Webinar On Demand
Mature RCM Adoption for a Cyber Resilient Strategy
Well, thank you, everybody. This is Jonathan Wick. I'm the vice president of health insights at FinThrive. I am joined by the brilliant Greg Surla, our Senior Vice President and Chief Information Security Officer, our CISO.
Chapter
Introduction to Cyber Resilience Strategy
This is part three of a three part series surrounding a cyber resilience strategy. And Greg and I wanted to dive into a little bit today some of the things that we're seeing specific to revenue cycle and vendor relations. I'll cover the revenue cycle part and then Greg will talk about some of the things he's starting to see and understand as we as a business partner in the industry, are encountering with a lot of our healthcare partners and then also just how FinThrive itself, is investing in this very important technology and, I would argue, capability to ensure that data and, I would argue, business is protected.
Chapter
Understanding Redundancy in Healthcare
So we'll dive right in here. We've got ten, twelve short minutes with one another, so we'll get into the content. This is an OR suite. You may have seen the slide before from me.
I I like to talk about redundancy when I talk about cyber resilience. I've attended several conferences this year, and I as Greg, we're both kind of knowledge sponges. We're gonna go into a conference or an area. Him and I were just talking before this.,
He's gonna be in DC out at HIMSS at the cybersecurity conference out there and I wish him well. And but I know what he's gonna do is what I do is we're going to take notes and understand what's happening in the market and where we're at. And I come from the hospital space and this OR picture here, it's one thing I want you to look at is just the number of people and the number of things and there's there's almost two of everything too. And you don't see that level of depth or coverage in revenue cycle, at least not predominantly.
I think you're starting to see it evolve a little bit more.
But there are two anesthesia machines. There are two surgical lights. There are two physicians.
There are, several nurses at the ready. There are supplies.
Behind the scenes of this room, there is lots of other things. There are secondary chillers, backup generators, a secondary data feed.
And cybersecurity isn't nearly as I think event ups and backups and redundancies. And Greg will get into the details with that. But just as you have redundancy across the major infrastructure within a healthcare system or hospital or facility, you need to have that level of redundancy surrounding your EHR and specific transactions that exist. And I call these the big four.
Any one of these four that get disrupted is gonna end up having a bad day from a cash flow standpoint.
Upper right corner in that purplish color are your eligibility two seventy two seventy one transactions that we're all familiar with.
Lower right in the blue are your claims transactions and ERAs, eight thirty sevens and eight thirty fives. ERAs, I'm sorry, over there on the green, the cash posting parts. And then in the upper left corner, access to that data in terms of being able to understand what is happening as you're posting and reconciling those accounts down to zero. And in those pre visit claims, payment posting and other activities of any of those get turned off, your cash flow and your business operations start to get impacted.
Chapter
Impact of Cyber Events on Cash Flow
Well, you might ask how much, Jonathan, do they get impacted? Well, this is a study that Stratosphere did, which I really like. And it said roughly around seventeen percent is what you see or we saw, I'm sorry, with the change health care event that happened. And I have talked to several hospitals that have had ransomware and other cyber attacks.
Since this event, Accenture was one of the larger ones. They were down for few days there as well, and and and they would attest that this fifteen, sixteen, seventeen percent range is accurate. And most hospitals don't have that level of pause or infrastructure to afford the cash flow reserves to accommodate that for any extended period. We saw that with the change event.
Secondarily, it's also this workload, right? We're not staffed as an industry. I know hospitals aren't from where I came from to manage anything other than business as usual or BAU. And that's submitting claims, posting cash, admitting patients, registering accounts. There isn't this flex or serve staff kind of sitting on a shelf somewhere that says, oh, we're down, we need to switch to paper or we need to cut over to this other system and start keying things in this way. It's not something that's thought about proactively.
Chapter
Evaluating Vendor Relationships Post-Crisis
And I think since the change event, we've seen hospitals more closely evaluate that relationship. They are exploring a secondary clearinghouse.
And maybe that's on the professional billing side and they're going to take the hospital billing side and maybe commingle those accounts or inventory by payer or or data service or amount or or or or other types of demographics and really run a parallel system to where if this ever happens again and it's not really an if it's a when that these connections aren't cut off and not impacted to the level that they were then. If anything, never let a crisis go to waste. Right? You hear that a lot with this event, and you want to be able to be more prepared and have more operational sustainment and less business interruption when this is happening. And so you're going to start seeing a lot of organizations evaluate very closely what they're doing from a clearinghouse standpoint. This is a survey that was performed by eliciting insights and HFMA.
And they talked about strategies they're they're considering for long term business continuity. Just to orient you to this graph, you see changes the primary clearing house there about there are fifty one providers being asked here. So, you know, roughly around twenty six or so of them said, yep, we use them. And and and they're they're they're partnering with multiple clearing houses as well. So over the half, some are are not doing anything. I would put those in the other category or the or the ten percent there at the front, no change. They're gonna stick it out.
So went to the portals and and actually key the information in. And I like to give kind of the the poker or the the, solitaire example there. Once you play that card, you kinda have to play the handout that way for lack of a better way and to put them into English. If you submitted things in portal, the the answers will come back in the portal.
If you submitted things in paper, things will come back in paper. So that kind of downstream wake of rework is going to continue to occur where we're at, where you're at. If they have changed health care as a secondary or as another clearing house besides change, I should say, over there on the right, forty five percent didn't change anything and that kinda makes sense, right, because they weren't impacted. But I really wanna lean into that one that, as I mentioned before, it's not a matter of if, it's a matter of when.
There's twenty two percent, they're partnering with multiple clearing out. That's a lot. One in four health systems or hospitals, at least in this survey, and I've seen other surveys, I'm happy to share them with you after the call, have indicated that they absolutely are creating levels of redundancy beyond their clearinghouse. And ThinThrive has positioned its systems very well, I think in this regard and we want to make sure that there is minimal disruption to business operations.
Chapter
Implementing Backup Plans for Claims and Eligibility
So we've created standby eligibility and claims because those are two of the main big four that I talked about that have impacts that may occur when the cyber event is here. We want eligibility to continue to run. If you're not running eligibility, you're running blind as an organization and you may be doing services for free or maybe billing them to the wrong place or not understanding the cost share contractual provisions in terms of prior off notifications, all of those business and payment rules. And then if you can't get claims out the door or payments back in, we saw what a big deal that is.
So on the claim side, we've created that as well. Just to have a backup plan, we've got different tiers and things within that that allow for that at a and I would say rather economical rate that really gives you as an organization a peace of mind to ensure that you are prepared and can mitigate these attacks as they occur.
Benefits of that or you have less denial rates, your AR days aren't impacted, your rejection rates or claims aren't having the dramatic impact that they had before, your costs are down. Even though you're investing in technology in a redundant way, net that I will put my reputation up there on this. If you've got multiple clearing houses, you're gonna have less cost over time than you will by having a single one simply because the impacts to your clearing houses are going to be impacted. And if you arrange your partnerships and and and and and and transactions in a way, you actually probably could save some money too if you think about it.
And I could certainly expand on that as well. Clean claims rate, accelerating that reimbursement as cash flow we talked about. You really wanna maintain staff productivity, morale, it's very hard to get workforce now, and you don't want anything to interrupt their day. And then finally, efficiency and performance without adding headcount is huge, right?
So you wanna make sure that you've got that level of technology there and and and and are using it to the best of your ability to not have any interruptions to your business, especially in the eligibility and claim space. I'm gonna turn it over to Greg, and he's gonna talk through some of these challenges that are happening from the cyber resilience. Welcome, Greg.
Chapter
Challenges in Cybersecurity and Resilience
Thank you, Jonathan. Appreciate it. So, talking to peers in the technology and the security world, some of the things that come up to cyber risk and resiliency, those challenges that we're facing is there's accelerated change. We've all seen it with Gen AI being the flavor of the of the minute right now.
And, technology teams are having to adapt to that. So that that adds some challenges there. And then, you know, modularity and efficiency and services that that can impact changes to our business services that are out there. One that Jonathan just talked about workflow and, excuse me, workforce and workplace resource shortages of availability, talent and skills.
In IT and especially security, we see that a lot. You don't have a great deal of people, that are dedicated, to helping you with this cyber risk and cyber resiliency.
So, we need to be aware of that.
Cross functional collaboration, who's doing, who's responsible for what amongst business leaders when when we're having, to respond to, a cyber event.
And then, you know, see the proliferation of data, you know, data is constantly growing. We we have more data than we know what to do with.
And what do we need to do, to to, keep control of that data? And regulatory requirements make managing that that data, especially in an RCM environment, pretty challenging. And then finally, third party and vendor risk. Nobody anticipated change.
Nobody anticipated, CrowdStrike, having such a huge impact on the, not only the healthcare industry, but in in the case of, CrowdStrike, in pretty much the world. And so, those risks are always gonna be there. We've known about supply chain risk, for a while, but, it's only been in the past couple of years where it's come to, come to fruition and we're starting to see the impacts of the of of third parties and vendor risk. I'll switch over to the next one.
So, you know, with, with FinThrive and and, you know, with these challenges, one of the things that we have to do is be pragmatic about things and, focus our our security controls, focus our resilience efforts on those areas that have the most impact. You know, when you talk about resources, FinThrive as a company, we've looked at what we're spending our capital on. And we've decided, we need to up our security spending. We're at eleven percent.
Percent. The Gartner industry benchmark right now, the five point five percent. We're spending a significant amount of money on, in, of our revenue and then per employee.
For our resource, I T, and security resources, we're at six point one percent of security research security, full time employees that are dedicated.
In a security role, Let's go ahead and move on to the next one.
Chapter
FinThrive's Security Measures and Team Structure
With that, you know, we have FinThrive has a dedicated team of globally dispersed security experts. We have, you know, our security operations center, who is our first line of defense. They're doing twenty four by seven by three sixty five, monitoring.
They're responsible for user access management and they're processing threat intelligence. For threat intelligence, one of the things that we've done was we shifted, not just looking at the threats that are in the, you know, overall, we're looking closely at healthcare based threats.
Because healthcare has has specific, targets, and those, bad actors are targeting these organizations, health care organizations in a specific way. So we wanna understand where that's happening. That's why we're focusing a lot of our threat intelligence towards the health care industry.
We also have security engineering team, our application security team who is doing our pen testing, red team testing.
And then we have a risk management team that is constantly running, risk assessments, threat threat assessments, and others to make sure that we're shoring up our defenses in a way, that makes a lot of sense. Let's go ahead and move on to the next one. And then finally, we wanna talk about the FinFrog Security Council. We're all in this together.
And one of the things that we've been doing is, having, I believe, is quarterly meetings where we're, where we're talking to the rest of, we're talking to the healthcare industry. We've got some individuals, who are, sorry about that, who are, helping us, you know, having a conversation with us. Oh, my goodness. Sorry.
Having a conversation with us and with each other. And we wanna crowdsource, what those results or what those, solutions everyone's coming up with in order to meet the problems that we're seeing in cybersecurity and and cyber resilience.
If you are interested in joining that that Security Council, please reach out to me, greg dot s u r l a at FinThrive dot com, or you can reach out to your, your, FinThrive representative.
Chapter
Conclusion and Call to Action
And with that, thank you. Jonathan?
You bet. Thanks, Greg. Greg's information to get contacted is right there as well as is mine. I wanna thank you all.
My advice, and I'm sure Greg would echo this, is, like the Boy Scouts of America, be prepared. I think you can't be more prepared as an organization these days. The bad guys are out there and girls. And so it's very, very important to have a preparedness and I would argue mitigation and response strategies we outlined today. And if you need any help understanding what those might look like and what investment strategies you can do, please reach out to Greg or I and you all have a great rest of your week. Thank you so much.
Thank you.