Showing posts with label health law. Show all posts
Showing posts with label health law. Show all posts

Friday, July 29, 2022

Utilizing NIST Safeguards to reduce liability under the Stored Communications Act

With remote working and devices being interconnected, it is imperative to appreciate the implications of accessing electronic information without consent, even if it’s a spouse. Importantly, passwords and consent should not be given to a spouse, partner, or roommate. If a person works in a sensitive field such as healthcare, law, accounting, or finance for example (not to mention government employees and contractors), then setting boundaries that adhere to a plethora of laws and professional obligations should be implemented. As an aside the application of providing access to electronic communications that are part of work, even personal archived emails, social media, or smart phones that are accessed without consent are subject to violating a variety of laws including the Computer Fraud and Abuse Act (1986), which enables individuals to use this federal criminal law to sue others for civil claims based on unauthorized access, as well as other laws explained below.

A recent example that brings the significance of not securing information to light is the 25 page indictment brought by federal prosecutors against Seth Markin who allegedly stole from his then-girlfriend, an associate at a prominent law firm who was working at home during the pandemic on an acquisition deal related to a major pharmaceutical company’s acquisition of a therapeutic company. Additionally, the U.S. Securities and Exchange Commission also filed insider trading charges against Markin and one other person.

Enacted in 1986, the Stored Communications Act, 18 U.S.C. §§ 2701, et seq. (SCA) has a primary purpose that is analogous to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule - to protect the privacy and unauthorized disclosure of stored electronic communications. While HIPAA is specific to protected health information (PHI) and the Security Rule is limited to electronic protected health information (ePHI), the SCA extends to stored electronic communications. As the U.S. Department of Justice explains, “[e]lectronic storage is defined in 18 U.S.C. § 2510(17) as both any temporary, intermediate storage of a wire or electronic communication incidental to the electronic transmission thereof and the storage of such communication by an electronic communication service for purposes of backup protection of such communication.”Like HIPAA, which extends beyond external hackers, so does the SCA. In Ehling v. Monmouth-Ocean Hospital Service Corp., No. 2:11-cv-03305 (WJM) (D.N.J. Aug 20, 2013) the District Court for the State of New Jersey held that non-public Facebook posts, which are configured to be private are indeed covered under the SCA because they are:

  • electronic communications;
  • transmitted via an electronic communication service;
  • in electronic storage; and
  • not accessible to the general public.

Although the court recognized and applied the “authorized user” exception – one of two exceptions in the SCA, caution should be taken regarding if the person providing authorization has the authority or right to do so. Also, if a person’s Facebook or other social media is linked to an email, separate permission is needed for each application. Also, as lawyers appreciate potential clients may reach out through private social media or a colleague may send a link to an article and reference a case that is been worked on. Regardless of whether the person gave the roommate or spouse permission, professional rules and other laws dictate otherwise.

The HIPAA Security Rule has Security Standards (45 CFR § 164.306(b)). As HHS reinforces in a bulletin, “[t]he Security Rule is clear that reasonable and appropriate security measures must be implemented, see 45 CFR 164.306(b), and that the General Requirements of § 164.306(a) must be met.” The task of addressing the changing cybersecurity landscape on both a professional and a personal level may seem daunting and, in some ways, it is. Here are some compliance tips, which can be used in healthcare, a variety of other industries, and personally:NIST is a great resource and utilizing its standards may mitigate liability. I always recommend SP 800-53 (rev. 5 is the current version), as well as a HIPAA specific one. “NIST’s new draft publication, formally titled Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide is designed to help the industry maintain the confidentiality, integrity and availability of electronic protected health information, or ePHI. The term covers a wide range of patient data, including prescriptions, lab results, and records of hospital visits and vaccinations.”
Adopt a Remote Worker checklist for working from home and traveling. Some fundamental items are: (1) secure WiFi at home and when traveling (use a hotspot); (2) ensure that if you are syncing your Apple products (or other devices and software) that your private messages are not connected to another person’s account – whether family, friend, or colleague; (3) educate yourself and understand how your private messages on social media may end up being looked at by a spouse, roommate, or child (hint: if you get alerts know where the alerts are going and who has access to your phone, tablet, or email account); (4) set policies and procedures and have workforce members and contractors review and sign off on them, so they understand the potential legal liability that may come with sharing information; and (5) if you are a small business (or even a one person physician practice or law firm), have your disaster recovery plan as well as incapacity plan in place and pick a trusted person and have the information in a safe deposit box to be accessed only when needed.
Training is critical. Workforce members should also be educated as part of cybersecurity and HIPAA training on social engineering, phishing, and wrongful disclosure of both PHI and personally identifiable information.


15% Off Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)


VIEW ALL

Friday, July 1, 2022

Unexpected surprises in the No Surprises Act: How medical practices should respond

The No Surprises Act (NSA) has been in effect since January 1 to protect patients against an estimated 12 million surprise bills this year. Yet, while the goals of consumer protection, price transparency, and cost concessions are important and necessary, the legislation is starting to present real challenges to practices’ financial stability.

Fulfilling the new regulations places additional burden on practices’ already tight time and labor resources. For practices to survive without further unexpected surprises, they must act quickly.

New Jersey Brain and Spine, a subspecialty neurosurgery practice located in Northern New Jersey, has been closely monitoring and adjusting to the No Surprises Act legislation. “We firmly believe in the need to protect patients from surprise medical bills,” said neurosurgeon Reza Karimi, MD, of New Jersey Brain and Spine. “The law does place additional burdens on practices like ours, including new expenses for added billing paperwork, legal consulting and hiring an arbitration specialist. We have been focused on putting the right structures in place.”

Protections for patients—and for practices


Providers would be wise to consider the legislation from two angles: protection and growth. For patients, protection means no surprise billing; for practices, it means preventing violations and preparing for arbitration.

In essence, the No Surprises Act prohibits out-of-network providers from billing patients more than a payer’s applicable in-network cost sharing amount, known as balance billing. If this happens, providers risk a penalty of up to $10,000 per violation. To protect themselves, providers must now be ready to:Provide a good faith estimate (GFE) of expected charges and diagnostic codes within one to three business days after an item or service is scheduled.
Submit any surprise out-of-network bill directly to the patient’s health plan, ideally with self-identified determinations of whether No Surprises Act protections apply.
Notify patients of their protections by posting information prominently at the location of the facility, posting it on a public website, and via a one-page handout.

Never ask patients to waive their rights for emergency services or certain non-emergency services, nor appear in any way to coerce a patient to do so.

The most significant area in which practices must start to protect themselves will likely be the new Independent Dispute Resolution (IDR) process, a strictly regulated baseball-style arbitration for contesting unreasonable reimbursement amounts with insurers. Physicians will not only need to become savvy at submitting bids to receive more favorable reimbursements but also because the loser in the arbitration may be required to cover fees for both parties.

John Abrahams, MD, physician and president of Brain & Spine Surgeons of New York, said his practice took drastic steps to prepare for the arbitration process. “We went through about 5,000 cases of our lumbar and cervical fusions over the past eight years. We documented lengths of stay, readmissions, and outcomes over three, six and 12 months,” Dr. Abrahams said. “It was a Herculean effort, but we felt we had to do it because we don't know what we're going to be compared to moving forward.”

Will the No Surprises Act help or hinder growth?


Whether the law will allow physicians, especially those who take call or provide emergency care, to grow their practices under their current business models remains to be seen. That’s because the cost of achieving and sustaining NSA compliance and retaining legal counsel may overtake revenue from reimbursements.

If a portion of a provider’s revenue stream now moves to just above Medicare reimbursement levels, it will be difficult for practices to stay viable. There are a few options to combat this, and all require additional time or money or both before they generate ROI: Increasing volume, negotiating with more insurers to go in-network, and adding ancillary services, although those services may also be regulated by the NSA.

Another issue impacting growth is the uncertainty around the IDR process, as the rules keep changing. Early this year, several state medical associations and air ambulance companies filed suits about the interim final rule that bases appropriate reimbursements on insurers’ qualifying payment amounts (QPA). In April, 2022, CMS retracted its stance on just how much weight QPAs should carry in arbitrators’ decision making.

Still unclear, too, is whether state or federal mandates will be used to determine appropriate reimbursement amounts. “If we have state-based plans going over to federal arbitration guidelines, and if the federal arbitration guidelines are very unfavorable, we will have to make some potentially drastic changes to the way we practice,” Dr. Karimi noted. “Everything comes down to the federal IDR process.”

Steps practices should take to prepare


Domenic Segalla, Healthcare Market Leader, Principal at Withum Advisory Services, which provides advisory, tax and audit services to hospitals and physicians, says practices first need to ensure they have a firm understanding of the regulations and their potential financial repercussions.

“We have been working with medical practices to estimate the potential financial impact this law could have on them as well as developing workflows to manage the appeals process,” he said. “Many physicians still need education on this law and what’s coming down the pike.”

Practices should begin taking the following steps to limit any negative impacts of the No Surprises Act:Track the data. Data analytics are now more important than ever. Make the effort to start building case data to prove a track record. Gather data for each case on complications and readmissions. Reach out to hospitals to gather length-of-stay data. Ideally, as a provider collects more data his or her outcomes can be compared to published national norms.
Promote quality via marketing. Physicians must continually market the quality of their care through practice statistics, patient stories, blogs, public relations, and social media. This substantiates a provider’s ability and availability to referring physicians while establishing a record of quality and expertise in the public domain. It also helps create a groundswell of patient demand that can motivate insurers to negotiate a competitive in-network contract and increase volume.
Focus on outcomes. In addition to quality measures, IDR arbitrators can consider factors including the experience and training of the provider. The physician is allowed to present this type of information at arbitration to justify a higher payment than the QPA. The physician can also present data showing that his or her outcomes for the case or disease are superior to the norms as well as how its data has helped the practice improve efficiencies and quality controls.
Enlist an advisor. Smart providers will invest in additional labor or outsourcing to manage the new billing and arbitration requirements. That means preparing to invest in legal and workflow advisors who specialize in healthcare and can help providers prepare for the new normal.
Do the math. Physicians must become acutely aware of their own revenue cycles: What they’re getting paid, by whom, payment timeframes, and which procedures are continually denied.

The onus lies on providers and practice administrators to ensure that they understand and prepare for the requirements of the No Surprises Act. It is vital for to proactively evaluate strategies to respond to these market changes and ensure practice health and financial stability.


15% Off Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)


VIEW ALL

Friday, May 13, 2022

Tips for protecting the confidentiality and integrity of patient data

On April 26, 2022, Tenet healthcare Corporation (NYSE: THC) announced that a cybersecurity incident occurred a week before. “The Company immediately suspended user access to impacted information technology applications, executed extensive cybersecurity protection protocols, and quickly took steps to restrict further unauthorized activity.” In essence, and in accordance with HIPAA, the two hospitals that were impacted immediately invoked its disaster recovery and business continuity plans in order to, first and foremost, mitigate the impact on the delivery of patient care.

Tenet is a publicly traded company, so the timing of its disclosure to the market is also crucial in avoiding potential liability under a variety of SEC rules and regulations. On March 9th, the SEC issued proposed rules on a variety of items related to cybersecurity, including incident disclosure by public companies. As SEC Chair Gary Gensler stated, "cybersecurity is an emerging risk with which public issuers increasingly must contend. Investors want to know more about how issuers are managing those growing risks. A lot of issuers already provide cybersecurity disclosure to investors.”



What can organizations do to be proactive in protecting personally identifiable information (PII) and protected health information (PHI)? The National Institute of Standards and Technology (NIST) published SP 800-122 - Guide to Protecting the Confidentiality of Personally Identifiable Information (PII), which provides sage advice for maintaining the confidentiality, integrity, and availability of data through prevention, detection, and correction. When I conduct audits, one item that never ceases to amaze me is the use of the following for passwords: PASSWORD, LAST 4 DIGITS OF SS#, OR a DATE OF BIRTH. These partial identifiers are also “considered PII because they are still nearly unique identifiers and are linked or linkable to a specific individual.” (p. 2-2).

NIST proscribes the following action items:Identifiability. Organizations should evaluate how easily PII can be used to identify specific individuals. For example, a SSN uniquely and directly identifies an individual, whereas a telephone area code identifies a set of people.
  • De-identify records and information so that the individual cannot be identified.
  • Update policies and procedures and have tiered sanctions in place for failing to adhere to the basic tenet of not using PII or PHI as part of or a whole a password.

The scrutiny on cybersecurity measures will only become more intense. In healthcare, one must always consider the ultimate adverse patient outcome – death. As cybercriminals ratchet up their tactics on hospitals and other providers, prevention and detection are going to be critical to mitigating the risk of an attack, as well as responding to one.


15% Off Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)


VIEW ALL