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
42 ◾ Information Governance for Healthcare Professionals
◾ Business objectives – IG planning must begin with a focus on business objectives. Organizational goals and objectives are the key reason for implementing an IG program. They provide the business rationale for investing resources. The objectives for the IG program must align with and support the organization’s overall strategic plan and IT strategy. Objectives must then be broken down into measureable, relevant metrics to track progress. Key objec- tives for healthcare concerns may be: – Lower deaths due to medical mistakes by 10% over the previous five year average, within
two years; – Reduce e-discovery litigation costs by 20% per GB for document review, within one
year; – Reduce lost, stolen, or compromised mobile devices by 50% over the previous year. – Beyond stated, measureable objectives, there may be longer-term goals the organization
strives for that the IG program can help support, such as: • Deliver premium patient care with unwavering attention to personal privacy; • Optimize HIPAA compliance capabilities; • Harvest anonymized patient data and leverage Big Data tools for research and
analysis, to improve patient care. ◾ Executive sponsor – This is the manager with the budget authority and the motivation to
build the IG program. The executive sponsor is involved with developing the blueprint and overall building plan but leaves the specifics to those with expertise in key areas. She or he stays in the loop, and, at times, may have to intervene. However, at other times, the executive sponsor is the one offering coffee and donuts in the morning or springing for a pizza party on a Friday afternoon after a long week of work where good progress was made. A good executive sponsor uses both carrots and sticks. More information on executive sponsorship is presented later in this chapter, since it is such a critical piece of IG program success.
◾ IG Lead – The IG Lead must be a talented individual with a diverse skillset. They may come from one of the core areas of IG, such as IT, Information Security, Legal, HIM, or Information Privacy, but they also must be conversant in the other complementary disci- plines. In addition, they must have excellent interpersonal skills, as this person must be a change agent, actively promoting and selling the IG program, helping to embed it into the corporate culture. The IG Lead is accountable for executing the IG strategic plan on a day-to-day basis. They must orchestrate the completion of milestones within the budget, resource, and time constraints approved by the executive sponsor. When the IG Lead runs into roadblocks, they should bring in the executive sponsor for support.
◾ Cross‑functional IG team – Just as architects, bricklayers, plumbers, electricians, and car- penters are needed to build a house, an IG program will need a blend of professionals. They should be leaders in key functional areas, including IT, Legal, HIM, Privacy, and Information Security—but also business unit heads/information owners, and potentially other key areas such as Change Management, Risk Management, Communications, Training, and other spe- cialties as appropriate. IG team representation will vary, as organizations have differing corpo- rate structures and cultures, and so business objectives, resources, appetite for risk, and other variables are different, even for similar healthcare entities operating in the same region.
◾ Standards and Best Practices – A review of relevant standards and Best Practices should be done to determine which ones to select to help guide the IG program.
◾ Survey and evaluation of external factors – Once the IG team is in place and the IG plan is harmonized and aligned with the organization’s strategic plan and IT strategy, good progress will have been made. In evaluating external factors, take into consideration the economic and
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
Building an IG Framework ◾ 43
competitive business environment, technology trends and developments, regulatory and legisla- tive issues, and even the political environment, which could affect pending regulatory demands.
◾ IG reference models or frameworks – Survey and select key IG models and frameworks to help guide decisions.
◾ Program metrics, monitoring, auditing, and enforcement – An IG program must have established metrics and controls to determine the level of employee compliance, its impact on key operational areas, and progress made toward key business objectives. Testing and auditing provide an opportunity to give feedback to employees on how well they are doing and to recommend changes they may make. In addition, having objective feedback on key metrics also will allow the executive sponsor to see where progress has been made, where improvements need to focus, and where resources are needed.
◾ Program communications and training – IG programs must include a communications and training component as a standard function. The stakeholder audience must be made aware of new policies and practices that are to be followed, and how this new approach con- tributes toward accomplishing business objectives. This assists in the change management effort. But critically, stakeholders must receive training on the new approach, and constant and consistent reinforcement of new IG precepts.
By including the above elements in the IG framework, the organization will have established a solid foundation to build the IG program, and it will have greatly increased its odds of success.
iG Leaders in Healthcare Leading healthcare organizations that have implemented IG programs share some common
characteristics:1
1. Value information as an asset – Understand the value and risks of information and strive to link information value to organizational objectives;
2. Collaborative culture – Recognize that interdisciplinary cooperation is key, and that clin- ical and business process owners must have strong support from IT, Legal, HIM/RIM, Privacy/Security;
3. Strong executive sponsorship – Executives understand the linkage between quality infor- mation and quality patient care, and understand that minimizing information risks protects patient trust, brand equity, and shareholder value;
4. Operational efficiency focus – Organizational competence in policymaking, business pro- cess design, and process improvement;
5. Continuous improvement ethos – A cultural commitment to be a learning organization where continual improvement is valued and reinforced.
executive Sponsor Role versus iG Program Manager The role of an executive sponsor is high level, requiring periodic and regular attention to the
status of the program, particularly with budget issues, staff resources, and milestone progress. The role of a project or program manager is more detailed and day-to-day, tracking specific
tasks that must be executed to make progress toward milestones. Both roles are essential. The
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
44 ◾ Information Governance for Healthcare Professionals
savvy PM brings in the executive sponsor to push things along when more authority is needed but reserves such program political capital for those issues that absolutely cannot be resolved without executive intervention. It is best for the PM to keep the executive sponsor fully informed but to ask for assistance only when absolutely needed.
The PM must manage the relationship with the executive sponsor, perhaps with some gentle reminders, coaxing, or prodding, to ensure that the role and major tasks of executive sponsorship are being fulfilled. The successful PM monitors progress and collects data to support their case to the executive sponsor. If the executive sponsor is losing interest or becomes less responsive, it is up to the PM to have a heart-to-heart talk with them to get the program back on track or consider abandoning it.
An eager and effective executive sponsor makes all the difference to a program—if the role is properly managed by the PM. It is a tricky relationship, since the PM is always below the executive sponsor in the organization’s hierarchy, yet the PM must coax the superior into tackling certain high-level tasks. Sometimes a third-party consultant who is an expert in the specific project can support requests made of the executive sponsor and provide a solid business rationale.
While the executive sponsor role is high level, the PM’s role and tasks are more detailed and involve day-to-day management.
evolving Role of the executive Sponsor The role of the executive sponsor necessarily evolves and changes over the life of the initial IG
program launch, during the implementation phases, and on through the continued IG program. To get the program off the ground, the executive sponsor must first own the business case. They
must make a solid business case and obtain adequate budgetary funding and resources. Some cost savings as a result of direct actions within the IG program can add to the cost/
benefit analysis. Yet an IG effort requires more than budget money; it takes time—not just time to develop new policies, redesign processes, and implement new technologies, but the time of the designated PM, program leaders, and needed program team members.
In order to get this time set aside, the IG program must be a top priority of the organization. It must be recognized, formalized, and aligned with organizational business objectives. The up-front work of making the business case and aligning the IG program with business objectives is the responsibility of the executive sponsor.
Communications and training Plan is Key Once the business case is made and the IG steering committee is formed, team members must
clearly understand why the new program is important and how it will help the organization meet its business objectives. This message must be regularly communicated and reinforced by the execu- tive sponsor; he or she must not only paint the vision of the future state of the organization but articulate the steps in the path to get there.
When the formal program effort commences, the executive sponsor must remain visible and accessible. They cannot disappear into everyday duties and expect the program team to carry the effort through. The executive sponsor must be there to help the team confront and overcome business obstacles as they arise and must praise the successes along the way. This requires active involvement and a willingness to spend the time to keep the program on track and focused.
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
Building an IG Framework ◾ 45
The executive sponsor must be the lighthouse that shows the way even through cloudy skies and rough waters. This person is the captain who must steer the ship, even if the first mate (PM) is seasick and the deckhands (IG program team) are drenched and tired.
The multi-modal IG program communications strategy should be reinforced through consis- tent and regular training on IG program aspects.
After the program is implemented, the executive sponsor is responsible for maintaining its effec- tiveness and relevance. This is done through periodic compliance audits based on pre-established metrics, utilizing testing and sampling, and holding scheduled meetings with the ongoing PM.
iG Requires Change Management It is important to bear in mind that an IG effort is truly a change management effort, in that it
aims to change the work processes, guidelines, and information access rules within which clini- cians and business process owners operate. It may even change the user interface to systems and the way they work through everyday business processes.
The overall cultural change—one that values information as an asset and seeks to protect and lever- age it—must occur at the very core of the organization’s culture.
It must be embedded permanently, and for it to be, the message must be constantly and consis- tently reinforced. Achieving this kind of change requires commitment from the very highest levels of the organization and a planned change management effort.
Which technologies Help to enable iG Programs and enforce Controls?
This section presents a brief overview of the key IG-enabling information technologies that help implement and monitor new information-related processes. These are some of the technolo- gies that the IG Lead and steering committee should be tracking.
Beginning with a compact definition of IG, the technologies are listed in its three key areas. IG, in short, is defined as “security, control, and optimization of information.” This is a concise
definition yet it covers a wide expanse. Listed below are some categories of products that may be leveraged in IG programs. This is not an exhaustive list but rather a demonstrative one.
First, “Security” of information:
1. Electronic document security – Technologies in this group include information rights man- agement (IRM), and its little brother, file encryption. IRM technology acts like a “security wrapper” that, upon creation, secures confidential e-documents by controlling the “rights” to view, print, edit, forward, copy, or save e-documents. The rights can even be controlled by time of day (e.g. access during work hours only) or type of device (e.g. access on the PC but not mobile devices). Rights are assigned upon creation of the document, usually according to roles (levels) in the organization. These access rights travel with the e-document itself, and access can be turned off remotely (via the Cloud or a server) if an employee has had their laptop or computing device compromised or stolen, or if the employee has been terminated. So even if an organization like Anthem Health were hacked and completely compromised, ePHI, ePII, and confidential documents would still be protected, in an encrypted state. Or if a rogue hacker or internal bad actor accesses thousands of electronic health records, they
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
46 ◾ Information Governance for Healthcare Professionals
would not be viewable and could not be copied or printed. Certainly, technologies in this category are a part of supporting an IG program.
2. Data loss prevention (DLP) – Software that continuously monitors and thoroughly inspects information that flows (e.g. e-mail, e-documents) on a network and attempts to prevent ePHI, ePII, or certain sensitive information containing certain key words or phrases from exiting the organization past its firewall. DLP is often used in conjunction with IRM software and also to assist in data mapping efforts.
3. Digital signatures – Software that can break up business process bottlenecks that can occur for authorizations/approvals. Digital signatures carry detailed audit information used to detect unauthorized modifications to e-documents and to authenticate the identity of the signatory (in a process known as non-repudiation).
4. Database activity monitoring (DAM) and database auditing tools monitor databases in real time for anomalies and unusual activity and create an audit trail generated in real time that can be the forensic smoking gun when attacks have occurred.
5. Print security – To help secure large print files—which contain highly useful information for hackers as the information is distilled and in one place—specialized hardware devices designed to sit between the print server and the network “cloak” print files and they are only visible to those who have a properly configured cloaking device on the other end.
6. Security vulnerability/penetration testing software – Software in this category allows organizations to test and find any security vulnerabilities they may have, and to address these weaknesses through security patches and other methods;
7. Stream messaging – For confidential communications, this approach leaves no record of an e-mail exchange; that is, once the e-mail message is read, it “vaporizes” completely. This prevents printing, forwarding or altering the message.
Next, information technologies that assist in the “Control” of information (and, of course there is some overlap with Security):
1. Electronic Health Record (EHR) – Software to capture and track the record of diagnosis and treatment of a patient. Contains both clinical data and unstructured output such as dictated history and physical, narrative notes, diagrams (e.g. EKG), images (e.g. x-ray, CAT), and other information related to patient care.
2. Identity and Access Management (IAM) controls logon credentials, and aims to prevent unauthorized access. IAM governs access to information through an automated, continuous process. Implemented properly, IAM keeps access limited to authorized users.
3. Document analytics – This type of software monitors access, use, and printing of e-documents in real time. Graphical reports are created—so if a user normally downloads or prints 10 documents a day, and on one day they download or print 1,000 or 10,000—red flags go off.
4. Document labeling is the process of attaching a label to classify a document, which is a simple way to increase user awareness about the sensitivity of a document—for instance, by labeling it “confidential.”
5. Business Process Management Suites (BPMS) – This software allows organizations to control business processes and to model and simulate business process routing and process- ing options to automate a process from end to end. The ability to make intelligent changes in process based on metrics and real-time feedback facilitates optimization of the efficiency of business processes.
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
Building an IG Framework ◾ 47
6. Enterprise Content Management (ECM) to manage all types of unstructured content. ECM controls access and manages versions of e-documents, web pages, reports and other digital assets. ECM is being somewhat displaced by cloud-based Enterprise File Synch and Share (EFSS) platforms such as Box and Dropbox.
7. Mobile Device Management (MDM) to manage and control the network of mobile devices. MDM allows an organization to update mobile devices en masse with security patches and updates, to remotely wipe lost or stolen devices of confidential data, and to monitor the mobile network.2
Lastly, technologies that assist in the “Optimization” of information:
1. File analysis, classification, and remediation (FACR) – Software tools in this category scan the entire collection of information (e.g. e-documents) across shared drives, storage area networks, and all other storage devices to conduct “file analysis.” File analysis can scan and find metadata such as author, topic, file type, date of creation, date of last access, etc. This process can help the healthcare organization to locate where personal confidential informa- tion like ePII, ePHI, and ePCI is stored so it may be protected with encryption, and also to dispose of it as is legally required. Further, the more sophisticated tools can actually begin to insert classification metadata tags to help organize the content and to assist in the reme- diation process, which includes deleting duplicates and “data debris,” which no longer has business value to the organization.
2. Advanced Data Analytics – Software with the capability far beyond traditional business intelligence (BI).3 Categorized as descriptive analytics (“what happened”), diagnostic analytics (comparing historical data to determine “why” some events occurred – e.g. “a healthcare provider compares patients’ response to a promotional campaign in different regions”)4, predictive analytics (“what might happen”), and prescriptive analytics (“what we should do to exploit a promising trend or head off a looming problem”). Advanced ana- lytics can process and analyze thousands or even millions of data points to help harvest new clinical insights and make predictions/recommendations that can help in improving patient outcomes and patient satisfaction, as well as find innovations to improve operational effi- ciency and financial performance.
Complexity
A d
d ed
-v al
u e
co n
tr ib
u ti
o n
Descriptive analytics
Diagnostic analytics
Predictive analytics
Prescriptive analytics
3. Predictive coding – During the early case assessment (ECA) phase of the e-discovery legal process, predictive coding is a “court endorsed process” that can be utilized for document
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
48 ◾ Information Governance for Healthcare Professionals
review. Legal experts review a subset of documents and “teach” the software which docu- ments are responsive in a particular legal matter, and the software goes through a sorting and sifting process to find similar documents. This is an iterative process where the human legal expert continues to review a sampling of the documents found by the software to provide input and facilitate improved accuracy by the software in finding responsive docu- ments. The result is drastically reduced costs for document review, which can be accom- plished in a much shorter timeframe giving legal teams more insights and more time to develop strategy. When applied to business data, predictive analytics can also help you to find new insights and trends to act upon, perhaps to improve operational efficiency, cross- sell customers, or even to develop new products and services. In healthcare, leveraging predictive coding technology can go further and assist caregivers in anticipating patient needs, and can assist researchers in finding patterns and new insights to develop new treat- ment regimens.
4. Business intelligence (BI) uses software tools and techniques to analyze raw (structured) data to help provide useful insights for managers and executives to make more informed decisions. New insights into the data can be gleaned, which can help spur innovation in marketing, product and patient services development, finance, and other key business areas.
5. Content analytics (CA) software applies BI and business analytics to better gain insights into content volumes and patterns, and how the content may be used. CA can help improve findability of websites, brands, and products;
6. Master data management (MDM) – This type of software helps organizations to perform data governance and data quality functions, which are key to IG efforts not only in the IT department but also in maintaining patient records with high quality data. The goal of MDM software is to ensure that accurate, reliable data from a single source is leveraged across business units. That is, the key aim is to establish “a single version of the truth” and eliminate multiple, inconsistent versions of data sets. Downstream reports which rely on this data are therefore more accurate and trusted by managers;
With just the above examples, it is quite clear that there are a number of technology tools which can be leveraged to address various aspects and aims of IG programs.
Chapter Summary: Key Points ◾ An IG framework (IGF) provides the guardrails to guide decisions in the IG program. ◾ An IGF begins with stated business objectives. Begin IG planning with a focus on organiza-
tional business objectives and be sure that IG objectives are aligned to support them. ◾ A strong executive sponsor is critical to IG program success. ◾ The IG Program Lead or Program Manager (PM) plays a key role in managing the relation-
ship with the executive sponsor and IG steering committee. ◾ IG requires a change management effort. ◾ There are a number of key information technologies and emerging technologies that help to
secure, control, and optimize information. ◾ Advanced analytics technologies can help caregivers anticipate patient needs, improve treat-
ment regimens and patient outcomes, and even improve marketing effectiveness.
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .
Building an IG Framework ◾ 49
notes 1. Linda Kloss, Implementing Health Information Governance: Lessons from the Field (AHIMA Press,
2015), p. 10. 2. “Mobile Communications and Records and Information Management,” ARMA technical report
TR-20-2012, ARMA International, August 2012. 3. “Advanced Analytics,” Gartner IT Glossary, https://www.gartner.com/it-glossary/advanced-analytics. 4. Aliaksander Bekker, “4 Types of Data Analytics to Improve Decision-Making,” ScienceSoft, July 11,
2017, https://www.scnsoft.com/blog/4-types-of-data-analytics.
F., Smallwood, Robert. Information Governance for Healthcare Professionals : A Practical Approach, Productivity Press, 2018. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/franklin-ebooks/detail.action?docID=5515223. Created from franklin-ebooks on 2022-08-27 15:57:23.
C o p yr
ig h t ©
2 0 1 8 . P
ro d u ct
iv ity
P re
ss . A
ll ri g h ts
r e se
rv e d .