Showing posts with label HITECH. Show all posts
Showing posts with label HITECH. Show all posts

Wednesday, December 18, 2013

10 Compliance Issues for Physicians, Health Systems and Providers in 2014


Meaningful Use Audits: Physicians, hospitals, and others that have received incentive payments to integrate electronic medical records into their practices will likely be subject to an audit from either Medicare or Medicaid to assess whether the providers have actually made meaningful use of these funds and systems. Auditors are likely to demand evidence of meaningful use of incentive monies and repayment when providers cannot back up the attestations made for Stage 1 compliance.  Providers should be on the lookout for audit request letters sent via email by the contracted auditor.  Make sure that whoever has the email address registered with CMS checks for an audit letter.  In addition, providers should make sure that all meaningful use attestations are backed up and documentation is maintained for the six years that CMS requires. Some of the required evidence includes EHR vendor agreements, attestation reports on clinical quality measures, statements from EHR vendors, information used to generate numerator and denominator values for reporting, et cetera. If an audit letter is received, contact should be made immediately.   Providers need to pay attention to these responses; a failure to respond adequately could result in more than just a request for repayment.
Assuring and Measuring Compliance with HIPAA and HITECH: Increased audit and enforcement activities related to HIPAA and HITECH are coming and providers should ensure that they have implemented required changes such as identifying business associates and executing compliant business associate agreements as well as implementing security standards and testing for patient information and reporting breaches.   Also, expect increased enforcement activities from Kentucky’s Attorney General as HITECH granted enforcement authority to the Attorney General along with the opportunity to seek damages.
Stark Law Application to Medicaid Claims: While the Stark Law on its face applies only to Medicare, recent court decisions have found that a Medicaid claim filed in violation of the Stark Law also constituted a false claim.  Courts have now found False Claims Act liability for Medicaid claims filed in violation of the Stark Law.  Historically, the federal government had focused enforcement efforts on Medicare claims.    Carving out Medicaid referrals and claims in health care transactions is no longer prudent. All contracts and transactions should be reviewed for compliance with the Stark Law even if the contract only applies to services for private pay or Medicaid patients.
Medicaid Integrity Contractor Audits:  As the Medicaid review auditors are finalizing their review of the big data to identify providers who fall outside billing standards, these reports are being released to Medicaid for provider audits and collection of overpayments.  Challenging overpayments must be made through Kentucky’s Medicaid appeal process, which establishes important deadlines for requesting a dispute resolution meeting when an overpayment is identified.  If a DRM is not requested, then repayment is due in 30 days.  Providers should pay close attention to these deadlines and exercise their ability to challenge overpayments.
Measuring Quality:  As CMS’ Physician Compare website joins the nursing facility and hospital compare websites, physicians must be ever mindful that quality scores will ultimately impact reimbursement for all payors, not just Medicare and its incentive payments. Physician groups as well as all providers should carefully develop their quality measures. As ACOs, hospital systems and payors develop their own quality measures, individual physicians must be aware of those measures and how they affect them.  Participation in networks, ACOs, and even Medicaid may become tied to performance.  All physicians, even those who are employed by health systems, should be careful in their contracting and knowledgeable about their individual quality and performance.
Medical Staff Membership and Credentialing:  Changes in Joint Commission for Accreditation of Health Care Organization’s requirements for medical staff credentialing have made evaluation of a physician’s quality of care an element of the credentialing and recredentialing process.  How this evaluation takes place and the factors that are considered are left to the medical staff, which, in reality, usually means administration.  The information about this evaluation becomes a permanent part of a physician’s records.  Every physician should be aware of this, find out about evaluation results, and challenge them if necessary. A challenge does not mean that a physician impairs his/her privileges, but rather seeks to maintain an accurate credentialing file.
Retention of Overpayments:  Retention of a Medicare or Medicaid overpayment can create false claims liability and treble damages recovery when the overpayment is not returned within 60 days.  The ACA created the duty to report and return known overpayments.  While the law sounds simple, its application is anything but simple and creates a host of issues for providers including determining when an overpayment is known to the provider.  For example, is the billing clerk’s knowledge imputed to the physician owner of the practice?  Also, when reporting an overpayment, does a provider have a duty to look back to see if there are other overpayments?
Expansion of Medicaid Beneficiaries: With Kentucky’s successful rollout of its Health Insurance Exchange and the possibility of 308,389[i] new Medicaid   beneficiaries, what is the health care provider’s duty to take on more Medicaid patients?  Should a provider establish express limits on the number of Medicaid patients that a practice will accept as patients? Does this create liability under provider agreements with Medicaid Managed Care payors?  These issues will become even more important as the number of beneficiaries increases.
Prescribing Controlled Substances in Kentucky:  The war on prescription drug abuse has taken a terrible toll on physicians as House Bill 1 and the implementing regulations issued by the Kentucky Board of Medical Licensure have forever changed how and when a physician may prescribe controlled substances.  While the regulations have been slightly tweaked, physicians must take extraordinary efforts to build the procedures and processes required for prescribing into their day- to- day practice.  Physicians should be aware that the Drug Control Branch of Kentucky’s OIG routinely reviews KASPER data and reports the highest prescribers of controlled substances to the KBML for investigation.  Physician responses to these investigations must be careful and complete with the understanding that there is little recourse if a violation is found.
Getting Paid:  All providers must take active steps to assure that they are paid, which includes keeping abreast of a myriad of payment issues and policies.  A provider’s staff must be diligent in following up with insurance companies, Medicaid, and Medicare to seek payment.  The squeaky wheel gets oiled first.  Providers also need to be aware that preventive benefits such as cholesterol screenings and vaccinations are now free of charge through all Marketplace plans and many other insurance plans, including Medicare, Medicaid, and private insurance plans.  Providers should be prepared that they will no longer be able to collect a copay from any member of these plans, regardless of whether that member has met his or her deductible.  A list of preventive benefits covered by most plans under the ACA can be found at https://www.healthcare.gov/what-are-my-preventive-care-benefits/.  Providers, particularly physicians, should pay attention to proposed federal legislation that will finally repeal the sustainable growth rate and replace it with a methodology that ties payments to quality and efficiency, incorporates alternative payment models and improves the fee for service system by including value-based performance measures. This bill has the support of both Senate and House committees.  We will see…….

Thursday, December 5, 2013

The Office for Civil Rights Did Not Meet All Federal Requirements in Its Oversight and Enforcement of the Health Insurance Portability and Accountability Act Security Rule

11-21-2013

Summary

The Office for Civil Rights (OCR) did not meet certain Federal requirements critical to the oversight and enforcement of the Health Insurance Portability and Accountability Act Security Rule (Security Rule). OCR had not assessed risks, established priorities, or implemented controls for its Federal requirements to provide for periodic audits of covered entities to ensure their compliance with Security Rule requirements. In addition, OCR's Security Rule investigation files did not contain required documentation supporting key decisions made because management had not implemented sufficient controls, including supervisory review and documentation retention, to ensure investigators follow investigation policies and procedures for properly initiating, processing, and closing Security Rule investigations. Further, OCR had not fully complied with Federal cybersecurity requirements for its information systems used to process and store investigation data because it focused on system operability to the detriment of system and data security.
We recommended that OCR (1) assess the risks, establish priorities, and implement controls for its HITECH auditing requirements; (2) provide for periodic audits in accordance with HITECH to ensure Security Rule compliance at covered entities; (3) implement sufficient controls, such as supervisory reviews and documentation retention, to ensure policies and procedures for Security Rule investigations are followed; and (4) implement the National Institute of Standards and Technology Risk Management Framework for systems used to oversee and enforce the Security Rule. In its comments on our draft report, OCR generally concurred with our recommendations and described the actions it has taken to address them. In specific comments on our second recommendation, however, OCR explained that no funds had been appropriated for it to maintain a permanent audit program and that funds used to support audit activities previously conducted were no longer available.
Get the entire report in PDF here

Friday, November 15, 2013

Data Mining, Meaningful Use, Secondary Use, & Potential Misuse of Electronic Health Records



Donna Hanrahan
Donna Hanrahan
Ethical Technology

Posted: Nov 15, 2013

Healthcare providers are establishing electronic health record (EHR) systems at an astonishing rate, due in part to the Health Information Technology for Economic and Clinical Health (HITECH) Act. The HITECH Act was created as a part of the American Recovery and Reinvestment Act of 2009.
i The $27 billion dollar piece of legislation offers eligible providers incentives for expanding the use of healthcare information technology (HIT).ii This includes promoting the “meaningful use” of EHRs. The “meaningful use” standard was designed to use HIT to improve quality of care and health outcomes for patients, as well as to lower costs by eliminating repeat medical tests and reducing preventable medical errors that pervade the health-care system today. This legislation has been extremely effective in persuading healthcare providers to use of electronic health records. In fact, the incentives outlined in the HITECH Act are estimated to increase EHR adoption rates to 90% of all physicians by 2019.iii Despite healthcare technology’s vast potential to improve patient health in the medical arena, there exists a host of complex legal, technical, and ethical concerns surrounding the use of HIT as incentivized in the HITECH Act, namely issues of privacy, confidentiality, autonomy, and the preservation of the physician-patient relationship.
The HITECH Act and “Meaningful Use”
The Health Information Technology for Economic and Clinical Health (HITECH) Act offers hospitals and eligible healthcare professionals incentives for expanding the use of healthcare information technology, including the “meaningful use” of EHRs.iv Incentive payments are made available through the Medicaid and Medicare programs. The Centers for Medicare & Medicaid Services (CMS) judges whether a health care provide has satisfied the meaningful use core objectives through the use certified health technologies.
The Department of Health and Human Services defines meaningful use as using certified EHR technology to: (1) improve quality, safety, efficiency, and reduce health disparities; (2) engage patients and families; improve care coordination, and population and public health; and (3) maintain privacy and security of patient health information.v The “meaningful use” framework incentivizes improvement to clinical care and quality by encouraging healthcare professionals to take advantage of instantaneous and patient-specific information. There are three stages of “meaningful use.” The first stage is the use of HIT for basic data collection, including demographic and medication history. The second stage is the use of EHR data to improve clinical processes including patient controlled data, clinical decision support, health information exchange (HIE), and quality measurement and research. The third stage is the use of EHR data to improve health outcomes, quality, safety, efficiency, and population health at the national level.vi Hospitals and providers eligible for the EHR Incentive Program do not need to attest to meaningful use in their first year of participation. Rather, they must simply implement an EHR to receive an incentive payment from their State.
The incentive payments under HITECH are quite substantial. To receive payments, eligible professionals and hospitals must meet at least 5 of the “meaningful use” criteria defined, consisting of 15 core data points and 10 menu options.vii These criteria include the entry of patient demographic and insurance information,
e-prescribing, and the use of drug interaction software to ensure patient safety.viii Eligible professionals and hospitals that meet the criteria can be rewarded up to $44,000 in Medicare and $63,750 in Medicaid payments over 5 years. After 2015, physicians who fail to meaningfully use EHRs will be subject to reductions in Medicare and Medicaid reimbursement.ix
Health Information Exchanges
The HITECH Act is a step towards the eventual goal of a national, interoperable, private, and secure electronic system to allow information to be shared among all the sites where patients receive care.x While still in its infancy, Health Information Exchanges (HIEs) are being established at the community, state, and national level to facilitate the electronic exchange between systems. The State Health Information Exchange Cooperative Agreement and the Nationwide Health Information Network (NHIN) received $600 million in federal funding to create a platform for health information exchange across the United States. xi At the state level, governments are creating statewide health information networks (HINs). At the national level, the Office of the National Coordinator (ONC), which oversees deployment of the HITECH Act, is executing plan to create a National Health Information Network (NHIN). Provider organizations participating in NHIN include Kaiser Permanente, the Cleveland Clinic, and the Veterans Administration.
These networks can lead to the development of data repositories filled with rich sets of health data for millions of individuals. Such data repositories can provide researchers with information necessary to improve quality of care and make significant discoveries in medicine that they may not otherwise have access to. Despite their great potential, progress in developing HIEs and repositories has been gradual. Many hospitals and clinics are hesitant to implement the systems because they do not have the finances or infrastructure necessary to do so. Moreover, there are also significant concerns over patient privacy and autonomy, which is to be discussed “Ethical Implications” sections below.
Secondary Use of Health Data
Until recently, collecting data for “secondary use” was an arduous task. “Secondary use” in healthcare is defined as the use of information collected from health records, electronic or manual, outside of direct patient care delivery. This includes data collection for the purpose of “research, quality and safety measurement, public health, payment, provider certification or accreditation, marketing, and other business applications.”xii Such use of healthcare data in biomedical research has the potential to drastically improve the quality and affordability of healthcare services in the United States. EHRs contain structured information about patients, which is extremely valuable in research because now information can be retrieved in a much quicker and more efficient fashion than more traditional methods of record keeping. Researchers can develop algorithms to search through EHRs, including free-text clinician notes, to find data valuable to a specific study.xiii
The effective secondary use of health data for research has great potential to improve health outcomes, reduce medical errors, predict health trends, and demonstrate the comparative value of drugs and other treatments.xivOther benefits include the increased ability to analyze the efficacy of treatment options and identify evidence-based best practices. Furthermore, predictive modeling techniques may be applied to electronic health data to identify medical conditions before the onset of symptoms and promote earlier interventions. While experimental studies, such as randomized controlled clinical trials, are likely to continue to be the gold standard of clinical research compared to observational studies, they more expensive and time consuming. As such, electronic health data serves as a rich resource for the conduction of observational studies.
Nevertheless, the unprecedented surge in the amount of healthcare data, as well as the relative ease with which that data can be aggregated and exchanged between providers and researcher will raise ethical questions about its use in research, specifically concerning patient privacy and autonomy. The Health Insurance Portability and Accountability Act (HIPAA) requires patient health information (PHI) to be de-identified or authorized by the patient for release. However, de-identified data would omit significant clinical, demographic, and time-related data that would render the data sets much less useful for many research purposes. While de-identified data is invalid and leads to incomplete data sets, it seems like is a small price to pay for protected the privacy of patients, especially those with stigmatized conditions.
Accordingly, researchers are forced to walk a fine line between ensuring patient privacy and maximizing the descriptive power of their data sets. Before the value of secondary use can be fully realized, ethical considerations surrounding the mining of electronic health data must be explored, namely infringements on an individual's privacy, confidentiality, and autonomy. It is necessary to establish a national framework of policies for the secondary use electronic health data to allow stakeholders to harness valuable information to improve the U.S. health care systems while maintaining patient autonomy and privacy protections.xv
Ethical Implications of EHRs and Meaningful Use: Data Quality Concerns
The mass of recent electronic health data makes it possible to assess the overall burden of disease and evaluate the impact of interventions on a national scale. Despite its promise, research through electronic health data mining and “secondary use” is not without flaws. Data quality concerns are inherent in data that is being used for any purpose other than what it was originally intended, especially considering the fragmented nature of the healthcare industry and the numerous platforms on which data is being collected.xvi First, there are hundreds of different EHR systems, each with a distinct representation of data that makes it difficult to aggregate. Second, even within the same EHR system, information incompleteness, inaccuracy, and inconsistency are common challenges, as different healthcare professionals tend to use the same system differently.xvii Third, clinicians tend to prefer using free text compared to structured data entry because it is more easily adapted to their individual practice styles and work flows, although it may make it more difficult to compile and analyze. xviii While there are established clinical coding standards such as SNOMED and ICD-9 to facilitate easier data aggregation, consistency has still proved to be a challenge in clinical research. Fourth, incomplete and duplicate records threaten the quality of research using data mined from EHRs.
Furthermore, some critics may argue that EHRs make it more possible for clinician to falsify charts and reports, which would lead to both data quality and trust issues with patients. However, the falsification of records would not only violate the moral imperative against lying, but also infringe on the fiduciary relationship between the physician and patient. Furthermore, there are methods to protect against such acts, include audits, fraud charges, and reclamation of funds under the False Claims Act and the Deficit Reduction Act.xix These measures act as valid disincentives to data falsification when it comes to patient records. Lastly, while the incentives and mandates of HITECH and “meaningful use” have led to an enormous amount of data being stored and generated by the U.S. healthcare system, there is an extreme lack of interoperability. The electronic data exists in different formats on hundreds of different systems.
Aggregating this sizeable amount of this data for research purposes will prove difficult, if not impossible, without a national regulatory framework to reduce intersystem variation and improve data quality. The federal government must determine national data standards or guidelines and clinicians to decrease data variation between systems. By implementing legislation to address these issues, the federal government can alleviate many ethical concerns and while allowing the United States healthcare system to benefits from more effective and larger scale use of secondary data.
Ethical Implications of EHRs and Meaningful Use: HIPAA and Privacy Concerns
With improved access to data comes increased risk of wrongful disclosure of patient health information. EHR data is at risk of human error, hacking, IT glitches, and theft of hardware than contains such information. HITECH challenges certain the notions of privacy and security found in the Health Insurance Portability and Accountability Act of 1996 (HIPAA), yet enhances others. HIPAA prohibits the disclosure of protected health information (PHI) without the consent of the patient except for the purposes treatment, payment, or healthcare operations. Under HIPAA, “business associates” of covered entities with access to PHI are not directly regulated. xx Rather, they are obliged to comply with HIPAA pursuant to mandatory written agreements within the covered entities for which they work. The HITECH Act, on the other hand, provides for regulation of business associates and stipulates that HIPAA’s privacy and security rules directly apply to them.
When it comes to a security breaches involving PHI, HITECH mandates public notification when unsecure, unencrypted PHI is disclosed or used for an unauthorized purpose, similar to many state and federal financial data breach laws. The HITECH Act also requires that patients be notified of both internal and external breach of their data security. If a breach affects over 500 patients, the Department of Health and Human Services (HHS) must also be notified and the name of the breaching institution will be posted on the HHS web site. There are also certain circumstances where local media will need to be notified to inform the public of breaches than effect many people within a given area.xxi
While HITECH is a federal law, it the Department of Health and Human Services and state attorneys general are granted with the authority to enforce the law. Subtitle D of the HITECH Act addresses the privacy and security concerns of EHRS by strengthening both the civil and criminal enforcement of the HIPAA rules. xxii Section 13410(d) of the HITECH Act revised the Social Security Act by establishing significant penalties for violation of security policy of the HITECH Act.xxiii If an institution or individual is unaware of a violation despite due diligence, the minimum penalty is $100 per violation, with a cap of $25,000 for violations of an identical requirement within the same year.xxiv If the security violation is due to “willful neglect,” the minimum penalty is $10,000 per violation, with a cap of $250,000. xxv The maximum penalty is $50,000 per violation, with a cap of $1.5 million. xxviThese are clear examples of the HITECH’s acts attempts to deter data breaches and mitigate security concerns.
The healthcare industry continues to tread carefully when it comes pursuing “meaningful use” of HIT while protecting patient privacy under HIPAA regulations. Critics current HIPAA does not accommodate the powerful research opportunities that may become possible as HIT and HIEs become more commonplace. The public health benefits of secondary use merit judicious consideration of how such data can be optimized while protecting patient autonomy.
Ethical Concerns of EHRs and Meaningful Use:Confidentiality & Physician-Patient Relationship
Patients often express concerns about keeping their PHI is kept confidential and secure. Moreover, patients may fear re-identification of their de-identified health information. Furthermore, understanding that EHRs provide a rich source of data that is highly desirable to pharmaceutical companies, insurance firms, and researchers, it seems valid to be concerned that these entities may try to purchase, use, and resell this data. There must be high security standards and regulations set to ensure that patient information is secure and not vulnerable to such misuse. Such concerns by the patient are harmful to the vital physician-patient relationship. The physician-patient relationship is a unique and complex status in which confidentiality is key; Privacy of a patient’s health information is considered sacred in the medical field. Any perceived infringement on patient privacy will severely damage this unique physician-patient relationship.
If a patient does not feel confident about the security of his or her health information, he or she may feel the need to conceal sensitive information. For example, a patient might fear that sensitive health matters such as those relating to sexual health and mental health could be accessed by others and refrain from sharing information about those issues. This is particularly true pertaining to sensitive health issues, such as sexually transmitted infections or mental health disorders. As a result, the patient’s health and treatment may be compromised. This may result in patients not fully disclosing important facts or, worse, avoiding medical care entirely, which would clearly result in negative health outcomes.
Accordingly, it is essential for physicians to ensure doctor-patient confidentiality by openly discussing these concerns with patients and explaining the security attempts detailed above that are in place to mitigate them. Furthermore, it is important that patients be able to access their EHRs with relative ease. It would be wise to allow patients to have a degree of control over the records’ content by allowing them to write notes or amendments to the record. Lastly, a new informed consent system must be established to enable patients to play a role in the decisions about how much of their EHRs they wish to make public to researchers and other stakeholders. A system must established to enable patients to play a role in the decisions about how much of their EHRs they wish to make public to researchers. Allowing patients to set the level if access they choose to share with certain health care providers and researchers will maintain respect for their autonomy and right to confidentiality. While variation in data due to informed consent redactions may result in significant differences in the completeness of individual datasets, making them less powerful tools for research, it is a risk that we must face to protect patient autonomy while optimizing the research potential of electronic health data. xxvii Patient ownership of their health data, in terms of both privacy and content, is critical to the ethical to use EHR data.
Ethical Concerns of EHRs & Meaningful Use: Autonomy, Informed Consent, and Syndromic Surveillance
While the secondary use of electronic health data has the potential to improve the quality of care in the United States, there are several ethical considerations that must be addressed before a national framework is implemented to address issues of autonomy and informed consent. Patient autonomy is threatened when an individual’s personal health information is shared without that person’s knowledge or consent. When data mining electronic health data, it is unlikely that patients are told that their data is being accessed. It is even less likely that they are contacted for their consent. This is concerning, as champions of patient autonomy would argue that informed consent is necessary for the secondary use of health data. Patients often believe they have a right to know who is viewing their medical information, why it’s being accessed, and how it is being used. Additionally, those who champion patient autonomy believe that patients have a right to take an active part in decisions about the access, content, and ownership of EHR data. It would appear to be a violation of autonomy to aggregate and generate new information about a patient’s health without their knowledge or permission. Patients provide information to healthcare professionals in confidence with the specific goal of advancing their own personal health outcome. If the principle of autonomy is intrinsically linked to advancing an individuals own personal health outcome, then any form of secondary use (by definition as the use of PHI outside of direct patient care delivery) appears to be a violation of the principle of “respect for persons.” The real question here is whether or not you can turn a patient into a research subject without their knowledge or consent.
To overcome these issues of autonomy, patients should be able to access their EMRs with relative ease. Moreover, patients should maintain the right to have a degree of control over the records’ content. While it seems unreasonable to allows patients to modify or delete any of the content entered by health care professionals per se, it seems judicious to allow autonomous patients to review, annotate, or challenge their own electronic medical record. Furthermore, federal regulations must be reassessed to determine considered valid informed consent for research using electronic health data specifically. Some HIEs are attempting to develop new consent processes to overcome HIPAA compliance issues. Some are calling for a blanket “opt-in” or “opt-out” policy, while others suggest the independent ability to exclude certain types of sensitive data in one’s own health record. Ideally, to maintain the highest level of patient autonomy, the patient would have full say as to what specific information may be shared and with whom it may be shared.
That being said, there are certain public health situations where it is necessary and desirable to use electronic health data without informed consent. This is particularly true in public health emergencies. In the interest of population health, the HITECH framework allows for syndromic surveillance to notify public health officials of reportable conditions. Syndromic surveillance systems seek to use existing health data in real time to provide immediate analysis for early detection of disease outbreaks, and to monitor disease trends.xxviii It has been well established the government has the authority to do so under their police power authority to regulate for the safety and welfare for the population. However, it is important to consider from a bioethical perspective where the line ends between public health surveillance and an intrusion on one’s own individual liberty and autonomy. On the other hand, it could be argued that it would be a “tragedy of the commons” if individuals independently acted according to each one's self-interest and refused to be surveilled. To take a communitarian perspective, aggregation of public health data is an essential resource to public health officials and necessary for the welfare and beneficence of the population as a whole.
It is also necessary to note the point of “electronic exceptionalism.” There is a longstanding history of manual disease surveillance. However it seem more ethically unsettling when this process is done with high technology tools that can quickly aggregate and share data in unprecedented ways. While critics may look at syndromic surveillance through EHR data as exceptional because of its electronic nature, its use may not be so different than traditional methods after all. There has been mandatory reporting of certain conditions to public health officials at the local and national level for decades before EHRs existed, including the reporting of drug-resistant tuberculosis, certain cancers, and HIV. EHRs will make reporting of these conditions and others deemed necessary to protect public health easier, and may actually do a better job at protected patient health data by encrypting and preventing unauthorized access through password protection.
Ethical Implications of EHRs and Meaningful Use: Meaningful for Whom?
It is clear that the “meaningful use” of EHRs is on the rise, but is important to question for whom is it meaningful, and how meaningful is it? Let us consider one of the primary goals of “meaningful use,” which is to provide patients with electronic resources to increase participation in their own care. This involves providing patients with an electronic copy of their health information within three business days if requested, including diagnostic test results, medication lists, allergies, discharge summary, and procedures.xxix Accordingly, providers often offer patients access to online personal health record (PHR). PHRs are largely secure as they are encrypted and password-protected. However, it is important to note that patients need more than just Internet access and a very basic understanding of health information to fully benefit from PHRs.xxx Rather, they need access to the basic resources required to act on the information provided through this technology. Not only must patients be able to read and interpret lab results; they must be willing and capable to act on the information he or she receives. This point has been largely neglected in discussions surrounding the HITECH Act. For those without access the Internet, those with very limited health literacy, and those unable to act on that information for financial or other reasons, EHRs have limited to no directed benefit. It is important to note this limitation and ethical concern of the HITECH Act, as well as to acknowledge the justice and access issues it presents.
It is also necessary to consider community outreach and education programs that focus on Internet and health literacy, rather than merely advertising new electronic and personal health record capabilities.xxxi Many fear that patients will misunderstand or misinterpret information if they read it without a medical professional to interpret it. It is possible that the HITECH Act granted health care providers a new ethical obligation to work with patients to ensure they understand these tools and how to use them. Furthermore, healthcare professionals run the risk of relying solely on PHRs to communicate important health information to their patients. This stands to cause great harm to the doctor-patient relationship. Electronic tools must not replace the face-to-face communication between healthcare provider and patient that is essential to maintaining trust and achieving improved health outcomes.
Beneficence of Electronic Data in Medical Research
Despite the ethical concerns addressed above, the use of electronic health data is critical to ensuring patient health, improving our healthcare system, and making new scientific discoveries in this technological age. Critics may question whether EHRs are truly meaningful or whether it is an “excessive bureaucratic requirement to spend public dollars on doctors’ computer systems.”xxxii This answer to this question can be discussed through the principle of justice. It is ethical, one could argue, to expend public funds for EHR systems that provides for the greater good and benefits for the public as a whole. Having data that is structured and easily retrievable benefits clinicians, patients, and the greater population. These benefits include safer prescribing, prevention of medication errors, epidemiological tracking to protect population health, and public medical error reporting. Furthermore, there is a clear need to switch from outdated, burdensome, and inefficient clinical charting traditions to electronic format.
EHR adoption aims to reduce cost, which is a primary goal of health reform in the United States. The increase in information available to clinicians can help prevent redundant or unnecessary tests and imaging. Furthermore, EHRs can provide point-of-care clinical decision support (CDS) as doctors prescribe tests, medications, and imaging requests, which can also help reduce costs. Lastly, “shared savings,” or “gain-sharing,” allows hospitals and healthcare providers to collaborate to reach quality metrics.xxxiii Accordingly, EHRs enable users to measure desired outcomes and report this data more quickly and easily, saving both time and money. With regard to the costs associated with EHRs, studies have documented the strong return on financial investment that may be achieved following EHR implementation.xxxiv Other financial benefits include increased revenues due to improved care coordination, averted costs of paperwork, chart pulls, and billing errors, and fee-for-service savings including the rate of new procedures and charge capture. Furthermore, the secondary use of health record information is anticipated to become one of the healthcare industry’s greatest assets and the key to greater quality and cost savings over the next five years.xxxv In fact, a recent report by the McKinsey Global Institute, estimates the potential annual value to the healthcare industry at over 300 billion dollars.xxxvi These savings in cost benefit both the patient and provider.
There are also several patient-centered benefits that result from the “meaningful use” EHR data. Perhaps one of the most promising results of EHR data mining is the use of predictive modeling techniques to identify medical conditions and promote interventions before the onset of symptoms. Furthermore, retrospective analysis of the health data mined from EHRs could expedite scientific discovery in medicine by providing valuable information for research. In addition, physicians’ access to data and analysis could demonstrate the efficacy of different treatment options across large populations, which could help treat and prevent chronic conditions. Lastly, such data can be used to identify evidence-based best practices, identify potential patients for clinical trials, and monitor patient compliance and drug safety. These measures show beneficence towards the patient by providing better more individualized care.
Conclusion
EHRs can facilitate the efficient delivery of health care in a cost-effective, safe, and patient-centered way. The safety, privacy, and of patients and potential research participants is of utmost concern and can be maintained while capitalizing on technological advances to improve the United States healthcare system. It is possible to reconcile the use electronic health data for research while maintaining respect for patient’s autonomy. Accomplishing this will require collaboration among ethicists, researchers, clinicians, informatics specialists, and policy makers.xxxvii By reevaluating, clarifying, and enforcing HIPAA guidelines as they pertain specifically to secondary use, the federal government could point the healthcare field in a direction that both protects of patients’ privacy and autonomy while empowering researchers with valuable data sets. Permitting the establishment HIEs and data repositories of EHR data for research purposes has great potential for identifying evidence-based best practices, monitoring patient compliance and drug safety, and showing the efficacy of different treatment options across large populations. However, we must provide patients with the right to dictate which information they choose to share and allow them to opt out of the platform to protect patient autonomy while optimizing the research potential of electronic health data. Moreover, EHRs cannot be considered a cure-all for patient health and we must acknowledge the effect it may have on the physician-patient relationship.
The HITECH Act’s initiatives take us a step closer to President Obama’s stated goal of “an EHR for every American by 2014.”xxxviii The integration of HIT into our health care system is more than just a technological upgrade; it represents a fundamental change in our approach healthcare practice in the United States. EHRs will continue to evolve as a critical component in the medical field, and can be ethically integrated to deliver the highest quality healthcare to Americans in the 21st century.


Thursday, September 26, 2013

Fax Sent to Wrong Number Results in HIPAA Violation


Fax Sent to Wrong Number Results in HIPAA Violation
Fax Sent to Wrong Number Results in HIPAA Violation
Dr. G, 58, was a urologist with a solo practice. His business was thriving, and he employed both a nurse and an office manager to help him.
One morning, the office manager got a call from one of the practice's patients, Mr. M, a 52-year-old, HIV-positive man who had been seeing Dr. G for a decade. Although he was happy with the treatment he had been receiving, Mr. M's company was promoting him and he was relocating to another town. He called to ask Dr. G to fax his medical records to his new urologist.
The office manager was juggling numerous tasks, but managed to send the fax out later that day. The office did not have personalized fax cover sheets, just sheets that the office manager printed off once a week which had spaces to fill in the “to” and “from” sections. She hurriedly filled them in and shot off the fax, one of several she had to do before checking in the next patient.
At the end of the day she told Dr. G that it had been done. He thought nothing of it until the following Monday when the office manager came into the back office to speak to him. She was pale and looked shaken, and the physician immediately asked if she was okay.
“It's Mr. M,” the office manager said. “He just called – absolutely furious. He says that we faxed his medical records to his employer rather than his new doctor, and that now his company is aware of his HIV status. He is extremely upset.”
“I'm so sorry,” the office manager said tearfully. “I was the one who sent that fax out. I must have accidentally grabbed the wrong number from his file. What should we do?” She looked at Dr. G for guidance.
Dr. G was holding his forehead, and trying to figure out how to remedy the situation. “The first thing we're going to do is to call Mr. M and apologize. Then we'll take it from there.”
The office manager and Dr. G called Mr. M and apologized profusely for the mix-up. Mr. M understood that it had not been done maliciously, but he was still not satisfied and reported the incident to the U.S. Department of Health and Human Services' (HHS) Office for Civil Rights (OCR). 
An initial investigation indicated that the incident was not criminal and so it was not referred to the Department of Justice. Rather, it was handled by the OCR. OCR officials appeared at Dr. G's office to look into the matter, and after a thorough investigation, the OCR issued a letter of warning to the office manager, referred the office staff for HIPAA privacy training, and had the office revise the fax cover sheets to underscore that they contain a confidential communication for the intended recipient only.

Legal Background


The Health Insurance Portability and Accountability Act, commonly known as HIPAA, protects personally identifiable health information of patients, and specifies to providers how such information may be used. HIPAA has been in effect for about a decade, and in that time, the HHS has received a total of almost 80,000 complaints.
Of those, more than 44,000 were dismissed, 19,000 were investigated and resolved with changes to privacy practice, and 9,000 were investigated but no violations were found. 
According to HHS, private medical practices were the ones most often required to take corrective action as a result of enforcement. The top two compliance issues most frequently investigated are impermissible use and disclosure of protected health information and lack of safeguards for protected health information.
When a HIPAA complaint is filed with the HHS, the first determination made is whether there was a possible privacy violation and whether it was of a criminal nature. If it was determined to be criminal, the case is referred to the Department of Justice for investigation and possible prosecution. If it was determined that it was not a criminal issue (as in this case) the violation is investigated by the OCR. 
If it is determined that a HIPAA violation did, in fact, take place, the OCR can either obtain voluntary compliance, corrective action or some other voluntary agreement with the offender, or the OCR can issue a formal finding of violation and force the offender to change its practices.
In this particular case, the office manager and Dr. G recognized the mistake and immediately tried to take corrective action by apologizing to the patient. Dr. G's office also voluntarily agreed to extra compliance training for the staff and to a change in their faxing procedures to indicate that the faxed materials are confidential.

Protecting Yourself


This particular scenario was the result of a careless error. While a careless error can happen to anyone, one such as this could cause irreparable harm to the patient if his employer now views or treats him differently because of the new knowledge of his HIV-positive status.
Confidential patient records must be treated with the greatest of care as they contain information of an extremely personal nature. Many HIPAA cases have involved the unintentional divulging of the HIV or AIDS status of a patient. 
In a similar case, a dental practice was reported for using red stickers and the word AIDS on the outside of patient folders. And in a case that took place in a hospital, a nurse and orderly lost their jobs for discussing a patient's HIV status within earshot of other patients.
A good rule of thumb is to treat a patient's confidential information as you would want yours to be treated, and then add a little extra security for good measure.


Wednesday, September 18, 2013

OCR, ONC Release Model Notices for HIPAA Compliance


TOPIC ALERT:

Two HHS agencies have released model notices that health care providers can use to comply with new HIPAA privacy and security rules that take effect in less than a week, Health Data Managementreports (Goedert, Health Data Management, 9/16).

Background

The final HIPAA omnibus rule -- which includes four final rules that implement tougher privacy and security provisions -- was called for under the 2009 federal economic stimulus package's HITECH Act and the Genetic Information Nondiscrimination Act. The rules:
  • Clarify when breaches must be reported to HHS' Office for Civil Rights;
  • Establish new standards for the use of patient-identifiable information for fundraising and marketing;
  • Expand liability to "business associates" of hospitals and other "HIPAA-covered entities," such as data miners and health IT service providers; and
  • Raise the maximum penalty for noncompliance to $1.5 million per violation.
The new federal privacy and security regulations will take effect Sept. 23 (iHealthBeat, 9/10).

Details of Models

The examples were developed by HHS' Office for Civil Rights and the Office of the National Coordinator for Health IT.
OCR and ONC released the model notices in three formats:
  • A booklet;
  • A layered notice with a summary of the information on the first page and full content on additional pages; and
  • A notice with the design elements of a booklet, but formatted for full-page presentation.
Covered entities also can download a text-only version (Miliard, Healthcare IT News, 9/17).

Thursday, August 29, 2013

HIPAA Can Be The Biggest Hurdle In Healthcare M&A

Tony Kong and Matt Sondag, September 2013

The importance of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) is undeniable – protecting an individual’s personal health information is a vital responsibility for any organisation in the healthcare space. Doctors and hospitals (‘covered entities’ in HIPAA lingo) have been doing this for decades, building a trust level with patients. But, for service providers that work with healthcare providers and payers, and especially private equity firms that invest in companies that serve healthcare providers and payers, HIPAA is overwhelmingly complex and, quite frankly, intimidating.

Understanding HIPAA

The Center for Medicaid and Medicare Services (CMS) and Health and Human Services (HHS) established the overall policy and governance for HIPAA. According to CMS, the definition of a Covered Entity (CE) is: (i) a healthcare provider that conducts certain transactions in electronic form (such as claims transactions, electronic prescriptions, and transmitting patient data electronically); and (ii) a healthcare clearinghouse (an organisation that serves and processes EDI transactions, such as claims transactions, eligibility verification, claims status, and remittance vouchers).
Providers and payers have been required to comply with HIPAA regulations since 1996, but in 2009 HIPAA compliance requirements were extended to organisations who are service providers to healthcare providers and payers (Covered Entities) as part of the American Recover and Reinvest Act’s (ARRA) electronic medical record (EMR) initiatives. This was done to provide additional security around patients’ Protected Health Information (PHI) as providers implement EMR systems.
Service providers to covered entities were mandated to sign BAA (Business Associate Agreements) in 2009, therefore making these companies liable under the same HIPAA compliance requirements, and subject to the same level of fines as a covered entity.

HIPAA has been around for years: what’s changed?

In 2012, the HIPAA governing body, HHS, spent $12m to hire a consulting firm to conduct ‘pilot’ compliance audits with covered entities. A year later, the HHS tripled its spend to $40m to audit a larger number of covered entities and business associates. The fines for violations discovered during the audits range from $50,000 up to $1.5m.
During the 2012 audits, one of the most common violations was a lack of encrypted laptops, desktops, tablets and smartphones. It’s an addressable requirement, which means you either have to do it or have a good reason for not doing it (and, therefore, have an equivalent, alternative protection in place). It’s a very low cost item and straightforward to implement, but often ignored.
In one recent case, an employee’s mobile device was stolen in a bar, which triggered an investigation and led to an initial fine of $25,000 due to: (i) failure to have adequate HIPAA compliance policies and procedures as administrative safeguards; (ii) failure to complete HIPAA security training for their staff; (iii) failure to implement access controls as physical safeguards; and (iv) failure to encrypt the information on the device or have an equivalent protection.
However, follow-up audits showed they continued to be out of compliance so the maximum fine of $1.5m was levied against the organisation. These fines are real and companies are feeling monetary pain.

Implement safeguards now to avoid costly penalties later

Private equity firms are, in a sense, two degrees removed from any patient interaction. And yet, if HIPAA isn’t top of mind, it can derail a deal or put your portfolio company in the red. So, how can private equity firms understand the intricacies of what constitutes protected health information, what safeguards need to be in place, and how to manage these controls on an ongoing basis? Without teams and compliance experts on staff, who takes ownership?
Smart private equity firms should implement simple safeguards to protect their investments, as outlined below.
Do your homework early.Conduct a thorough HIPAA due diligence and technical vulnerability scan analysis prior to a transaction to understand your target company’s HIPAA readiness in case of an audit. An initial investment in this readiness review can mitigate your risk and potential fines for gaps discovered during subsequent audits. Evaluate and select the right resources to address the administrative, physical and technical controls required and implement them effectively.

Put it in writingMake sure that HIPAA compliance policies are documented and communicated effectively.
Get everyone on the same page.Conduct training with staff so they understand the importance of HIPAA compliance, as well as the severe penalties associated with non-compliance.
Lock up your devices.Implement access controls for all systems that contain PHI; this includes encrypting all technology in case of loss or theft. With the growth and remote use of mobile devices, tablets, and laptops by employees, this is one of the biggest vulnerabilities to all companies regardless of size. In addition to ensuring encryption of these devices, CIOs, at a minimum, must: (i) have written device security policies and procedures; (ii) hold annual device training sessions with all employees; and (iii) implement system tools and procedures to enforce compliance with these policies and procedures.

Through our work with clients and work on M&A transactions, we have yet to encounter a single mid-market organisation that is fully confident it is ready for a random audit. The frequency of audits is increasing, as are the fines associated with violations, meaning that HIPAA HITECH compliance continues to be a thorn for many companies, especially those under $100m in revenue.
If you are evaluating a new deal or an existing portfolio company that is a business associate to covered entities, you should consider investing in a HIPAA readiness assessment and a technical vulnerability scan analysis.

This will determine the current state of the company’s HIPAA readiness, and serve as a preparatory exercise in the event of a random audit. Often, a readiness review acts as a catalyst for the company to spring into action and prioritize the work needed to address any gaps in administrative, physical and technical controls.

http://www.financierworldwide.com/article.php?id=11061

Tuesday, August 27, 2013

Sept. 23 deadline looms for business compliance with HITECH Act on patient privacy

Organizations handling healthcare data have a month to comply with new security and privacy requirements under the Health Information Technology for Economic and Clinical Health (HITECH) Act.
After Sept. 23, all covered entities, including online storage vendors and cloud service providers, will be subject to new breach notification standards and limitations on how they can use and disclose PHI. They will also be required to ensure that their business associates and subcontractors are compliant with the privacy and security requirements of the Health Insurance Portability and Accountability Act (HIPAA). The HITECH Act amended portions of HIPAA by adding new security and privacy provisions on patient information.
In addition, covered entities will be required to have updated patient privacy notices in place that state the patient's rights over the data and how the data can be used and shared.
Unlike the original HIPAA privacy and security rules, which primarily applied to healthcare organizations and insurance companies, the new HIPAA Omnibus rules apply to business associates and their subcontractors. Under the omnibus rules, a business associate of a healthcare provider, such as a cloud service provider, is directly liable for protecting any patient data it handles, even if the vendor is just storing the data.
Business associates are also liable for ensuring that any subcontractor it hires, such as a document-shredding company, is similarly protecting PHI.
The new rules for safeguarding PHI create a complex liability chain, said Peter MacKoul, president of consulting firm HIPAA Solutions LC. A covered entity or a business associate could face stiff civil penalties for a breach by a subcontractor, regardless of how far down the chain the subcontractor might be, he said.
Under Omnibus HIPAA rules, covered entities and business associates are directly responsible for protecting against the use of PHI by employees, contract workers, trainees and even unpaid volunteers and interns, MacKoul noted.
The rules also give healthcare organizations and business associates less latitude to determine when to make a breach notification, he said.
Previously, a healthcare organization needed to notify individuals of a data breach only if there was a serious risk of financial or reputational harm. Under the new requirements, covered entities and business associates will be required to issue a breach notification in most cases, unless they can specifically show there is a "low probability" of the breached data being misused, MacKoul said.
Healthcare companies will be required to consider four specific factors, including the nature of the data that was breached and whether PHI was acquired or viewed only, to determine the seriousness of a breach. Importantly, breach notification requirements can be triggered even if an employee, contractor or unpaid volunteer uses PHI in an impermissible manner, he said.
Healthcare entities need to identify all their business associates, especially newly covered entities such as data storage companies, and ensure they have proper business associate agreements with them by Sept. 23, said William Maruca, a partner with Fox Rothschild LLP.
Healthcare companies also must have updated patient privacy notices in place by the deadline, Maruca said. The notice must specifically state that the covered entity is required to obtain the patient's authorization to use or sell his or her information for marketing or other purposes and to use or disclose psychotherapy notes, Maruca said. Privacy notices will also need to include a description of how an individual can revoke an authorization and explain their right to receive a notification in the event of a data breach, Maruca said.
"I think the readiness level varies considerably," Maruca noted. "Larger health systems and similar organizations with dedicated health privacy officers may be ahead of the curve, and some savvy smaller entities have been very proactive," he said. But "others are dragging their feet. I think it may take a high-profile enforcement ... to get the attention of the smaller players."
Deborah Peel, founder and chairman of the advocacy group Patient Privacy Rights , noted that while the changes are designed to improve patient privacy, several loopholes remain.
Despite the changes, most health data can still be sold, she said. There is also no chain of custody for health data despite the generally strong security and contract requirements for business associates and subcontractors, Peel said.
As a result there is no way for patients "to obtain a complete map or picture of who used your health information or why. Without a complete data map that tracks all flows of data, we have no idea about the harms and misuses, making it impossible to weigh the risks vs. benefits of using," health information technology systems, she noted.

Thursday, May 30, 2013

CIOs Seek Tech Prescription to Patient Privacy Rule

A new federal rule that gives patients more control over healthcare information they choose to share with insurance companies pose challenges for CIOs who must build out technology to support it. One CIO said software can be fashioned to filter out information before it is passed to another party. But such software raises the sticky issue of who is best positioned—the patient, the physician or another party–to decide when such data is best withheld.
revision to the Health Insurance Portability and Accountability Act requires doctors and hospitals not to disclose medical information to a patient’s insurer if the patient requests it and pays for services themselves. Doctors frequently make notations in their patients’ medical file, which could include information that allows insurers to make inferences about the patient’s health that patients may prefer to keep private. CIOs say that stopping the information from being revealed in notes is difficult, potentially setting up their organizations for paying millions of dollars in compliance penalties.
Beyond compliance issues, the new law brings into question whether patients would be informed enough to know the repercussions of their decisions. Speaking on a hypothetical software solution that would give patients the power to select data they didn’t want to share, Scott Joslyn, CIO of MemorialCare Health System, cited safety concerns. Clinicians would “lack a complete medical picture for the patient,” he said. Patients could check a default box that blocks potentially life-saving information from physicians providing them treatment.
The challenge of data segmentation isn’t limited to healthcare organizations. CIOs in retail and other industries offer consumers services that aim to take advantage of the glut of data people create on social software and mobile devices. Consumers often blindly opt-in, or agree to receive notifications or have their information shared with other service providers without realizing the implications of who they are allowing to do what with their data.
Given the topic, the stakes are higher when it comes to data segmentation and one’s own health records.
Physician notes about treatments provided and medications administered to patients’ healthcare records can help physicians better treat the patient in the future. But this is not always the case. For example, while it might be helpful for a dermatologist to read a note referencing a patient’s allergy to penicillin, a note that he had been treated for alcohol abuse at a clinic 20 years ago may not be germane to the treatment, said John Halamka, CIO of Beth Israel Deaconess Medical Center.
Under the new rule, a patient paying out of pocket for the service can choose that hospitals and physicians block service records from their insurer. This would provide patients more privacy and the peace of mind that insurance providers won’t use the notes as causes to increase health insurance premiums for patients they believe pose increased risks. “I, the patient, want to control data transferred for a specific purpose to a specific person,” said Mr. Halamka. Mr. Halamka equated the concept to the sharing on social networks where the user controls what information to share and with whom.
Mr. Halamka, a co-chair of a federal advisory committee on data standard, said healthcare CIOs need software that can identify potentially sensitive medical annotations in an electronic medical record (EMR), and redact them before the record is transferred. He said the problem could be addressed with an algorithm that automatically tags notes for removal before the record is passed to an insurer. The application would present check boxes that allow users to decide with whom what information gets shared.
Although such software is technically feasible — Facebook Inc. has built something similar for its social graph of over 1 billion users — it raises a significant question: who is best positioned to decide how data is segmented?
Martin Harris, CIO of the Cleveland Clinic, said such data segmentation is a “tricky area” because it is unclear whether the pathologist, a physician or a patient would have to set up the application to keep certain information private. Physicians might have to meet with patients to explain the potential outcome of selecting rules that would block information from the eyes of insurers and others. Even then, trying to account for every single nuance in who can see what is challenging. Mr. Harris said “many people need to be involved in understanding the nuances” of this issue.
These challenges will make it hard for hospitals to meet the Sept. 23 deadline for complying with the Congressional rule revision, which will be enforced by the U.S. Department of Health and Human Services Office for Civil Rights, the agency that oversees HIPAA. HHS declined to make a spokesperson available to comment in time for this article. But a spokesperson for the office told the Wall Street Journal earlier this month that HHS’ “hands are tied” with the out-of-pocket rule because it was mandated by Congress. That puts the onus squarely on CIOs at hospitals charged with implementing technologies and workflow processes that adhere to HIPAA rules.
Judy Hanover, an analyst tracking healthcare for IDC, said the issue is so complex that the only way she could think this could possibly work is if the patients paid cash, used an assumed name and a fake birth date. “It doesn’t fit the workflow in any way… it’s going to be hard to do it,” Ms. Hanover said.
Meanwhile, healthcare CIOs must brace for the fact that more patients may seek to eliminate paper trails by paying for healthcare services out of pocket. And they will reserve their right to have healthcare information stricken from their records. “There will always be a segment of the population that cares about granular control,” Mr. Halamka said.