Go back

Identifying Your Benchmarks- What to Measure

from Rx for Hospital Quality

25m 48s

Identifying Your Benchmarks- What to Measure

This podcast discusses a shift from compliance-based to risk-based healthcare quality management, emphasizing that risk is not about meeting rigid benchmarks but identifying barriers to delivering safe, effective patient care. Unlike traditional accrediting bodies, DNV does not impose fixed requirements but instead guides hospitals to define their own benchmarks based on industry standards or internal strategic goals. The core of risk management lies in understanding internal and external factors that hinder or support organizational success. Key emphasis is placed on focusing internal audits on high-risk areas, pain points, and process failures rather than broad compliance checks. Organizations are encouraged to evaluate the effectiveness of corrective actions and measure return on investment, ensuring that efforts are aligned with patient safety and organizational value. Risk planning must include a clear evaluation of how well mitigation strategies work, with ongoing review to prevent stagnation. The approach promotes simplicity, accountability, and strategic focus—moving beyond compliance to sustainable improvement. Ultimately, healthcare leaders are urged to prioritize initiatives that deliver tangible value, asking not just if something is done, but whether it brings real return on investment for patients, finances, and reputation. This risk-based model supports a dynamic, evolving culture of quality that adapts to real organizational needs.

Transcription

4098 Words, 22741 Characters

English
Hello, I'm Kelly Proctor, the President of D&D Healthcare USA Incorporated. Thank you for joining us for this episode of our podcast, Rx for Hospital Quality. It's my privilege to introduce podcast host, Simley Miller. Hello, healthcare world, and welcome to this edition of Rx for Hospital Quality. We're your host, Simley Miller, and Woody Conway. What are you doing today? Good, good, good. Hello, healthcare world. Let's talk about some risky business today. Yeah, we want to have a conversation with everyone regarding identifying risk in your organization. We do understand that we approach this very differently than maybe what you've been used to by your previous accrediting organization. We do not have, I guess you could say, what traditionally has been called required benchmarks, things that you have to meet. The reason we do not have those traditional required benchmarks is because healthcare is organic and it evolves and no hospital is the same. So what is relevant to you and the things you're trying to achieve may not be the same as what another hospital down the road or a state over is trying to achieve. So it doesn't make sense for us to have a cookie cutter approach to the benchmarks of what you need to try to accomplish. So the way that we approach risk is through ISO requiring you to be certified with ISO 9001. And I think it's important for us to start off right off the batwoody with the definition of what risk is from an ISO perspective. Well, we talk about risk, what is your risk in your organization, we are not talking about your high risk procedures, what we are talking about is what is your barriers to your processes, where are you struggling. So if your ultimate goal is to produce quality, safe patient care, what are the barriers to achieving that, that's typically the easiest way to explain what we're talking about when we say, are you identifying your risk, what would you add to that. So I think I would add that and if you have ever taken one of my classes, when we start off the review of the ISO standard in 4.1 it is always amazing to me that the ISO standard in that very first auditable sentence kind of defines its purpose and its purpose is to see you succeed. Well, what do you mean? What does that have to do with risk? Well, let me walk you through this. It starts off by saying, okay, what is your purpose and your strategic direction. And then if you back up to the beginning of the sentence, it says, okay, what are those internal and external issues that are going to help you or hinder you, opportunity or risk, you define what it is that you are struggling with. You define what's going to kill your strategic business plan, what is going to make people not believe your mission statement, what is going to keep you from achieving your organizational objectives, your departmental performance initiatives, your KPIs, whatever you call them, those are the risks and opportunities, what can help me, what can hinder me. Perfect, and a lot of hospitals struggle with, okay, great, so I understand what you're saying or I kind of understand what you're saying, but let me better understand or can you explain to me how we get there, how do we identify those and I want to start out with what NIO requires and it will get more into the ISO component of it. So NIO right now all most of you know that NIO requires under QM7, the quality management chapter under QM7, that you comply with measuring and monitoring and the list of areas that are under that section, I think, depending on if you're critical access or if you're acute care, there's basically between 18 to 20 things that you're required to measure monitor. The key here is for those requirements is that when you look at one of those processes, you're determining what is your struggle in that area, so if you're required to measure and monitor something and let's say anesthesia services, which is on that list. The expectation is you're looking at your anesthesia services and saying, okay, where is our barrier, what is our, what is preventing us to hit our quality for this process and the expectation is that is what you then become or that is what you begin to then measure monitor for performance improvement. Now we all know that the quality dashboard, God love it, the red, yellow, green dashboard, which is really common tends to measure sometimes hundreds of things, sometimes you guys go really crazy on that dashboard, if you are measuring everything under the sun, and I'm not saying that's wrong, what I'm saying is that is not the intention of ISO maturity. The intention is that you, the quality management oversight group, where all that gets reported up to is focusing on your biggest pain points, your biggest struggles, your biggest barriers. So what are the things that you are really struggling with and it's a cultural change, you have to get your departments to begin to report to you to report up, where are they struggling, not what they're doing well. I typically pick on the facilities management people because that's where I was born originally in healthcare. And that's because in facilities management, especially if you look at biomed, we tend to report that our PM completion rates are at 98% or 100%, and when you look, they've been at that rate for 10, 15, 20 years. And there's no value in continuing to report that. I mean, kudos, you're doing a fantastic job. Thank you for that. However, the intention here is to improve and to be able to identify where are struggles so that we can consistently work towards meeting our quality safe patient care. So we would expect them to be reporting up, what are they working on for improvement, where are they struggling in the physical environment, what is their focus. What do you what would you add to that when we start to ship that over into more of the ISO train of thought about regarding measuring and monitoring. So risk management in the ISO 9001 standard comes out of the ISO 31,000 standard and two of my favorite sections into 31,000 standard is the risk analysis and risk evaluation in risk analysis. If you look into that section of the 31,000 standard, it really asks you what is your appetite, what is your tolerance, what is your magnitude level for risk. And we'll go back to similes illustration here for a minute and we're talking about 98% on biomedical maintenance calibration, we're doing 98% or better. Okay, that has met my tolerance level. I do know I no longer need to look at that, but wait a minute. Now I have with my vendors, my nurses and my clinical staff continue to tell me that we have medical devices coming into the facility headed to the OR and we have no objective evidence that those devices have ever been calibrated. So we're spending all our time trying to get 98% up to 100 instead of looking at 100% failure on our vendors part. So that analysis saying wait a minute, what can I tolerate, what can I not tolerate, what is my appetite, what is my analysis tell me my analysis tells me biomed internal is doing great. However, my analysis is telling that I've got a weakness in the back door of my hotel where my vendors are bringing in product that I have no idea is adequate equipment to be used on my patients. Yep, very good, very good analogy there, Woody, I would like to say that every once in a while we get questions from hospitals regarding when we do measure and monitor something, if it's an area where we're trying to improve, we're not always sure what to compare it to. What is our comparison, you know, we're doing 70% how do we know if that's good, how do we know if that's bad and to be honest with you, there are two rules of thumb on this one is look at industry standards if there's not already a benchmark out there, a lot of times there is kind of an industry standard benchmark that everybody achieves a certain percentage whether it's 100% 90% and that you can tend to benchmark to that, but honestly when there is the absence of a true benchmark or industry standard, the intention is that you're benchmarking to yourself, what's your expectation, what are you trying to achieve, where are you trying to go. We're about continue improvement you may have a process it's very, very difficult and you're at 49% right now and you're all small at some point is 100% but maybe you know for this year you're trying to at least get to 55% or at least get to 60% now I want to clarify when there is a standard requirement that says you must do something 100% for compliance then of course your benchmark is 100%. We cannot go against CMS if they say that you have be 100% compliant with something that's not what I'm talking about here. I'm talking about measuring and monitoring how well we are doing our processes consistently and how we are overcoming our barriers. So it's important to note that you have some flexibility here but it's important to hold yourselves accountable to your own expectations as well. The other thing that we did mention which is really, really common for hospitals. Well, not just hospitals, all organizations regardless of what industry were in to miss is the risk regarding planning. When you are planning a change, which often is corrective action. You have determined there's an issue and you're implementing corrective action so you're going to change a process, maybe implement a new software, maybe create a brand new process. There are risks associated with that and if you look under clause six in the ISO standard, it says that you must identify those risks and opportunities and you need to acknowledge them. Now how you handle those risks will depend greatly on the type of risk. Is it a hello risk? Is it a high risk? But what you can't do is ignore it and just pray, all goes well. You may want to pray but you need to do something more than that. You need to acknowledge the risk and then that becomes also rolls into your focus risk areas. That's why we often say that with high risk change, when you're implementing a high risk corrective action or implementing a high high risk new process, we often roll that into our internal audit program to audit to make sure that we are maintaining the integrity of our system during that implementation. What do you what would you add regarding the change risk? So this one, I've given this illustration many, many times and I'm not even sure that I'm going to give it in. So we identify a big risk. Okay great and we put together a plan on how we're going to deal with it and we implement the plan and great everything is fantastic but it's very interesting and most people miss this in section six one two of the ISO standard. It says within that plan, we need to define the organization, shall plan, have a plan so we haven't implemented anything yet. When we develop that plan, how are we going to evaluate the effectiveness of what we're doing? How are we going to evaluate the effectiveness of our risk mitigation? How are we going to evaluate the achievement of our opportunity? And I'll give you a great example. This came up in one of our proactive risk management classes. The class, we were talking about what projects we wanted to work on for this class and they said, I said, well, you've identified staff burnout and I was like, okay, let's work on staff burnout. They go, oh, no, no, no, no, leadership took care of that. I go, oh, really? They go, yeah, they bought us, they have an online employee assistance program where anybody can jump online and get the support and the help and the counseling if need be anytime they want to. They just log on from home and they're good to go. I go, oh, really? They go, yeah, it's, yeah, I go, how long have we had this? And they go about six months. I go, how many people have logged into this? They go, I don't know. I go, how much are you paid for this? I don't know. I said, okay, by first thing tomorrow morning, I want those answers. Six months, $20,000 for people logged in. Oh, wow. Oh, yeah. Yes. All of a sudden, we, because in that original plan, we did say, what is our measure of success? What's going to be return on investment for these mitigation activities for all this work that we're going to do? And it even goes back to those scorecards. How many items on those scorecards and dashboards can we point to return on investment? We achieved return on investment five years ago. Now it's a controlled process. Maybe it's time to move on. Yes. Now, I'm glad you said that because I do think we do have a bad habit in health care of hanging on to things way too long. Once you've achieved your goal or you've achieved your, you know, your percentage, if you will, if you've had a hundred percent, for example, I understand the need to measure a monitor, but that could live, honestly, guys, at a department level. The intention is, okay, we've, quote unquote, fixed that or gotten a solid process in place with that, and we have measured a monitor to see if it was effective, and it is. So now let's move on to the next high risk thing. So note that it should be a continual evaluation. It's a living breathing system. Risk management is. It is a revolving of, okay, what are we focusing on? How are we measuring a monitoring it? What are we doing about it to improve it? Then how are we measuring a monitoring to see if that's effective? And then moving on to the next thing that's high risk. Once that's been accomplished. So that's important. Don't just hang on to it because, you know, that's what you've done the last couple of years working on that project. Move on, guys. Move on. Make your lives more simplistic. I think the other thing, we don't have a whole lot more time, but one of the things that I do want to talk about as well, and we have a podcast on this. So if you want more information on this one, there's actually an older podcast you can go back and listen to, but I want to talk about auditing your internal audit program. You know, I think the old school way when we first came on the scene was everybody just picked a process and then went out and did an internal audit on it with the intention of hitting all of their processes. And that's not really the maturity level of ISO 9001. Do you want to talk a little bit about the intention of ISO when it comes to focusing on risk for internal audits? So sure, I'm going to get myself in trouble. So similarly, similarly is responsible for pulling the reins and bringing me back into the crowd. I got the edit button ready. So it is my opinion, my opinion. Everybody heard that I'm going to say one more time. This is my opinion. What do you think? I believe, I believe that leadership from management review, from the quality management oversight committee or whatever you call it in your organization. From that entry point, all that data, all that information is going to tell leadership, where in my hospital am I struggling with the achievement of my goals and objectives? Where am I struggling with new risk? Where do I see new opportunities? Where is their identified weaknesses within my organization? As a leader, that is where I am going to send my audit team. Because I want them to go into those processes and help, they're not going into gig people, they're going into identify celebrations, a variation, nonconformances that are keeping the process from achieving its intended results. So I'm going to send those some of the best trained auditors into those departments to fair it out those failure modes and eliminate the risk in those departments. Yeah, I don't disagree with you, Woody. I've always said there are three primary areas. Not the only areas. Don't get us wrong. There's a lot of variation to this, depending on your organization, how your organization is set up. But I've always said there's three primary areas where internal audit scopes come from. One is, of course, that leadership team. If it's getting elevated up to that management review level, remember, that's the highest level of authority. That's the help me help me. And sometimes, management review needs an internal audit of our processes, that they're seeing the things that are getting reported up to them to get a better idea of what's going on. Because they can't always come up with decisions and actions as they're required to do. If an internal audit isn't done for them to have the full data, the full picture of the process and everything touching the process, because remember, internal audits is process auditing. You must look at the process and everything that touches the process within a defined scope. The other areas, I think, that would come up as well, Woody, is sometimes we have implemented a new high-risk process or a corrective action, a high-risk corrective action. And it's difficult to measure a monitor the effectiveness. So we may have to go do an internal audit to fully see if that corrective action or that new process is working well and maintaining the integrity. And I think the third one that comes up is sometimes you may get a high-risk situation, a complaint, or maybe the data is just really egregious. And we need to quickly get in there and do an internal audit to determine and need for an immediate corrective action depending on the situation. So I think we're on the same point, either based on data, some high-risk situations come up based on data, based on your leadership team, your Bayesian Review, leadership team identifying something that they need you to focus on or that implementation or change that planning of a new process or a change to an existing process. So we're on the same page there. If you want more information about internal audits, we have a whole podcast on it. So we also have a whole class for you guys who are not aware. you know, we have a plethora of classes. I think we're up to 16 or 17 classes that we teach in person. And then we have our on-demand library with topics as well. With our in-person classes, the internal audit classes, it's a three-day course and out of that, you walk away with train internal auditors. So if you want more information on that, we can provide it as well. Why don't we also, since we're talking about classes because we can't help it, we are the Ted Trading and Education Department, aka Ted, talk about the proactive risk course, which really helps align with this topic. Yeah, the risk management course has been one of my favorite courses to teach. It is probably one of the most complex courses. We try to limit that class in size. You cannot have 30 people in that class. It just is way too overwhelming. That class is designed to not only teach, but to give you return on investment. If I've got a class of 16 people, that means four teams of four and four projects, that's a grand total of 16 risk management projects started or completed by the time that class is over. So it's one of the ones that I'm very proud that we can say there's return on investment. And we walk through not only the ISO 9001 standard, but begin to develop your organization into the criteria, not requirements criteria, of the ISO 31,000, which just raises the bar to a new level. It actually will teach your people how to prove to readership what their anticipated return on investment is going to be for a risk management project. We spend a, it's a two and a half day class, and it's one of the ones that I hear we have definitely gotten our money's worth in this class. Yeah, a lot of people really, really love that class. I'm always impressed with the feedback that we get from it. Okay, so in summary guys, to kind of summarize the topic of this podcast, you know, we originally talked about how do you, you know, the topic is how do you identify risk in the absence of required benchmarks? And the truth is you still have required benchmarks, but you determine what those benchmarks are based on industry standards based on your expectations for your organization. It would be silly for us to say that you need a monitor and measure something in an area that is not affecting you. That's a waste of time. And remember, the DNV approach is to make things more simplistic, to get us back to a controlled environment so that you can focus on patient care and not doing things just for compliance. So we would invite you to consider looking at your culture, looking at your approach to ensure that you're shifting to a risk-based thinking. It doesn't mean you stop measuring and monitoring all the things. It just means that maybe those measuring and monitoring activities live at the department level, not necessarily at a quality management level or a leadership level. We need our quality team, and we need our leadership team to be focusing on the risk, our pain points. Where do we need to improve? And it doesn't mean that you don't still acknowledge people who are hitting the green, doing well in their areas, but that's not the intention when it comes to measuring and monitoring, and determining are we hitting our benchmarks that you've determined for your organization, which should be the areas where you're trying to improve. Any last thoughts, Woody? I guess, you know, with that last statement, I would be like, when it comes to everything we're doing in the organization, I always ask the question, what is my return on investment? Now, if it's a legal statutory regulatory requirement, it can't help you, but outside of that, all this effort, because your people are crazy busy. Health care people are crazy busy. They're better be return on investment for what I'm doing, and that's why DNV allows you to do just that. Pick those items that are going to be your return on investment to your patients, to your organization, to your finances, to your security, legally, and to your reputation. Return on investment. And you guys have heard me say, and I just say it a little different, you can tell Woody's more business focused on more health care focus or clinically focused. So I always say, do what brings your organization value? Where is the value? So they mean the same thing, and it's basically you get to decide what that is for your organization. We will never be prescriptive. Unless, of course, there's a regulatory requirement that we all have to comply with than our hands are tied. So that's kind of our risk, a risky business in a nutshell. So thank you for joining us, and as always, please be safe out there and take care of yourselves. Until next time. Thank you for listening. RX for Hospital Quality is a podcast produced by DNV Health Care USA Incorporated. To learn more about subjects covered here, or to download any of our standards or requirements, please visit our website at www.dnvhealthcare.com.

Podcast Summary

Key Points:

  1. Risk in healthcare is defined as barriers to achieving quality, safe patient care, not just high-risk procedures.
  2. ISO 9001 emphasizes identifying internal and external factors that hinder or support organizational goals, forming the basis for risk assessment.
  3. Instead of rigid benchmarks, organizations should benchmark against industry standards or their own strategic expectations for continuous improvement.
  4. Risk management includes proactive identification of risks during planning, especially in high-risk corrective actions or process changes.
  5. Internal audits should focus on high-risk areas, pain points, and failure modes, not on routine compliance, to drive meaningful improvement.
  6. Organizations must evaluate the effectiveness of risk mitigation plans, including measurable return on investment, to ensure sustainability.
  7. A culture of continuous risk review is essential—once a goal is met, focus should shift to the next high-risk area to avoid stagnation.
  8. Value-driven decisions should guide risk management, with emphasis on return on investment for patient safety, operational efficiency, and organizational reputation.

Summary:

This podcast discusses a shift from compliance-based to risk-based healthcare quality management, emphasizing that risk is not about meeting rigid benchmarks but identifying barriers to delivering safe, effective patient care. Unlike traditional accrediting bodies, DNV does not impose fixed requirements but instead guides hospitals to define their own benchmarks based on industry standards or internal strategic goals. The core of risk management lies in understanding internal and external factors that hinder or support organizational success.

Key emphasis is placed on focusing internal audits on high-risk areas, pain points, and process failures rather than broad compliance checks. Organizations are encouraged to evaluate the effectiveness of corrective actions and measure return on investment, ensuring that efforts are aligned with patient safety and organizational value. Risk planning must include a clear evaluation of how well mitigation strategies work, with ongoing review to prevent stagnation.

The approach promotes simplicity, accountability, and strategic focus—moving beyond compliance to sustainable improvement. Ultimately, healthcare leaders are urged to prioritize initiatives that deliver tangible value, asking not just if something is done, but whether it brings real return on investment for patients, finances, and reputation. This risk-based model supports a dynamic, evolving culture of quality that adapts to real organizational needs.

FAQs

Risk management in healthcare refers to identifying barriers and struggles in processes that hinder quality, safe patient care. It focuses on internal and external factors that either support or threaten organizational goals, rather than just measuring compliance with rigid benchmarks.

DNV avoids cookie-cutter benchmarks and instead focuses on an organization’s unique challenges and strategic goals. It emphasizes identifying real pain points and barriers to quality, aligning with the organic and evolving nature of healthcare.

ISO 9001 requires organizations to define their purpose, strategic direction, and internal/external issues that impact performance. This foundational step enables systematic identification of risks and opportunities that affect quality and safety.

When no industry benchmarks exist, hospitals should set benchmarks based on their own organizational goals and expectations. The focus is on continuous improvement, not just compliance, and on achieving specific, measurable targets over time.

Implementing new processes introduces risks such as failure to maintain process integrity, lack of monitoring effectiveness, or unintended negative outcomes. These risks must be identified, assessed, and managed through proactive planning and evaluation.

Organizations must define clear success metrics and return on investment (ROI) goals in their risk management plans. These metrics should be reviewed regularly to ensure the mitigation strategies are effective and aligned with organizational objectives.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.