Showing posts with label Law. Show all posts
Showing posts with label Law. Show all posts

Monday, September 21, 2020

Joint Cybersecurity Advisory issued; Internet of Things Cybersecurity Act updates

Since Physicians Practice® has a wide breadth of readers, which include physicians that are owners in companies that participate in U.S. Government procurement processes with various government agencies, I wanted to provide an overview of some key terms and standards, as well as share some take-aways, which relate back to healthcare providers.

But, first, there are two recent cybersecurity items which deserve attention. The FBI and CISA issued a Joint Cybersecurity Advisory to warn of “a widespread campaign from an Iran-based malicious cyber actor targeting several industries mainly associated with information technology, government, healthcare, financial, insurance, and media sectors across the United States. The threat actor conducts mass- scanning and uses tools, such as Nmap, to identify open ports.” Given the increase in cyberattacks during COVID-19, as well as the increase in telecommuting and telehealth, which were rapidly deployed, it is critical for covered entities, business associates, and subcontractors to conduct their annual risk analyses.

Another item is the House passing the Internet of Things (IoT) Cybersecurity Improvement Act, which was initially introduced in the Senate in 2017 and reintroduced in 2019. The bill received bi-partisan support to improve “the cybersecurity of Internet-connected devices by requiring that devices purchased by the U.S. government meet minimum-security requirements.” If adopted, the bill would require the following:
  • Require the National Institute of Standards and Technology (NIST) to issue standards and guidelines addressing, at a minimum, secure development, identity management, patching, and configuration management for IoT devices.
  • Direct the Office of Management and Budget (OMB) to issue guidelines for each agency that are consistent with the NIST recommendations, and charge OMB with reviewing these policies at least every five years.
  • Require any Internet-connected devices purchased by the federal government to comply with those recommendations.
  • Direct NIST to work with cybersecurity researchers, industry experts, and the Department of Homeland Security (DHS) to publish guidance on coordinated vulnerability disclosure to ensure that vulnerabilities related to agency devices are addressed.
  • Require contractors and vendors providing information systems to the U.S. government to adopt coordinated vulnerability disclosure policies, so that if a vulnerability is uncovered, that can be effectively shared with a vendor for remediation.

Many of these requirements are similar to other areas of procurement. First and foremost, the National Institutes for Standards and Technology (“NIST”) requirements must be met. This makes sense because the U.S. Government has these compulsory requirements internally. In order to mitigate the risk of hiring a vendor with inadequate technical, administrative, and physical safeguards, the Government uses NIST as a foundation.

NIST is also incorporated into a variety of laws including, but not limited to the following:
The Federal Acquisition Regulation (“FAR”) - The purpose of “[t]he Federal Acquisition Regulations System is established for the codification and publication of uniform policies and procedures for acquisition by all executive agencies. The Federal Acquisition Regulations System consists of the Federal Acquisition Regulation (FAR), which is the primary document, and agency acquisition regulations that implement or supplement the FAR.” See 48 C.F.R. § 1.101. Basically, FAR provides the groundwork for procurement.
  • The Procurement Integrity Act - was amended in 1996 under the National Defense Authorization Act, Pub. L. 104-106 (Feb. 10, 1996), implemented through FAR, 48 C.F.R. § 3.104. Its primary purpose was to ensure integrity in the Federal government’s procurement process.
  • Federal Risk and Authorization Management Program (“FedRAMP”) – was created to provide a “standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. NIST advises FedRAMP on FISMA compliance requirements and assists in developing the standards for the accreditation of independent 3PAOs.”

What can physicians, covered entities, and business associates take-away from the government procurement process? First, NIST standards should be incorporated into an entity’s annual HIPAA risk analysis and related policies and procedures. Second, providers contract with the Centers for Medicare and Medicaid Services to participate in Medicare, Medicaid, and TRICARE–read the provider agreement, as well as the attestation portion of the CMS and TRICARE claim forms. Lastly (and it should really go without saying), be truthful when submitting any document to the government, especially when payment is involved.

Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)


VIEW ALL

.

Saturday, August 15, 2020

Approaching the government with an antitrust complaint

When a hospital has significant market power, the hospital can use that market power to harm competing independent physicians. This can violate the federal antitrust laws.


___________________________________________________


Physicians face significant challenges in modern healthcare markets. The electronic medical records revolution, complex federal and state healthcare payment programs, and compliance with regulatory programs and requirements all eat up time and money that could be better spent on patient care.

In today’s market, these issues are compounded by an even bigger threat: the consolidation of healthcare markets and the squeezing out of local private practices.


Antitrust: Squeezing Out Independent Physician Practices


The consolidation of hospital markets and the integration by locally dominant hospitals into physician services has made operating a private physician practice difficult. The older paradigm— in which a hospital granted independent physician’s privileges and independent physicians then managed the hospital’s medical staff—has largely been replaced with hospitals employing a broad range of medical specialties who answer to hospital administrators. As a result, employed physicians have become profit and loss centers for hospitals, making hospitals warry of independent physician practices and the competition they bring. As a result, relationships between hospitals and independent physicians have become strained, and in some cases, dominant hospitals are actively working to drive independent practices out of the market or force them into employment relationships.

In competitive markets, competition between hospital-employed physicians and independent physicians can benefit consumers, giving patients more options. But when a hospital has significant market power, the hospital can use that market power to harm competing independent physicians. This can violate the federal antitrust laws.

The federal antitrust laws are designed to protect the competitive process, and thereby protect consumers, by prohibiting the misuse of market power by dominant firms. These laws are critical because a hospital with market power can harm independent physicians in different ways. For example, a dominant hospital can:
  1. Enter into contracts with health insurers that prevent those health insurers from doing business with independent physicians
  2. Engage in predatory hiring, e.g., stealing physicians from independent practices in order to harm those groups
  3. Deny or cancel physician admitting privileges to a hospital, refusing to give appropriate operating room time to independent surgeons, or putting unreasonable call coverage obligations on independent physicians.


What Independent Physician Groups Can Do


Suing a hospital under the antitrust laws for anticompetitive conduct is an option, but such lawsuits are expensive and can take a long time to work their way through the court system.

An alternative is to file a complaint with one of the two relevant federal antitrust enforcement agencies: the Antitrust Division of the United States Department of Justice or the Federal Trade Commission (FTC).

However, filing a complaint with one of these agencies is not as easy as filling out a form. These agencies enforce the antitrust laws in many different industries, which makes getting their attention its own challenge.


Elements of a Strong Compliant


A physician group filing a complaint must carefully prepare a position paper that contains the type of information the Antitrust Division and FTC would need to evaluate whether the identified improper conduct violates the antitrust laws.

Key to this is understanding that the Antitrust Division and FTC employ both attorneys and economists. Because the underlying theory of the case will be that a particular hospital has market power and has used that power to harm competition, hiring an economist is a crucial step. This person provides the research and analysis needed to build a consumer harm narrative. A strong theory of consumer harm is the backbone of a healthcare antitrust case, as the Antitrust Division and FTC are concerned about how a hospital’s role in the local market may be negatively impacting everyday patients.

Preparation of the claim must also include interviewing members of the physician practice and other related parties on topics including the:
  • Structure of the physician practice
  • Practice’s size and role in the market
  • How competition works in the market
  • Relationship between the practice and the hospital
  • Nature of the hospital’s misconduct

The facts uncovered by the investigation and the analysis prepared by the economist are then integrated into a position paper that is sent to the relevant enforcement agency.

The antitrust enforcement agencies receive many complaints and must prioritize their limited resources when determining what to investigate. Developing a strong position paper with a solid economic analysis increases the chance that the Antitrust Division or the FTC will consider your case.

Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)

VIEW ALL

Wednesday, July 15, 2020

Reopening Facilities After COVID-19: Strategies for mitigating risk

Industries throughout the country have all been affected, to some degree by the COVID-19 pandemic; however, assisted living facilities and nursing homes have perhaps been struck the deadliest of blows.

The resident population of skilled care and assisted living facilities are the most vulnerable to COVID-19: elderly, immunocompromised, and with a host of co morbidities. By one study, nursing home patients have accounted for close to 40 percent of all COVID-19 related deaths. Now that some states are beginning to open up public spaces, what should nursing homes and assisted living facilities do to mitigate their risk for lawsuits going forward?

There is never a more appropriate time to remember your mother’s words, “Better safe than sorry.” Despite the fact that some states are opening up their public spaces like bars and restaurants, COVID-19 cases are on the rise in many states. For example, on June 18, South Carolina saw a record one day new diagnosis total of over 900 cases. For comparison, in March of 2020, the average daily new case total hovered around 150. Facilities should think long and hard before opening the facility to visitors for anything other than compassionate visits for dying patients, especially when cases in the community at large are increasing, not decreasing.


The Centers for Medicaid and Medicare Services (CMS) have guidelines in place as to when it is appropriate to open back up to visitors. Those guidelines include:
  • Zero new nursing home onset of cases for 28 straight days;
  • Zero staff shortages;
  • Adequate supplies of cleaning and personal protective equipment;
  • Ready access to testing for patients and staff; and,
  • Adequate bed capacity at referring hospitals if the need arises to transfer.

Probably the most important and difficult of the above criteria includes the ready access to testing for patients and staff. Many states have difficulty in providing enough tests to test patients and staff on any sort of regular basis, which creates an uncertainty about those who may be positive but asymptomatic.

CMS also recommends that facilities lag behind general opening of public spaces by at least 14 days. In areas in which the community is seeing spikes in cases, nursing homes should consider not opening their doors to the public, even if other public places are open, given their vulnerable population. Facilities that do open up need to keep up with rigorous safety precautions, including temperature checks of employees and patients daily, use of cloth masks for visitors, temperature checks for visitors, use of hand sanitizer for visitors and social distancing. CMS also recommends the testing of employees weekly. The results of those tests should be documented in the employee’s personnel file, and copies kept in a central location so that should litigation arise in the future, the facility can show it was complying with the recommended safeguards at the time. Again, given the lack of access to testing in certain areas, this requirement may prohibit the facility from opening back up to the public until reliable and ready access to testing can occur.

In short, now is not the time to relax the precautions and safeguards that have been in place for the last 90 days. Failure to take a cautious, measured, approach will result in increased COVID-19 cases, and open up the facility to new and additional legal exposure.


Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)

VIEW ALL