Healthcare Administration Fundamentals
Overview of Healthcare Settings
TYPES OF HEALTHCARE ORGANIZATIONS:
Hospitals: acute care, critical access, specialty (psychiatric, rehabilitation)
Physician Practices: solo, group, multi-specialty, academic medical centers
Ambulatory Surgery Centers (ASC): outpatient procedures only
Long-Term Care: skilled nursing facilities (SNF), assisted living
Home Health Agencies: nursing, therapy, aide services at home
Hospice: end-of-life care (comfort-focused, not curative)
Behavioral Health: psychiatric hospitals, outpatient counseling
Federally Qualified Health Centers (FQHC): safety-net clinics
OWNERSHIP TYPES:
Not-for-profit (501c3): most hospitals, community mission
For-profit: investor-owned, shareholder returns (HCA, Tenet, Steward)
Government: VA, county hospitals, public health departmentsHealthcare Stakeholders
PAYERS:
Medicare: federal, age 65+ | disability | ESRD
Part A: hospital, SNF, hospice
Part B: physician, outpatient, DME
Part C: Medicare Advantage (private plans)
Part D: prescription drugs
Medicaid: state/federal, low income
Each state administers differently
CHIP: children's health insurance program
Commercial: employer-sponsored or individual market
Blue Cross Blue Shield, Aetna, UnitedHealth, Cigna, Humana
PPO: freedom to choose any provider
HMO: must use network, PCP referral needed
HDHP: high deductible health plan + HSA
PROVIDERS:
MD/DO: physicians (medical doctors / doctors of osteopathy)
NP: nurse practitioners (can practice independently in many states)
PA: physician assistants (require physician supervision)
RN: registered nurses | LPN: licensed practical nurses
PT/OT/SLP: physical, occupational, speech therapists
REGULATORS:
CMS: Centers for Medicare & Medicaid Services (federal)
State health departments: licensure, Medicaid oversight
Joint Commission (TJC): voluntary accreditation
OSHA: workplace safety for healthcare workers
OCR: HIPAA enforcement under HHSHIPAA Basics
HIPAA PRIVACY RULE:
Protects PHI (Protected Health Information)
PHI = any information that identifies patient + relates to health
18 identifiers: name, DOB, SSN, address, phone, email, etc.
Minimum necessary standard: share only what is needed
Patient rights: access, amendment, accounting of disclosures
HIPAA SECURITY RULE:
Applies to electronic PHI (ePHI) only
Administrative safeguards: policies, training, access management
Physical safeguards: workstation security, device controls
Technical safeguards: access controls, audit logs, encryption, MFA
HIPAA BREACH:
Unauthorized acquisition/access/use/disclosure of unsecured PHI
Risk assessment: determine if it is a breach requiring notification
Notification: patient (60 days) + OCR (60 days) + media if 500+ in state
Penalties: $100-$50,000 per violation, up to $1.9M/year per categoryStudy Resources
•ACHP Healthcare Administration Guide — free overview
•CMS website (cms.gov) — all federal healthcare programs
•ACHE.org — American College of Healthcare Executives resources
•AHIMA Body of Knowledge — health information management

