Showing posts with label Compliance. Show all posts
Showing posts with label Compliance. Show all posts
Thursday, July 10, 2014
Friday, April 4, 2014
HHS Releases HIPAA Compliance Assessment Tool
By Katie Wike, contributing writer
New HHS tool helps providers assess security risks to HIPAA compliance
According to HealthIT.gov, “ONC, in collaboration with the HHS Office for Civil Rights (OCR) and the HHS Office of the General Counsel (OGC), developed a downloadable Security Risk Assessment Tool (SRA Tool) to help guide” providers through the HIPAA-required assessment.
The Security Risk Assessment (SRA) Tool is meant to help providers in small to medium offices conduct risk assessments and, a HIPAA regulations require providers to regularly examine the way protected health information is handled, this new tool is a valuable asset to those looking for a way to meet the requirement.
“By conducting these risk assessments, healthcare providers can uncover potential weaknesses in their security policies, processes and systems. Risk assessments also help providers address vulnerabilities, potentially preventing health data breaches or other adverse security events. A vigorous risk assessment process supports improved security of patient health data,” wrote HHS in a press release.
"Protecting patients' protected health information is important to all healthcare providers and the new tool we are releasing today will help them assess the security of their organizations," said Karen DeSalvo, M.D., national coordinator for health information technology. "The SRA tool and its additional resources have been designed to help healthcare providers conduct a risk assessment to support better security for patient health data."
"We are pleased to have collaborated with the ONC on this project," said Susan McAndrew, deputy director of OCR's Division of Health Information Privacy. "We believe this tool will greatly assist providers in performing a risk assessment to meet their obligations under the HIPAA Security Rule."
Monday, February 3, 2014
A Sustainable Healthcare System Depends on Equal Access to Quality Education
“Without continual growth and progress, such words as improvement, achievement, and success have no meaning.” – Benjamin Franklin
Health Care Management Systems was created to provide free, high quality, on-demand learning to all of those involved in the frontlines of healthcare!
Why?
Because we have proven that “equal access to high quality education” is the missing link in the healthcare equation. Yes, proven through a unique double blind study that you have probably never heard of…
You see, this story begins about 3 years ago on the Texas gulf coast when two unlikely partners teamed up to change the way managed care was delivered to a certain Medicare population.
The strategy was devised from a simple physics theory – to influence the greatest amount of change in the shortest amount of time possible – equal pressure must be applied in all directions.
Education was the single greatest variable that was common to all groups – so our hypothesis was built on the assumption that through simultaneous and continuous education at the point of care, we could make a measurable impact on both the cost and the experience of care!
The project was a huge success from both a financial and cultural perspective. Two years later that “little experiment” is now out funding larger markers – all without ever auditing a chart!
Lighting in a Bottle –
Okay, so our hypothesis was a success, but where do go from here? We were so amazed and excited about the outcome that we wanted to find a way to offer it to everyone – anywhere, anytime, anyplace and on any device!
So, we developed a vehicle: Global Health Care Management Systems (globalhcms.org) – an innovative learning platform that can deliver our proven education to everyone on the frontlines!
Anyone involved who wants to learn is invited to join the HCMS Academy!
To ensure that this tool will continue to be available to all of those we serve, we have teamed up with other healthcare leaders to provide employer sponsored learning as well.
A big THANK YOU to all of our partners and sponsors – without them none of this would be possible….
To learn more about our pilot program please visit: www.ermconsultinginc.com.
To find out how you can partner with us to ensure equal access to quality education email: kgifford@ermconsultinginc.com.
How Do I Sign Up?
HCMS ACADEMY-
We invite everyone currently working on the frontlines or those contemplating a new career in healthcare to register for the HCMS Academy. Register for free courses and receive certifications in Medicare Risk Adjustment, ICD-10 Coding and Rapid Practice Innovation. As a member of the Academy you are invited to join our conversation on the “Innovation X-Change.” The X-Change provides a secure, HIPPA compliant meeting space for visionaries to share ideas and collaborate on future projects. Join a group or start your own. Register today at www.globalhcms.org – What are you waiting on – it’s totally FREE!
SPONSOR E-LEARNING-
Are you involved in health care? If so, we invite you to join us in our mission! By sponsoring e-learning for your employees or industry partners you can help ensure that everyone has equal access to high quality education.
By partnering with HCMS, you extend our proven education to your organization at no cost and we are able to provide you with state of the art analytics including dashboards to track implementation and progress across large organizations in real time. This system was built on an API that accepts up to 5 data sources which potentially allows us to measure and analyze financial, educational and utilization data together for the first time. All of this at a fraction of the cost of traditional analytics.
To learn more about how we can partner for a better tomorrow, please contact: kgifford@ermconsultinginc.com
Labels:
ACO,
Compliance,
Education,
elearning,
frontlines,
Healthcare,
ICD-10,
innovation,
IPA,
lean,
medical record certification,
MRA,
patient experience,
process improvement,
Risk adjustment,
Training
Tuesday, January 28, 2014
Can you GAME your way to 5 STARS?
On-Demand E-Learning for Your Entire Office
Medicare plans and providers face a crucial task each year: achieve the highest Medicare star ratings possible or face the consequences. With major revenue and competitive positioning at stake — including the possibility of losing Medicare contracts if certain measures earn fewer than three stars for three consecutive years — Medicare Advantage and Medicare Part D prescription drug plans must take every step possible to maximize performance on all of the star rating quality measures.
But what if we could game our way to a 5 STAR Rating?
What if we could make all of these initiatives in healthcare fun?
How could we influence both the experience and the outcome of healthcare through innovative learning?
Log on today, for FREE...
Click the logo below to launch the game....
Sunday, December 29, 2013
Wednesday, December 18, 2013
10 Compliance Issues for Physicians, Health Systems and Providers in 2014
Meaningful Use Audits: Physicians, hospitals, and others that have received incentive payments to integrate electronic medical records into their practices will likely be subject to an audit from either Medicare or Medicaid to assess whether the providers have actually made meaningful use of these funds and systems. Auditors are likely to demand evidence of meaningful use of incentive monies and repayment when providers cannot back up the attestations made for Stage 1 compliance. Providers should be on the lookout for audit request letters sent via email by the contracted auditor. Make sure that whoever has the email address registered with CMS checks for an audit letter. In addition, providers should make sure that all meaningful use attestations are backed up and documentation is maintained for the six years that CMS requires. Some of the required evidence includes EHR vendor agreements, attestation reports on clinical quality measures, statements from EHR vendors, information used to generate numerator and denominator values for reporting, et cetera. If an audit letter is received, contact should be made immediately. Providers need to pay attention to these responses; a failure to respond adequately could result in more than just a request for repayment.
Assuring and Measuring Compliance with HIPAA and HITECH: Increased audit and enforcement activities related to HIPAA and HITECH are coming and providers should ensure that they have implemented required changes such as identifying business associates and executing compliant business associate agreements as well as implementing security standards and testing for patient information and reporting breaches. Also, expect increased enforcement activities from Kentucky’s Attorney General as HITECH granted enforcement authority to the Attorney General along with the opportunity to seek damages.
Stark Law Application to Medicaid Claims: While the Stark Law on its face applies only to Medicare, recent court decisions have found that a Medicaid claim filed in violation of the Stark Law also constituted a false claim. Courts have now found False Claims Act liability for Medicaid claims filed in violation of the Stark Law. Historically, the federal government had focused enforcement efforts on Medicare claims. Carving out Medicaid referrals and claims in health care transactions is no longer prudent. All contracts and transactions should be reviewed for compliance with the Stark Law even if the contract only applies to services for private pay or Medicaid patients.
Medicaid Integrity Contractor Audits: As the Medicaid review auditors are finalizing their review of the big data to identify providers who fall outside billing standards, these reports are being released to Medicaid for provider audits and collection of overpayments. Challenging overpayments must be made through Kentucky’s Medicaid appeal process, which establishes important deadlines for requesting a dispute resolution meeting when an overpayment is identified. If a DRM is not requested, then repayment is due in 30 days. Providers should pay close attention to these deadlines and exercise their ability to challenge overpayments.
Measuring Quality: As CMS’ Physician Compare website joins the nursing facility and hospital compare websites, physicians must be ever mindful that quality scores will ultimately impact reimbursement for all payors, not just Medicare and its incentive payments. Physician groups as well as all providers should carefully develop their quality measures. As ACOs, hospital systems and payors develop their own quality measures, individual physicians must be aware of those measures and how they affect them. Participation in networks, ACOs, and even Medicaid may become tied to performance. All physicians, even those who are employed by health systems, should be careful in their contracting and knowledgeable about their individual quality and performance.
Medical Staff Membership and Credentialing: Changes in Joint Commission for Accreditation of Health Care Organization’s requirements for medical staff credentialing have made evaluation of a physician’s quality of care an element of the credentialing and recredentialing process. How this evaluation takes place and the factors that are considered are left to the medical staff, which, in reality, usually means administration. The information about this evaluation becomes a permanent part of a physician’s records. Every physician should be aware of this, find out about evaluation results, and challenge them if necessary. A challenge does not mean that a physician impairs his/her privileges, but rather seeks to maintain an accurate credentialing file.
Retention of Overpayments: Retention of a Medicare or Medicaid overpayment can create false claims liability and treble damages recovery when the overpayment is not returned within 60 days. The ACA created the duty to report and return known overpayments. While the law sounds simple, its application is anything but simple and creates a host of issues for providers including determining when an overpayment is known to the provider. For example, is the billing clerk’s knowledge imputed to the physician owner of the practice? Also, when reporting an overpayment, does a provider have a duty to look back to see if there are other overpayments?
Expansion of Medicaid Beneficiaries: With Kentucky’s successful rollout of its Health Insurance Exchange and the possibility of 308,389[i] new Medicaid beneficiaries, what is the health care provider’s duty to take on more Medicaid patients? Should a provider establish express limits on the number of Medicaid patients that a practice will accept as patients? Does this create liability under provider agreements with Medicaid Managed Care payors? These issues will become even more important as the number of beneficiaries increases.
Prescribing Controlled Substances in Kentucky: The war on prescription drug abuse has taken a terrible toll on physicians as House Bill 1 and the implementing regulations issued by the Kentucky Board of Medical Licensure have forever changed how and when a physician may prescribe controlled substances. While the regulations have been slightly tweaked, physicians must take extraordinary efforts to build the procedures and processes required for prescribing into their day- to- day practice. Physicians should be aware that the Drug Control Branch of Kentucky’s OIG routinely reviews KASPER data and reports the highest prescribers of controlled substances to the KBML for investigation. Physician responses to these investigations must be careful and complete with the understanding that there is little recourse if a violation is found.
Getting Paid: All providers must take active steps to assure that they are paid, which includes keeping abreast of a myriad of payment issues and policies. A provider’s staff must be diligent in following up with insurance companies, Medicaid, and Medicare to seek payment. The squeaky wheel gets oiled first. Providers also need to be aware that preventive benefits such as cholesterol screenings and vaccinations are now free of charge through all Marketplace plans and many other insurance plans, including Medicare, Medicaid, and private insurance plans. Providers should be prepared that they will no longer be able to collect a copay from any member of these plans, regardless of whether that member has met his or her deductible. A list of preventive benefits covered by most plans under the ACA can be found at https://www.healthcare.gov/what-are-my-preventive-care-benefits/. Providers, particularly physicians, should pay attention to proposed federal legislation that will finally repeal the sustainable growth rate and replace it with a methodology that ties payments to quality and efficiency, incorporates alternative payment models and improves the fee for service system by including value-based performance measures. This bill has the support of both Senate and House committees. We will see…….
Friday, August 2, 2013
Compliance-watchword of healthcare companies and possible other companies in China
- King & Wood Mallesons
- China
- July 31 2013
Recently, allegations of a massive bribery scheme on the part of the Chinese unit of a famous British multinational pharmaceutical company have grabbed headlines in China and abroad. China’s Ministry of Public Security officially announced on July 11 that senior executives of this company are under criminal investigation on suspicion of using travel agencies to bribe government officials, hospitals, doctors, and medical industry associations in a scheme to increase sales. Some of the company’s senior executives and employees are also suspected of taking bribes from third party vendors.
According to the news reports, the national Ministry of Public Security began the investigation in late June, when local public security bureaus visited the company’s Shanghai, Changsha and Zhengzhou offices. Reportedly, company documents have been seized and some employees detained.
While this investigation is high-profile, it is by no means alone. In early July, the National Development and Reform Commission announced an investigation into the costs and prices charged by 60 domestic and international pharmaceutical companies operating in China.
These investigations of drug makers signal China’s intention to push forward with reforms in the healthcare sector, which will impact all companies operating in that space.
It is not just healthcare companies that need to take note of these investigations. Companies in other sectors can have high compliance risks if they, for example, frequently use third party intermediaries or have a high degree of interaction with government officials or State-owned enterprises. Companies that fit this profile are advised to pay attention to enforcement trends and take proper responsive measures.
In the current regulatory climate, companies are advised to stay focused on their compliance programs to ensure that they are robust and fully implemented. Recommended steps include the following:
Review and revise internal policies and procedures on, among other things, hospitalities, “dawn raid” guidelines in the event of government inspections, employee handbooks and manuals; and the process for handling “whistleblowers;”
- Prepare a training course for employees on how to handle investigations;
- Conduct compliance and legal risk assessment;
- Review and “stress-test” internal control procedures on, among other things, financial and accounting practices;
- Conduct proactive internal audits and investigations of suspected violations;
- Conduct detailed due diligence on third party intermediaries such as agents and sales representatives;
- Take prompt action if faced with evidence or allegations of wrongdoing.
Companies should exercise caution when an investigation has been initiated before embarking on any internal assessment and audit process.
Friday, July 26, 2013
Medicare and Medicaid Programs; Quarterly Listing of Program Issuances—April Through June 2013
DEPARTMENT OF HEALTH AND HUMAN SERVICES
Centers for Medicare & Medicaid Services [CMS–9080–N]
Medicare and Medicaid Programs; Quarterly Listing of Program Issuances—April Through June 2013
AGENCY: Centers for Medicare & Medicaid Services (CMS), HHS.
ACTION: Notice.
SUMMARY: This quarterly notice lists CMS manual instructions, substantive and interpretive regulations, and other Federal Register notices that were published from April through June 2013, relating to the Medicare and Medicaid programs and other programs administered by CMS.
Read more: http://www.gpo.gov/fdsys/pkg/FR-2013-07-26/pdf/2013-17967.pdf
Centers for Medicare & Medicaid Services [CMS–9080–N]
Medicare and Medicaid Programs; Quarterly Listing of Program Issuances—April Through June 2013
AGENCY: Centers for Medicare & Medicaid Services (CMS), HHS.
ACTION: Notice.
SUMMARY: This quarterly notice lists CMS manual instructions, substantive and interpretive regulations, and other Federal Register notices that were published from April through June 2013, relating to the Medicare and Medicaid programs and other programs administered by CMS.
Read more: http://www.gpo.gov/fdsys/pkg/FR-2013-07-26/pdf/2013-17967.pdf
Wednesday, July 17, 2013
Innovate your Medicare Risk Adjustment Program
In an era of accelerating medical costs and flat payments
from CMS, accurately reflecting the health status of your members through
proper HCC (Hierarchical Condition Category) management is the only way for
your Medicare Advantage plan to remain financially viable. The secret to successful long-term risk
adjustment for your Medicare Advantage plan is to properly educate your
providers as to the value of complete and accurate coding of every member,
every year. Historically, providers have coded for payment, which simply
doesn't work well in the new world of 100 percent risk-based plan compensation,
where complete and accurate coding of every patient on an annual basis is
imperative.
Compliant Coding = Compliant Documentation
The quality
of the documentation is vital to nearly every aspect of health care, and
accurate chart documentation and diagnosis reporting determines reimbursement
for the CMS Medicare Advantage Plans under the Risk Adjustment Program. However, CMS validation findings indicate
that coded conditions are not supported in approximately 30 percent of the
records reviewed.
Risk adjustment data validation is the process of verifying
that diagnosis codes submitted for payment by the MA organization are supported
by medical record documentation for an enrollee. You should assume that—sooner
or later—CMS will audit your medical records, and potentially your program.
Explaining the role of clinical documentation and its impact
on CMS-HCC will enable everyone to have a good understanding of the big
picture.
Important points you should make include:
- Well-documented
medical records facilitate communication, coordination, and continuity of
care, and promote the efficiency and effectiveness of treatment.
- Accurate
coding is the key to prompt reimbursement, practice profiling, and
contract negotiations. It is important for both financial and compliance
reasons.
- Chronic
conditions are important to show not only resource utilization, but also
severity of illness for statistical purposes.
- Specificity
is important for further research into treatment effectiveness for chronic
conditions.
- Showing
medical necessity means you are justifying your treatment choice and help
support E/M levels.
Evaluate you Program and Process
There may be opportunities within your current process to
capture a more appropriate CMS-HCC code. For instance, consider this list of
the top Ten Coding Errors for Risk Adjustment published by the AAPC:
- The
records must contain a legible signature including a credential.
- EMR
records must be authenticated, such as “electronically signed by,”
followed by the providers name and credential
- Highest
degree of specificity refers to assigning the most precise ICD-9-CM code
that fully explains the narrative description in the medical chart of the
symptom or diagnosis.
- Discrepancy
between the diagnoses codes being billed versus the actual written
description in the medical record. If the record indicates depression, NOS
(311), but the diagnosis code written on the encounter document is major
depression (296.20) these codes do not match; in addition, they map to a
different HCC category. The diagnosis code and the description should
mirror one another
- Documentation
does not indicate that the diagnoses are being monitored, evaluated, assessed/addressed,
or treated (MEAT).
- Status
of Cancer is unclear, treatment is not documented
- Chronic
conditions such as hepatitis or renal insufficiency not documented as
chronic.
- Specificity:
unspecified Arrhythmia coded rather than the specific type of arrhythmia.
- Chronic
conditions or status codes not documented in the medical record at least
one per year.
- Missing
linkage or causal relationship for diabetic complication/Failure to report
mandatory manifestation code.
Regardless of where you find shortcomings, you’ll want to
consider options to improve clinical documentation.
Develop a compliance
plan and/or a coding integrity plan.
Limit retrospective reviews and implement proactive policies
with ongoing monitoring and feedback.
Many plans use analytics to detect members who might have
missing diagnosis codes based on the analysis of pharmacy, claims, and DME
data. Analytics are a good tool to point you in the right direction, but they
are not a solution alone. Even if the
analytics identify the patient is missing a diagnosis, and the medical record
indicates the patient has the condition, often the doctor has not documented
the condition in the appropriate manner (MEAT, etc.) which, from a coding guideline perspective, means that code cannot be
submitted.
Prospective chart reviews reduce the chances of submitting
invalid or non-specific diagnose codes to CMS, and also reduce providers’
compliance risk. Having a review program in place also allows you to identify
problem areas quickly, and identify opportunities for provider education and
interaction.
The medical record
should tell a complete story. Coders need to understand what the physician
is thinking and know when the provider isn’t documenting the complete
information to assign the most specific diagnosis code. Ensure that all
opportunities for documentation improvement are identified.
ICD 10 and Risk Adjustment
2014 is sure to bring a unique set of challenges to the Risk
Adjustment Arena.
Currently, there is a
30% shortage of certified coders in the US, and that is expected to jump by 57%
with the implementation of ICD-10
What is the potential impact of this transition? Consider
these 7 potential risks:
·
ICD-10 requires changes at the core of
healthcare business, especially how patient care is documented (Compliance will
require far more effort than learning a new code),
·
Inadequate allocation of training and education resources
will have a more significant impact with ICD-10 than it ever did with ICD-9,
·
Reimbursement losses due to ineffective,
physician clinical documentation will be magnified,
·
Without sustained physician leadership and sponsorship,
the possibility for negative political impacts related to poor physician
clinical documentation will increase,
·
Training physicians can be a challenging effort,
·
Fraud and
abuse is now more aggressively pursued so that poor clinical documentation can
pose a higher risk than previously experienced, and
·
Less than appropriate clinical documentation
results in a lack of compliance within medical staff by-laws specific to
Medicare patients, and is applicable to both out-patient and in-patient
settings.
RETURN ON INVESTMENT CDI Education
Consider the following ROI example from “Cracking the Code”
A Physician Clinical
Documentation Improvement Program is a self-funded initiative.
While each healthcare organization must balance funding
numerous concurrent or planned initiatives, a program for Physician Clinical
Documentation Improvement is one of a few initiatives that can be self-funded
based on the increased revenue that consistently is generated from improved
documentation. Why is this true? The
cost of a program will initially yield an ROI of a ratio of 1 to 5 or 1 to 4.
Example based on
actual returns after a Physician Clinical Documentation
Improvement program has been enacted:
Small Hospital (100 beds): Investment in program (external
resource) = $25,000
Increase in Revenue = $ 125,000
RETURN ON INVESTMENT – CODING + CDI + Lean Practice Management
Education Empowers. It empowers physicians, NP’s and PA’s,
Receptionist, Nurses, Coders, Medical Records Clerks, Patients and Care Takers.
ERM’s unique Rapid
Practice Innovation program routinely returns 300%+, but the greatest gift
of all is the desire for something better. In as little as a week, we have
successfully “revived” dying practices.
The greatest investment that you can make in yourself, your practice and
your employees is education!
Monday, June 24, 2013
More than 300,000 uninsured in Valley, federal official says at healthcare fraud conference - The Monitor: Local News
McALLEN — The billions lost to fraud and the thousands of uninsured here are interconnected inside the broad and complicated world of health care.
To address the topics, the two-day Rio Grande Valley Healthcare Fraud and Compliance Conference was held at the McAllen Convention Center. It ended Wednesday and brought hundreds of healthcare providers together to learn more.
Keynote speaker Majorie McColl Petty said 4.8 million uninsured Texans will be able to enroll via a state Health Insurance Marketplace, created under the federal Affordable Care Act (ACA), beginning Oct. 1.
President Barack Obama appointed Petty as director of region VI — which includes Texas, New Mexico, Oklahoma, Arkansas and Louisiana — under the U.S. Department of Health and Human Services.
In Hidalgo and Cameron counties, there are 328,941 uninsured residents, according to information Petty provided. The area, she said, is among the top seven in the nation with large uninsured populations.
Employers and existing federal insurance programs like Medicaid and Medicare — for the low-income and elderly, respectively — already provide insurance, Petty said.
“But, there’s a large population that is left uncovered,” she explained, saying state marketplaces are aimed at this group.
Starting Jan. 1, 2014, plans selected via the marketplace will take effect.
The Texas marketplace, or insurance exchange, will be run by the federal government because state leaders have said they will not implement it. Texas is also one of more than a dozen states that have opted out of the ACA’s Medicaid expansion, though residents will still pay federal taxes for the program.
An obvious proponent of the ACA, Petty listed a number of points about the federal legislation she said has begun to shift people’s thinking on health care and spark important dialogues.
The federal reform, she said, has also allowed for changes in the way services are carried out that help curtail fraud.
“I don’t think we could be at a better place in time,” she told a large audience, adding that healthcare reform has been a hot topic for decades.
Rachanna Rodriguez, director of programs for Senior Community Outreach Services, Inc. — the nonprofit group hosting the event — said it was the first of its kind on such a large scale. FBI representatives and other officials spoke to healthcare providers about how to avoid, prevent and report fraud.
McAllen Mayor Jim Darling attended a session with Petty along with officials from other cities, public agencies and hospital administrators. He said for cities, health care is a crucial economic component also tied to the well-being of residents.
“It’s important that we do it right,” he said. “It’s hard to get that kind of education in any one place, so I think this is a fantastic opportunity for (healthcare providers). It’s a great program.”
Petty couldn’t immediately point to federal data supporting the widespread claim that the Valley is the second-ranked hot spot for federal healthcare fraud. She declined to discuss factors why, saying it would be speculation.
“It’s everybody’s responsibility to, just like with the Senior Medicare Patrol, to monitor it — to be certain that all of us are being responsible and scrutinizing our bills,” she said.
Senior Medicare Patrol, a federally funded program, recruits volunteers who conduct outreach about healthcare fraud among seniors.
As Rodriguez, who is also involved with the SMP, closed her own remarks, she said fraud has damaged the reputation of healthcare providers here.
“That overshadows anything and everything that you do that’s good,” she said to the audience.
Fraud is so widespread, Rodriguez said, that most people at the conference likely know of someone who’s been busted.
“So, today I end with a question: Who’s next?” she said.
Go to www.healthcare.gov/ to learn more about the ACA and state marketplace.
More than 300,000 uninsured in Valley, federal official says at healthcare fraud conference - The Monitor: Local News
Sunday, June 23, 2013
How the New HIPAA Regulations Affect Billing Companies and Their Subcontractors as Business Associates - HBMA - Healthcare Billing and Management Association for 1st and 3rd Party Billers - Medical Billing, Practice Management
How the New HIPAA Regulations Affect Billing Companies and Their Subcontractors as Business Associates
Develop an Action Plan for Your Copmany and Subcontractors
An article by Robert A. Polisky, Esq., taken from the May/June issue of HBMA Billing.On January 25, 2013, the Office for Civil Rights of the U.S. Department of Health & Human Services (OCR) published the anticipated final omnibus rule (the Final Rule). This rule created significant changes to the Privacy, Security, Breach Notification, and Enforcement Rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), many of which are required by the Health Information Technology for Economic and Clinical Health Act (HITECH Act). The Final Rule also implements changes to the Genetic Information Nondiscrimination Act of 2008.The scope of the Final Rule is extensive, and enhances OCR's ability to enforce HIPAA. In the press release announcing the Final Rule, OCR Director Leon Rodriguez proclaimed that the Final Rule "marks the most sweeping changes to the HIPAA Privacy and Security Rules since they were first implemented" and "strengthen[s] the ability of my office to vigorously enforce the HIPAA privacy and security protections…." Individuals and entities affected by the Final Rule must comply with most of its provisions by September 23, 2013.
This article addresses key provisions of the Final Rule applicable to billing companies and their subcontractors, enforcement changes, and recommended action items needed for compliance by billing companies and their subcontractors.
KEY PROVISIONS
BUSINESS ASSOCIATES AND THEIR SUBCONTRACTORS
Expanded Definition of "Business Associate"The Final Rule expands the definition of a "business associate" to include any individual or entity that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity. Companies that code, bill, and/or collect claims on behalf of a health care provider (i.e., a covered entity), are business associates under HIPAA. Notably, the Final Rule includes subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate as business associates themselves. Thus, any subcontractors that a billing company engages to assist in coding, billing, or collections, and any subcontractors that store or transmit any healthcare records on the billing company's behalf, are business associates of the billing company.
Direct Liability
As business associates, the Final Rule requires billing companies and their subcontractors to comply with the Security Rule's administrative, physical, and technical safeguard requirements as well as with the Security Rule's policies and procedures and documentation requirements. These requirements apply to business associates in the same manner as they apply to covered entities, such that billing companies and their subcontractors can be held civilly and criminally liable for violations of these requirements. Similarly, the Final Rule applies certain Privacy Rule requirements to business associates and establishes direct liability of business associates for violations of these requirements. A billing company does not need to provide a notice of privacy practices or designate a privacy official unless the covered entity designated such a responsibility in the billing company's business associate agreement.
Specifically, billing companies and their subcontractors, as business associates, have direct civil and criminal liability exposure for the following items.
- impermissible uses and disclosures of PHI
- failure to provide breach notification to the covered entity
- failure to provide access to a copy of electronic PHI to either the covered entity, the individual, or the individual's designee (whichever is specified in the business associate agreement)
- failure to disclose PHI to OCR where required by OCR to investigate or determine the business associate's compliance with HIPAA
- failure to provide an accounting of disclosures
- failing to enter into business associate agreements with subcontractors that create or receive PHI on the business associate's behalf
- failure to comply with the requirements of the Security Rule
Business Associate Agreements
The Final Rule clarifies that a covered entity is not required to enter into a business associate agreement with a billing company's subcontractor. Rather, the billing company that engaged a subcontractor to perform a function or service involving the use or disclosure of PHI is required to enter into a business associate agreement with the subcontractor. Each business associate agreement in the business associate chain needs to be at least as restrictive as the agreement above it in the chain with respect to permissible uses and disclosures of PHI.
The Final Rule expands the requirements of a business associate agreement by obligating a business associate to comply, where applicable, with the Security Rule with regard to electronic PHI; report breaches of unsecured PHI to the covered entity; and ensure that any subcontractors that create or receive PHI on its behalf agree to the same restrictions and conditions that apply to the business associate with respect to such information.
Transition Period
The Final Rule delays compliance until September 22, 2014 for a covered entity or business associate to enter into a business associate agreement with a business associate or subcontractor if, prior to January 25, 2013, the covered entity or business associate had a business associate agreement with the business associate or subcontractor, as applicable, that complied with HIPAA prior to the Final Rule (unless the business associate agreement was modified or actively renewed between March 26, 2013 and September 23, 2013). In all other cases, covered entities and business associates will need to execute business associate agreements with their business associates and subcontractors no later than September 23, 2013.
MODIFICATION TO THE BREACH NOTIFICATION RULE
BackgroundUnder the HITECH Act, a covered entity is required to notify affected individuals and OCR following discovery of a breach of unsecured PHI; a covered entity also needs to notify the media of a breach involving more than 500 residents of a state or jurisdiction. A business associate, in turn, is required to notify a covered entity following discovery of a breach of unsecured PHI at or by the business associate.On August 24, 2009, OCR issued an interim final rule implementing the HITECH Act's breach notification provisions ("Breach Notification Interim Rule"). In the Breach Notification Interim Rule, a "breach" is defined as the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that "compromises the security or privacy" of the PHI, with certain exceptions. Moreover, under the Breach Notification Interim Rule, "compromises the security or privacy" of the PHI is defined to mean that an impermissible use or disclosure of PHI poses a significant risk of financial, reputational, or other harm to the individual (the "harm standard").
Revised Definition of "Breach"
The Final Rule significantly revises the definition of "breach" to clarify that an impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised. By replacing the "harm standard" with this "low probability" standard, it is more likely under the Final Rule than under the Breach Notification Interim Rule that covered entities and business associates will determine that an impermissible use or disclosure of PHI "compromises the security or privacy" of the PHI, resulting in many required breach notifications that would not have been required previously.
Modification of Risk Assessment
Under the Final Rule, to determine whether there is a low probability that PHI has been compromised, covered entities and business associates need to conduct a risk assessment that considers at least the following factors:
- the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
- the unauthorized person who used the PHI or to whom the disclosure was made;
- whether the PHI was actually acquired or viewed; and
- the extent to which the risk to the PHI has been mitigated.
RIGHT TO RESTRICT DISCLOSURE TO A HEALTH PLAN
Under the Final Rule, health care providers, upon request from an individual, must agree to restrict disclosure of PHI about the individual to a health plan if the disclosure would be for the purpose of carrying out payment or healthcare operations, and is not otherwise required by law, or the PHI pertains solely to a healthcare item or service for which the individual, or person acting on the individual's behalf (other than the health plan), has paid the covered entity in full. To avoid payment issues, a health care provider may want to require payment in full at the time of the individual's request for a restriction. Health care providers may request assistance from billing companies to comply with this new restricted disclosure requirement.ENFORCEMENT
DiscretionThe Final Rule gives OCR discretion to use informal means to resolve HIPAA violations. However, OCR is permitted to impose a civil monetary penalty without exhausting informal resolution efforts, especially when the HIPAA violation is due to willful neglect. The Final Rule also allows OCR to coordinate with other law enforcement agencies, such as state attorneys general and the Federal Trade Commission, with respect to pursuing remedies against HIPAA violators.
Tiered Penalty Amounts
Under the HITECH Act, there are four tiers of increasing penalty amounts that correspond to the levels of culpability associated with a HIPAA violation. The minimum fines range between $100 and $50,000 per violation, and are capped at $1.5 million for all violations of the same HIPAA provision during any calendar year (see below table). The lowest category of violation covers situations where the covered entity or business associate did not know, and by exercising reasonable diligence would not have known, of the HIPAA violation. The second lowest category of violation applies to violations due to reasonable cause and not to willful neglect. The third category applies to situations where the violation was due to willful neglect and was corrected within 30 days of when the covered entity or business associate knew, or should have known, of the violation. The fourth category applies to situations where the violation was due to willful neglect and not corrected within 30 days of when the covered entity or business associate knew, or should have known, of the violation.
The Final Rule modifies the definition of "reasonable cause" to mean "an act or omission in which a covered entity or business associate knew, or by exercising reasonable diligence would have known, that the act or omission violated [HIPAA], but in which the covered entity or business associate did not act with willful neglect." The Final Rule keeps the definition of "willful neglect" as the "conscious, intentional failure, or reckless indifference to the obligation to comply" with HIPAA.
Counting Violations
In the preamble to the Final Rule, OCR states that how it counts HIPAA violations for purposes of calculating a civil monetary penalty varies depending on the circumstances surrounding the violation. OCR explains that where multiple individuals are affected by a HIPAA violation (e.g., a breach of unsecured PHI), it is anticipated that the number of identical HIPAA violations would be counted by the number of individuals affected. OCR also explained that, with respect to continuing violations (e.g., a lack of appropriate safeguards for a period of time), it is anticipated that the number of identical HIPAA violations would be counted on a per day basis (i.e., the number of days the covered entity or business associate did not have appropriate safeguards in place to protect the PHI). OCR notes that in many HIPAA breach cases, there would be an impermissible use or disclosure as well as a safeguards violation, for each of which OCR would be entitled to calculate a separate civil monetary penalty. Needless to say, the amount of civil monetary penalties that could be imposed against a billing company or one of its subcontractors for a HIPAA violation can be quite substantial.
Factors Used to Determine a Penalty
The Final Rule lists the following five factors that OCR will consider in determining the amount of a civil monetary penalty.
- the nature and extent of the HIPAA violation, including the number of individuals affected and the duration of the violation
- the nature and extent of the harm resulting from the violation, including physical, financial, and reputational harm, and any hindrance to an individual's ability to obtain healthcare
- the history of prior compliance with HIPAA, including whether the current violation is the same/similar to prior indications of noncompliance by the covered entity or business associate and their attempts to correct that noncompliance
- the financial condition of the covered entity or business associate, including any financial difficulties that could have affected compliance and whether a civil monetary penalty could jeopardize the future provision of healthcare
- such other matters as justice may require
The Final Rule makes covered entities and business associates liable for the acts of their business associate agents, regardless of whether the covered entity or business associate knew of the violation or had a compliant business associate agreement in place. According to OCR, the key factor in determining whether an agency relationship exists between a covered entity and its business associate, or between a business associate and its subcontractor, is the principal's right to control the agent's conduct in the course of performing a service on behalf of the principal. OCR observes that a business associate agent's conduct generally is within the scope of agency when its conduct occurs during the performance of the assigned work or incident to such work, regardless of whether the work was done carelessly, a mistake was made in the performance, or the business associate disregarded a covered entity's specific instruction. OCR further observes that, in contrast, a business associate agent's conduct generally is outside the scope of agency when its conduct is solely for its own benefit (or that of a third party), or it pursues a course of conduct not intended to serve any purpose of the covered entity. To protect itself, a billing company's services agreement with a subcontractor should specify that the subcontractor is engaged as an independent contractor, not as an agent, and the billing company does not have the right to control the subcontractor's performance.
RECOMMENDED ACTION ITEMS
Although billing companies and their subcontractors have until September 23, 2013 to fully comply with the Final Rule, they should begin preparing soon in light of the significant number of new or modified compliance obligations. In particular:- Covered entities will need to revise, negotiate, and execute business associate agreements with billing companies compliant with the Final Rule by September 23, 2013 to the extent they did not have business associate agreements in place as of January 25, 2013 that were HIPAA compliant. They have until September 22, 2014 to do so to the extent they had business associate agreements in place as of January 25, 2013 that were HIPAA compliant. OCR gives a fair amount of latitude in the content of business associate agreements, so it is important for billing companies to ensure that they are not overcommitting to responsibilities or deadlines that are not required under HIPAA.
- Billing companies that use subcontractors that create, receive, maintain, or transmit PHI on their behalf will need to draft, negotiate, and execute business associate agreements with them by September 23, 2013. Billing companies will need to ensure that these business associate agreements are at least as stringent as their business associate agreements with covered entities, and enable billing companies to meet deadlines in their business associate agreements with covered entities.
- Billing companies, including subcontractors, will need to conduct a security risk assessment, implement a written HIPAA security plan, designate a security official, and create certain written HIPAA privacy policies by September 23, 2013 to the extent they have not already done so. OCR has posted guidance on compliance with the HIPAA Security Rule found at www.hhs.gov/ocr/privacy/ hipaa/administrative/securityrule that may be helpful to billing companies and their subcontractors and facilitate their compliance efforts.
- Billing companies and their subcontractors will need to perform a gap analysis to determine what HIPAA policies and procedures need to be revised to comply with the Final Rule, and then will need to revise them by September 23, 2013 based on the gap analysis.
- Billing companies and their subcontractors will need to update by September 23, 2013 their breach notification policies and any tools concerning how to conduct a risk assessment to determine whether breach notification is required.
- Healthcare providers may ask billing companies to implement by September 23, 2013 a method to flag or make a notation in the record with respect to PHI concerning an item or service paid in full by an individual – or person acting on the individual's behalf (other than a health plan) – to ensure that such information is not inadvertently sent to or made accessible to a health plan for payment or healthcare operations purposes, such as audits by the health plan.
- Billing companies and their subcontractors will need to update their HIPAA training materials and then train their workforce members (i.e., employees, volunteers, trainees, and other persons under their direct control) by September 23, 2013 to comply with HIPAA.
Robert A. Polisky, principal of the Law Offices of Robert A. Polisky (www.rphealthlaw.com), is a healthcare attorney based in Los Angeles. Robert represents healthcare providers and companies, including billing companies and their subcontractors, in healthcare transactions, healthcare regulatory (including HIPAA, Medicare enrollment and reimbursement, and fraud and abuse), and general business law. Robert opened his law firm last April after spending over 8 years in-house at Alliance HealthCare Services and, for several years before that, working at healthcare law firms, clerking for a federal judge, and interning at the U.S. Department of Justice. How the New HIPAA Regulations Affect Billing Companies and Their Subcontractors as Business Associates - HBMA - Healthcare Billing and Management Association for 1st and 3rd Party Billers - Medical Billing, Practice Management
Tuesday, June 18, 2013
How much do you know about Medicare Risk Adjustment?
Ignorance is no longer a defense, take our Medicare Risk Adjustment assessment today.
In this climate of regulatory reform, our best defense is a great offense, and education is the only way to ensure compliance.
This assessment covers general risk adjustment, documentation and HCC coding principles.
If you work in the industry, I challenge you and anyone you work with to test yourself.
The results, might surprise you...
What do your employees know about risk adjustment?
What type of training have you done?
Does your company provide on-going accessible education 24/7?
Do you know where your records are from the training class 2 years?
Empirical Risk Management can design and build custom solutions for your company as well as mobile training platforms targeted to individual deficiencies. Online secure records are accessible from anywhere for 10 years.
Call us today 772-210-2823
Friday, June 14, 2013
RAPID PRACTICE INNOVATION
“Rapid Practice Innovation” is a scientific process of
implementing positive, whole system change within a medical practice. Our
rigorous approach begins at the initial point of contact and provides practical,
proven strategies for rapid innovation. ERM’s proprietary model enables clients
to shift directions rapidly. Inspired by lessons from lean manufacturing, our
unique process integrates education and process improvements to improve the overall
experience for all stake holders.
Rapid Practice Innovation in 180 Days
1) Initial on-site “audit” of
practice processes.
a. Comprehensive practice evaluation
and needs assessment including baseline knowledge of all staff.
b. Detailed findings that outline a
specific plan of action to meet compliance and revenue goals.
c. Education and training that
includes general compliance and regulatory issues, as well as specific areas
for clinical documentation and practice improvement
d. Development of a meaningful
compliance plan that is effective for your individual needs.
e. Create Quality improvement
initiatives that will enhance staff buy-in and improve the patient experience.
2) On-going education, training and
monitoring to asses effectiveness of current initiatives and to prepare for
upcoming changes (6 months)
a. Annual Compliance training for
all staff
b. Online training to reinforce
initiatives
c. ICD-10 Mapping of Top 50 HCC
Codes
d. Clinical documentation
improvement
e. Risk adjustment methodology /
provider responsibilities
f. Contract level requirements
g. HEDIS, PQRS and “Pay for
Performance” education and training
h. Patient Centered Medical Home education
and training
Visit us online for more information: www.ermconsultinginc.com
Subscribe to:
Posts (Atom)

