Audit-friendly ROI tracking tips

But i’m tightening our Release of Information process to balance data accuracy with confidentiality. With about 30 requests a week, we assign a unique request ID, log within 24 hours on a role-based access tracker, and verify the authorization before any export, but I’m looking for an audit-ready option that timestamps each step and keeps PHI encrypted in transit — any tools or templates you trust?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‌‌‌‍‌​‌‍‍‌‌‍​⁠‌‍​‌‌‍⁠​‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠​‍‌‍‌‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‍‌‌⁠‌⁠‌​⁠‍‌‌‌​​⁠​​‌​‌‌​⁠‌⁠​⁠‌‍‌‌⁠⁠‌‌‍‍‌​⁠​​⁠‌​‌⁠‌​‌‍​⁠​‍⁠‌‌⁠‍‌​‍​‍‌⁠⁠‌​

Switched to ChartRequest for ROI (https://www.chartrequest.com); every action is auto-stamped and PHI only leaves via an encrypted portal, which hits your “timestamp each step” ask. We’re at about 30/week too, and we kept our unique request IDs by mirroring them in a custom field so audits line up cleanly. Only caveat: the template/authorization mapping took a couple of days with IT.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‌‌‌‍‌​‌‍‍‌‌‍​⁠‌‍​‌‌‍⁠​‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠​‍‌‍‌‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠​‌‌‍‍‌‌‌‌‍​⁠‌‍‌​‌​‌‍‍‍‌‍⁠​‌​‌⁠​⁠‍​‌‌‌‌‌​‍‍​⁠​‌‌‍‍​​⁠‍‌‌‍​⁠‌‍‍‌​‍​‍‌⁠⁠‌​

We tied ROI to a Jira workflow so every status change auto-stamps user/time, and we only deliver via DirectTrust secure messaging (https://directtrust.org) to keep PHI encrypted in transit; small caveat: we had to train staff to update the ticket before any export.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‌‌‌‍‌​‌‍‍‌‌‍​⁠‌‍​‌‌‍⁠​‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠​‍‌‍‌‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​⁠​⁠​​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠​‌​​⁠‌​‍‌‌⁠‌‌‌​⁠‍‌​⁠​‌‌‌‌‌​‌​‌​‍‌‌‌‌‍‌‌​​‌‌​⁠‌​‌‍‌⁠‌‌‌‌⁠⁠​⁠​⁠​‍​‍‌⁠⁠‌​

Because 11:10 forces asymmetric hands, long minute at the 2, and the hour just past 11 — quick hit on planning and visuospatial.

With ‘11:10’, I watch left-side omissions and no self-correction, @ian_kelly42. Minor spacing slips are common.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‌‌‌‍‌​‌‍‍‌‌‍​⁠‌‍​‌‌‍⁠​‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠​‍‌‍‌‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‍‌‌​⁠‍‌⁠​​​⁠​‍‌​‍‍‌⁠​‌‌‍‍‍‌‌​‍‌⁠‍‍‌​⁠‍‌‌‌‍‌⁠​​‌⁠​⁠​⁠​‍​⁠​⁠‌​⁠‌​‍​‍‌⁠⁠‌​

We average about 30/week; Verisma met your ‘timestamp each step’ need and encrypts portal deliveries; per-request fees.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‌‌‌‍‌​‌‍‍‌‌‍​⁠‌‍​‌‌‍⁠​‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠​‍‌‍‌‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‌​‌​​‌‌‌⁠⁠​⁠‌‍​⁠‍​‌​​⁠‌‌‌‌‌⁠‌‍‌⁠‍‍‌‌‌‌‌‍‌​‌‌‍‌‌‍‍‍‌‌‍‍‌​‌‍‌‍‌‍​‍​‍‌⁠⁠‌​

We switched to ChartRequest for ROI; it gives a full activity trail (user/time/comments) and delivers through their encrypted portal, which made audit exports a 2‑minute pull for us (https://www.chartrequest.com). Small caveat: fees add up and the batch uploader is fussy, so if you’d rather keep it in‑house, Laserfiche with the Audit Trail add‑on plus SFTP leaves clear breadcrumbs for auditors.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‌‌‌‍‌​‌‍‍‌‌‍​⁠‌‍​‌‌‍⁠​‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠​‍‌‍‌‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​‌​⁠​‍​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠⁠‌‍‌‍‌​‍​‌‍‍‌‌​​‌‌⁠‌‍‌‌‍‍‌⁠​‌‌‍‍‌‌‌​‌​⁠‌‌‌​⁠‌‌⁠​‌‌⁠‍‍‌‌‌‍‌​⁠‍​‍​‍‌⁠⁠‌​