Thursday, August 29, 2013

Florida leads nation in another type of inappropriate Medicare billing

Florida health care firms have added a new category of inappropriate Medicare billing to lead the nation in: diabetes test strips.
South Florida was already notorious for nation-leading Medicare fraud in areas like durable medical equipment, mental health centers, prescription drugs, HIV infusion and home health. Now the drain on taxpayers has apparently expanded to another area.
The new report by the Department of Health and Human Services’ Office of Inspector General found a startling amount of the “inappropriate and questionable” Medicare billing in Florida by diabetes test strip (DTS) suppliers in 2010 and 2011.
The Port St. Lucie/Treasure Coast area led the nation with $115 million in questionable DTS billing, with South Florida in second at $113.1 million. They combined for 54 percent of the national total in questionable DTS billing.
After Nashville and New York, the Tampa Bay area placed fifth at $14.2 million.
In the Treasure Coast, 11 of the 79 total DTS suppliers had questionable billing. One provider on the Treasure Coast accounted for the majority of that, $114.7 million.
In South Florida, it was 222 of the 1,125 DTS suppliers who had questionable billing.
The OIG report didn’t identify any suppliers by name, but it gave a few interesting tidbits. One Miami DTS provider stood out for having over four types of questionable billings and $14 million in allowed claims. A Fort Lauderdale supplier ordered 14,741 DTS for store pickup for beneficiaries who lived more than 20 miles away, for a total of $2.3 million in Medicare claims.
Of the 10 suppliers with the highest amount of questionable DTS billing in the nation, the big one on the Treasure Coast tops the list and five from South Florida joined it, including the No. 2 supplier with $19.9 million in questionable billings. A Tampa-area DTS supplier also made the Top 10, giving Florida seven spots.
The OIG said it referred the problematic suppliers to regulators for further action.
Overall in 2011, Medicare paid $1.1 billion in claims for DTS for 4.6 million beneficiaries. Starting in 2011, Medicare put all mail-order DTS in a competitive bidding program in large metro areas, including South Florida. Store bought DTS are not in that program.
The OIG study found that Medicare paid $6 million in clearly unallowable DTS bills plus another $425 million in highly questionable bills. About 10 percent of DTS suppliers had a billing problem.
Reasons that the OIG study considered the DTS claims inappropriate or questionable include them being for a patient without a diagnosis for diabetes, overlapping with an inpatient hospital or nursing home stay, billing for an unusually high number of strips per patient, or billing patients who lived far away from the DTS store. In some cases, suppliers gave beneficiaries “free” DTS and billed Medicare for them, or mailed them DTS but billed Medicare for the more expensive store-bought service, the OIG reported.
The OIG report recommended that Medicare increase its monitoring of DTS suppliers.


Aetna pulls out of New York health insurance exchange

(Reuters) - Aetna Inc, the No. 3 U.S. health insurer, said on Thursday it has decided not to sell insurance on New York's individual health insurance exchange, part of the country's healthcare reform.
New York is the fifth state where Aetna has pulled its application to sell the plans that go on sale on October 1 and into effect on January 1, 2014. It has also reversed course in Maryland, Ohio, Georgia, and Connecticut, where it is based.
Aetna spokesman Cynthia Michener said it made the move after assessing its business strategy, following the acquisition of smaller insurer Coventry Healthcare in May. Coventry also filed applications to sell plans in more than 10 states.
"Our goal for 2014 is to participate in a limited number of state exchanges where we can be competitive and add the most value to the market," she said in an emailed statement.
She said the company will continue to serve small business and large business customers in New York and will offer individual products outside of the exchanges.
New York's market for individuals is currently only about 17,000 people, but the exchange is expected to bring in 1 million people during the first three years. The exchange announced insurance participants on August 20. Aetna was not on the list.
(Reporting by Caroline Humer; Editing by Jeffrey Benkoe)

HIPAA Can Be The Biggest Hurdle In Healthcare M&A

Tony Kong and Matt Sondag, September 2013

The importance of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) is undeniable – protecting an individual’s personal health information is a vital responsibility for any organisation in the healthcare space. Doctors and hospitals (‘covered entities’ in HIPAA lingo) have been doing this for decades, building a trust level with patients. But, for service providers that work with healthcare providers and payers, and especially private equity firms that invest in companies that serve healthcare providers and payers, HIPAA is overwhelmingly complex and, quite frankly, intimidating.

Understanding HIPAA

The Center for Medicaid and Medicare Services (CMS) and Health and Human Services (HHS) established the overall policy and governance for HIPAA. According to CMS, the definition of a Covered Entity (CE) is: (i) a healthcare provider that conducts certain transactions in electronic form (such as claims transactions, electronic prescriptions, and transmitting patient data electronically); and (ii) a healthcare clearinghouse (an organisation that serves and processes EDI transactions, such as claims transactions, eligibility verification, claims status, and remittance vouchers).
Providers and payers have been required to comply with HIPAA regulations since 1996, but in 2009 HIPAA compliance requirements were extended to organisations who are service providers to healthcare providers and payers (Covered Entities) as part of the American Recover and Reinvest Act’s (ARRA) electronic medical record (EMR) initiatives. This was done to provide additional security around patients’ Protected Health Information (PHI) as providers implement EMR systems.
Service providers to covered entities were mandated to sign BAA (Business Associate Agreements) in 2009, therefore making these companies liable under the same HIPAA compliance requirements, and subject to the same level of fines as a covered entity.

HIPAA has been around for years: what’s changed?

In 2012, the HIPAA governing body, HHS, spent $12m to hire a consulting firm to conduct ‘pilot’ compliance audits with covered entities. A year later, the HHS tripled its spend to $40m to audit a larger number of covered entities and business associates. The fines for violations discovered during the audits range from $50,000 up to $1.5m.
During the 2012 audits, one of the most common violations was a lack of encrypted laptops, desktops, tablets and smartphones. It’s an addressable requirement, which means you either have to do it or have a good reason for not doing it (and, therefore, have an equivalent, alternative protection in place). It’s a very low cost item and straightforward to implement, but often ignored.
In one recent case, an employee’s mobile device was stolen in a bar, which triggered an investigation and led to an initial fine of $25,000 due to: (i) failure to have adequate HIPAA compliance policies and procedures as administrative safeguards; (ii) failure to complete HIPAA security training for their staff; (iii) failure to implement access controls as physical safeguards; and (iv) failure to encrypt the information on the device or have an equivalent protection.
However, follow-up audits showed they continued to be out of compliance so the maximum fine of $1.5m was levied against the organisation. These fines are real and companies are feeling monetary pain.

Implement safeguards now to avoid costly penalties later

Private equity firms are, in a sense, two degrees removed from any patient interaction. And yet, if HIPAA isn’t top of mind, it can derail a deal or put your portfolio company in the red. So, how can private equity firms understand the intricacies of what constitutes protected health information, what safeguards need to be in place, and how to manage these controls on an ongoing basis? Without teams and compliance experts on staff, who takes ownership?
Smart private equity firms should implement simple safeguards to protect their investments, as outlined below.
Do your homework early.Conduct a thorough HIPAA due diligence and technical vulnerability scan analysis prior to a transaction to understand your target company’s HIPAA readiness in case of an audit. An initial investment in this readiness review can mitigate your risk and potential fines for gaps discovered during subsequent audits. Evaluate and select the right resources to address the administrative, physical and technical controls required and implement them effectively.

Put it in writing. Make sure that HIPAA compliance policies are documented and communicated effectively.
Get everyone on the same page.Conduct training with staff so they understand the importance of HIPAA compliance, as well as the severe penalties associated with non-compliance.
Lock up your devices.Implement access controls for all systems that contain PHI; this includes encrypting all technology in case of loss or theft. With the growth and remote use of mobile devices, tablets, and laptops by employees, this is one of the biggest vulnerabilities to all companies regardless of size. In addition to ensuring encryption of these devices, CIOs, at a minimum, must: (i) have written device security policies and procedures; (ii) hold annual device training sessions with all employees; and (iii) implement system tools and procedures to enforce compliance with these policies and procedures.

Through our work with clients and work on M&A transactions, we have yet to encounter a single mid-market organisation that is fully confident it is ready for a random audit. The frequency of audits is increasing, as are the fines associated with violations, meaning that HIPAA HITECH compliance continues to be a thorn for many companies, especially those under $100m in revenue.
If you are evaluating a new deal or an existing portfolio company that is a business associate to covered entities, you should consider investing in a HIPAA readiness assessment and a technical vulnerability scan analysis.

This will determine the current state of the company’s HIPAA readiness, and serve as a preparatory exercise in the event of a random audit. Often, a readiness review acts as a catalyst for the company to spring into action and prioritize the work needed to address any gaps in administrative, physical and technical controls.

http://www.financierworldwide.com/article.php?id=11061

Wednesday, August 28, 2013

High-tech monitors will help patients and their caregivers

TVs in your hospital room are so yesterday.
In the near future, flat-screen terminals mounted on the wall or near your bedside might offer a lot more than entertainment. Patients will be able to surf the Internet, order their meals, communicate with nurses and view their latest X-rays — all through interactive patient-care systems.
Educational videos on managing medical conditions, prescription orders and medical records can be flashed on the same screen where patients view dozens of television channels and just-released movies.
“The nice thing is it really puts the patient in the driver’s seat,” said Gary Harper, a registered nurse specializing in information management and communication at the West Palm Beach (Fla.) VA Medical Center in Riviera Beach, Fla., where 259 high-tech terminals should arrive by year’s end. “And it will help the nurses give even better care.”
West Palm Beach VA is one of six veterans hospitals in Florida scheduled to have systems installed in the next year, according to GetWellNetwork Inc., the Maryland technology company handling the project.
Hospital technology experts predict interactive systems, which have been around for more than a decade, will start taking off for one simple reason: They make patients happier. And that could make a big difference to a hospital’s bottom line.
Medicare now collects patient satisfaction data and cuts reimbursements for facilities performing poorly, said Nathan Larmore, a principle-and-practice leader at Sparling, a Seattle-based technology consulting firm advising the health care industry.
And using interactive tools to get patients more involved in their care should reduce hospital readmissions, Larmore said, which is another factor affecting reimbursements.
“In the past, hospitals looked at bedside technologies that improved a patient’s experiences as luxuries. But once they were mandated to focus on patient satisfaction, there was renewed interest,” Larmore said. “Hospitals being built in the last eight years are starting to look more like hotels, which is the industry where some of this technology has come from.”

Larmore estimates that about 10 to 15 percent of acute-care hospitals nationwide have interactive patient terminals. Costs have held many of them back, he said, as systems can run “several hundred dollars to a couple thousand dollars” per room.
“Project managers are used to spending millions of dollars on a fancy lobby, but not several hundred dollars on a television system,” Larmore said.
Children leading the way
Many of the early adopters have been children’s hospitals, he said, “because kids focus on their environment and adapt to the technology.”
Joe DiMaggio Children’s Hospital in Hollywood, Fla., has replaced televisions with interactive monitors. The GetWell Town system, a pediatric product from GetWellNetwork, was part of the new Joe DiMaggio building construction in 2011, then was expanded into the original hospital.
“When we were doing the new building, we talked to the kids about what they wanted, and they said a computer in their room,” said Michelle Barone, director of patient and family centered care for Joe DiMaggio and Memorial Regional Hospital, also in south Florida. “They wanted to be able to get on the Internet and watch movies without waiting for a volunteer to bring them a DVD.”
GetWell Town does all that — plus medical education videos, a hospital-wide game show, and an interface that lets young patients bring in their own Xbox or Wii games.
Barone said Memorial has discussed bringing interactive systems to the adult hospitals, “but right now, it’s all about the numbers,” she said. “When kids are in the hospital, we go above and beyond to cheer them up. We forget that when you’re an adult, you want to be coddled a little, too.”
Officials with the VA, which has its own federal health care funding, say the monitoring systems will greatly improve life for veterans residing in their Community Living Centers, which will be the among the first units to get the terminals.
The Miami VA, the first Florida veterans’ hospital to receive its systems, started the $2.4 million project in June, installing 230 units in the living center and some inpatient rooms.
Chuck Rivenburgh III, 43, is one of four paralyzed vets in Miami’s living center who got a “sip and puff” adapter, allowing him to flip through 48 television channels and pick from among 30 recently released movies by blowing through what looks like a double-pronged straw. The monitor is mounted on a flexible arm attached to the wall, allowing it to be pulled close to Rivenburgh’s bedside.
Rivenburgh, who served in the Army during Desert Storm but was injured after returning home, has lived at the VA hospital for 14 years. Before the GetWell system, he said he was limited to 14 TV channels, none of which included NFL games.
He is thinking of adding a keyboard to his tray table so he can access the Internet through his bedside monitor rather than at the computer on the other side of his crowded room.
“My TV is on pretty much all day long, so all these functions are a huge improvement,” he said.
Louis Marcus, GetWell’s interactive patient care manager for the South Florida VA installations, said the system will be upgraded so that doctors and nurses can leave notes, check pain levels and allow patients to order meals. Such terminals will become even more valuable as medical records go electronic, Marcus said.
As for the veterans, “The feedback has been great,” Marcus said. “I had one family who was visiting sit down with me for half an hour and tell me how grateful they were.”

The Centers for Medicare and Medicaid Services has released a fact sheet on participating in the 2013 Physician Quality Reporting System/Medicare Electronic Health Record Incentive Pilot Program.


Under the program, eligible professionals can meet Stage 1 meaningful use clinical quality measure reporting requirements while also reporting for the PQRS program by submitting their clinical quality data electronically. Participating physicians must submit 12 months of CQM data between Jan. 1 and Feb. 28 of 2014.
The six-page fact sheet covers determining eligibility for the program, indicating intent to participate, verifying that an EHR vendor is PQRS-certified and the EHR is MU-certified, choosing measures to report, generating required reporting files, and submitting test data prior to data submissions for payment, among other issues. 
The fact sheet is available here.

7 Accountable care groups serving Medicare patients in Illinois

CHICAGO (AP) — More than 200,000 Illinois Medicare patients will have their health care needs coordinated by federally designated accountable care organizations. 

Below is a list of the seven ACOs based in Illinois and another six based in other states but serving some Illinois patients:
  • Alexian Brothers Accountable Care Organization, based in Arlington Heights: 16,000 Medicare patients.
  • Christie Clinic Physician Services, Champaign-Urbana: 7,500 Medicare patients.
  • Independent Physicians' ACO of Chicago: 14,000 Medicare patients.
  • Medicare Value Partners (Presence Health), Chicago: 18,000 Medicare patients.
  • Advocate Physician Partners Accountable Care, Rolling Meadows: 119,000 Medicare patients.
  • Chicago Health System ACO (Vanguard Health Systems), Westmont: 9,800 Medicare patients.
  • OSF Healthcare System, Peoria: 33,000 Medicare patients.

_______
Accountable care organizations in other states with Illinois Medicare patients:
  • Franciscan Union ACO, Terre Haute, Ind.: 1,700 Illinois Medicare patients.
  • BJC HealthCare ACO, St. Louis: 5,500 Illinois Medicare patients.
  • Deaconess Care Integration, Evansville, Ind.: 760 Illinois Medicare patients.
  • Jackson Purchase Medical Associates, Paducah, Ky.: 550 Illinois Medicare patients.
  • UnityPoint Health Partners, West Des Moines, Iowa: 19,400 Illinois Medicare patients.
  • Genesis Accountable Care Organization, Davenport, Iowa: 5,600 Illinois Medicare patients
http://www.necn.com/08/27/13/Accountable-care-groups-serving-Medicare/landing_nation.html?&apID=ed3c92a746584a93ac28aa164e00ecff

Telemedicine conference speakers say technology to connect patients, doctors is "effective and efficient" | jacksonville.com

Telemedicine, the delivery of health care services using technology such as video conferencing, is “a cost-effective, hassle free and patient centered” approach to health care.
That’s the message State Rep. Cary Pigman and a dozen other speakers delivered Tuesday during the 2013-2014 Telemedicine Public Policy Symposium, held at the Mayo Clinic’s Jacksonville campus.
The symposium was hosted by State Rep. Mia Jones of Jacksonville and by Pigman, an emergency physician. After the conference, Jones said she and Pigman plan to co-sponsor a bill that would require Medicaid and private insurers in Florida to reimburse health care providers who treat patients using telemedicine. Currently, 21 states have such legislation.
Telemedicine “is effective and efficient,” said Anne Burdick, the associate dean for Telehealth and Clinical Outreach at the University of Miami Miller School of Medicine. “It should be reimbursed.”
“So much of what we do in health care is directed toward rescue,” Pigman said. “This would enable [physicians] to do more maintenance and preservation.”
Jeff Wacksman, practice operations director for Mobile Physician Services, which provides in-home visits to homebound patients in the Tampa Bay area, noted that 5 percent of Medicaid patients account for 54 percent of Medicaid spending.
One major reason the care of those patients is so expensive is that “they are accessing health care at its most expensive point” by showing up often in emergency rooms.
Providing new ways for such people to access health care could save a lot of money, he said. In fact, if the law were changed to allow homebound patients anywhere in the state to be treated in their homes using telemedicine approaches, the state could save billions, Wacksman said.
Toree Malasanos, a pediatric endocrinologist who is director of the Florida Initiative in Telehealth and Education at the University of Florida, said that using telemedicine techniques to treat kids with diabetes at a clinic in Daytona Beach had resulted in a 70 percent drop in emergency room visits and an 88 percent decrease in hospitalizations.


Telemedicine conference speakers say technology to connect patients, doctors is "effective and efficient" | jacksonville.com

Yakima Doctor convicted of Medicare fraud to forfeit $129K

YAKIMA, Wash. — A sentencing hearing has again been postponed in the case of Dr. Curtis Holden, who late last year was convicted of Medicare and Medicaid fraud. However, under a recent settlement, Holden agreed to pay $129,000, far less than what a jury found he stole from the U.S. government.
Holden, formerly of Advanced Podiatry Specialists of Yakima, was convicted in early December on 32 counts of health care fraud for routinely “upcoding” patient visits billed to Medicare and Medicaid, effectively changing patient records to exaggerate what services he had performed in order to get higher reimbursement from the government.
Prosecutors in the case said his fraudulent billing practices lasted for several years in the 2000s, though the counts on which he was found guilty are from 2006 and 2007.
In the forfeiture document, filed Friday, Holden agreed to turn over his 2004 BMW X5 along with $129,675.84 seized by the FBI from various bank accounts.
The document also noted that Medicare is still holding $54,157.32 in payments that Holden had billed but the government suspended when it discovered he had misrepresented the services billed.
The forfeited funds will go directly toward restitution to the government health plans. The document says that figure “settles all criminal and civil claims” filed last June and “the Complaint for Violations of Federal False Claims Act” filed in June 2010.
The government previously contended that Holden owes Medicare and Medicaid about $630,000 more than the settlement amount. But the defendant disputed the sum, and at a hearing on the matter, “the amount was compromised,” according to court documents.
Assistant U.S. attorney Joe Harrington said the settlement was determined to be appropriate by both parties, and that the decision to accept the figure was made by U.S. attorneys after consulting with Medicare. Part of the reason for settling was the “litigation risk” attorneys would carry if they tried to further pursue the full amount in court.
“We have an adversarial criminal justice system; there’s two sides to every story ... There’s always litigation risk that your position wouldn’t be accepted by the court,” Harrington said.
The court has scheduled Holden’s sentencing hearing for Oct. 22. It was originally scheduled for July 9, then was pushed back by a postponement of the forfeiture hearing, which was canceled this week as the two parties came to an agreement on forfeiture motions.
It’s possible Holden could receive a prison sentence, but Harrington said it would be impossible to speculate on that likelihood.


Mobile Doctors CEO, physician charged with Medicare fraud

The head of a Chicago-based company that manages physicians who make house calls and one of its most prolific doctors were arrested Tuesday on charges the company fraudulently billed Medicare for millions of dollars by inflating the level of care given patients.
A criminal complaint charged Dike Ajiri, chief executive officer of Mobile Doctors, with health care fraud and Banio Koroma, a physician who has worked for the company since 2007, with making false statements.
Federal agents raided Mobile Doctors' headquarters in the 3300 block of North Elston Avenue and branch offices in Detroit and Indianapolis and also sought to seize about $2.6 million in alleged fraudulent proceeds from various bank accounts, prosecutors said.
During a brief hearing at the Dirksen U.S. Courthouse, U.S. Magistrate Judge Mary Rowland ordered Ajiri, 42, of Wilmette, held in custody at least until a detention hearing Thursday. Koroma, 63, of Tinley Park, was freed on $50,000 bail but barred from contact with patients.
Before the hearing, Ajiri, a former college football and rugby player, stood with his hands cuffed behind his back, joking with supporters in the courtroom.
Prosecutors said that Mobile Doctors operates in six states, arranging hundreds of thousands of home visits and contracting with doctors who perform the visits. Current and former employees and doctors told investigators that a typical visit with a patient lasts 10 to 30 minutes and is routine in nature.
But according to the charges, Ajiri schemed over the last seven years to increase Medicare billings by falsely claiming the patient visits were more complicated and took longer than they actually did.
A former manager of the Chicago office told investigators that Ajiri set up a system so that the two highest fee codes allowed by Medicare automatically kicked in so that patient visits would be worth the doctors' time and the cost of gas, according to prosecutors.
According to the complaint, the manager quoted Ajiri as telling his physicians, "I don't pay for the ones or twos," a reference to the lower fee codes. From 2006 to 2012, Mobile Doctors received more than $34 million in payments on claims using the two higher codes, according to the charges.
The charges also alleged that Mobile Doctors' physicians falsely certified that patients they visited were confined to their homes, enabling home health care agencies to claim fees for additional services for patients who were not actually qualified to receive them.
Some 16,000 patients had been certified as homebound by the company since 2006, leading to more than 83,000 home health visits, many of them fraudulent, according to prosecutors. Koroma alone accounted for more than 6,000 of the certifications and allegedly billed Medicare for about 17,500 patient visits he made, more than any other Mobile Doctors physician, prosecutors said.

Tuesday, August 27, 2013

Researchers Create New 'Education-Centered Medical Home' Teaching Model

August 26, 2013 02:46 pm Sheri Porter – Researchers at the Northwestern University Feinberg School of Medicine in Chicago confronted two opposing truths back in 2011. The AAFP-supported patient-centered medical home (PCMH) model of care -- a team-based model that features easily accessible, high-quality health care coordinated by a primary care physician -- was gaining popularity nationwide as a means of improving patient care and lowering health care costs, but few medical schools were introducing PCMH concepts to students via curricular changes.
As a result, researchers set out to test the feasibility of a longitudinal clerkship based on PCMH principles and anchored by PCMH educational objectives. Researchers developed a model they dubbed the "education-centered medical home" and enlisted 56 student volunteers and four faculty preceptors from the medical school to participate in a study from June 2011 to April 2012.
The overall objective, according to study authors, was to "assess the feasibility and perceptions of an education-centered medical home clerkship on students and preceptors."
At the study's conclusion, program evaluations completed by participants revealed that students gained confidence in their understanding of PCMH principles and, in particular, appreciated experiencing early clinical exposure, continuity of care with patients and peer teaching. Faculty members also responded positively. In fact, all preceptors and 39 of 42 non-graduated students said they wanted to continue participation in the education-centered medical home clinics in the 2012-13 academic year.
STORY HIGHLIGHTS
  • Researchers at Northwestern University Feinberg School of Medicine tested the feasibility of a longitudinal clerkship based on patient-centered medical home (PCMH) concepts and anchored by PCMH educational objectives. 
  • They created an "education-centered medical home" model and enlisted 56 volunteer medical students and four physician preceptors to participate in a study from June 2011 to April 2012. 
  • Students liked the early clinical exposure, continuity of care and peer teaching experiences; all four preceptors and 39 of 42 non-graduated medical students wanted to continue participation in the model. 
The research is summarized in an article titled "The Patient-Centered Medical Home as Curricular Model: Perceived Impact of the 'Education-Centered Medical Home'(link.springer.com)" in the August 2013 issue of the Journal of General Internal Medicine.

Program Setup

For purposes of the study, education-centered medical homes were established at four existing faculty practices. Two of the clinic sites are federally qualified health center family medicine clinics, another is an academic general internal medicine clinic, and the fourth is an academic pediatric pulmonary clinic. Student teams were formed with first-, second-, third- and fourth-year medical students on each team. High-risk patients were recruited in each setting. Clinical education was achieved via a traditional physician preceptor model with the additional component of third- and fourth-year students directly observing first- and second-year students. All students attended monthly grand rounds conferences.
Curriculum was developed with three objectives in mind. Researchers aimed to
  • maximize student continuity experiences with patients, preceptors and peers;
  • demonstrate patient-centered care principles of the PCMH model; and
  • incorporate students in the delivery of PCMH care as health coaches and coordinators.
Researchers said the implementation of the education pilot at the Feinberg School of Medicine was a success and announced plans to expand the model in the 2012-13 academic year. They also acknowledged the study's limitations. For example, the authors said establishment of an education-centered medical home "would require significant financial resources and a substantial number of preceptors to incorporate all students at an institution."

Corresponding Author Answers Questions

AAFP News Now asked corresponding author Daniel Evens, M.D., an assistant professor of medicine-general internal medicine and geriatrics at Northwestern University Feinberg School of Medicine to answer a few questions about the project.
Q. What drove your interest in giving medical students training in a PCMH setting?
A. My career path as a "hybrid" ambulatory/hospitalist physician has placed me three months per year on our inpatient teaching service and the rest of the year in the clinic as a primary care physician. As a result, I recruited a large number of medically complex patients to my panel, and I have learned the hard way how difficult it is to coordinate care for these patients with chronic illness.
I've come to appreciate that there is no way that I can do it alone, and that I need a team to help me manage these patients. I also learned that medical students are eager to have continuity with complex patients and are willing to help with service learning projects.
During our recent curriculum renewal at Feinberg, we floated the idea of merging the needs of our primary care docs (e.g., the need for care coordinators and health coaches for our complex patients) with the desires of our students (e.g., the desire to have continuity with a panel of patients and learn how to manage chronic illness) into a new educational model called the education-centered medical home.
Q. What do you make of the highly positive evaluations from participating students and preceptors?
A. The positive student reaction to our education-centered medical home was not a surprise to our steering group. We knew that the average medical student was graduating after four years having never seen a single patient back for a continuity visit, so we knew that any program focused on continuity would be well received. The major question before our steering group was whether or not we could we create a program that was feasible from the viewpoint of the preceptors, and our retention of 13 out of 13 preceptors from last year's program gives us tremendous confidence that we are on the right track.
Q. Did the findings hold any surprises for you and your colleagues?
A. We started with the model of 16 students per preceptor mainly out of convenience (it was a multiple of four, easy for organizing four classes of students) and out of necessity (our limited funding required a large student-to-preceptor ratio). However, we were delighted to learn just how impactful it was for our preclinical students to pair up and have third- and fourth-year students directly observing patient encounters as peer teachers. The peer teaching aspect of the education-centered medical home ended up being rated just as highly as the continuity aspect of the program, and this was a wonderful unintended consequence of our 16:1 preceptor formula.
Q. Can immersing students in the PCMH model via the education-centered medical home help drive students to primary care specialties?
A. It will take several years to find out if our education-centered medical home program impacts the career choice of our graduates. We certainly hope that placing students into high-functioning primary care clinics that are committed to practice transformation will inspire some students to become medical home leaders themselves. Just as important, we hope that our graduates who still choose (sub)specialty practice will have a better understanding of the scope of primary care medicine and will be better prepared to be collaborative medical neighbors in the future.
Q. What's the most important take-away message from this project?
A. There is a large appetite among our students for continuity experience and the opportunity to learn about the medical home model. Our trainees are excited to work in the PCMH environment, and medical educators need to advocate on their behalf to create opportunities to involve them in practice transformation activities. For our part, we are happy to collaborate and share teaching materials with other institutions who are considering similar programs.

OIG Advisory Opinion supports remote health monitoring arrangements

In an Advisory Opinion posted on Aug. 16, 2013, the Office of Inspector General (OIG) of the Department of Health and Human Services (HHS) assessed an arrangement under which a vendor of technology platforms (the “Vendor”) proposed to contract with hospitals to provide services to certain patients following hospital discharge in an effort to reduce preventable hospital admissions (the “Arrangement”). The OIG concluded that it would not impose penalties under the Anti-Kickback Statute even though the Arrangement could potentially generate prohibited remuneration if the requisite intent was present. The OIG further concluded the Arrangement would not constitute grounds for the imposition of civil monetary penalties under a provision prohibiting inducements to beneficiaries.
The Proposed Arrangement
The Vendor, a wholly-owned subsidiary of a pharmaceutical manufacturer, has developed technology platforms and services that are designed to help hospitals avoid payment reductions associated with excess readmissions by coordinating care and facilitating patient adherence to discharge plans. The Vendor will offer the Arrangement to hospitals either directly or indirectly through a group purchasing organization (GPO), patient-centered medical home (PCMH) or managed care organization (MCO). Agreements for the Arrangement would be in writing, for a term of at least one year, fees would be set at fair-market value and discounts would be structured in compliance with the discount exception to the Anti-Kickback Statute. Fees for the Arrangement will include (1) an initial flat fee; (2) an annual fee, based on patient volume, which can only be adjusted and increased if the actual use exceeds the baseline use already paid for by the annual fee; and (3) additional fees for additional services requested by a hospital.
Services provided by the Arrangement (the “Services”) include the availability of patient liaisons to monitor a participating patient’s adherence to the hospital discharge plan and his or her current health status. The Services would also include scheduling follow-up appointments, the provision of refill reminders, transportation support and the generation of reports to help the hospitals monitor the use of the Services and readmission rates. Finally, the Vendor certified that neither the Vendor nor nurses contracted by the Vendor would promote the pharmaceutical manufacturer’s products. In addition, regardless of the patient’s question or symptom, the nurses contracted by the Vendor would not refer the patient to any provider or supplier other than the patient’s established providers and suppliers.
Minimal Risk Under the Anti-Kickback Statute
Although the parties to the Arrangement are potential referral sources (i.e., the hospital’s staff is in a position to order drugs manufactured by the Vendor’s parent company and the Vendor’s employees could refer patients to the hospital), the OIG concluded the Arrangement posed a low risk of fraud and abuse under the Anti-Kickback Statute for the following reasons:
  1. The Arrangement is unlikely to lead to increased costs or overutilization. In contrast, the Services could actually save federal healthcare programs money if the Arrangement is successful in furthering its goal of decreasing hospital readmissions.
  2. The Arrangement is unlikely to interfere with clinical decision-making. The Services would be rendered after a participating patient is diagnosed and discharged from the hospital.
  3. The purpose of the Arrangement is to promote compliance with a participating patient’s discharge plan and all prescribed therapies, regardless of which drugs are prescribed to the patient. The Vendor certified that it would implement a number of safeguards to prevent the Arrangement from being used to increase drug sales by the pharmaceutical manufacturer. Further, the Vendor certified that the fees charged would be consistent with fair market value in an arm’s length transaction.
  4. The Arrangement is unlikely to result in inappropriate patient steering. Individuals contracted by the Vendor to interact with participating patients would be prohibited from referring the patients to any provider, practitioner or supplier other than a patient’s established provider, practitioner or supplier.
Beneficiary Inducement Concerns Do Not Exist
The OIG may assess civil monetary penalties against an individual if the individual offered or transferred remuneration to Medicare or Medicaid beneficiaries and the individual knows, or should have known, that the remuneration is likely to influence a beneficiary to order or receive a federally payable item or service from a particular provider, practitioner or supplier. The OIG found that although the participating patients would receive a valuable service without cost under the Arrangement, the Arrangement is a low-risk method of guiding patients through the post-discharge period without influencing a participating patient to order or receive a federally payable item or service or limiting a participating patient’s choice of provider, practitioner or supplier.

Sept. 23 deadline looms for business compliance with HITECH Act on patient privacy

Organizations handling healthcare data have a month to comply with new security and privacy requirements under the Health Information Technology for Economic and Clinical Health (HITECH) Act.
After Sept. 23, all covered entities, including online storage vendors and cloud service providers, will be subject to new breach notification standards and limitations on how they can use and disclose PHI. They will also be required to ensure that their business associates and subcontractors are compliant with the privacy and security requirements of the Health Insurance Portability and Accountability Act (HIPAA). The HITECH Act amended portions of HIPAA by adding new security and privacy provisions on patient information.
In addition, covered entities will be required to have updated patient privacy notices in place that state the patient's rights over the data and how the data can be used and shared.
Unlike the original HIPAA privacy and security rules, which primarily applied to healthcare organizations and insurance companies, the new HIPAA Omnibus rules apply to business associates and their subcontractors. Under the omnibus rules, a business associate of a healthcare provider, such as a cloud service provider, is directly liable for protecting any patient data it handles, even if the vendor is just storing the data.
Business associates are also liable for ensuring that any subcontractor it hires, such as a document-shredding company, is similarly protecting PHI.
The new rules for safeguarding PHI create a complex liability chain, said Peter MacKoul, president of consulting firm HIPAA Solutions LC. A covered entity or a business associate could face stiff civil penalties for a breach by a subcontractor, regardless of how far down the chain the subcontractor might be, he said.
Under Omnibus HIPAA rules, covered entities and business associates are directly responsible for protecting against the use of PHI by employees, contract workers, trainees and even unpaid volunteers and interns, MacKoul noted.
The rules also give healthcare organizations and business associates less latitude to determine when to make a breach notification, he said.
Previously, a healthcare organization needed to notify individuals of a data breach only if there was a serious risk of financial or reputational harm. Under the new requirements, covered entities and business associates will be required to issue a breach notification in most cases, unless they can specifically show there is a "low probability" of the breached data being misused, MacKoul said.
Healthcare companies will be required to consider four specific factors, including the nature of the data that was breached and whether PHI was acquired or viewed only, to determine the seriousness of a breach. Importantly, breach notification requirements can be triggered even if an employee, contractor or unpaid volunteer uses PHI in an impermissible manner, he said.
Healthcare entities need to identify all their business associates, especially newly covered entities such as data storage companies, and ensure they have proper business associate agreements with them by Sept. 23, said William Maruca, a partner with Fox Rothschild LLP.
Healthcare companies also must have updated patient privacy notices in place by the deadline, Maruca said. The notice must specifically state that the covered entity is required to obtain the patient's authorization to use or sell his or her information for marketing or other purposes and to use or disclose psychotherapy notes, Maruca said. Privacy notices will also need to include a description of how an individual can revoke an authorization and explain their right to receive a notification in the event of a data breach, Maruca said.
"I think the readiness level varies considerably," Maruca noted. "Larger health systems and similar organizations with dedicated health privacy officers may be ahead of the curve, and some savvy smaller entities have been very proactive," he said. But "others are dragging their feet. I think it may take a high-profile enforcement ... to get the attention of the smaller players."
Deborah Peel, founder and chairman of the advocacy group Patient Privacy Rights , noted that while the changes are designed to improve patient privacy, several loopholes remain.
Despite the changes, most health data can still be sold, she said. There is also no chain of custody for health data despite the generally strong security and contract requirements for business associates and subcontractors, Peel said.
As a result there is no way for patients "to obtain a complete map or picture of who used your health information or why. Without a complete data map that tracks all flows of data, we have no idea about the harms and misuses, making it impossible to weigh the risks vs. benefits of using," health information technology systems, she noted.

Monday, August 26, 2013

3 quality, coordination lessons from the Beacons

Being able to digitally submit clinical quality measures (CQMs) to Medicare is one of the big promises of health IT for physicians and providers — and it’s still coming, along with other administrative simplifications.
But digital CQMs have been put to good use on the ground by some of the 17 Beacon Communities, the Office of the National Coordinator for Health IT argues in an issue brief. As the ONC and the Centers for Medicare & Medicaid Services finalize novel eCQMs for Medicare, in the areas of clinical care, care coordination and outcomes, here are three lessons from the Beacons on using quality measurements.
1. Beyond billing.
One common complaint from some physicians has been that particularly older EHR software systems are mostly designed for documentation and billing, with analysis tools being limited and not very usable.
Nowadays, providers are increasingly able to put their EHRs to use measuring their patients’ trends and their clinical performance, which can help develop a culture of improvement — providers turning to their data to scrutinize their care quality.
Through the Crescent City Beacon Community, in New Orleans, 17 providers worked with payers, vendors and other partners to start standardizing digital clinical data, with the goal of using the local health information exchange as a source of clinical quality measures.
Before they can do that, the health data is being validated. Data accuracy is especially important in a city where thousands of patients’ paper-based medical histories were lost to the floods of Hurricane Katrina.
The community-wide HIE will eventually be put to use reporting quality measures, offering community dashboards, provider performance and Meaningful Use reports.
The HIE is also currently deploying a software offering the ability to track patients and coordinate their care management across settings.
2. Aligning CQMs with value-based payments.
Much as Farzad Mostashari, MD, has heralded the decline of fee-for-service (often Tweeting #FFSdemise), only a minority of the healthcare services rendered in the U.S. are currently reimbursed through some type of accountable care or valued-based contract.
Still, healthcare made accountable or measured for value is happening, such as in Indiana. Through the Central Indiana Beacon Community’s Quality Health First program, the Indiana Health Information Exchange offers analytics and patient summaries for docs — showing them, for instance, all patients due for preventative screenings — to help them develop intervention and management programs for patients with chronic diseases.
The program helps providers submit Meaningful Use compliance attestation reports, and lets payers access clinical data, beyond claims, to track provider performance and tailor reimbursement. As of January, 114 provider groups representing 2,252 primary care physicians and 1.4 million patients have participated in the program.
3. Building consensus among unaffiliated orgs.
Fee-for-service’s “misaligned incentives” resulted in a culture of health organizations often only reluctantly sharing patient data with unaffiliated providers, if not “hoarding” the data by default, and that’s resulted in poorly coordinated care for some patients being served by primary care doctors, specialists, hospitals and other providers. And that’s in addition to patients having to navigate healthcare finances from separate providers.
In Bangor, Maine, the small city where Stephen King lives, the Bangor Beacon Community in large part incentivized collaboration for the care of the region’s most vulnerable, with clinicians and care managers meeting to discuss disease management strategies, and robust HIE services performing the bulk of the data management.
The Beacon launched a care coordination project for patients with diabetes, congestive heart failure, COPD and/or asthma, among 124 primary care doctors from three large healthcare organizations, Eastern Maine Medical Center, St. Joseph Hospital, and Penobscot Community Health Care.
For those patients, hospital admissions decreased 42 percent, emergency room visits by 43 percent, and walk-in care visits decreased by 75 percent over the course of 2011 and 2012.
With the goal of tracking the quality of care particularly for diabetes, heart disease, COPD and asthma, the collaborative approved data definitions, revised operational terms, identified regional target goals, and created common EHR patient encounter forms and workflow processes. Powered by Maine HealthInfoNet, the statewide HIE, the providers use a data registry that’s automated with their EHRs and sends them patient summaries.
The Bangor Beacon was successful with multi-organization quality metrics, the ONC concluded, in part because the “third-party centralized disease registry fostered a simplified, less competitive environment for negotiating data sharing agreements.” It also meant independent checks of data integrity.



Health care companies get new sustainability accounting standards

Friday, August 23, 2013

HHS settles with health plan in photocopier breach case


Under a settlement with the U.S. Department of Health and Human Services (HHS), Affinity Health Plan, Inc. will settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules for $1,215,780.  Affinity Health Plan is a not-for-profit managed care plan serving the New York metropolitan area.

Affinity filed a breach report with the HHS Office for Civil Rights (OCR) on April 15, 2010, as required by the Health Information Technology for Economic and Clinical Health, or HITECH Act. The HITECH Breach Notification Rule requires HIPAA-covered entities to notify HHS of a breach of unsecured protected health information.  Affinity indicated that it was informed by a representative of CBS Evening News that, as part of an investigatory report, CBS had purchased a photocopier previously leased by Affinity.  CBS informed Affinity that the copier that Affinity had used contained confidential medical information on the hard drive.

Affinity estimated that up to 344,579 individuals may have been affected by this breach. OCR’s investigation indicated that Affinity impermissibly disclosed the protected health information of these affected individuals when it returned multiple photocopiers to leasing agents without erasing the data contained on the copier hard drives.  In addition, the investigation revealed that Affinity failed to incorporate the electronic protected health information (ePHI) stored on photocopier hard drives in its analysis of risks and vulnerabilities as required by the Security Rule, and failed to implement policies and procedures when returning the photocopiers to its leasing agents. 

"This settlement illustrates an important reminder about equipment designed to retain electronic information: Make sure that all personal information is wiped from hardware before it’s recycled, thrown away or sent back to a leasing agent," said OCR Director Leon Rodriguez.  “HIPAA covered entities are required to undertake a careful risk analysis to understand the threats and vulnerabilities to individuals’ data, and have appropriate safeguards in place to protect this information.”

In addition to the $1,215,780 payment, the settlement includes a corrective action plan requiring Affinity to use its best efforts to retrieve all hard drives that were contained on photocopiers previously leased by the plan that remain in the possession of the leasing agent, and to take certain measures to safeguard all ePHI.

For more information on safeguarding sensitive data stored in the hard drives of digital copiers: http://business.ftc.gov/documents/bus43-copier-data-security. 

The National Institute of Standards and Technology has issued guidance on media sanitation: http://csrc.nist.gov/publications/drafts/800-88-rev1/sp800_88_r1_draft.pdf. 

OCR offers free training on compliance with the HIPAA Privacy and Security Rules for continuing medical education credit athttp://www.medscape.org/sites/advances/patients-rights.


The HHS Resolution Agreement and CAP can be found on the OCR website athttp://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/affinity-agreement.html

HHS settles with health plan in photocopier breach case