Issue:
How to set up security in OrthoTrac.
Solution:
From the main menu of OrthoTrac select Functions, Maintenance/Setup, Security.
By Staff Type - This option allows the configuration of security for each staff type. By configuring a security profile for each staff type, new staff members added to OrthoTrac will automatically receive the pre-defined security profile.
By Staff - This option allows the configuration of security for individual staff members. Once security has been changed for an individual staff member, the security profile for their staff type will no longer apply to them.
If security has never been configured in OrthoTrac it is necessary to define a security administrator.
How to define a security administrator
There can be more than one security administrator but be careful in setting up a security administrator. Normally the doctor (and possibly the office manager) are set up as security administrators.
1. Select Functions, Maintenance/Setup, Security from the main menu of OrthoTrac. (If prompted for a password use jfer.)
2. Select By Staff.
3. Select the security administrator from the By Staff pull-down list.
4. Select Maintenance from the Category list.
5. Use the Security Maintenance pull-down list to select Yes.
6. Click OK.
7. Restart OrthoTrac.
How to set up security profiles By Staff Type
NOTE: Staff Types are defined in System Maintenance. From the main menu of OrthoTrac select Functions, Maintenance/Setup, System Maintenance. Select Staff Titles. Staff types can be added, modified, or removed from this window.
How to set up security profiles By Staff
Prior to setting up individual staff security profiles define the By Staff Type profiles. This will save time in changing the individual profiles.
NOTE: Individual staff security profiles in By Staff will override whatever settings are used in By Staff Type, regardless of what staff type that staff member belongs to.
How to Configure Overrides
Overrides allows OrthoTrac to be configured so that a user who encounters a message about not being able to access a part of the software can (with assistance) temporarily access that area.
1. Select Functions, Maintenance/Setup, Security from the main menu of OrthoTrac.
2. Select Overrides.
3. Select a category.
4. Select the item for the override.
5. Select either Password or Login.
If Password is selected the user who is not allowed access to an area of the software must enter a password to get in. If this option is used then when someone is prompted for the password the person who has the password should enter it themselves rather than telling the user what it is.
If Login is selected then when someone is unable to access a part of the software a login screen will be presented. A user that DOES have security permissions to enter that area of the software must log in. Transactions logged in the secured area will be logged under the name of the person who logged into it.
Security Recommendations
Please note that these are only that -- recommendations. Individual decisions as to what options are and are not available to individual staff must be decided by doctors and office managers.
Security - (In the Maintenance Category) Most staff should NOT have access to security. It is recommended that ALL Staff Types have no access to Security. Instead, set up access to security under individual security profiles.
Staff Maintenance - (In the Maintenance Category) Most staff should NOT have access to Staff Maintenance. It is recommended that ALL Staff Types have no access to Staff Maintenance. Instead, set up access to security under individual security profiles.
Mail VS Clerk Login - From the main menu of OrthoTrac select Options, Environment. From this window select the Miscellaneous tab. In the Staff Login Settings select Clerk. In order to set this to Clerk on ALL systems turn on HIPAA Security Audit Logging.
Environment Options - (In the Main Menu Category) Access to to this window can enable a user to set the Staff Login Settings to Mail.
Turn on HIPAA Security Audit Logging - In addition to the issue already mentioned (Mail VS Clerk Login) enabling HIPAA Security Audit Logging allows tracking of what each user does in OrthoTrac.
System Configuration - (In the Maintenance Category) Turning off this item blocks users from accessing System Maintenance and more importantly it blocks them from accessing the System Options window where HIPAA Security Audit Logging can be turned off. This change must be applied carefully since it also blocks access to the entire System Maintenance menu. Consider using an override for this item.
Restrict Access to Adjust Time Cards - To restrict access to adjust Time Cards set Time Clock Maintenance (in the Maintenance category) to NO and set Adjust Time Cards (in the Other Category) to NO.
Restrict Access to Purge HIPAA Security Audit Log - In the Reports Category set Purge HIPAA Security Audit Log to NO.
Web Updates - Access to this feature should be restricted to one person. When web updates are available, accessing this feature will stop OrthoTrac on all systems until the update is complete. To restrict access set Check for Updates (in the Main Menu Category) to NO.
Individual categories and some additional notes are listed below.
Category | Function | Notes |
Financials |
| |
Financials | Financial Functions |
|
Financials | Charges and Payments | ** Pass Through Access is allowed to this function if Patient Check Out is set to Yes |
Financials | Adjustments |
|
Financials | Charge Adjustment | Must have access to Financials and Adjustments |
Financials | Payment Adjustment | |
Financials | Contract/Plan Adjustment | |
Financials | Refund/Over-payment | |
Financials | Late Charge Adjustments | |
Financials | Adjust Aging | |
Financials | Transfers | |
Financials | Discounts | |
Financials | Write-Offs | |
Financials | Location Change | |
Financials | Balance Adjustment | |
Financials | View Totals | Must have access to Financials |
Financials | View Ledger | |
Financials | Contracts | |
Financials | Promises | |
Financials | Auto Payments | Must have access to Financials. May be needed for Office Expert |
Financials | QuickBooks Export |
|
Financials | Zuelke Automated Credit Coach |
|
Category | Function | Notes |
Maintenance |
| |
Maintenance | Unlock Financial Roll |
|
Maintenance | Carrier Maintenance | **Allows Pass Through access to Employer Maintenance |
Maintenance | Database Field Maintenance |
|
Maintenance | Daysheet Setup |
|
Maintenance | Employer Maintenance | ** Pass Through access allowed to this function if Carrier Maintenance is set to Yes |
Maintenance | Form Editor |
|
Maintenance | Insurance Claim Options |
|
Maintenance | Office Expert Maintenance |
|
Maintenance | Other Referral Source Maintenance |
|
Maintenance | Outside Doctor Maintenance |
|
Maintenance | Patient Flow Options |
|
Maintenance | Procedure Maintenance |
|
Maintenance | Schedule Maintenance |
|
Maintenance | Security Maintenance | ***Security critical - If a staff member can get to this feature they can change their own security profile enabling them to get to any features of the software. |
Maintenance | Staff Maintenance | *** Security critical - If a staff member can get to this feature they can change their Staff Type and therefore their security profile. |
Maintenance | Statement Options |
|
Maintenance | System Configuration |
|
Maintenance | Ticket Message Maintenance |
|
Maintenance | Time clock Maintenance | Also allows access to Edit Time Cards |
Maintenance | Charting Options |
|
Maintenance | Treatment Plan Maintenance |
|
Maintenance | Unlock Locked Out User |
|
Maintenance | eService Setup |
|
Maintenance | Patient Ed Integration Setup |
|
Maintenance | QuickBooks Export Maintenance |
|
Maintenance | Pearl Call List Options |
|
Category | Function | Notes |
Main Menu | Quick Add | ** Allows Pass Through Access to Schedule Appointments |
Main Menu | Patient Check Out | * Needed to check patients out ** Allows Pass Through Access to Post Charges & Payments and Schedule Appointments |
Main Menu | Collections | May be needed for Office Expert |
Main Menu | Contact Experts | ** Allows Pass Through Access to Post Letters and Post Cards |
Main Menu | Referrals | |
Main Menu | Patient Flow | |
Main Menu | Roladdress | |
Main Menu | Checklist | |
Main Menu | Environment Options (From Main Menu select Options > Environment ) | ***Security critical – If a user can access the environment the Staff Login Settings can be changed to Mail, disabling security |
Main Menu | TeleVox T.Link |
|
Main Menu | Office Expert | ** Allows Pass Through Access to all functions in Office Expert (Does NOT allow access to Office Expert setup) |
Main Menu | Check for Updates |
|
Category | Function | Notes |
Insurance |
| |
Insurance | Claim Processing | May be needed for Office Expert |
Insurance | Claim Reports | |
Insurance | Continuation of Treatment | |
Insurance | eClaims | |
Insurance | Post Bulk Payment | |
Insurance | Individual Claims | |
Insurance | Add Claims | |
Insurance | Change Claims | |
Insurance | Delete Claims | |
Insurance | Print Claims |
Category | Function | Notes |
AWPS |
| |
Word Processing | Letter Setup | |
Word Processing | Post and Print Letters | |
Word Processing | Post Letters | |
Word Processing | Print Letters | |
Word Processing | Remove Letters | |
Word Processing | Confirm Letters | |
Word Processing | Communications Setup | |
Word Processing | Display Questionnaires | |
Word Processing | Execute Questionnaires |
Category | Function | Notes |
Scheduling |
| |
Scheduling | Schedule Appointments or Recalls | ** Pass Through access is allowed if Quick Add or Patient Check Out is set to Yes |
Scheduling | Change/Cancel Appointments or Recalls |
|
Scheduling | Change Existing Schedule Days |
|
Scheduling | Confirm Appointments |
|
Scheduling | Add/Change Schedule Messages |
|
Scheduling | Override Block Outs |
|
Scheduling | Override Dr. Time |
|
Scheduling | Override Dr. Cross Reference |
|
Scheduling | Override Pre-Block |
|
Scheduling | Change Existing Schedule Doctor |
|
Scheduling | Change Existing Schedule Defaults |
|
Category | Function | Notes |
Patient Chart |
| * Needed to check patients out |
Patient Chart | Edit Patient Information | Must have access to Patient Chart |
Patient Chart | Comment Only Charting | |
Patient Chart | Edit Charting | |
Patient Chart | Patient Tracking | |
Patient Chart | Add Tracking/HIPAA Comments | |
Patient Chart | Remove Tracking Items | |
Patient Chart | Print Tracking History | |
Patient Chart | Add Database Fields | |
Patient Chart | Add Database Field Answers | |
Patient Chart | Remove Database Fields | |
Patient Chart | Access Ortho Imaging | |
Patient Chart | Move Scanned Documents |
Category | Function | Notes |
Other | Adjust Timecards | |
Other | Remove Patients | |
Other | Remove Carriers | |
Other | Remove Employers | |
Other | Remove Other Referral Sources | |
Other | Remove Outside Doctors | |
Other | Point of Care |
|
Other | Prepare Backup Files |
|
Other | Satellite Extraction |
|
Other | eForms |
|
Category | Function | Notes |
Reports | Patient Information Form |
|
Reports | Patients Added In a Specific Month |
|
Reports | Patients Added Since Specific Date |
|
Reports | Patient Listing |
|
Reports | Patients by.. | May also be needed for Office Expert |
Reports | Patients with.. |
|
Reports | Patients without.. |
|
Reports | Patient Procedure History |
|
Reports | Patient Birthdays |
|
Reports | Chart Labels |
|
Reports | Patient Statistical Profile |
|
Reports | Patient Completion Report |
|
Reports | Patient Progress Review |
|
Reports | Missing Patient Data |
|
Reports | Removed Patients |
|
Reports | Missing Responsible Party Data |
|
Reports | Responsible Parties Without.. |
|
Reports | Unlinked Siblings Report |
|
Reports | Available Appointments |
|
Reports | Scheduled Appointments |
|
Reports | Daily Schedule |
|
Reports | Daily Collections |
|
Reports | No Show Report |
|
Reports | Future Procedures |
|
Reports | Recall Labels |
|
Reports | Recall Cards |
|
Reports | Balancing Worksheet |
|
Reports | Selected Billing Types |
|
Reports | Statement Code/Late Charge |
|
Reports | Ledger Scan |
|
Reports | Coupon Books |
|
Reports | Contract Summary |
|
Reports | Revenue Projection |
|
Reports | Aged Receivables by.. |
|
Reports | Auto-Payment Reports |
|
Reports | Post Auto-Payments | ** Pass Through Access is allowed to this function if Roll Accounts or Daysheeet (Daily) is set to Yes |
Reports | Auto-Payments Receipts |
|
Reports | Statement Exception Report |
|
Reports | Generate Statements | May also be needed for Office Expert |
Reports | Print/View Statements |
|
Reports | Individual Statement |
|
Reports | Integrity Check |
|
Reports | Process Daysheet (Daily) | ** Allows Pass Through access to Post Auto Payments and Roll Accounts |
Reports | Quick View Daysheet |
|
Reports | MTD Daysheet Reports |
|
Reports | Roll Accounts | ** Allows Pass Through access to Post Auto Payments** Pass through access allowed to this function if Daysheet (Daily) is set to Yes May be needed for Office Expert |
Reports | Print Roll Report |
|
Reports | All Questions for a Questionnaire |
|
Reports | Bucksheet |
|
Reports | Carriers and Associated Patients |
|
Reports | Carrier/Employer Listing |
|
Reports | Doctor Listing |
|
Reports | Mailing Labels |
|
Reports | Patient/Responsible Part Xref |
|
Reports | Procedures |
|
Reports | Status Code Listing |
|
Reports | Staff Listing |
|
Reports | Type Code Listing |
|
Reports | Bracket Tray Covers |
|
Reports | Patients with Appt on Specific Date |
|
Reports | Patients Scheduled with No History |
|
Reports | History for Range of Dates |
|
Reports | History for Rage of Patients |
|
Reports | Patient Tracking | May also be needed for Office Expert |
Reports | Patient Flow |
|
Reports | Time Clock Reports |
|
Reports | Time Clock View Errors |
|
Reports | View HIPAA Security Audit Log |
|
Reports | Purge HIPAA Security Audit Log |
|
Reports | Settle Credit Card Authorizations |
|
Reports | Treatment Plan Reports |
|
Reports | Future Patients Report |
|
Reports | Suspicious Balances |
|
Reports | Financial Analysis |
|
Reports | Online Payments |
|
Reports | OrthoMetrics |
|
Reports | ACH Return Report |
|
Reports | Print Prior settlement |
|
Reports | Smart Call Summary |
|
Category | Function | Notes |
Office Expert |
| |
Office Expert | Past Due Patient Accounts | Must also set Aged Receivables by.. To Yes |
Office Expert | Past Due Insurance Accounts | |
Office Expert | Patient Credit Balance Accounts | |
Office Expert | Insurance Credit Balance Accounts | |
Office Expert | Statements Generated | Must also set Generate Statements to Yes |
Office Expert | Apply Contract Charges | Must also set Roll Accounts to Yes |
Office Expert | Apply Late Charges | |
Office Expert | Daysheet Closed |
|
Office Expert | Unposted Auto Payments | Must also set Auto Payments to Yes |
Office Expert | Payment Promises Due | Must also set Collections to Yes |
Office Expert | Continuation of TX Generated | Must also set Continuation of Treatment to Yes |
Office Expert | Unprinted Paper Claims | Must also set Claim Processing to Yes |
Office Expert | Unprocessed eClaims | Must also set Claim Reports to Yes |
Office Expert | eClaims Transmitted |
|
Office Expert | Patients Due for Progress Review | Must also set Patient Progress Review to Yes |
Office Expert | Patients Past Est. Completion Date |
|
Office Expert | Patients Near Completion w/Balance | Must also set Contact Expert to Yes |
Office Expert | Active Patients w/o Contract |
|
Office Expert | Treatment Futures Due |
|
Office Expert | Patients w/o Appt or Recall | Must also set Patient Tracking Reports to Yes |
Office Expert | Patients with Alpha Recall | Must also set Contact Expert to Yes |
Office Expert | Patients with Open Recall | Must also set Recall List to Yes |
Office Expert | No Show Report | Must also set No Show Report to Yes |
Office Expert | Scheduled Patients with Balance | Must also set Daily Collections to Yes |
Office Expert | Unscheduled Appointments |
|
Office Expert | Unprinted Letters | Must also set AWPS Print Letters to Yes |
Office Expert | Unconfirmed Letters | Must also set AWPS Confirm Letters to Yes |
[[Article ID: 10326CTL85]]
There should be an option to reset all user's rights to their assigned Staff Type. We have 600 users and no way to identify users whose rights were modified By Staff instead of By Staff Type. It is ridiculous that we would have to audit and update every single user anytime there is a security change to ensure it's applied. At minimum, it should reset if the user's Staff Type is changed. Then we could do one clean-up.
Carestream Dental LLC
3625 Cumberland Blvd. Ste. 700
Atlanta, GA 30339
© 2019 Carestream Dental, LLC. All Rights Reserved