← Back to portfolio

Hospital Readmission Risk & PHI Access-Audit Dashboard

A combined analytics + security view: where avoidable readmissions concentrate, and where patient-data access needs review.

25.2%
Heart Failure 30-day readmit
+2.0 pts
Above national benchmark (HF)
1,829
Discharges analyzed
6
PHI access events flagged

Panel 1 — Readmission Analytics DATA ANALYTICS

So what: Heart Failure readmissions run 2.0 points above the real CMS/AHRQ national benchmark (23.2%) and have trended upward over the last 6 months, peaking in January. HF is the single largest driver of excess readmissions in this dataset — targeting discharge follow-up and medication reconciliation here would yield the largest reduction in CMS penalty exposure.

Panel 2 — PHI Access Audit CYBERSECURITY / HIPAA

UserRoleRecord DeptTimeStatus
U204NurseMaternity06-15 14:22Review
U622IT SupportOncology06-16 23:51Review
U118PhysicianBehavioral Hlth06-17 16:44Review
U509NurseOncology06-18 03:47Review
U204NurseCardiology06-15 09:12Clear
U267Lab TechLaboratory06-16 08:30Clear
So what: 6 of 20 access events tripped a rule — the highest-risk being after-hours cross-department access (e.g., an Emergency nurse opening an Oncology record at 3:47 AM). These are exactly the patterns a HIPAA audit looks for: each flagged event is a potential improper-access incident that should be confirmed against a documented business reason before it becomes a reportable breach.

Why this matters

Hospital readmissions and improper PHI access are two of the most expensive risks a health system carries — and they are usually owned by different teams who rarely see the same dashboard. CMS penalizes excess 30-day readmissions under the Hospital Readmissions Reduction Program, so the 2.0-point Heart Failure gap above the national benchmark translates directly into withheld reimbursement and worse patient outcomes. Meanwhile, a single unjustified PHI access can trigger a HIPAA breach investigation, mandatory notification, and fines.

This project demonstrates the ability to (1) clean and analyze clinical operational data, benchmark it against real national rates, and surface the one insight a manager can act on, and (2) review access logs with a security lens to flag the patterns that matter. The combination — analytics judgment plus privacy instinct — is what reduces both financial and compliance risk for a healthcare employer.