What Is Enterprise Risk Management
Enterprise risk management, often abbreviated ERM, is a structured approach to identifying, assessing, and managing risks across an entire organization rather than addressing risks in isolated silos. RHIA candidates should understand how HIM departments contribute to and benefit from an organization-wide risk management program.
Categories of Risk in HIM
- Compliance risk, such as HIPAA violations or coding fraud
- Operational risk, including system downtime or staffing shortages
- Financial risk, such as claim denials from documentation deficiencies
- Reputational risk from data breaches or public disclosures
- Strategic risk from failing to adapt to industry changes
The Risk Management Process
- Identify potential risks through audits, incident reports, and staff input
- Assess the likelihood and potential impact of each risk
- Prioritize risks using a risk matrix or heat map
- Develop mitigation strategies for high-priority risks
- Monitor and reassess risks on an ongoing basis
The Risk Matrix
A risk matrix plots likelihood against severity to help leaders prioritize which risks require immediate attention. A risk with high likelihood and high severity, such as inadequate access controls on a system containing protected health information, demands urgent mitigation.
Risk Mitigation Strategies
Avoidance, Reduction, Transfer, and Acceptance
Organizations can avoid a risk by not engaging in the risky activity, reduce a risk through controls such as staff training, transfer a risk through insurance or vendor contracts, or accept a risk when the cost of mitigation exceeds the potential impact.
HIM Specific Risk Areas
Common HIM risk areas include unauthorized access to patient records, improper disclosure through release of information errors, coding compliance issues that trigger audits, and business continuity risks from system outages affecting record availability.
Business Continuity Planning
HIM leaders should maintain downtime procedures and business continuity plans to ensure patient care is not disrupted when electronic systems are unavailable.
Exam Tip
Be familiar with the four risk mitigation strategies, avoidance, reduction, transfer, and acceptance, as exam scenarios often ask which strategy best fits a described risk situation.