Tuesday, April 16, 2013

Shiny New Gadget Of The Month: Ultra-Small Bluetooth Location Stickers

Shiny New Gadget Of The Month:   Ultra-Small Bluetooth Location Stickers
    
With Stick-N-Find, never lose your keys again, find your remote control, track your luggage or keep a virtual leash on your pet fluffy so that you get notified when they go too far away.

   About the size of a quarter and 0.16 inches thin, you can stick these just about anywhere!  Stick them to any device, person or animal and find them with your smartphone.
    With an Apple iOS or Android app, you can view your misplaced items on a radar screen and decide if you would like to have it buzz, flash or do both. Or create a “virtual leash” with the sticker – if that sticker moves away more than a selected distance, your phone will alarm you. Lastly, “Find It” alerts allow you to be alerted when your lost item comes in range of your phone.
   Stick-N-Find Stickers have a Range of about 100 feet with a battery that lasts for over a year.
Find out more at www.sticknfind.com.

Do you have a cool gadget that you'd like to share with us?   Please let me know!  225-751-4444
Thank you!   

~Henry Overton



Monday, April 15, 2013

Mobile Devices: BYOD or COPE?


 BYOD or COPE? Do You Allow Employees To Use Their Own Devices For Work?

    The evolution of personal mobile devices and the rise of how necessary they are to business success these days are forcing many small business owners to make a choice. BYOD or COPE? Or “Bring Your Own Device” vs. “Corporate Owned, Personally Enabled”.

The Typical Solution - BYOD.    According to the CDW 2012 Small Business Mobility Report, 89% of small-business employees use their personal mobile devices for work. But the headache involved here is how do you support and secure all of these devices? The scary thing is that most small businesses don’t even try!  The CDW survey found that only 1 in 5 small businesses have deployed (or plan to deploy) any systems for managing and securing employees’ personal devices.

The Alternative - Is COPE Any Better? A minority of small businesses has implemented a Corporate Owned, Personally Enabled (“COPE”) policy instead. They buy their employees’ mobile devices, secure them, and then let employees load additional personal applications that they want or need. And the employers control what types of apps can be added too. And the “personally enabled” aspect of COPE allows employees to choose the company-approved device they prefer while permitting them to use it both personally and professionally. COPE is certainly more controlled and secure, but for a business with a limited budget, buying devices for every employee can add up pretty quick. If you go the COPE route and are large enough to buy in volume, you can likely negotiate substantial discounts.

Security Concerns With BYOD. If you have client information that must be kept secure or other industry specific regulations regarding the security of client data, then COPE is likely your best approach. It takes out any gray area of whose data is whose. Plus there is a certain comfort level in being able to recover or confiscate any device for any reason at any time to protect your company without any worries of device ownership.

Advice For BYOD Companies. Despite the numerous advantages of COPE, most small businesses will still choose BYOD because it can save them money. Here are 2 of Lawrence Reusing’s (GM of mobile security at Imation) important rules for BYOD. Consider these when creating your mobile device policy.

1. Assume employees will use personal devices on the corporate network even if they are told not to. 50% of employees use personal devices to take confidential data out of companies every day.
2. Assume employees value convenience more than security. If your policies are inconvenient, employees will work around them.

For our friends in the healthcare industry: here's a good site with short, educational videos about mobile device security (and why it's basically a must now...): http://www.healthit.gov/providers-professionals/your-mobile-device-and-health-information-privacy-and-security 


If you have any questions about managing and securing your mobile devices, give us a call at 225-751-4444!




Wednesday, March 27, 2013

Turn Key Solutions on LPB for Small Business

When:  March 27, 7:00PM

Where:  LPB

The LPB program “Louisiana Public Square” (http://www.lpb.org/publicsquare) topic will be “Tax Reform 2013” and will feature an interview with John Overton.   John is one of the owners of Turn Key Solutions, Chairman of the Small Business Council of BRAC, Chair-elect of the Leadership Council of the NFIB, and serves on the Small Business Advisory Council, BRAC board of directors and BRAC Executive Committee. 

From the perspective of a small business owner serving other small business across the state and a leader in several small business groups, John sees pros and cons of the Jindal administration’s tax reform package.  Turn Key Solutions’ commitment to the communities we serve is to advocate for the success of fellow small businesses—both in terms of the technology they use and the legislative environment in which businesses operate.  We encourage small business owners to run the numbers on how the package will affect them, and join us in working with our lawmakers to preserve the parts that help small business grow and modify the parts that could be impediments.

Additional airings of the LPB program featuring Turn Key Solutions will be as follows:

03/27/13, 9:00 pm LPB2
03/31/13, 12:00 pm LPB
04/09/13, 9:00 pm LPB2

Friday, March 1, 2013

Advocate for your Success

Turn Key Solutions and Turn Key Health are more than just technology companies.  We’re your advocate for success.  Our core competencies are summed up by our motto, “We make technology work for you!”  However, our commitment to our clients is also demonstrated by our dedication to affecting the legislative environment in which both we and our clients operate. 

With this legislative session getting off to a fast start, there are numerous bills that represent threats and opportunities.  A prime example of both is the Tax Reform package.  Much media ink has been devoted to speculating on what will be in the package and how it will affect various demographics.  Long before the session, the leadership team of Turn Key has been meeting with leaders in the Jindal administration and numerous small business groups to make sure the interests of our clients are protected.  As a partner and the CFO of Turn Key, I also serve as chairman of the Small Business Council (SBC) of the Baton Rouge Area Chamber (www.brac.org), a member of the BRAC board’s Executive Committee, chair-elect of the Louisiana Leadership Council of the National Federation of Independent Business (www.nfib.org), and a member of the state's Small Business Advisory Council.  In these roles I work to protect the interests of small business, provide resources to small business, and build coalitions with other business groups to amplify our impact. 

There are numerous provisions of the Tax Reform package that will affect small business.  A few of the positive pieces will centralize tax collection(making it easier for businesses to collect and remit sales tax), eliminate corporate income tax, eliminate inventory tax, and eliminate franchise tax.  Those are all very small business-friendly.  However, there is also a potential down-side in the expansion of sales tax to include many of the services that we provide our clients.  Repair services are already taxable, but we believe that taxing consulting services will add an unnecessary burden on our clients. 

Turn Key has not raised our service rates in many years, despite constant increases in operating cost—especially with the rising costs of the healthcare benefit package we offer our valued employees and the increase in fuel and insurance costs.  Although we are being forced to seriously consider a moderate price increase on some services, we are also evaluating the potential increased tax burden on our clients.  And more importantly we are fighting FOR beneficial legislation and AGAINST harmful legislation.  It’s all a part of our mission to serve YOU, our valued clients and our community. 

If you have concerns about a particular piece of legislation and/or want to know how to make an impact, please contact John Overton at 225-751-4444.

Tuesday, February 12, 2013

HIPAA COMPLIANCE IS A JOURNEY, NOT A DESTINATION

So are most things that are really worthwhile - wouldn't you agree?

I just googled "hipaa compliance process" out of curiosity.   My browser says there's "About 5,570,000 results."

That's fairly daunting.   How do you do HIPAA compliance CORRECTLY with the time you've got every week,  and the thousand or so other responsibilities you've got?

Here's my simple, easy, solution for you:    Get started.   Do something.   And then keep doing something, regularly.

But please, please, please - don't stick your head in the sand.   Audits are coming faster every day now, and PHI breaches seem to be almost inevitable, no matter the size of your practice.

And what's the first something to do?   

I would suggest that you begin with the practical guidance from the HIPAA law itself - start with implementing a Risk Analysis Process.

Looking at the HHS's guidance on how to start compliance with the Security Rule here - http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/radraftguidance.pdf - their guidance is clear:

"In Summary 
Risk analysis is the first step in an organization’s Security Rule compliance efforts. Risk analysis is an ongoing process that should provide the organization with a detailed understanding of the risks to the confidentiality, integrity, and availability of e-PHI."




This is why, at Turn Key Health, we follow this Risk Management Process with our clients:  

Visit us at www.tkshealth.com to learn more.
Step 1: Identify Risk Areas

Step 2: Assess Risks

Step 3: Create a Risk Management Plan

Step 4: Implement Risk Controls

Step 5: Re-evaluate & Measure

Step 6: Go to Step 1






I truly believe that Step 1 is the most important - take the time to thoroughly draw out EXACTLY where your ePHI is stored, where it travels, where it can be accessed, and draw the lines between those systems.    This is the one time in your  whole HIPAA compliance journey when you have my blessing to be really pessimistic and let your mind dwell on everything that could possibly go wrong.

Quoting again from the above HHS paper: 

"The following questions adapted from NIST Special Publication (SP) 800-66 are examples organizations could consider as part of a risk analysis.  These sample questions are not prescriptive and merely identify issues an organization may wish to consider in implementing the Security Rule:

  • Have you identified the e-PHI within your organization? This includes e-PHI that you create, receive, maintain or transmit.  
  • What are the external sources of e-PHI? For example, do vendors or consultants create, receive, maintain or transmit e-PHI? 
  • What are the human, natural, and environmental threats to information systems that contain e-PHI?"

If you take your time and do a thorough job at this step, it will make you WAY more effective in the ensuing steps.

We've all heard the quote "A journey of a thousand miles begins with a single step", right?  (Lao-tzu, Chinese philosopher)

Let's get stepping!  You can do this!







If you want to find out how we can make HIPAA compliance painless, visit us at www.TKSHEALTH.COM


Monday, September 17, 2012

When Isaac came to town, were you 100% confident in your backups?

When Isaac came to town, were you 100% confident in your backups?


Let me ask you a tough question: 
When Isaac came to town, were you 100% confident in your backups?

Every year during hurricane season, we evaluate hundreds of business networks’ security and backups.   This year, I have noticed that an alarming majority of Louisiana businesses are missing a critical step that could be implemented in a single day, saves money, and could literally make the difference between staying in business after a disaster or not.

Here Is What We Are Recommending...

Thanks to major advancements in backup technology, you can now have your choice between 2  incredible protection solutions against Hurricanes, fires, and accidents:

Solution 1: Basic Offsite Data Backup: For as little as $10 / month, your files can be securely backed up, automatically.   NO business should be without some sort of Offsite Data Backup solution.

This simple concept of backing up just your most critical files and databases could literally keep your doors open after a disaster.     This works great in environments where you have just a few gigabytes of data that is really important to you, and/or in environments where your upload speeds are limited.

Simple, fast and cheap, this backup solution doesn't prepare you for every disaster scenario, but it can be used to cover you in these:

1. Accidental data loss (Such as: "Oops!  I deleted the quickbooks database!", or "Oh no, the computer that had the quickbooks database on it died!"
2. Accidental data corruption (As seen on: "Oh nuts!   I think we made a mistake a week ago on this project.   Can you recover the file back to the way it was 2 weeks ago??"
3. Total disasters (Like: "Our office is destroyed, we know it's going to be a rough few days, but let's restore our accounting files, our customer database, and our collections reports so we can at least keep up with customer needs and our collections...")

Solution 2: Business Continuity Backup Solution: For a complete, automated, managed and monitored solution that will keep you UP AND RUNNING DURING the next disaster, we offer the ultimate "Business Continuity Backup Solution," often for as little as $200 / month in many configurations.   

Configured correctly, here's just SOME of what this solution provides you:



  1. The Business Continuity Backup device takes an image (snapshot) of your server many times throughout the day, automatically. That means you wouldn't lose an entire day’s worth of work if your server crashed or melted down; just a few minute’s worth.
  2. You don’t have to swap out tapes or drives every day or lug them around in your car.
  3. We will monitor the system 24x7x365 and notify you immediately if your server fails, and be ready to make the Business Continuity Backup Server TAKE OVER for your server if you need it to.   This means you’ll be up and running within minutes instead of potentially being down for  DAYS.
  4. Your data and server image get replicated to another data center far away from  Hurricane Alley to make sure your backup has a backup! This is FAR MORE secure and reliable than old tapes, USB drives, etc.



In either scenario you don't have to worry:
• "Is my critical information safe?"
• "Could I really restore my files if I had to?"
• "If I lose these files, will I go out of business?"


Call us today, and KNOW that you're prepared for the next disaster.


There's simply no excuse for being worried about your backups.


Don't delay - call us at 225-751-4444.   





Friday, May 4, 2012

Small Business Day at the Capitol--Our voice for you.

Did you know that most legislators never hear from their constituents, even on key legislation?  According to Renee Amar, Louisiana State Director of the national Federation of Independent Business (www.NFIB.com) if a legislator hears from 4 or 5 constituents "it is like the world is on fire" – your voice—yes YOURS—can make a difference. 

The Small Business Day at the Capitol on May 3rd connected small business owners with our legislators and gave us an opportunity to learn about legislation that affects our operations.  Getting informed is the first step to making an impact. 

Turn Key Solutions is committed to serving not only our clients but also our community.  Because most of our Clients are small businesses (defined by the SBA as under 500 employees), we believe that advocacy is essential to the success of all of us.  It is a challenge for me to take time away from running my businesses to get informed about legislation, serve on the Baton Rouge Area Chamber's Small Business Council (www.BRAC.org) as Co-Chair of the Advocacy Committee, and serve on the NFIB's Leadership Council.  But it is a commitment that my partners, Henry and Harold, and I have made because we cannot stick our heads in the sand and just let legislation and regulations happen to us. 

There are so many bills and regulations that threaten the success of small businesses, especially in the controversial area of healthcare.  Because of our experience in serving the healthcare industry in everything from HIPAA/HITECH compliance to servers and network security, we have seen first-hand how legislation and regulations can turn an entire industry on its head. 

Amar, one of the keynote speakers at the Small Business Day at the Capitol, went on to describe how legislators often only hear from lobbyists—and they have their place (who else is going to keep up with thousands of pieces of legislation?!)  But when our lawmakers are being pushed and pulled from opposing lobbies, the voice of even one business owner can make all the difference in how they vote.

Turn Key Solutions is your advocate—not just in getting you the technology that helps you meet your business goals, but also by fighting for your interests as a small business.  BUT you too can make an impact.  If you want to learn more about the issues threatening your success and how you can get involved, comment on this blog.  Together our voices are louder; together we help each other succeed.  Don’t risk your future by letting legislation and regulations just happen to your business.

Tuesday, April 17, 2012

Turn Key Solutions Takes a “H.I.T.” for Small Business

Business owners, what’s more frustrating than your healthcare premiums going up 15% again this year? Not getting any meaningful information WHY!

Turn Key Solutions is in a unique position to help Louisiana small business owners. We are leveraging our expertise in Healthcare Information Technology (HIT) to push through House and Senate bills that would give small business owners much more control over one of our biggest expenses—healthcare insurance benefits.

Currently at annual renewal time, Louisiana small business who ask why their premiums went up so much (again) receive scant information—just a claims-to-premium ratio. As co-owner and CFO of Turn Key Solutions, I recently testified at a House Insurance Committee meeting in support of Representative Huval’s HB989. A simple ratio is not enough to go on to make business decisions about such a significant business expense! HB989 forces providers to disclose much more information so owners can make sure they are getting the coverage that best fits their employees’ needs and at the most competitive price.

Insurance providers have vigorously opposed this and similar legislation that shift some control from the powerful providers to small businesses. Often their opposition has been hidden behind misleading claims that the release of this information would either violate HIPAA and HITECH rules regarding disclosure of Protected Health Information (PHI) or put small businesses and their employees at greater risk of privacy violations.

Turn Key Solutions (www.tkshealth.com) specializes in Healthcare Information Technology—we help our clients comply with HIPAA and HITECH. I testified in front of the House Committee that this bill does not require disclosure of any of the 18 components of PHI and that similar, more expansive legislation has been on the books in Texas for 5 years without a single HIPAA violation suit.

HB989 passed through committee without objection.

In addition to serving the technology needs of our clients, we are also frequent advocates for small business on issues that affect our ability to operate effectively and profitably. I am co-chair of the Baton Rouge Area Chamber’s Small Business Council Advocacy Committee and serve on the National Federation of Independent Business (www.NFIB.com) Louisiana Leadership Council. I will testify again in support of similar legislation in the Senate, SB283, in May.

If you are a small business owner and want to support this legislation, call us and join the fight.

-- John Overton

Monday, March 19, 2012

THE AUDITORS ARE COMING!! (HIPAA / HITECH series continued)

HHS & the OCR may or may not be gunning for you.  
How prepared are you?
In warning that up to 150 organizations are going to be audited this year, the OCR just fired a big fat warning shot across your bow.

A short summary of the deal is found at their website, as follows:

"... OCR is piloting a program to perform up to 150 audits of covered entities to assess privacy and security compliance.   Audits conducted during the pilot phase will begin November 2011 and conclude by December 2012."

What does this mean for managers, owners, and other leaders at Covered Entities and Business Associates?

Simply enough: the audits are real, the audits are under way, and it would be in your best interest to at least take the whole concept seriously and start the simple, cheap steps to prepare your organization for compliance.

Quick reminder about why you care.....  the law requires from $100 to 1.5 million dollars fines to be levied this year.   Read this summary from the AMA for more details.



So, what do you do to prepare?    What simple steps will go a LONG WAY towards keeping your money in your pockets, and keeping your business in business?

Quite simply, as Turn Key Solutions & Turn Key Health (and a lot of other educated organizations) have been preaching for some time now: START WITH A PERIODIC, ANNUAL INTERNAL AUDIT.


A great summary from Chiroeco.com of what needs to happen next is as follows:


1. Get your documentation in place
2. Get your business associate agreements in place
3. Evaluate your compliance (periodic internal audits)
4. Implement a training program
5. Assemble your internal subject matter experts as relates to the HIPAA / HITECH laws
6. Prepare for a timely response 



If you need help with any of these steps, call us at 225-751-4444.    As the Gulf South regions' premier Healthcare Information Technology services team, we're helping clients every day run their practices and their clinics more efficiently, building HIPAA & HITECH compliance into every piece of their business.

And we'll be honored to help you, too.


Find out more about Turn Key Health here: http://www.tkshealth.com

Wednesday, March 14, 2012

WHY in the world would anyone do business with us?


In trying to grapple with what kind of customers we do best with, and what sort of employees do best @ Turn Key Solutions, I'm asking myself for the 984th time, "Why does Turn Key Solutions exist?   Why do I come to work every day?"

Here's what I've scribbled, scratched, and drawn out over the last few weeks:  

My partners and I, and our key employees, and, I think, all of our employees actually believe the following things (I believe so, because these are the things we constantly talk about, these are things we discuss in the lunchroom, these ideas are the heart of our conversations all the time.):

What Turn Key Solutions really thinks:
... that small businesses are terribly important (and borderline almost sacred), and that they shouldn't be taken advantage of.
... that every time our customers win, we win.   Not because they're going to give us money, or PO's, or references, but because we were a part of that victory.
... that business owners and employees need success for the american dream to happen
... that customers need to be protected because every time a business fails, families suffer and dreams fail.
... that in an industry as dynamic as Information Technology, businesses need reliable, proven solutions to safeguard their budgets.
... that rapidly evolving technologies often have an important place in the business environment
... that our depth and breadth of experience, our passion for our clients' success, and our appreciation for reliable technologies creates a culture whereby we can dramatically help clients that will PARTNER with us, TRUST us, and COMMUNICATE with us.



So maybe instead of talking about how big our office is, or how awesome we are, I need to start communicating with the world about what we believe.   

Because everybody thinks they're an I.T. company.   Heck, there's 2 other IT companies within a stone's throw of our front door.   Probably 5 within a 1 mile radius.   But what makes us different?   The above stuff - how we think, the filters through which we run every decision.

Are we the right I.T. partner for every company in the Gulf South USA?   Nope.   But I do believe there are plenty of people that think the same way we do.

And that's enough business for us.   

After all, when it really comes down to it, why do we come to work?   To provide for our families and to help someone so that at the end of the day, we hopfully can know that we made  difference to the people that trust us.

That's why.



Wednesday, March 7, 2012

What we do best

After being in business since 1999, it's dizzying to think of the sheer volume of products and solutions we've tested, tried, chucked out the window, and/or supported for 13 years now.

Thousands, I guess.  

And in the end, that's okay.  It's good - after all, Info Tech is a changing, dynamic industry by its nature.   

So take some dramamine, and stop spinning - that's what I always tell myself.   Then, let's focus on our primary goal here: protect our clients and help them grow.  

And how do we do that?   I AM SO GLAD YOU ASKED...   

I working on updating our website to the new Joomla 2.5 CMS, and updating our "products and services" page - check it out here.   Short version, though is that here is what we focus on:

Solutions Consulting - figuring out the best way to meet a new need, a new business problem every day.   

Security & Compliance - keeping our clients' data secure, and keeping them in front of ever-changing legal and industry regulations.

Cloud Services - "cloud" stuff is cool because it's the best way to meet a lot of business goals.  BUT NOT ALL OF THEM.   Our job is to help clients figure out when it's a fit, and then pick from the 9 million cloud vendors out there.

Complete I.T. Management - day in, day out, 24 x 7 x 365, we watch our clients' infrastructure, we protect them, we staff them with caring & competent IT professionals, and we just make stuff work.

Hardware & Software - after reviewing so many products, we know what works good.   That's why we sell stuff - because we are trying to make it easy for our clients to get the right parts.   Certainly not because there's tons of profit in hardware anymore. :(

Disaster prep & recovery - few things stink worse than losing data.   Except poopy diapers, maybe.  (I have 5 kids and 2 decades of IT experience, still not sure which stinks worse, honestly.)

Healthcare I.T. Specialization - somehow we've gotten a ridiculous amount of experience helping healthcare clients with every aspect of their business, and we love it.  It's one of the specialized industries we really enjoy and focus on.

So that's it.   That's what we do best.   Somehow, website design is no longer on that list.   So if our site isn't perfect, we'll get around to that.   But in the meantime, I've got customers' problems to fix first. 


Wednesday, February 22, 2012

I'm emailing you 1.5 million bucks... (HIPAA / HITECH Part 4: Email Security, ePHI & HIPAA)

How many times have you accidentally emailed something you wish you hadn't?   Forgotten to remove someone's address from a "reply all?"

These sort of simple, unintentional slip-ups can LITERALLY COST YOU MILLIONS in this age of enforced penalties for HITECH / HIPAA breaches.

If your organization handles Protected Healthcare Information (PHI), and you want a way to protect yourself from this scenario, read on...

Quick recap:  here's the quick summary of our suggestions on how to get started with HIPAA & HITECH compliance:

If you've not done it, though, I cannot stress enough the importance of #1 - The Self Assessment.   You simply have to get a good baseline for where you stand.    CALL US  for more details.   (Hint - it can probably be done very well for under $100 / mo)

Now that you've done your self-assessment....









On to an important part of #7 - EMAIL ENCRYPTION.

The HHS specifically addresses email security in several documents.   An easy read is one of the "Safeguards" documents you can find right here.

Specifically, is email encryption mandated for all transfer of ePHI?   No.

BUT......    the safeguard principle that colors every aspect of compliance states the following:

SAFEGUARDS PRINCIPLE: Individually identifiable health information should be protected with reasonable administrative, technical, and physical safeguards to ensure its confidentiality, integrity, and availability and to prevent unauthorized or inappropriate access, use, or disclosure.

AND.....  there are very, very clear commentaries in several places that email is allowed under very specific situations.

AND... there are new cases of organizations (BA's and CE's) accidentally breaching PHI with email....  most of the time accidentally!

AND.... keep in mind that the annual max fines are between $25,000 and $1.5 Million dollars.   Not sure about you, but even getting slapped with a $25k fine would be enough to really irritate me.


So, if it's now cost-effective and technically simple to encrypt all PHI that may be transmitted via your email servers, would it' it seem reasonable?



Without hammering this point needlessly, I would suggest you look into how simple the solutions are for encrypting your clients' email.

While there are several great vendors on the market now, we sell and recommend the solutions from ZIXCORP.   They're the leaders in this industry, and we simply have not seen a cheaper, more flexible, more powerful solution on the market place.   Their basic ZixMail solution that will protect PHI and keep your email secure costs between $4 and $10 / user / month for most of our clients, depending on their size & specific needs.

From $4 to $10 / user / month.    And this issue is put to bed.

And you don't have to worry about your staff accidentally emailing out up to $1.5 MILLION worth of breaches.

Seems like a "reasonable administrative, technical, and physical safeguards" to put in place to me.

Curious?   Want to see a demo?   Contact us at www.tkshealth.com or read more at www.zixcorp.com.


Monday, February 13, 2012

AAAAGGHHH!!! We're growing again!!!! (Are you coming to see us anytime soon???)

You heard it right!   

Turn Key Solutions is excited to announce that we just brought on board two additional technicians.    That's after screening almost 200 resumes, putting about 30 through basic screening, and more interviews that I want to admit.   We're picky - we looked long and hard for technicians with the skills to do the job, the heart to take care of clients, and the personality that will be a joy to work with.

But, the good news is that with these two new guys, we've added about 13 years of experience to our team, and they fit our culture and our client needs really well.

So, yes, as a small business owner, it's a little scary to add on staff.  But it was time - we've been working our technicians a little too hard for the last year, and we needed the extra capacity to meet the growth of projects our clients are firing up. 


Oh, and did I mention that we moved offices, for the first time in over 11 years?    Yup!   In the last 4 years we've gone from using 2500 square feet to now we have about 7500 square feet of office space.    The big upshot?   We are planning on using the new space to add some great services to our clients and community.   Already we've been able to host one neighborhood community event on-site, and we're working to be able to have an open house or two in the upcoming days.


Needless to say, we are thankful to be so blessed on so many fronts, and we really look forward to finding new and better ways to bless our community and our clients in 2012.


SO....   drop on by, meet our long-term and new staff, and come grow with us!

-Henry Overton





Tuesday, February 7, 2012

Here's what's big for TKS in 2012... (Subtitle: New Years' resolutions are stupid.)

Congratulations!  You've made it through the first month of 2012.


And, if you're like most people I know, you've quietly forgotten about most of your new years' resolutions.  (Quit eating greasy burgers in the car, stop watching Dancing with the Stars, etc, etc...)


If you're like a lot of small business owners I know, though, you're just getting started with your business goals.


Better yet, you may just be formalizing your goals for 2012.


At Turn Key Solutions & Turn Key Health, we're refining our business goals every day.   The most significant goals we've got all work to meet our new, refined vision statement:


Turn Key Solutions empowers businesses across the Gulf South region to focus on what they do best by providing technology teams and environments our clients can depend upon, grow with, and enjoy interacting with. 


We are passionate about providing the best solutions, excellent customer service, and overall excellent experiences for our customers EVERY DAY.



So this isn't quite as full of flair as the "Holstee Manifesto" but it captures everything we see in Jim Collin's "Good to Great" "Hedgehog Principle" -


1. What is Turn Key Solutions passionate about? - Harold Robinson and I (Henry Overton), as founders, really are passionate about technology.  We love it.  That's why our new office has thermostats with I.P. addresses.   It's why we actually enjoy reading the manuals for firewalls, operating systems, and our dvd players.


2. What can Turn Key Solutions be the best in the world at? -  I truly believe we can be best at these:


A. Custom crafting top-quality business technology solutions designed exactly, perfectly for our business partners (ie, clients) and


B. Providing an excellent customer service experience, every time.

3. What drives our economic engine?   Service, service, and more service.   Some specialized solutions do have better profit margins, yes, but it's been 15 years since any regional I.T. company made real money reselling computers.   




SO....  All that said, here goes our biggest goals for the year:


1. Provide excellent customer experiences, and excellent solutions, every time.   


              closely followed by...


2. Get the word out that we're doing this, and carefully grow our client base.


If you have any feedback already on how we're doing, PLEASE LET US KNOW!




So.... now that we've shown our cards, how are your goals coming for the year?









Monday, November 28, 2011

We've got a lot to be thankful for.


@ Turn Key Solutions we have so much to be thankful for that even on the Monday after Thanksgiving, it's still hard to write this list & not miss something.   But here's a start...

We're thankful for our customers. We appreciate your support and your loyalty more than we can express. We are so blessed to have the opportunity to serve people, to make your day better, and to make your technology work so that you can make things happen.

We're thankful for our opportunities and our freedoms here in the USA.

We're thankful for God's blessings on our country, our business, and our families.

We're thankful for our courageous military and their families that give up so much to protect our freedoms.

We're thankful for our team members.   (Interesting aside - we recently took an in-house survey, and every one of us, without exception, listed their primary motivator as "Helping People.")

We're thankful for our new office.    YES!  You heard it first right here!   Over the next 4 weeks, we're moving about 4 miles over to a much nicer, bigger office building.   We are looking forward to launching a whole new series of customer training sessions in our brand new office.   Stay tuned - we'll have an open house soon, and you'll be invited!

Okay, I could go on quite a bit here.   We've got so many great customers, employees, vendors, solutions, opportunities and blessings all around, that all I know to do is say "Thank You.".  
And brace yourself.   2012 is going to be a great year.

Our entire team and I look forward to hearing from you and helping you as you make the most of your blessings and opportunities too.

Sincerely, 

Monday, November 7, 2011

I don't need no stinking risk assessment. (HIPAA, HITECH & YOUR TECH Part 3)

In our previous blog about HIPAA & HITECH compliance we walked through a simple outline of steps towards meeting HIPAA / HITECH compliance, all of which are based on a walk-though of the HIPAA administrative simplifications.

Quick recap - step 1 is to familiarize yourself with the law and get a team together that can help you be compliant.   HERE's  a great document from HHS on how to do the risk assessment.

STEP #2 - The next step is  do a risk assessment.

"THIS IS STUPID.  WHY?" you ask.   "I know my risks.  I don't need you to tell me what my risks are."

Well, forget the fact that the HHS expects you to do it.  How about looking at this from a PURELY BUSINESS PERSPECTIVE.

What would you do if one of your employees accidentally lost a box of your patient charts?

What would you do if a major hurricane was coming?



What about if your practice was hit by a tornado?   Could you EVER recover your business data?  Collections reports?  Patient charts?


The shocking thing for me, as a consultant, is how QUICKLY we forget things like the Joplin tornadoes , and hurricanes Gustav and Katrina.






I WANT YOU
to give me your patients' data,
and all your money.   




But as a business owner or manager (and that's what you are, even though your business is healthcare..), here's the biggest threat you've got: UNCLE SAM.










SO, if you adhere to HIPAA / HITECH regulations, obamacare, or whatever you want to call it, great.  You're already looking for compliance solutions & doing your homework.

BUT IF YOU DON'T believe that HIPAA & HITECH are real threats to you, then forget about the risk assessment as a HIPAA mandate, but DON'T OVERLOOK IT AS A SOUND BUSINESS PRACTICE.

So, if you're interested, here's what your Risk Assessment should look like:

1. It should be periodic.   The world changes, your business changes, and risk factors change.  Your assessment from 2005 is outdated, refresh it or start a new one.

2. You should be involved in it.  If you pay a consultant to do it 100%, it won't reflect your organization accurately.

3. Your assessment should be thorough.   HIPAA law (164.308(a)(1)(ii)(A) states that you should assess the vulnerabilities to the
         A. Confidentiality
         B. Integrity, and
         C. Availability of electronic protected health information (ePHI) held by the covered entity.

SO HOW DO YOU DO A RISK ASSESSMENT?

Our recommendation is to use a company called eGestalt.
WHY?


1. For most practices, their solution costs at or under about $100 / month.
2. It's a secure offsite repository for your compliance plan.
3. It's built and maintained by a team of people who do nothing but obsess over security compliance, so they're keeping it up-to-date.
4. Simple reporting - with a few clicks, you can see in color and in pictures EXACTLY how compliant you are.
5. Comprehensive reporting - with a few clicks, you can pull an extensive report on your compliance status, complete with your supporting policies & documents, to provide an auditor.
6. It's HIPAA / HITECH simplified - all throughout the process of their assessments, you're provided both detailed links to the actual law, and also great explanations & templates for how to meet the legal requirements.

Are there options out there?

You bet.

But this one is a cheap, simple and comprehensive way for you to meet this incredibly important part of HIPAA & HITECH.   And it's proven, reliable, and industry-accepted as a strong solution.

So, when you're ready, CALL US at  225-751-4444 or visit us online at www.TKSHEALTH.COM to learn more or to get started on your audit.






http://www.hhs.gov/ocr/privacy/hipaa/enforcement/cmscompliancerev08.pdf

Friday, October 21, 2011

We forgot to say "Happy Improve Your Office Day!" (and a review of my new Lenovo e420s laptop)

Wow, I feel like such a toad.  I forgot to wish everyone a very happy "Improve Your Office Day" on October 4th this year.

Really, it's an official sort of official holiday!  Check it out yourself - http://www.daysoftheyear.com/days/improve-your-office-day/

Well, probably that's because my new Lenovo E420s laptop hadn't shown up yet, and John and Harold's had.  I admit, I was a grump.

Well, I got mine a week later, and I have been loving it.   For the life of me, I can't figure out why I waited so long to get a new laptop.   As a techie, you'd think I'd be all about trying out the latest toys, the newest gadgets.

Strangely enough, though, I'm a late adopter of new toys.   I have some personality flaw that makes me like to keep what I've got working for as long as I can.   Perhaps it's inherited from parents that lived through WW2 and got ingrained with "Fix it up, wear it out" mentalities.

Anyway, so here I am, 2 weeks later, and I have to say, this is my all time favorite laptop yet.

The Lenovo e420s is now officially on my list of things I love.
A quick run-down of my favorite features, in non-techie language:

  • $799 list price
  • Intel Core I5 CPU (FAST!  Windows 7 sees 4 cores)
  • 4 gb ram
  • 320 gb hd
  • Light weight
  • Big keyboard
  • Big monitor
  • Fingerprint security (ie, it can log you in with a finger swipe)
  • High resolution camera & good microphone (just hosted a webinar today, they were perfect for the job)
  • A LIGHT at the top of the LCD monitor that you can turn on when typing at night (using it right now - it's very effective!)
  • Bluetooth
  • HDMI video output.


Anyway, look, here's the moral of the story....   I was tinkering along with a great computer that is about 5 years old before this that was awesome when I got it, and still runs Windows 7 fine, but good grief this new laptop is WWWWAAAAY faster, tons more features, and it was cheap!

So here's the deal....    As a business owner, I try to be cheap.   Don't you?   Instinctively, we want to keep expenses down.   Which means employees don't really need anything faster than that dinosaur of a computer you bought sometime during President Clinton's 2nd term, right?

WRONG.    They're wasting your time and your money using that dog.   Not intentionally.   But the time it takes for them to wait for it to boot, wait for print jobs, wait for reports, etc, etc, etc, is time not making you money.   It's time they could be spending helping your customers.

Instead, what are they most likely doing?   Telling your customers they're having computer problems.

So take a minute, go around your office and figure out how old your computers all are.  

HERE'S A GOOD RULE OF THUMB that's held true for the last decade....   for most office workers, if their computer is:
 ..... 5 years old or older, replace it now.
 ..... 4 years old, put it on next years' budget.
 ..... 3 years old, evaluate if it's a truly business critical machine - chances are there's no warranty on it anymore, and you either want to increase your backup routine on it, extend the warranty on it, or move the computer to a non-critical position in your business, and get this employee a new or newer computer.

If you're of the mindset that your staff should run their computers until the monitors melt, you're saving pennies  & burning dollar bills.   Oh, and you're probably really ticking off your employees.  Check out this recent survey from Staples.... http://investor.staples.com/phoenix.zhtml?c=96244&p=RssLanding&cat=news&id=1612573

So that's all for now.   I am loving this Lenovo e420s laptop, and hope to have many happy years of use out of it.

But not too many....

Friday, October 7, 2011

A tale of two Covered Entities (Prologue)

This week we met with two different healthcare providers, or, in HIPAA-speak, "Covered Entities" (CE)

And they couldn't possibly have had more different responses to the concept of HIPAA / HITECH compliance.

The first CE, we'll use the pseudonymn "London Healthcare" didn't know that much about HIPAA / HITECH requirements.  Over the course of our conversation, though, they were extremely receptive to learning what they could about it, and quickly got to the point of detailing a gameplan.  

We wrapped up our 2 hour meeting with some clear action items for both parties, and an enthusiastic, positive mood all around.

The second CE, we'll call them "France Healthcare," knew precious little about the subject either.   And over the course of our 24 minute conversation, it was painfully clear that they didn't want to know any more, either.  

Their perspective was that HIPAA / HITECH was frivolous law, and that rumors of auditors assessing fines were all fake propaganda.   We left each other without any progress, and tangible distrust and frustration being the remaining attitudes all around.



So, what was the difference?   Why did these two small CE's have such completely different perspectives on the significance of HIPAA  & HITECH?

After thinking it over for a few days, here's the best explanation I can come up with:

1. TRUST (or the lack thereof):
   

Our positive, receptive CE, "London Healthcare" (again, real names changed to protect the innocent...), TRUSTS ME AND MY COMPANY.    We've got a relatively long relationship where they've trusted us with pretty much their entire I.T. operations, and we've not let them down.   In their words, we've always been quick to respond, looked out for their best interest, and on top of things.  So there was already a high degree of trust there.

On the other hand, our not-so-receptive client, "France Healthcare," is a new client for us, and doesn't quite yet trust us.  They're obviously holding us at arms' length still.

2. HOW WE APPROACHED THE SUBJECT:

We went to "London Healthcare" to start planning a major I.T. infrastructure refresh, but we walked through it from the perspective of how each piece is colored by HIPAA / HITECH.   I think this helped them understand that these laws aren't completely frivolous, but that they're a good framework for looking at all your practice's I.T. decisions and infrastructure.

We went to "France Healthcare," though, to talk about HIPAA / HITECH.   I'm fairly certain that from the moment we walked in the door, they felt like they had to be on the defensive, and that they knew they weren't compliant, but didn't want to acknowledge that it's "that big of a deal."

SO, end result?  Shame on me, at least to some extent.   My customers, and our healthcare community at large, need to prepare themselves appropriately against the threat of a HITECH audit. 


Don't believe me?   Do you think this "HITECH junk" is smoke & mirrors?


1. Check out the Department of Health & Human Services' wall of shame here.
   (Here's the full URL: http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html)

There are two companies in my home town of Baton Rouge, LA listed there!   And these are just for breaches affecting 500 or more individuals!


2. Did you know that HHS imposed a $4.3 million fine earlier this year for HIPAA violations, as it's first official fine?   In the Office of Civil Rights' directors' words...

“Today the message is loud and clear:  HHS is serious about enforcing individual rights guaranteed by the HIPAA Privacy Rule and ensuring provider cooperation with our enforcement efforts,”  -OCR Director Georgina Verdugo.

There are other cases of fines too, but that was a nice way for them to get the party started.



Anyway, back to my two customers, "London" and "France."

Congratulations to London.   Clients that are raving fans are usually going to be more receptive to new ideas, but this client looked at the whole concept from a business perspective, quickly realized that the HIPAA regulations just detailed good business practices anyway, and almost immediately set up an action plan, a timeline, and an educational agenda.    WOW.


And France?   We've both got some work to do.   I'm going to continue trying to educate them, gently and persistently.   And we'll talk about it next time piece by piece, and perhaps from a different perspective.

So, our tale of two cities is just getting started.

I'll keep you posted on how the war goes. :)