Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Monday, March 28, 2016

New Round of HIPAA Audits For Business Associates and How to Survive Them

As the role of analytics and electronic health records systems grows in healthcare, the number of vendors interacting with patient data has grown exponentially. Because of the numerous access points to patient data, the federal government appears to be clamping down on the sometime porous flow of patient data handled by contractors, whose security failures have been linked to the exposure of nearly 33 million individuals' medical records since 2009.

Under HIPAA, these contractors are referred to as “business associates.” And now, these business associates will be included as primary audit targets in the second round of HIPAA audits by the Department of Health and Human Services’ Office for Civil Rights.

The audit of business associates is necessary to keep out firms who are insincere about becoming HIPAA compliant, and are thus reckless with patient data.

According to Adam Greene, a partner in the Washington, D.C., office of Davis Wright Tremaine, some larger healthcare organizations have employed hundreds and in some cases as many as a thousand business associates.

In one sense, by including the business associates, the civil rights office is simply catching up with privacy and security rules it issued three years ago. But the OCR announcement also means that enforcement of these more stringent rules could give healthcare organizations more leverage to get stronger agreements with their contractors.

Upgrades to the HIPAA privacy and security rules in the health IT provisions of the American Recovery and Reinvestment Act of 2009 puts BAs on an equal legal footing with HIPAA covered entities – hospitals, physician practices, health plans and claims clearinghouses. That means vendors that violate the rules are subject to civil monetary penalties of up to $1.5 million a year.

The first phase of audits will involve OCR staff and special hires conducting “desk audits,” not requiring agents to go into the field. Covered entities will be asked to provide basic information about their business associates. “It won't be a complete list,” Green said, but it will provide a starting point for identifying business associates to audit.

Just as business associates now share equal legal liability under HIPAA, they've long shared culpability for data breaches, according to federal records.

That said, how can business associates “survive” a HIPAA audit? According to Hayes Management Consulting, there are six key steps to getting through a HIPAA audit successfully.

First, prepare and practice. Before the OCR audit, conduct an internal round of HIPAA compliance audits and risk assessment. To impress OCR, show proof of conducting such assessments on a regular schedule.

Second, evaluate your privacy and security policies. Perform an in depth assessment of your current privacy and security policies and procedures, or active HIPAA compliance program. Similarly, designate a HIPAA Compliance Officer. HIPAA privacy compliance should focus on PHI access, administrative requirements, uses and disclosures. For security compliance, concentrate on administrative physical and technical safeguards.

Third, perform an internal review of electronic files. Encrypt all electronic files, especially patient sensitive data. Verify and validate which electronic files are being encrypted, and which are not. Do this before any external audits are done.

Fourth, assess organization compliance risks. OCR Phase 1 HIPAA Audits revealed two-thirds of organizations could not demonstrate they were performing complete and accurate HIPAA security risk assessments. To ensure that your organization can meet compliance standards, start by inventorying all of the organization’s systems that handle ePHI, and develop some remediation action plans.

Fifth, compile a list of all vendors and business associates. OCR will ask to see all business associates that have access to your organization’s PHI. Include anyone that works behind the scenes with your hospitals, health plans or providers. For example, such associates include contractors, consultants, software vendors, and data storage companies.  

Sixth and finally, evaluate, evaluate, evaluate. Inspect your HIPAA policies and procedures, most importantly employee access, new hire employee training, ePHI policies, eFILE sharing procedures, faxing, emailing, notice of privacy policies, data breach mitigation, disaster recovery, data backup and be sure to update policies and procedures regularly.  



The original article by Joseph Conn can be found at the following address: http://www.modernhealthcare.com/article/20160323/NEWS/160329942?utm_source=modernhealthcare&utm_medium=email&utm_content=20160323-NEWS-160329942&utm_campaign=am

Friday, March 4, 2016

ONC Blog Series Part 4: Quality Assessment/Quality Improvement and Population-Based Activities Examples

The fourth and final installment of the ONC’s four-part blog series on HIPAA, “The Real HIPAA: Quality Assessment/Quality Improvement and Population-Based Activities Examples,” focuses once again on illustrating the interoperability of HIPAA through examples. The examples are a continuation of Part 3 and are taken directly from the ONC’s blog post.


Example 4: Quality Assessment/Quality Improvement – 45 CFR 164.506(c)(5)

Providers participating in the ACO/OHCA may permit the ACO quality committee to access the Protected Health Information (PHI) needed for the quality assessment. An Accountable Care Organization (ACO) that consists of multiple providers operating as an Organized Health Care Arrangement (OHCA) has a quality committee made up of professionals from within the ACO. In order to improve patient health and meet Medicare’s quality improvement requirements, the quality committee plans to obtain and review treatment and health outcomes of ACO patients who experienced hospital-acquired infections and surgical errors.

Where the ACO is not operated as an OHCA, but the quality committee is evaluating care quality on behalf of the individual providers in the ACO, the providers participating in the ACO may permit the ACO quality committee to access the necessary PHI for the quality assessment, but only for patients whom the requesting and disclosing providers have in common, pursuant to 164.506(c)(4), instead for all the patients in the ACO.
In both instances, (OHCA and non-OHCA), access to, or disclosure of, electronic PHI can be made using Certified EHR Technology, so long as the HIPAA Security Rule is complied with.


Example 5: Quality Assessment/Quality Improvement – 45 CFR 164.506(c)(1) and (c)(4)
As part of a quality review, a health care provider may need to know the health outcome of a patient that the provider treated but no longer has contact with (e.g., patient was transferred to another provider). The provider may query a Health Information Exchange (HIE) for the relevant health outcomes of the individual, or the provider could directly ask the subsequent provider for information.


Example 6: Population-Based Activities – 45 CFR 164.506(c)(1) and (c)(4)A provider that has treated the patient and is responding to this query may use Certified EHR Technology to send the relevant information directly to the requesting health care provider, or may disclose to the requesting provider using the HIE. Disclosure of electronic PHI by Certified EHR Technology or other electronic means requires HIPAA Security Rule compliance. This scenario also works for health plans with a relationship with the patient; it is not limited to providers.
Unaffiliated hospitals in the same community often see the same patients and may not be able to tell whether a patient’s hospital-acquired infection resulted from care received at the current treating hospital or from a prior visit to a separate hospital in the community.

The hospitals that have treated or are treating the patient may use Certified EHR Technology to share relevant PHI to try to determine the source and/or cause of the infection in order to prevent further infections.

Disclosure of electronic PHI by Certified EHR Technology or other means requires HIPAA Security Rule compliance.


This post concludes the four-part series on HIPAA.

Tuesday, February 23, 2016

ONC Blog Series Part 3: Care Coordination, Care Planning, and Case Management Examples Under HIPAA

In the third installment of ONC’s four-part blog series on HIPAA, care coordination, care planning, and case management are in focus. Blog post Part 3: “The Real HIPAA: Care Coordination, Care Planning, and Case Management Examples” gives additional practical examples of exchange for Treatment and exchange for Health Care Operations. The following examples are taken directly from the ONC’s post.

Example 1: Care Coordination – 45 CFR 164.506(c)(2)

A hospital is preparing to discharge a patient who will need ongoing, facility-based care. The inpatient facility needs to identify a rehabilitation facility to accept the patient. Prospective facilities will need Protected Health Information (PHI) about the patient to determine whether they can provide the right care.

The current hospital may disclose the relevant PHI to prospective facilities without first obtaining the patient’s written authorization. The disclosing hospital may use Certified EHR Technology, so long as the disclosure is done in a manner that meets the HIPAA Security Rule.

This disclosure is a treatment disclosure (in anticipation of future treatment of the patient by the rehabilitation facility) and thus, may be carried out under 45 CFR 164.506(c)(2).

But, you might wonder, because the PHI came from the inpatient facility, will the inpatient facility be held responsible under HIPAA for what the rehabilitation facilities do with the PHI once they have received it in a permissible way under HIPAA?

Under HIPAA, the inpatient facility is responsible only for complying with HIPAA in disclosing the PHI to the rehabilitation facility in a permitted and secure manner. This includes sending the PHI securely and taking reasonable steps to send it to the right address. After the rehabilitation facility has received the PHI in accordance with HIPAA, the rehabilitation facility, as a covered entity itself, is responsible for safeguarding the PHI and otherwise complying with HIPAA, including with respect to any breaches that occur. The responsibility of the sending provider was to send it securely to the right address; the sending provider is not responsible for its security once received by another covered entity or the recipient covered entity’s business associate (BA).


Example 2: Care Planning By a Provider – 45 CFR 164.506(c)(1) and (c)(2)

A provider wants to ensure that her patients have a comprehensive care plan after they are discharged from the hospital. The provider hires a care planning company (i.e., its BA) to develop these plans for her patients.

To develop the plan, the care planning company requests pertinent PHI about each patient from the patients’ other providers, such as the hospitals to which the patients have been admitted for the same or similar medical care and the patients’ health plans. Each of these covered entities may disclose the relevant PHI for care planning purposes using Certified EHR Technology. Disclosure of electronic PHI by such technology or other electronic method requires HIPAA Security Rule compliance.

In this scenario, a business associate agreement (BAA) is only required between the covered entity that hires the care planning company and that company. The covered entities who permissibly disclose PHI in this scenario may do so directly to the provider’s care planning company for the provider’s care planning purposes (without the need to execute their own BAA) just as they could share this information directly with the provider. Electronic PHI disclosed in this scenario, for example using Certified EHR Technology, must be disclosed consistent with the HIPAA Security Rule.


Example 3: Case Management by a Payer – 45 CFR 164.506(c)(1) and (c)(4)

A health plan hires a health care management company to provide semi-monthly nutritional advice and coaching to their diabetic and pre-diabetic members. The care management company is a BA of the health plan. In order to provide appropriate nutritional advice and coaching, the health care management company needs additional information about these individuals to ensure the advice is consistent with the treatment they receive from their providers.

The health care management company may query the relevant providers to obtain information that could impact the nutritional advice. Providers may respond to the query using Certified EHR Technology and may disclose PHI necessary for the case management purpose for which the nutritional coach was hired by the health plan. Disclosure of electronic PHI by Certified EHR Technology or other method requires HIPAA Security Rule compliance.

In this scenario, the disclosures by the providers to the nutritional coach are for the Health Care Operations (“population-based activities relating to improving health or reducing costs” and “case management”) of the health plan, and therefore are Permissible Disclosures under HIPAA. Likewise, a BAA is only required between the health plan covered entity and the health care management company it hired. The providers may make permissible disclosures of PHI to that company without a BAA between the discloser and that company.


Once again, the providers sharing PHI with the health care management company hired by the health plan are not responsible under HIPAA for what that company or the health plan subsequently does with the information once it has been sent for a permissible reason and in a secure manner.

Tuesday, February 16, 2016

ONC Blog Series Part 2: Permitted Uses and Disclosures in HIPAA

In our continuing coverage of the ONC’s four-part blog series, we focus today on Part 2: “The Real HIPAA: Permitted Uses and Disclosures.” This blog post summarizes the new ONC fact sheets on HIPAA Permitted Uses and Disclosures for exchange, developed in conjunction with the Office for Civil Rights.

The HIPAA Privacy Rule defines when, under federal law, a covered entity may use or disclose an individual’s Protected Health Information (PHI). In general, a covered entity may only use or disclose PHI if either: (1) the HIPAA Privacy Rule specifically permits or requires it; or (2) the individual who is the subject of the information gives authorization in writing.

The HIPAA Privacy Rule specifically permits a use or disclosure of PHI for the covered entity that collected or created it for its own treatment, payment, and health care operations activities. Similarly, HIPAA also permits the covered entity that collected or created the PHI to disclose it to another covered entity for treatment, payment, and in some cases, the health care operations of the recipient covered entity.

If the covered entity wishes to use or disclose the PHI for something other than treatment, payment, or health care operations, it must obtain patient authorization to do so, unless the use or disclosure is permitted by another provision of the HIPAA Privacy Rule. One important such rule is when a patient requests a copy of her PHI, and asks that it be sent somewhere else.

OCR recently clarified that, when an individual requests a copy of her PHI and asks that it be sent directly to a third party, a provider must comply except in very narrow circumstances.

In regards to the national priority of interoperability, nationwide interoperable health information technology (health IT) will help make the right electronic health information available to the right people at the right time for patient care and health, no matter the care setting, organization, or technology supporting the information exchange. HIPAA’s Permitted Uses and Disclosure are rules that run “in the background” in support of this important nationwide goal. These background rules are made transparent to individuals through Notices of Privacy Practices. And, as to privacy protections, the HIPAA Privacy Rule applies the same whether the PHI is on a piece of paper or is electronic. (The Security Rule, in contrast, applies only to electronic PHI.)

ONC has released two new fact sheets to breakdown HIPAA’s permitted uses and disclosures.


As discussed in the Exchange for Treatment fact sheet, under HIPAA, a covered entity provider can disclose PHI to another covered entity provider for the treatment activities of the recipient health care provider, without needing patient consent or authorization. Treatment is broadly defined. It includes making and receiving referrals; coordination or management of health care and related services by a provider, even through a hired third party (for example, a nutritionist); and several other functions.

Likewise, a covered entity can disclose PHI to another covered entity (CE) or that CE’s business associate (BA) for the following subset of health care operations activities of the recipient covered entity without needing patient consent or authorization:
  • Conducting quality assessment and improvement activities
  • Developing clinical guidelines
  • Conducting patient safety activities as defined in applicable regulations
  • Conducting population-based activities relating to improving health or reducing health care cost
  • Developing protocols
  • Conducting case management and care coordination (including care planning)
  • Contacting health care providers and patients with information about treatment alternatives
  • Reviewing qualifications of health care professionals
  • Evaluating performance of providers and/or health plans
  • Conducting training programs or credentialing activities
  • Supporting fraud and abuse detection and compliance programs.

In general, before a covered entity can share PHI with another covered entity for one of the reasons noted above, the following three requirements must also be met:

  1. Both covered entities must have or have had a relationship with the patient (can be a past or present patient)
  2. The PHI requested must pertain to the relationship
  3. The discloser must disclose only the minimum information necessary for the health care operation at hand.
Under HIPAA’s minimum necessary provisions, a provider must make reasonable efforts to limit PHI to the minimum necessary to accomplish the purpose of the use, disclosure or request.  If the covered entities are in an “Organized Health Care Arrangement,” or “OHCA,” as defined in the HIPAA Privacy Rule (45 CFR 160.103), additional capabilities may exist for interoperable exchange of PHI.

Friday, February 12, 2016

ONC Blog Series Part 1: HIPAA and Interoperability

In February 2016, The Office of the National Coordinator for Health Information Technology (ONC) launched a new four-part blog series to explain the permitted uses of health information under HIPAA. The series emphasizes that HIPAA not only protects personal health information from misuse, it also enables personal health information to be accessed, used or disclosed interoperably, when and where it is needed for patient care.

We begin our coverage of the four-part series with Part 1: The Real HIPAA Supports Interoperability. This introductory post establishes HIPAA as serving the dual functions of protecting personal health information from misuse and also enabling personal health information to be used between Covered Entities (CE) under specific conditions.

ONC released two new fact sheets which give numerous examples of when electronic health information can be exchanged without first requiring an authorization or a writing of some type from the patient, so long as other protections or conditions are met. HIPAA provides many pathways for permissibly exchanging Protected Health Information (PHI).


The new fact sheets remind stakeholders through practical, real-life scenarios, that HIPAA supports interoperability because it gives providers permission to share PHI for patient care, quality improvement, population health, and other activities.

Next week, the blog series will continue to delve further into Permitted Uses and Disclosures. As per ONC, Blog #2 will be background on HIPAA’s Permitted Uses and Disclosures: what they are, and how they advance the national goal of interoperability. Blog #3 will give examples of exchange of health information for Care Coordination, Care Planning, and Case Management, both between providers, and between provider and payers. Finally, Blog #4 will give examples of interoperable, permissible exchange of PHI for Quality Assurance and Population-Based Activities, including via a health information exchange.

Thursday, April 26, 2012

Debt Collectors Find Their Way Into Hospitals

The New York Times reports that “Hospital patients waiting in an emergency room or convalescing after surgery are being confronted by an unexpected visitor: a debt collector at bedside.”  Go to http://www.nytimes.com/ to find the article, "Debt Collector is Faulted for Tough Tactics in Hospitals," in the NYT Business Day (April 24, 2012).


The online article, by Jessica Silver-Greenberg , continues: “This and other aggressive tactics by one of the nation’s largest collectors of medical debts, Accretive Health, were revealed on Tuesday by the Minnesota attorney general, raising concerns that such practices have become common at hospitals across the country.”


The article also indicates tactics of embedding debt collectors as employees in emergency rooms who would be expected to demand that patients pay before receiving treatment.


To patients, the debt collectors may look indistinguishable from hospital employees.  They may demand that the patient pay outstanding bills and may discourage the patient from seeking emergency care at all.  According to reported allegations, Accretive Health employees were told to stall patients entering the emergency room until they had agreed to pay a previous balance. 


The report indicates that in some cases these workers would have access to health information while asking patients to pay overdue bills, what the Minnesota attorney general speculates may be a violation of federal privacy laws.  The Minnesota general asserts that “the hounding of patients violated the Emergency Medical Treatment and Active Labor Act, a federal law requiring hospitals to provide emergency health care regardless of citizenship, legal status or ability to pay,” and that “by giving its collectors access to health records, Accretive violated the Health Insurance Portability and Accountability Act.” In addition, the attorney general says that the company broke state collections laws by failing to identify themselves as debt collectors when dealing with patients.


It is noted that hospitals “have long hired outside collection agencies to pursue patients after they have left hospital facilities,” and “to achieve promised savings, hospitals turn over the management of their front-line staffing — like patient registration and scheduling — and their back-office collection activities.”


According to the New York Times report, “Accretive says that it trains its staff to focus on getting payment through revenue cycle operations. Accretive fostered a pressurized collection environment that included mandatory daily meetings at the hospitals in Minnesota, according to employees and the newly released documents. Employees with high collection tallies were rewarded with gift cards. Those who fell behind were threatened with termination.”


The Minnesota attorney general is currently in discussions with state and federal regulators about a coordinated response to Accretive Health’s practices across the country.

Tuesday, March 13, 2012

HHS settles HIPAA case with BCBST for $1.5 million

Blue Cross Blue Shield of Tennessee (BCBST) has agreed to pay the U.S. Department of Health and Human Services (HHS) $1,500,000 to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules, Leon Rodriguez, Director of the HHS Office for Civil Rights (OCR), announced today. BCBST has also agreed to a corrective action plan to address gaps in its HIPAA compliance program. The enforcement action is the first resulting from a breach report required by the Health Information Technology for Economic and Clinical Health (HITECH) Act Breach Notification Rule.

The investigation followed a notice submitted by BCBST to HHS reporting that 57 unencrypted computer hard drives were stolen from a leased facility in Tennessee. The drives contained the protected health information (PHI) of over 1 million individuals, including member names, social security numbers, diagnosis codes, dates of birth, and health plan identification numbers. OCR’s investigation indicated BCBST failed to implement appropriate administrative safeguards to adequately protect information remaining at the leased facility by not performing the required security evaluation in response to operational changes. In addition, the investigation showed a failure to implement appropriate physical safeguards by not having adequate facility access controls; both of these safeguards are required by the HIPAA Security Rule.

“This settlement sends an important message that OCR expects health plans and health care providers to have in place a carefully designed, delivered, and monitored HIPAA compliance program,” said OCR Director Leon Rodriguez. “The HITECH Breach Notification Rule is an important enforcement tool and OCR will continue to vigorously protect patients’ right to private and secure health information.”

In addition to the $1,500,000 settlement, the agreement requires BCBST to review, revise, and maintain its Privacy and Security policies and procedures, to conduct regular and robust trainings for all BCBST employees covering employee responsibilities under HIPAA, and to perform monitor reviews to ensure BCBST compliance with the corrective action plan.

HHS Office for Civil Rights enforces the HIPAA Privacy and Security Rules. The HIPAA Privacy Rule gives individuals rights over their protected health information and sets rules and limits on who can look at and receive that health information. The HIPAA Security Rule protects health information in electronic form by requiring entities covered by HIPAA to use physical, technical, and administrative safeguards to ensure that electronic protected health information remains private and secure.

The HITECH Breach Notification Rule requires covered entities to report an impermissible use or disclosure of protected health information, or a “breach,” of 500 individuals or more to HHS and the media. Smaller breaches affecting less than 500 individuals must be reported to the secretary on an annual basis.

Individuals who believe that a covered entity has violated their (or someone else’s) health information privacy rights or committed another violation of the HIPAA Privacy or Security

Rule may file a complaint with OCR at: http://www.hhs.gov/ocr/privacy/hipaa/complaints/index.html.

The HHS Resolution Agreement can be found at http://www.hhs.gov/ocr/civilrights/activities/agreements/index.html

Additional information about OCR’s enforcement activities can be found at http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/index.html.

Source: HHS News Release

Wednesday, March 7, 2012

ONC Requests Input on Safeguarding Health Info on Mobile Devices

The ONC Office of the Chief Privacy Officer (OCPO), along with the HHS Office for Civil Rights (OCR), invites members of the public to provide input on mobile devices' uses and the current and emerging privacy and security best practices regarding protecting and securing health information while using mobile devices.

In conjunction with the input gathered during the Mobile Devices Roundtable: Safeguarding Health Information event, public input will help inform the development of an effective and practical way to bring awareness and understanding to those in the clinical sector regarding protecting and securing health information while using mobile devices.

ONC is seeking your input. The public comment period will remain open until Friday, March 30, 2012.

For more information, please click here.

Source: ONC News Release

Friday, February 17, 2012

HHS to Host Roundtable On Mobile Devices

On Friday, March 16, 2012, 8:30 a.m. – 12:30 p.m. EST, HHS will host a Mobile Devices Roundtable. The program is free and open to the public. Persons may participate in person or via webcast.

One of the key goals of the Federal Health Information Technology Strategic Plan is to inspire confidence and trust in health IT and electronic health information exchange by protecting the confidentiality, integrity, and availability of health information. ONC’s Office of the Chief Privacy Officer (OCPO), along with the HHS Office for Civil Rights (OCR), recently launched a privacy and security mobile device project. The project builds on the existing HHS HIPAA Security Rule - Remote Use Guidance and is designed to identify privacy and security good practices for mobile devices. The identified provider use case scenarios and good practices to address those scenarios will be communicated in plain, practical, and easy to understand language for use by health care providers, professionals, and other entities.

The objectives of the roundtable are to address the current privacy and security legal framework for mobile devices accessing, storing and/or transmitting health information;
discuss real world usage of mobile devices by providers and other health care delivery professionals to understand their expectations, attitudes, challenges and needs;
gather input regarding the information (and format) providers and other health care delivery professionals want and need to help them safeguard health information on their mobile devices; and gather input on existing and emerging privacy and security good practices, strategies and technologies for safeguarding data on mobile devices.

The Roundtable will include three panels comprised of federal agency representatives, practicing providers, and representatives of research, provider and industry organizations. The event will be an interactive discussion with moderators encouraging interaction between the panelists and the audience. Questions will be accepted in person, through email, and via Twitter.

The Roundtable event is free and open to the public, through in-person and webcast participation. Registration information will be posted by next Thursday, February 23.
Meeting Details:
Meeting Date & Time: Friday, March 16, 20128:30 a.m. – 12:30 p.m. EST(Registration/check-in begins at 7:30 a.m. EST)
Location:Hubert H. Humphrey BuildingU.S. Department of Health and Human Services – Great Hall200 Independence Avenue, S.W., Washington, DC
Or via webcast

For more information please click here.

Source: HHS News Release

Friday, January 20, 2012

EHNAC Announces 2012 Criteria for All Accreditation Programs

The Electronic Healthcare Network Accreditation Commission (EHNAC), a non-profit standards development organization and accrediting body, announced the adoption of new program criteria for 2012.

Following the standard, 60-day public comment period, EHNAC has incorporated feedback to finalize and adopt the enhanced criteria versions for the following programs:
ePAP – e-Prescribing Accreditation Program (Version 6.3)
FSAP EHN – Financial Services Accreditation Program for Electronic Health Networks (Version 2.3)
FSAP Lockbox – Financial Services Accreditation Program for Lockbox Services (Version 2.3)
HIEAP – Health Information Exchange Accreditation Program (Version 1.1)
HNAP-70 – Healthcare Network Accreditation Plus Select SAS 70©1 Criteria Program (Version 1.3)
HNAP EHN – Healthcare Network Accreditation Program for Electronic Health Networks (Version 10.3) 2
HNAP Medical Biller – Healthcare Network Accreditation Program for Medical Billers (Version 1.2)
HNAP TPA – Healthcare Network Accreditation Program for Third Party Administrators (Version 1.2)
MSOAP – Management Service Organization Accreditation Program (Version 1.1)
OSAP – Outsourced Services Accreditation Program2 (Version 1.2)
OSAP HIE – Outsourced Services Accreditation Program for Health Information Exchange Services (Version 1.1)

“The continued evolution and improvement of our accreditation programs is vital to support the dynamic climate of healthcare reform and industry standards,” says Mark Gingrich, EHNAC Commissioner and Criteria Committee Chair. “EHNAC is fully committed to regularly adjusting our program criteria for accreditation in all areas that affect health data processing to set the bar for the industry standards of today.”

EHNAC accreditation recognizes excellence in health data processing and transactions, and confirms compliance with industry-established standards and HIPAA regulations. Organizations that apply for accreditation or re-accreditation after Jan. 1, 2012 will now need to adhere to the enhanced criteria standards. Criteria for all EHNAC programs are posted online.

Source: EHNAC News Release

Thursday, January 5, 2012

New HHS Regs Streamline Health Electronic Funds Transfer; Cut Red Tape

New standards for electronic funds transfers in health care, required by the Affordable Care Act, will reduce up to $4.5 billion off administrative costs for doctors and hospitals, private health plans, states, and other government health plans, over the next ten years, according to estimates included in new rules published by the U.S. Department of Health and Human Services (HHS).

The standards build upon regulations published in 2011 that set industry-wide standards for how health providers use electronic systems to quickly and easily determine a patient’s eligibility for health coverage and check on the status of a health claim.

Together, the two regulations implementing the Administrative Simplification provisions of the Affordable Care Act and the Health Insurance Portability and Accountability Act (HIPAA) are projected to save the health care industry more than $16 billion over the next 10 years. These savings come from the adoption of electronic standards that will help eliminate inefficient manual processes and reduce costs.

“Thanks to the Affordable Care Act, health care professionals will spend less time filling out paperwork and more time focusing on delivering the best care for patients,” said HHS Secretary Kathleen Sebelius.

A May 2010 study in the journal Health Affairs found that physicians spend nearly 12 percent of every dollar they receive from patients to cover the costs of filling out forms and performing other excessively complex administrative tasks. The study found that simplifying these systems could save four hours per week of professional time per physician and five hours of support staff time every week – time that could be better spent on patient care.

“As a nurse, I know the importance of giving health care professionals time to focus on patient care,” said CMS Acting Administrator Marilyn Tavenner. “The less time a physician has to spend on paperwork is that much more time that can be devoted to patient care. Having standardized procedures across the health care industry can only lead to lower costs and greater efficiencies all around.”

The rule—the Adoption of Standards for Health Care Electronic Funds Transfers and Remittance Advice — adopts streamlined standards for the format and data content of the transmission a health plan sends to its bank when it wants to pay a claim to a provider electronically (through an electronic funds transfer) and to issue a Remittance Advice notice. Remittance Advice is a notice of payment sent to providers that may or may not accompany the payment the provider receives.

For example, currently when a provider submits a claim electronically for payment, a health plan often sends a Remittance Advice separately from the Electronic Funds Transfers payment. The disconnect between the two makes it difficult or sometimes impossible for the provider to match up the bill and the corresponding payment. The rule addresses this by requiring the use of a trace number that automatically matches the two. The new tracking system will allow health care providers to eliminate costly manual reconciliation that must currently be done.

Future administrative simplification rules will address adoption of:
- A standard unique identifier for health plans;
- A standard for claims attachments; and
- Requirements that health plans certify compliance with all HIPAA standards and operating rules.

The regulation is effective January 1, 2012. All health plans covered under HIPAA must comply by January 1, 2014.

To view the Interim Final Regulation with comment period, go to: http://www.regulations.gov

For more information on the June 2011 HIPAA Administrative regulation: Adoption of Operating Rules for Eligibility for a Health Plan and Health Care Claim Status, visit: http://www.hhs.gov/news/press/2011pres/06/20110630a.html

Source: HHS News Release

Wednesday, November 9, 2011

OCR Launches Privacy and Security Audits

The American Recovery and Reinvestment Act of 2009, in Section 13411 of the HITECH Act, requires the U.S. Department of Health and Human Services (HHS) to provide for periodic audits to ensure covered entities and business associates are complying with the HIPAA Privacy and Security Rules and Breach Notification standards. To implement this mandate, the HHS Office for Civil Rights (OCR) is piloting a program to perform up to 150 audits of covered entities to assess privacy and security compliance. Audits conducted during the pilot phase will begin in November 2011 and conclude by December 2012.

More information regarding OCR’s Pilot Audit Program is available on the OCR website at http://www.hhs.gov/ocr/privacy/hipaa/enforcement/audit/index.html

Source: OCR News Release

Monday, September 12, 2011

HHS Proposes to Increase Security of Patient Lab Info; Releases Model Privacy Notice

U.S. Department of Health and Human Services (HHS) Secretary Kathleen Sebelius proposed new rules designed to expand the rights of patients to access their health information through the use of health information technology (IT). Specifically, the new rules would empower patients and allow them to gain access to test results reports directly from labs. They would ensure that labs covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) provide such information, upon request, directly to patients or their personal representatives.

The announcement came at the kick-off of the first-ever HHS Consumer Health IT Summit, which brought consumers, providers, and the public and private sectors together to discuss how best to empower consumers to be partners in their health and care through health IT.

The Notice of Proposed Rulemaking (NPRM), jointly drafted by the Centers for Medicare & Medicaid Services, the HHS Office for Civil Rights (OCR), and the Centers for Disease Control and Prevention, proposes to amend the Clinical Laboratory Improvement Amendments of 1988 (CLIA) regulations and HIPAA privacy regulations to strengthen patients’ rights to access their own laboratory test result reports. The NPRM will be published in the Federal Register on September 14, 2011; public comments on the proposal will be accepted for 60 days after publication in the Federal Register.

Secretary Sebelius also unveiled an innovative voluntary Personal Health Record (PHR) Model Privacy Notice, which creates an easy-to-read, standardized template allowing consumers to compare and make informed decisions based on their privacy and security policies and data practices about PHR products. The new template is similar to the Nutrition Facts Labels in that it presents certain complex information in a simple way to improve transparency and consumer understanding about data practices. By making this Model Privacy Notice available, PHR companies can help build greater trust in PHRs.

For more information about the proposed amendments to the CLIA and HIPAA Privacy regulations, please visit https://www.cms.gov/apps/media/fact_sheets.asp.

Source: HHS News Release

Thursday, July 7, 2011

UCLA Health System Settles HIPAA Charges

Following an investigation by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), the University of California at Los Angeles Health System (UCLAHS) has agreed to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules for $865,500 and has committed to a corrective action plan aimed at remedying gaps in its compliance with the rules.

The resolution agreement resolves two separate complaints filed with OCR on behalf of two celebrity patients who received care at UCLAHS. The complaints alleged that UCLAHS employees repeatedly and without permissible reason looked at the electronic protected health information of these patients. OCR’s investigation into the complaints revealed that from 2005-2008, unauthorized employees repeatedly looked at the electronic protected health information of numerous other UCLAHS patients.

Through policies and procedures, entities covered under HIPAA must reasonably restrict access to patient information to only those employees with a valid reason to view the information and must sanction any employee who is found to have violated these policies.

“Covered entities are responsible for the actions of their employees. This is why it is vital that trainings and meaningful policies and procedures, including audit trails, become part of the everyday operations of any health care provider,” said OCR Director Georgina Verdugo. “Employees must clearly understand that casual review for personal interest of patients’ protected health information is unacceptable and against the law.”

The corrective action plan requires UCLAHS to implement Privacy and Security policies and procedures approved by OCR, to conduct regular and robust trainings for all UCLAHS employees who use protected health information, to sanction offending employees, and to designate an independent monitor who will assess UCLAHS compliance with the plan over 3 years.

“Covered entities need to realize that HIPAA privacy protections are real and OCR vigorously enforces those protections. Entities will be held accountable for employees who access protected health information to satisfy their own personal curiosity,” said Director Verdugo.

The HHS Resolution Agreement and CAP can be found on the OCR website at http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/UCLAHSracap.pdf.

Source: Department of Health and Human Services press release

Tuesday, May 31, 2011

HIPAA Accounting of Disclosures of Health Info Proposed Rule Released

The Department of Health and Human Services (HHS) Office for Civil Rights published and requests public comment a notice of proposed rulemaking to modify the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule’s standard for accounting of disclosures of protected health information. The purpose of the proposed modifications is, in part, to implement the statutory requirement under the Health Information Technology for Economic and Clinical Health Act (“the HITECH Act’’ or ‘‘the Act’’) to require covered entities and business associates to account for disclosures of protected health information to carry out treatment, payment, and health care operations if such disclosures are through an electronic health record.

Pursuant to both the HITECH Act and its more general authority under HIPAA, HHS proposes to expand the accounting provision to provide individuals with the right to receive an access report indicating who has accessed electronic protected health information in a designated record set.

Under its more general authority under HIPAA, HHS also proposes changes to the existing accounting requirements to improve their workability and effectiveness.

The proposed rule may be viewed here. HHS invites the public to submit comments on the proposed rule. Submit comments on or before August 1, 2011.

Source: HHS Notice of Proposed Rulemaking

Thursday, May 6, 2010

HHS Requests Information on Disclosures of Protected Health Information

In the May 3, 2010 issue of the Federal Register, the Office of Civil Rights of the Department of Health and Human Services has issued a request for information regarding the implementation of the Heath Information Technology for Economic and Clinical Health Act (HITECH Act). HHS requests information to help them understand the interests of individuals regarding the disclosure of their protected health information (PHI) and the administrative burdens that would be placed on healthcare and business entities covered under the act in order to account fro such disclosures.

HIPAA-covered entities are currently required to provide an account of certain PHI disclosures to a patient upon request. The HITECH Act would expand this rule to require covered entities to account for certain disclosures of PHI contained in a patient's electronic health record. HHS is seeking information from the public to assist in the drafting of this expanded rule.

The Federal Register announcement includes 9 questions that they would like commenters to answer. A list of the questions, along with information on how to submit comments can be found here:

http://frwebgate3.access.gpo.gov/cgi-bin/PDFgate.cgi?WAISdocID=1582723713+0+2+0&WAISaction=retrieve

Comments are due by May 18, 2010