A combined analytics + security view: where avoidable readmissions concentrate, and where patient-data access needs review.
Built by El’Azar Ferrer · Google Data Analytics & Google Cybersecurity Certified · Sample hospital vs. real CMS / AHRQ national benchmarks
25.2%
Heart Failure 30-day readmit
+2.0 pts
Above national benchmark (HF)
1,829
Discharges analyzed
6
PHI access events flagged
Panel 1 — Readmission Analytics DATA ANALYTICS
So what: Heart Failure readmissions run 2.0 points above the real CMS/AHRQ national benchmark (23.2%) and have trended upward over the last 6 months, peaking in January. HF is the single largest driver of excess readmissions in this dataset — targeting discharge follow-up and medication reconciliation here would yield the largest reduction in CMS penalty exposure.
Panel 2 — PHI Access Audit CYBERSECURITY / HIPAA
User
Role
Record Dept
Time
Status
U204
Nurse
Maternity
06-15 14:22
Review
U622
IT Support
Oncology
06-16 23:51
Review
U118
Physician
Behavioral Hlth
06-17 16:44
Review
U509
Nurse
Oncology
06-18 03:47
Review
U204
Nurse
Cardiology
06-15 09:12
Clear
U267
Lab Tech
Laboratory
06-16 08:30
Clear
So what: 6 of 20 access events tripped a rule — the highest-risk being after-hours cross-department access (e.g., an Emergency nurse opening an Oncology record at 3:47 AM). These are exactly the patterns a HIPAA audit looks for: each flagged event is a potential improper-access incident that should be confirmed against a documented business reason before it becomes a reportable breach.
Why this matters
Hospital readmissions and improper PHI access are two of the most expensive risks a health system carries — and they are usually owned by different teams who rarely see the same dashboard. CMS penalizes excess 30-day readmissions under the Hospital Readmissions Reduction Program, so the 2.0-point Heart Failure gap above the national benchmark translates directly into withheld reimbursement and worse patient outcomes. Meanwhile, a single unjustified PHI access can trigger a HIPAA breach investigation, mandatory notification, and fines.
This project demonstrates the ability to (1) clean and analyze clinical operational data, benchmark it against real national rates, and surface the one insight a manager can act on, and (2) review access logs with a security lens to flag the patterns that matter. The combination — analytics judgment plus privacy instinct — is what reduces both financial and compliance risk for a healthcare employer.