Saturday, February 13, 2010

HITECH Act's Changes to HIPAA Privacy Rule Soon Taking Effect

Covered entities and business associates subject to the HIPAA Privacy Rule, including health care providers and revenue cycle vendors, should take note that the amendments to the Rule brought about by the Health Information Technology for Economic and Clinical Health Act, §§13400-13424 of the American Recovery and Reinvestment Act of 2009 (the "HITECH Act"), take effect February 17, 2010.

Previously, business associates' only liability for mishandling Protected Health Information (PHI) arose under the business associate's contract with the health care provider, and the only party responsible for ensuring the existence of a proper Business Associate Agreement was the provider itself. Under the amended regulations, a business associate can now be held directly responsible for improper use of PHI and for the failure to maintain proper policies for its protection.  §13404(a).

The HITECH Act makes the following provisions, previously directed at covered entities only, applicable to business associates:

Additionally, while HIPAA previously required action on breaches only by covered entities, the HITECH Act requires business associates to take action on known breaches of their agreements by the covered entities they serve, including curing the breach themselves, terminating the agreement, and/or notifying the department of the covered entity's breach. §13404(b).

The breach notification requirements affecting covered entities and business associates have also changed. The HITECH Act requires notification by a covered entity to the individual whose PHI has been breached, within a reasonable time, not longer than 60 days. Business associates must notify covered entities of any breach within the same time period. The notice must be sent in writing via first class mail, and in the case where the breach concerns 10 or more individuals and the individuals cannot be located, notice must be posted on the breaching party's website and through public media. Notice regarding the breach must also be provided to the Secretary, immediately in the case of a breach concerning 500 or more individuals, and via an annual log in the case of a breach of fewer than 500 individuals. §13402.

The penalties for failing to comply with these provisions include criminal charges, §13409, and civil sanctions, §13410. 

From a practical standpoint, this means that agencies should implement their own documented policies for protecting PHI and should immediately ensure that a Business Associate Agreement is executed with the covered entities with which they do business. Covered entities should review the policies of each and every business associate. If an agreement already exists (which it should), it may need to be amended. It must limit the exchange and use of PHI to the minimum amount necessary for the business associate to carry out its function. HHS has a website discussing the recommended contract language, here. Our sample contract is found below. Note: the agreement requires customization based upon the use of PHI contemplated by the parties' business relationship.

Wednesday, July 1, 2009

Out-of-Network Healthcare Provider Payment News

Florida Senate Bill 1122 takes effect today. The law amends Florida Statutes section 627.638 to require health insurers to make payment directly to hospitals, physicians, and other providers of treatment when the provider is not a member of the insurer's network. Previously, despite the patient's assignment of healthcare benefits to the provider upon admission, some insurance companies relied on language in the member's handbook requiring payment to be made to the patient rather than the provider. Under the new law, the provider should expect to be reimbursed by the plan directly, irrespective of the terms of the patient's member handbook. The Florida Medical Association has more information on this legislation and its benefit at patientsoverprofits.com.

Also of note to healthcare providers, last week the Senate Commerce Committee issued a report for Chairman Rockefeller entitled Underpayments to Consumers by the Health Insurance Industry, detailing the pattern of inadequate payments by Managed Care Organizations for out-of-network treatment resulting from their improper method for calculating the usual and customary rate. We've blogged before about the insurers' use of Ingenix to unilaterally determine out of network provider reimbursement rates, and our law firm has been seeking reconsideration of underpayments on behalf of hospitals and physicians in State and Federal court for many years.

This report explains how underpayment for out-of-network care affects consumers. There is a definite benefit to patients in the ability to seek medical treatment from the provider of their choice, and according to the report insurance companies charge significant premiums for the patients' enjoyment of this benefit - roughly $1,700 per year for a Federal employee, for instance. But this benefit can only be enjoyed in full when the insurer reimburses the provider in accordance with the parties' intentions and with applicable law. According to statistics released by New York Attorney General Andrew Cuomo and cited by the Senate Committee report, health insurers' calculation of usual and customary rates results in payments equaling only 70% of the actual market rate, leaving the patient to pay the remainder, and thereby frustrating enjoyment of the benefit of choice paid for by the consumer. More on this issue as it relates to consumers can be read in this article at Health News Florida.

Attorney General Cuomo, the Senate Commerce Committee and the Florida Legislature are to be applauded by providers and patients alike for seeking to prevent future nonpayment or underpayment, but for the most part their legislative efforts do not address the issue of prior wrongs. Providers should be encouraged to seek independent analysis of the reimbursement rates received for out-of-network services and to seek appropriate and adequate compensation on all claims through available legal remedies.

Wednesday, May 20, 2009

Selling Healthcare Receivables through Established Relationships- The Benefit of Forward Flow Agreements

Selling delinquent debt has become commonplace in many industries, but it remains limited in the healthcare arena, for many reasons. Hospital financial services executives remain concerned with maintaining control over their account inventory and minimizing public relations risks. Moreover, the unique nature of medical debt requires that healthcare providers conduct considerable due diligence before embarking on the sale of their medical debt. The charitable mission of many acute care facilities, along with the public relations concerns that may result from aggressive third party collection tactics, dissuades many providers from selling their debt. Additionally, the absence of secondary markets has served to hold prices down.

However, facilities that have established a relationship with a collection vendor are now more comfortable with the possibility of an outright sale of their debt, as opposed to the traditional contingency fee contract relationship. In fact, forward-flow agreements are becoming more popular as healthcare providers seek to maximize revenue and immediate cash infusions. Ideally, these agreements contemplate the sale of receivables on a monthly basis, with the benefit of a look-back period which allows for more accurate pricing. As hospitals become more comfortable in the sale of their receivables, we expect that forward-flow agreements will become a routine avenue for revenue maximization.

Jorge M. Abril, P.A. encourages its clients to evaluate the sale of their delinquent receivables as a viable strategy for increasing cash revenues while minimizing their public relations risks.

Friday, April 24, 2009

Recovering the Usual and Customary Rate- What the Healthcare Provider Should Know

The settlements reached earlier this year between New York Attorney General Andrew Cuomo and a group comprised of the largest health insurers in the United States have prompted a series of lawsuits throughout the country against major health plans such as Wellpoint, AETNA, and Cigna. A summary of this litigation can be found on this website. Essentially, the lawsuits claim that companies utilizing the Ingenix database have inappropriately manipulated the level of reimbursement paid to providers for out of network medical care to the detriment of members and providers.

When a provider treats a patient needing emergency medical services who subscribes to a health plan that is not contracted with the provider, there is no set rate at which the provider should be paid. Many statutes provide that in this situation the provider is to be reimbursed at the "usual and customary rate." In Florida, for example, according to Florida Statutes section 641.513(5), the plan must reimburse the provider at the lesser of the provider's billed charges, the agreed upon rate, or the usual and customary rate. But few, if any, define what "usual and customary" means or how it should be calculated, and as a result, providers and plans often disagree as to the appropriate level of reimbursement.

The most recent lawsuits should demonstrate to providers of all sizes that they do have recourse when they are being underpaid by one or more Managed Care Organizations. The Healthcare Reimbursement and Latest News sections of our website have more information on how consulting an attorney can be of benefit.

Tuesday, April 21, 2009

HIPAA and President Obama's Economic Stimulus Package

President Obama expects his economic stimulus, the American Recovery & Reinvestment Act of 2009, to affect the lives of many Americans. I, for one, will be attempting to capitalize on the $8,000 tax credit for first time home buyers, which I'm sure you've all heard about.

Lesser known provisions of the legislation have significant effect on the way HIPAA covered entities and business associates handle Patient Health Information (PHI). For example, under the new law, covered entities will be required to notify individuals when there has been a breach of their PHI, and business associates will be required to notify the covered entities they contract with of breaches, regardless of the terms of their contract. There are many other provisions of this new law that healthcare reimbursement professionals who exchange or utilize PHI should note. The text of the request for information created by the Department of Health and Human Services is provided here.

More information is available on this blog, and in this summary, provided by the Center for Democracy and Technology.