With the HIPAA Omnibus Rule requiring greater identification, documentation, and management between medical practices and vendors, some new formalities may come into play.
Here's a link for a sample confidentiality agreement, drafted by attorney Amy Fehn of HealthLawOffices.com, to help put your vendors on notice and demonstrate to the federal government your good faith efforts to achieve HIPAA compliance.
Follow this link and click the download button: http://www.physicianspractice.com/hipaa/sample-hipaa-confidentiality-agreement-medical-practice-vendors?cid=fbP2011614
From Physicians Practice
Smart Billing Solutions is a full medical billing service. The owner of Smart Billing Solutions, Gina Thatcher, is the author of "How to Start Your Own Medical Billing Service". This blog was created for medical billers and aspiring medical billers. For anyone who wants to become self-employed. Please follow this blog for topics of discussion relating to medical billing and self-employment. Please also check out www.smartbillingsolutions.net
Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts
Monday, January 20, 2014
Monday, January 13, 2014
Complying With New Business Associate HIPAA Rules: 4 Changes to Know
When the HIPAA Omnibus Final Rule went into effect in March 2013, one of the most significant changes to HIPAA Privacy and Security Rules involved "business associate" (BA) agreements, and the rules that govern the relationship practices have with BAs.
Failure to properly follow these new rules governing agreements with BAs can lead to substantial penalties that have the potential to ruin a medical practice's reputation and cripple it financially.
Here are four changes practices should know about, and what they need to do to reduce their risk of exposure to penalties.
1. BAs can now be held directly liable for HIPAA breaches — but this doesn't protect covered entities.
Under the revised rules, a BA can now be held directly liable and subject to civil and criminal penalties for committing HIPAA violations. Individuals or companies considered BAs (which can include IT service providers such as my company and many others; see below to learn how the definition of BA has expanded) should be taking a number of steps to become compliant with the Omnibus Final Rule — steps practices need to know about, as is discussed in #4.
These steps include:
"Some covered entities [CE] may now have a false sense of security that because HIPAA reaches directly to the BA, they are not as culpable as they once were," he says. "In fact, a BA that's negligent or worse in handling PHI can cause significant liability to the CE. This makes it incredibly important to have a well-drafted BA agreement."
Not only is a practice statutorily required to have a BA agreement with any organization or individual PHI is disclosed to, the BA agreement should serve other purposes. It should clearly delineate the reporting obligations of the BA, in the event of a HIPAA violation, to the practice so the practice can comply with its reporting requirements to the government and affected patients.
"Another important element we put into all of our BA agreements is an indemnification provision that should the BA be responsible for causing a data breach, it is financially obligated to compensate the CE for the costs of responding to a breach," Morrone says. "These amounts can be fairly significant. It can cost hundreds of thousands of dollars just to do the reporting that's required under federal law."
2. The definition of BA has changed.
Under the revised rules, the definition of BA has been completely reworded. A BA now includes any vendor that creates, receives, maintains, or transmits PHI on behalf of a CE, even those that do not access PHI. BAs can now include organizations involved in patient safety activities, health information organizations and PHI data storage companies.
With this expanded definition, practices should determine whether any existing contracts should be replaced with BA agreements. In addition, practices should also review existing BA agreements. It is a common practice for BAs to request inclusion of a clause that removes themselves and their subcontractors from liability under HIPAA. A practice should now strongly object to its inclusion since BAs are now liable under the new rules.
3. The definition of BA has expanded to include subcontractors.
Subcontractors are now considered a BA of a practice if it has access to the practice's PHI. Practices would be wise to request information on these subcontractors, and research them as if the practice were contracting directly with the subcontractor.
Practices should require its BAs to ensure any subcontractors it may engage on its behalf that will have access to the practice's PHI agree to the same restrictions, conditions and requirements that apply to the BA with respect to such information.
Practices should also include in its BA agreement a stipulation that requires BAs to receive approval from the practice prior to engaging any new subcontractors that will have access to the PHI.
4. Practices must take steps to confirm its BAs follow HIPAA.
If a practice delegates duties to a BA, the practice now has a responsibility to confirm — to the best of its ability — the BA is handling those duties in conformity with HIPAA rules. There are a few steps practices should take.
Practices should request and review copies of the BAs risk assessment, and the policies and procedures developed to ensure the BA maintains HIPAA compliance. This should include the policy and procedure that states the practice will be notified if a breach occurs.
Practices should request information about a BA's HIPAA training program. Practices should also request a copy of a BAs cybersecurity insurance, which is designed to mitigate losses from a variety of cyber incidents, including data breaches.
While it is critical to take these steps to confirm a BA's services are HIPAA compliant, it is perhaps even more important for practices to perform careful due diligence on the companies it is considering as partners.
"The fines for not complying with HIPAA are as high as $1.5 million," Morrone says. "Having a well-drafted BA agreement can go a long way, but with so much at stake, CEs must carefully choose those companies they are engaging with to handle PHI."
By Nelson Gomes from Physician Practice: http://www.physicianspractice.com/blog/complying-new-business-associate-hipaa-rules-4-changes-know?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=17122013
Failure to properly follow these new rules governing agreements with BAs can lead to substantial penalties that have the potential to ruin a medical practice's reputation and cripple it financially.
Here are four changes practices should know about, and what they need to do to reduce their risk of exposure to penalties.
1. BAs can now be held directly liable for HIPAA breaches — but this doesn't protect covered entities.
Under the revised rules, a BA can now be held directly liable and subject to civil and criminal penalties for committing HIPAA violations. Individuals or companies considered BAs (which can include IT service providers such as my company and many others; see below to learn how the definition of BA has expanded) should be taking a number of steps to become compliant with the Omnibus Final Rule — steps practices need to know about, as is discussed in #4.
These steps include:
- Conducting a risk assessment of the methods used to protect patient health information (PHI);
- Developing and/or revising policies and procedures based upon that analysis to ensure HIPAA compliance is maintained;
- Training staff members on HIPAA rules and the BAs responsibility to protect PHI; and
- Entering into BA agreements with applicable subcontractors (see #3 to learn more about the changing responsibility of subcontractors)
"Some covered entities [CE] may now have a false sense of security that because HIPAA reaches directly to the BA, they are not as culpable as they once were," he says. "In fact, a BA that's negligent or worse in handling PHI can cause significant liability to the CE. This makes it incredibly important to have a well-drafted BA agreement."
Not only is a practice statutorily required to have a BA agreement with any organization or individual PHI is disclosed to, the BA agreement should serve other purposes. It should clearly delineate the reporting obligations of the BA, in the event of a HIPAA violation, to the practice so the practice can comply with its reporting requirements to the government and affected patients.
"Another important element we put into all of our BA agreements is an indemnification provision that should the BA be responsible for causing a data breach, it is financially obligated to compensate the CE for the costs of responding to a breach," Morrone says. "These amounts can be fairly significant. It can cost hundreds of thousands of dollars just to do the reporting that's required under federal law."
2. The definition of BA has changed.
Under the revised rules, the definition of BA has been completely reworded. A BA now includes any vendor that creates, receives, maintains, or transmits PHI on behalf of a CE, even those that do not access PHI. BAs can now include organizations involved in patient safety activities, health information organizations and PHI data storage companies.
With this expanded definition, practices should determine whether any existing contracts should be replaced with BA agreements. In addition, practices should also review existing BA agreements. It is a common practice for BAs to request inclusion of a clause that removes themselves and their subcontractors from liability under HIPAA. A practice should now strongly object to its inclusion since BAs are now liable under the new rules.
3. The definition of BA has expanded to include subcontractors.
Subcontractors are now considered a BA of a practice if it has access to the practice's PHI. Practices would be wise to request information on these subcontractors, and research them as if the practice were contracting directly with the subcontractor.
Practices should require its BAs to ensure any subcontractors it may engage on its behalf that will have access to the practice's PHI agree to the same restrictions, conditions and requirements that apply to the BA with respect to such information.
Practices should also include in its BA agreement a stipulation that requires BAs to receive approval from the practice prior to engaging any new subcontractors that will have access to the PHI.
4. Practices must take steps to confirm its BAs follow HIPAA.
If a practice delegates duties to a BA, the practice now has a responsibility to confirm — to the best of its ability — the BA is handling those duties in conformity with HIPAA rules. There are a few steps practices should take.
Practices should request and review copies of the BAs risk assessment, and the policies and procedures developed to ensure the BA maintains HIPAA compliance. This should include the policy and procedure that states the practice will be notified if a breach occurs.
Practices should request information about a BA's HIPAA training program. Practices should also request a copy of a BAs cybersecurity insurance, which is designed to mitigate losses from a variety of cyber incidents, including data breaches.
While it is critical to take these steps to confirm a BA's services are HIPAA compliant, it is perhaps even more important for practices to perform careful due diligence on the companies it is considering as partners.
"The fines for not complying with HIPAA are as high as $1.5 million," Morrone says. "Having a well-drafted BA agreement can go a long way, but with so much at stake, CEs must carefully choose those companies they are engaging with to handle PHI."
By Nelson Gomes from Physician Practice: http://www.physicianspractice.com/blog/complying-new-business-associate-hipaa-rules-4-changes-know?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=17122013
Why Cloud Services are Ready for Prime Time in Healthcare
By Marion K. Jenkins, PhD, FHIMSS from Physician's Practice
Chances are, you've heard about cloud computing but may not know much about it and how it relates to HIPAA. Here, we answer a few key questions about cloud services.
Cloud hosting — what is it?Cloud hosting has many variants and goes by many names, but it generally refers to the IT model where a medical practice uses computer servers and data-storage systems located in a service provider's data center rather than onsite at the practice. Some people think that since the word "cloud" is used, there is somehow magically no more hardware issues to worry about. On the contrary, a typical cloud-hosting facility has massive amounts of hardware and software systems. Cloud is so new, is it right for healthcare?Cloud hosting is actually not a new concept. In fact, versions of cloud hosting under different names have been around for nearly 30 years. In the early days of massive mainframes, such companies as Boeing Computer Services and Computer Science Corporation offered these services under the terms "timeshare" and "service bureau." Over the years many other labels have been used, including application service provider (ASP), software-as-a-service (SaaS),infrastructure as a service (IaaS), utility computing, and hosting. Finally about five years ago, the label "cloud" finally took hold, and although some of the terms above are still relevant in specialized circumstances, cloud hosting covers the overall concept.
What has made it an attractive solution for healthcare? Recent advances in several areas, including server and storage virtualization, and increased bandwidth of broadband services, have made cloud hosting much more attractive. In addition, server architecture — including both processing horsepower and processing (CPUs) — have become massively scalable. And improvements in management software have significantly added to both performance and reliability. These advances in technology have prompted significant changes in the way cloud services can be configured and delivered. What about the cloud and HIPAA?Cloud services are not automatically HPAA compliant. In fact,not only are many cloud providers not HIPAA compliant, they are wholly ignorant of HIPAA principles. The new HIPAA Omnibus rule released earlier in 2013 required all service providers to undergo a HIPAA compliance and remediation program by September 23, 2013.
(If you are using a cloud provider, you should contact them and request a copy of their HIPAA compliance program documents, and also request that they sign a Business Associate Agreement. If they cannot produce them, or they are reluctant to execute a BAA, you have a major problem.)
Cloud-hosting services can be made HIPAA compliant, provided proper HIPAA security is built into the platform, along with HIPAA-compliant processes and procedures for its operation. Note: There are some common "cloud services" that you may be familiar with or are already using that are definitely not HIPAA compliant. These include common web mail services from many Internet Service Providers (ISPs) such as AOL, Gmail, Hotmail, etc. These are not — nor can they be made to be — HIPAA compliant. In addition, most of them specifically prohibit any kind of business use, so in using them in conjunction with a medical practice typically violates their "Terms of Use" policies.
What are the big advantages of cloud over onsite servers, storage, etc.? Perhaps the biggest advantages are in the ability to grow as the practice’s needs grow, and to avoid the costly and disruptive effects of repeated computer upgrades every few years. Most people understand that new computer systems are obsolete within a few months after they are installed. So system designers have to anticipate future needs and buy more capacity than they really need, based on anticipated requirements of a few years down the road. Eventually the needs increase and even the "new" equipment becomes underpowered. So in a computer system "lifecycle," for the first few years there is too much capacity, and for the last few years there is too little capacity. Therefore for most of the time, the system is either too big or too small. Cloud services allow the computing horsepower — CPU, memory and hard drive space — to be "dialed-up" as needs increase, so it can keep pace with the needs of the practice. And generally that upgrade can be done without the downtime typically associated with a computer system "forklift upgrade."
And a good cloud provider is generally able to offer access to hardware and software tools that would be unaffordable to a typical practice.
What about support?This is critical, and it is important to make sure you understand what is being provided to the practice by a cloud provider. With onsite servers and other infrastructure, you have to have staff (or contract with an IT provider) to maintain your servers and take care of things like data backups, operating system patches, etc. With cloud hosting, those services are still necessary, and in most cases they can be provided more efficiently than with an onsite model. However not all cloud providers deliver those services automatically, so you need to check and make sure. Are cloud services foolproof?No, since there is still hardware, software — and people — involved, there is still the potential for outages and downtime, so you need to do your homework and make sure you understand the risks as well as the advantages
My EHR is hosted —does that mean I’m good to go as far as HIPAA is concerned?
Not at all. There has never been a reported HIPAA breach from an EHR — either hosted or onsite. The main culprits have been e-mail, files stored locally, and the theft of portable devices like laptops and USB drives. So you need to consider your non-EHR applications, and make sure they are properly secured. This is true whether those applications are running locally or with a cloud provider. One advantage of properly designed cloud services is that they tend to not allow healthcare data to be stored on local devices.
Courtesy of Physicians Practice http://www.physicianspractice.com/blog/why-cloud-services-are-ready-prime-time-healthcare?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=12122013
Monday, December 9, 2013
You Need to Adapt in Order to Survive: How Your Medical Billing Service Can Prosper During the Healthcare Industry Chaos
How Your Company Can Prosper During the
Healthcare Industry Chaos
By Patrick Phillips
The healthcare industry is facing a state of complete disorder and confusion: Uncertainty surrounding the implementation of the Affordable Care Act, the looming switch to ICD-10, EHR and "meaningful use" deadlines, hospital acquisitions of physician practices, new HIPAA rules, and Health Insurance Exchanges... the list goes on. It seems like a challenging time for medical billing companies – and it is.
The good news is that not only can you prosper, you can bring hope and financial stability to struggling practices and salvage some that would otherwise collapse and shut down (or get swallowed up by a hospital or other acquisition entity). How can you assure your and your clients' continued prosperity and growth?
Focus on becoming a full-service revenue cycle management company.
In today's dynamic marketplace, billing companies that do not keep up with the constant changes will be left in the dust by companies that do. You must not only stay current with what is happening in the industry, you need to make alliances with other companies that can provide services to your clients that will help them solve cash-flow challenges beyond just their medical billing. The more services you can offer to your clients, the more you will be perceived as "the expert" who can solve their cash flow problems.
A brief review of the latest issue of Billing will introduce you to vendors that can be valuable to you in assisting your clients with medical coding questions, HIPAA compliance, EHR Meaningful Use attestation, online document management, patient portals, integrated payment channels, patient collections, and other revenue cycle issues. Do not forget that HBMA conferences will introduce you to technology partners that can help you keep up with changes in this dynamic industry.
In today's dynamic marketplace, billing companies that do not keep up with the constant changes will be left in the dust by companies that do. You must not only stay current with what is happening in the industry, you need to make alliances with other companies that can provide services to your clients that will help them solve cash-flow challenges beyond just their medical billing. The more services you can offer to your clients, the more you will be perceived as "the expert" who can solve their cash flow problems.
A brief review of the latest issue of Billing will introduce you to vendors that can be valuable to you in assisting your clients with medical coding questions, HIPAA compliance, EHR Meaningful Use attestation, online document management, patient portals, integrated payment channels, patient collections, and other revenue cycle issues. Do not forget that HBMA conferences will introduce you to technology partners that can help you keep up with changes in this dynamic industry.
Make sure you are using a billing system that is fully integrated with an EHR system.
Many outdated, server-based billing systems are trying to patch together a practice management system with one of the new electronic health record systems designed by a different company or on a different platform. The company that developed the practice management (PM) system creates an interface with an EHR system developed by another company. Chaos generally ensues.
If this is the case with your PM system, you are only asking for headaches and a possible loss of clientele. EHR companies are dropping by the wayside every day. Some of them are also server-based. Trying to get them to work together with billing software is like using "bubble gum and bailing wire" and will only lead to ongoing issues in your company. Two different companies, with two groups of programmers, trying to keep all the different parts of both systems running smoothly is almost impossible and can lead to turmoil in your company.
As painful as it may seem now, it may be a good idea to begin looking for a billing system that is totally integrated with an EHR system. That means that it was designed from the ground up by the same programmers in the same company. There are such systems available, and most of them are cloud-based (accessed securely 24/7 through a browser via the Internet).
Anything less than total integration of the two systems could be a disaster waiting to happen. Start your research now and find a system that will take you into the future, especially with any new clients you bring on. And, as part of your due diligence, make sure there is a way to import the data from your current system into the new system (at least the patient demographics). Then, begin to educate your current clients on why they need to start using an EHR, if they are not already, and why they might need to use a system that is fully integrated with your billing system.
Look for a system that has a way to electronically communicate with insurance company databases. You need one that checks for eligibility and automatically imports the patient data directly from the insurance company's database to create new patient charts. This will save you hours of data input and will help you keep employee costs under control. It will also prevent you from submitting claims that are sure to be rejected because the patient was not eligible for the service and it will keep the practice from spending time seeing patients that insurances will not cover. This will increase your revenue for that practice and will eliminate a large number of claim rejections as well.
Many outdated, server-based billing systems are trying to patch together a practice management system with one of the new electronic health record systems designed by a different company or on a different platform. The company that developed the practice management (PM) system creates an interface with an EHR system developed by another company. Chaos generally ensues.
If this is the case with your PM system, you are only asking for headaches and a possible loss of clientele. EHR companies are dropping by the wayside every day. Some of them are also server-based. Trying to get them to work together with billing software is like using "bubble gum and bailing wire" and will only lead to ongoing issues in your company. Two different companies, with two groups of programmers, trying to keep all the different parts of both systems running smoothly is almost impossible and can lead to turmoil in your company.
As painful as it may seem now, it may be a good idea to begin looking for a billing system that is totally integrated with an EHR system. That means that it was designed from the ground up by the same programmers in the same company. There are such systems available, and most of them are cloud-based (accessed securely 24/7 through a browser via the Internet).
Anything less than total integration of the two systems could be a disaster waiting to happen. Start your research now and find a system that will take you into the future, especially with any new clients you bring on. And, as part of your due diligence, make sure there is a way to import the data from your current system into the new system (at least the patient demographics). Then, begin to educate your current clients on why they need to start using an EHR, if they are not already, and why they might need to use a system that is fully integrated with your billing system.
Look for a system that has a way to electronically communicate with insurance company databases. You need one that checks for eligibility and automatically imports the patient data directly from the insurance company's database to create new patient charts. This will save you hours of data input and will help you keep employee costs under control. It will also prevent you from submitting claims that are sure to be rejected because the patient was not eligible for the service and it will keep the practice from spending time seeing patients that insurances will not cover. This will increase your revenue for that practice and will eliminate a large number of claim rejections as well.
I can predict the success you are going to have in your business – and in life in general – if you will tell me just two things: the people you associate with and the books (and periodicals) that you read. Do not get bogged down in the details of your billing business. You need to set aside time to attend industry conferences at least once a year and to read industry newsletters and books.
The person who does not read is no better off than the person who cannot read, so set aside time each week to read about our industry and keep up with the constant changes. Change is what life itself is based on, and if you are willing to change along with the industry, you and your clients will prosper.
Do not assume you will have your current clients forever.
You won't. Things change in medical practices: staff turnover, new policies and procedures, new government rules and regulations, competition, updated technology, and the marketplace itself. All these things can cause you to lose a client from time to time. You must always be marketing.
Whether you realize it or not, your competition in this industry is not just other medical billing companies. The practice itself is your biggest competition. All it would take is for a new office manager to come into one of your practices and decide that they would rather not outsource their billing: they think they can do it themselves more efficiently and more economically. You must keep reselling your clients on your efficiencies and on your cost savings versus doing the billing themselves internally. Provide them with revenue reports that delineate what percentage of billed dollars (expected) are actually being collected. Show them you are the expert in this industry by producing and providing to them a professional newsletter with articles that show that you keep up with the changes in the industry. HBMA has a newsletter you can purchase and tailor with your company logo (www.hbma.org).
Take the practice administrator (or the doctor) to lunch from time to time and show them printed reports that illustrate the revenue collections from both insurance providers and patients. Hold "Lunch 'n Learns" on a regular basis with your clients to bring them up to date on what is happening in the medical industry. Position yourself as the expert. People want to do business with "the expert" in every field.
When you buy a home, you do not want the new real estate agent: you want the guy or gal who has sold 100+ homes. When you look for a CPA, you do not want one who just hung out his or her shingle: you search for one who pays less than double digits of their own taxes and has a number of clients who they service. The same is true of a doctor's office. They want to feel that they are dealing with the company that can bring in every last dime that is due to the practice.
Continue to network with other business people in the community and join your local BNI group or chamber of commerce. Get out once a week and let people know you can solve the cash crunch for doctors and help them build their practices through your contacts.
Set up an automated way of keeping in touch with everyone you come in contact with who is a prospective client. Let them know that you are the only company that they should do business with. When it comes time for them to decide to outsource their billing, you are the only choice that makes sense. People do not buy when you are ready to sell – they buy when they are feeling the pain. Be at the top of their list when they decide it is time for change.
Remind your current doctors and office administrators that you are looking to build your business. Assuming you have done a good job for them, ask them for a referral. You would be surprised as to how many billing company owners never ask their clients for referrals. Do not just ask for the name of someone. Ask your client to pick up the phone and call the other doctor or office administrator and tell them how pleased they are with your billing service and that they think it would be in their interest to meet with you.
You can shrivel up and die in this ever-changing industry, or you can make the choice to grow and prosper, starting right now!
Friday, November 22, 2013
Revenue Cycle Efficiencies and ICD-10
By Rachel V. Rose, JD, MBA from Physicians Practice
According to a Bank of America Merrill Lynch Executive Insight Report, Opportunities From Financial Efficiencies, produced in collaboration with HealthLeaders Media, financial leaders indicated that the "revenue cycle is where they could find the most efficiencies. The revenue cycle has been a focus of the industry for years, but the need for improvement is increasing given the payment model shifts that will come as a result of healthcare reform." (p. 2).
Given the upcoming October 1, 2014, transition to ICD-10, the revenue cycle is being scrutinized more closely than ever in preparation for the greatest impact on healthcare billing since the transition to prospective-payment, diagnosis-related groups (DRGs) in the early 1980s. Currently, physicians and other healthcare providers are considering how to contend with the decrease in claim-submission productivity due to the increased specificity, as well as potential denials and the effect on the revenue cycle.
Given the multiple aspects of ICD-10 transition, which could be focused on, I am going to provide some suggestions in the area of coding and compliance, which I have addressed directly with providers. First, like HIPAA, all entities are required to meet the ICD-10 requirements, regardless of their size. In light of this, coding and compliance policies and procedures should be established based upon state, federal and regulatory agency guidelines. Moreover, private payers may be implementing similar standards, especially those involved with Medicare Part C claims submissions.
For these private payers, state prompt-pay laws may be in effect that will enable providers to collect for untimely billing practices by private payers. Second, educating everyone throughout the revenue cycle proactively will enable efficiencies to be captured now and reduce the cash gap during the October 2014 transition. Third, regular compliance audits, including medical necessity, are critical to reducing adverse outcomes from RAC and ZPIC audits, as well as diverting the billing departments' efforts from clean claims submissions to reactively dealing with legal processes. Finally, the caliber of coders is crucial. It is inadvisable for providers to skimp on coder certification, training, and input. Outsourcing is also an option, but make sure that the appropriate HIPAA and Health Information Technology for Economic and Clinical Health, or HITECH, Act business associate requirements are in place.
In sum, "revenue cycle issues … caused the most anxiety among [the BAML] survey respondents, with 25 percent saying they felt 'very' exposed to potential losses." (Ibid. at p. 5). By being proactive and implementing effective compliance programs, healthcare providers can reduce their anxiety and potentially mitigate significant losses on the revenue cycle.
By Rachel V. Rose, JD, MBA from Physicians Practice
http://www.physicianspractice.com/blog/revenue-cycle-efficiencies-and-icd-10?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=19112013
According to a Bank of America Merrill Lynch Executive Insight Report, Opportunities From Financial Efficiencies, produced in collaboration with HealthLeaders Media, financial leaders indicated that the "revenue cycle is where they could find the most efficiencies. The revenue cycle has been a focus of the industry for years, but the need for improvement is increasing given the payment model shifts that will come as a result of healthcare reform." (p. 2).
Given the upcoming October 1, 2014, transition to ICD-10, the revenue cycle is being scrutinized more closely than ever in preparation for the greatest impact on healthcare billing since the transition to prospective-payment, diagnosis-related groups (DRGs) in the early 1980s. Currently, physicians and other healthcare providers are considering how to contend with the decrease in claim-submission productivity due to the increased specificity, as well as potential denials and the effect on the revenue cycle.
Given the multiple aspects of ICD-10 transition, which could be focused on, I am going to provide some suggestions in the area of coding and compliance, which I have addressed directly with providers. First, like HIPAA, all entities are required to meet the ICD-10 requirements, regardless of their size. In light of this, coding and compliance policies and procedures should be established based upon state, federal and regulatory agency guidelines. Moreover, private payers may be implementing similar standards, especially those involved with Medicare Part C claims submissions.
For these private payers, state prompt-pay laws may be in effect that will enable providers to collect for untimely billing practices by private payers. Second, educating everyone throughout the revenue cycle proactively will enable efficiencies to be captured now and reduce the cash gap during the October 2014 transition. Third, regular compliance audits, including medical necessity, are critical to reducing adverse outcomes from RAC and ZPIC audits, as well as diverting the billing departments' efforts from clean claims submissions to reactively dealing with legal processes. Finally, the caliber of coders is crucial. It is inadvisable for providers to skimp on coder certification, training, and input. Outsourcing is also an option, but make sure that the appropriate HIPAA and Health Information Technology for Economic and Clinical Health, or HITECH, Act business associate requirements are in place.
In sum, "revenue cycle issues … caused the most anxiety among [the BAML] survey respondents, with 25 percent saying they felt 'very' exposed to potential losses." (Ibid. at p. 5). By being proactive and implementing effective compliance programs, healthcare providers can reduce their anxiety and potentially mitigate significant losses on the revenue cycle.
By Rachel V. Rose, JD, MBA from Physicians Practice
http://www.physicianspractice.com/blog/revenue-cycle-efficiencies-and-icd-10?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=19112013
Thursday, October 31, 2013
New Measures in Pay-for-Performance Programs
Pay for performance, or P4P as it is more commonly known, is not a new concept and some plans have been using this type of initiative with providers for a decade or more. Those providers that participate in Medicare's Physician Quality Reporting System (PQRS) — which uses a combination of incentive payments and payment adjustments to promote reporting of quality information — as well as those participating in large Blues plans, will be most familiar with this model.
The shift What is new is the shift away from P4P as a "bonus" structure and a shift toward an "earning" structure. That is, the extent to which payers are incorporating P4P into their payment strategies means that a portion (or percentage) of providers' revenue is "earned" through meeting P4P targets or measures. These new models are referred to as "value-based," shifting away from straight fee-for-service payments to some combination of performance- and fee-based compensation, which puts some of the financial risk on providers. The hope is this type of compensation model will improve the quality of care, reduce medical costs over time, and improve patient outcomes. So you can think of the newer P4P models as Pay for outcomes, or P4O. Under Medicare The Affordable Care Act expands P4P efforts in hospitals through the establishment of a Hospital Value-Based Purchasing Program begun last year, where hospitals are rewarded for how well they perform on a set of quality measures, as well as on how much they improve in performance relative to a baseline. The healthcare law also extends the Medicare PQRS program through 2014. However, beginning in 2015 the incentive payments go away, and physicians who do not satisfactorily report quality data will see their payments from Medicare reduced. This marks the real beginning of P4O, in my view, due to the setting of a "quality care" baseline against which the ability to earn will then be tied.
By commercial payers For commercial payers, value-based contracts are springing up around Patient-Centered Medical Homes (PCMHs) and accountable care organizations (ACOs). However, new and negotiated contracts for generalized services — that is, practices that are not technically a PCMH or ACO — are now typically being crafted with P4P/P4O components that allow practices to "earn" additional dollars or year-to-year increases in multi-year contracts through meeting specific measures and targets. Theses measure are typically HEDIS-based (Healthcare Effectiveness Data and Information Set) which is a widely used set of performance measures developed and maintained by the National Committee for Quality Assurance (NCQA). Many of these measures are focused on high-cost conditions such as heart disease, diabetes, high blood pressure, as well as preventive measures like immunizations and medication management. New and changed measures for 2014 include breast- and cervical-cancer screenings.
Commercial payers utilizing P4P measures typically have a combination of HEDIS-type "quality" measures as well as "self-reported" measures, where practices can report on items such as EHR implementation and use, and status in achieving NCQA programs such as Patient-Centered Medical Home (PCMH), diabetes, heart/stroke, and back pain recognition programs. In addition to NCQA measures, there is substantial investment underway by the Agency for Healthcare Research and Quality (AHRQ) and other public policy organizations to identify further evidence-based medicine practices that could be used for measurement. And the National Quality Forum (NQF) is leading focused efforts to collect and normalize data, and endorse additional performance measures.
Article By Susanne Madden of physicians Practice http://www.physicianspractice.com/physician-compensation/new-measures-pay-performance-programs?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=31102013
The shift What is new is the shift away from P4P as a "bonus" structure and a shift toward an "earning" structure. That is, the extent to which payers are incorporating P4P into their payment strategies means that a portion (or percentage) of providers' revenue is "earned" through meeting P4P targets or measures. These new models are referred to as "value-based," shifting away from straight fee-for-service payments to some combination of performance- and fee-based compensation, which puts some of the financial risk on providers. The hope is this type of compensation model will improve the quality of care, reduce medical costs over time, and improve patient outcomes. So you can think of the newer P4P models as Pay for outcomes, or P4O. Under Medicare The Affordable Care Act expands P4P efforts in hospitals through the establishment of a Hospital Value-Based Purchasing Program begun last year, where hospitals are rewarded for how well they perform on a set of quality measures, as well as on how much they improve in performance relative to a baseline. The healthcare law also extends the Medicare PQRS program through 2014. However, beginning in 2015 the incentive payments go away, and physicians who do not satisfactorily report quality data will see their payments from Medicare reduced. This marks the real beginning of P4O, in my view, due to the setting of a "quality care" baseline against which the ability to earn will then be tied.
By commercial payers For commercial payers, value-based contracts are springing up around Patient-Centered Medical Homes (PCMHs) and accountable care organizations (ACOs). However, new and negotiated contracts for generalized services — that is, practices that are not technically a PCMH or ACO — are now typically being crafted with P4P/P4O components that allow practices to "earn" additional dollars or year-to-year increases in multi-year contracts through meeting specific measures and targets. Theses measure are typically HEDIS-based (Healthcare Effectiveness Data and Information Set) which is a widely used set of performance measures developed and maintained by the National Committee for Quality Assurance (NCQA). Many of these measures are focused on high-cost conditions such as heart disease, diabetes, high blood pressure, as well as preventive measures like immunizations and medication management. New and changed measures for 2014 include breast- and cervical-cancer screenings.
Commercial payers utilizing P4P measures typically have a combination of HEDIS-type "quality" measures as well as "self-reported" measures, where practices can report on items such as EHR implementation and use, and status in achieving NCQA programs such as Patient-Centered Medical Home (PCMH), diabetes, heart/stroke, and back pain recognition programs. In addition to NCQA measures, there is substantial investment underway by the Agency for Healthcare Research and Quality (AHRQ) and other public policy organizations to identify further evidence-based medicine practices that could be used for measurement. And the National Quality Forum (NQF) is leading focused efforts to collect and normalize data, and endorse additional performance measures.
Article By Susanne Madden of physicians Practice http://www.physicianspractice.com/physician-compensation/new-measures-pay-performance-programs?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=31102013
Wednesday, October 30, 2013
Ethics on Ending the Patient-Physician Relationship
Once you accept a patient into your practice, you are under an ethical and legal obligation to provide services to the patient as long as the patient needs them. There may be times, however, when you may no longer be able to provide care. It may be that the patient is noncompliant, unreasonably demanding, threatening to you and/or your staff, or otherwise contributing to a breakdown in the patient-physician relationship. Regardless of the situation, you must avoid a claim of "patient abandonment." Abandonment is a tort, similar to negligence, defined as the termination of a professional relationship between physician and patient at an unreasonable time and without giving the patient the chance to find an equally qualified replacement.
There must be some harm from the abandonment. The plaintiff must prove that the physician ended the relationship at a critical stage of the patient's treatment without good reason or sufficient notice to allow the patient to find another physician, and the patient was injured as a result. Usually, expert evidence is required to establish whether termination happened at a critical stage of treatment.
A physician who does not terminate the patient-physician relationship properly may also run afoul of ethical requirements, and find himself before the medical board. According to the AMA's Council on Ethical and Judicial Affairs, a physician may not discontinue treatment of a patient as long as further treatment is medically indicated, without giving the patient reasonable notice and sufficient opportunity to make alternative arrangements for care. Further, the patient's failure to pay a bill does not end the relationship, as the relationship is based on a fiduciary rather than a financial responsibility.
According to the AMA's Code of Medical Ethics, Opinion 8.115, you have the option of terminating the patient-physician relationship, but you must give sufficient notice of withdrawal to the patient, relatives, or responsible friends and guardians to allow another physician to be secured.
The Health Care District of Palm Beach County offers this advice regarding the appropriate steps to terminate the patient-physician relationship:
1. Giving the patient written notice, preferably by certified mail, return receipt requested;
2. Providing the patient with a brief explanation for terminating the relationship (this should be a valid reason, for instance non-compliance or failure to keep appointments);
3. Agreeing to continue to provide treatment and access to services for a reasonable period of time, such as 30 days, to allow a patient to secure care from another person (a physician may want to extend the period for emergency services);
4. Providing resources and/or recommendations to help a patient locate another physician of like specialty; and
5. Offering to transfer records to a newly-designated physician upon signed patient authorization to do so.
Following this protocol may be easier in some situations than others. For example, if a physician has signed a covenant-not-to-compete, chances are the employer will not hand over the patient list upon notice of departure. In instances such as these, you (in consultation with your attorney) may want to provide a model patient termination letter to the party withholding your patients' addresses, and request that the addresses and letter be merged for distribution to your patients.
Ideally, you should not be in a contractual arrangement that makes contacting your patients difficult. However, if you find yourself in this situation, work with an attorney to ensure that appropriate steps are taken.
Article By Martin Merritt of Physicians Practice http://www.physicianspractice.com/blog/ethics-ending-patient-physician-relationship?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=29102013
There must be some harm from the abandonment. The plaintiff must prove that the physician ended the relationship at a critical stage of the patient's treatment without good reason or sufficient notice to allow the patient to find another physician, and the patient was injured as a result. Usually, expert evidence is required to establish whether termination happened at a critical stage of treatment.
A physician who does not terminate the patient-physician relationship properly may also run afoul of ethical requirements, and find himself before the medical board. According to the AMA's Council on Ethical and Judicial Affairs, a physician may not discontinue treatment of a patient as long as further treatment is medically indicated, without giving the patient reasonable notice and sufficient opportunity to make alternative arrangements for care. Further, the patient's failure to pay a bill does not end the relationship, as the relationship is based on a fiduciary rather than a financial responsibility.
According to the AMA's Code of Medical Ethics, Opinion 8.115, you have the option of terminating the patient-physician relationship, but you must give sufficient notice of withdrawal to the patient, relatives, or responsible friends and guardians to allow another physician to be secured.
The Health Care District of Palm Beach County offers this advice regarding the appropriate steps to terminate the patient-physician relationship:
1. Giving the patient written notice, preferably by certified mail, return receipt requested;
2. Providing the patient with a brief explanation for terminating the relationship (this should be a valid reason, for instance non-compliance or failure to keep appointments);
3. Agreeing to continue to provide treatment and access to services for a reasonable period of time, such as 30 days, to allow a patient to secure care from another person (a physician may want to extend the period for emergency services);
4. Providing resources and/or recommendations to help a patient locate another physician of like specialty; and
5. Offering to transfer records to a newly-designated physician upon signed patient authorization to do so.
Following this protocol may be easier in some situations than others. For example, if a physician has signed a covenant-not-to-compete, chances are the employer will not hand over the patient list upon notice of departure. In instances such as these, you (in consultation with your attorney) may want to provide a model patient termination letter to the party withholding your patients' addresses, and request that the addresses and letter be merged for distribution to your patients.
Ideally, you should not be in a contractual arrangement that makes contacting your patients difficult. However, if you find yourself in this situation, work with an attorney to ensure that appropriate steps are taken.
Article By Martin Merritt of Physicians Practice http://www.physicianspractice.com/blog/ethics-ending-patient-physician-relationship?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=29102013
Wednesday, September 11, 2013
What Practices Need to Do Now to Prepare for HIPAA Omnibus Changes
The September 23, 2013, deadline for when covered entities such as physician practices must be in compliance with the HIPAA Omnibus Final Rule is quickly approaching. The rule marks the most sweeping changes to the HIPAA Privacy and Security Rules since they were first implemented.
While the final rule brings about many changes, there are three in particular that likely warrant the most attention from practices now. The following column identifies those changes and provides practical guidance to meet the new requirements.
Change 1: The definition of what a "breach" is has been modified.
What it means: Under the old law, a breach was an event that "compromises the security or privacy of the protected health information (PHI) such that the use or disclosure poses a significant risk of financial, reputational or other harm to the affected individual." Under the new rule, the definition of a breach is expanded to include even just the "risk" of impermissible use or disclosure of PHI. For example, if you have patient records on a thumb drive and that drive is lost, if the records are not password-protected or encrypted, that will be considered a breach even if the data is never accessed by anyone. An incident report should be filed with your HIPAA officer. If you lose a laptop but can prove the computer is encrypted and nobody is able to access the information without a secure ID, thus indicating a low probability of the PHI becoming compromised, you will not have committed a breach.
What practices should do: Perform a complete risk assessment in an effort to minimize security holes and prevent possible breaches. Three of the most common causes of breaches are stolen laptops, lost or stolen external hard drives or thumb drives, and sending PHI through unsecured email.
Change 2: The definition of a "business associate" (BA) has been completely reworded.
What it means: A BA is essentially a company or any person who is not a member of the workforce for the covered entity but has access to PHI. This would include contractors and now, under the new rule, subcontractors under the BA.
What practices should do: Review all BA agreements to see if they need to be revised or replaced. With older agreements, a BA could potentially include a clause that says the BA cannot be held liable for PHI breaches. Now, a BA can be held directly liable. BAs can still try to include the clause to remove themselves and their subcontractors from liability, but a practice would be wise to object to such a request and a BA will lack a strong argument for the clause's inclusion. An example of when a BA might be liable: If an IT company has an off-site data backup and somebody steals the backup device, the BA can be found personally liable for breach of all of the health records on that device. An example of when a subcontractor might be liable: If the IT company were to bring in a subcontractor to run network cable and electric lines in a new service center, that subcontractor would then be considered a BA and potentially liable since it could have access to PHI.Since all BAs are more stringent under the new HIPAA security laws, BAs themselves need to now remain HIPAA compliant.
Change 3: HIPAA audits will happen more frequently, fines will be substantially higher, and auditors will be incentivized to find security problems.
What it means: Periodic HIPAA audits by HHS were already authorized and underway, but covered entities can expect them to happen more frequently once the new rule is enacted.In addition, fines associated with penalties due to HIPAA violations will become significantly higher and essentially without a limit.Finally, auditors will receive what amounts to a "kickback" for each security violation discovered during an audit, which incentivizes auditors to dig deep and find any and all holes.
What practices should do: The best practice is to perform at least quarterly risk assessments. This will help ensure security hole fixes put in place are working and holding and identify other potential problems. If you can indicate to an auditor that you performed a risk assessment, identified a problem, and have a plan in place to fix it, the auditor is more likely not to consider the problem an issue unless it remains unresolved. Many covered entities rely upon an external company to perform such risk assessments. These companies are not only skilled in identifying security problems and issues often overlooked by covered entity staff members, they have the knowledge and ability to take care of requirements such as creating policies and procedures for administrative safeguards, setting up employee training and changing all IT systems so they have a data backup plan, specific user names, and password policies in place.
Larger organizations may consider hiring someone to handle these responsibilities, but this may be cost prohibitive. For smaller organizations, it's often more cost-effective to hire a company to handle all of these tasks and help ensure year-round compliance.
-
Article By Nelson Gomes and Michael Daly of Physicians Practice http://www.physicianspractice.com/blog/what-practices-need-do-now-prepare-hipaa-omnibus-changes?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=10092013
While the final rule brings about many changes, there are three in particular that likely warrant the most attention from practices now. The following column identifies those changes and provides practical guidance to meet the new requirements.
Change 1: The definition of what a "breach" is has been modified.
What it means: Under the old law, a breach was an event that "compromises the security or privacy of the protected health information (PHI) such that the use or disclosure poses a significant risk of financial, reputational or other harm to the affected individual." Under the new rule, the definition of a breach is expanded to include even just the "risk" of impermissible use or disclosure of PHI. For example, if you have patient records on a thumb drive and that drive is lost, if the records are not password-protected or encrypted, that will be considered a breach even if the data is never accessed by anyone. An incident report should be filed with your HIPAA officer. If you lose a laptop but can prove the computer is encrypted and nobody is able to access the information without a secure ID, thus indicating a low probability of the PHI becoming compromised, you will not have committed a breach.
What practices should do: Perform a complete risk assessment in an effort to minimize security holes and prevent possible breaches. Three of the most common causes of breaches are stolen laptops, lost or stolen external hard drives or thumb drives, and sending PHI through unsecured email.
Change 2: The definition of a "business associate" (BA) has been completely reworded.
What it means: A BA is essentially a company or any person who is not a member of the workforce for the covered entity but has access to PHI. This would include contractors and now, under the new rule, subcontractors under the BA.
What practices should do: Review all BA agreements to see if they need to be revised or replaced. With older agreements, a BA could potentially include a clause that says the BA cannot be held liable for PHI breaches. Now, a BA can be held directly liable. BAs can still try to include the clause to remove themselves and their subcontractors from liability, but a practice would be wise to object to such a request and a BA will lack a strong argument for the clause's inclusion. An example of when a BA might be liable: If an IT company has an off-site data backup and somebody steals the backup device, the BA can be found personally liable for breach of all of the health records on that device. An example of when a subcontractor might be liable: If the IT company were to bring in a subcontractor to run network cable and electric lines in a new service center, that subcontractor would then be considered a BA and potentially liable since it could have access to PHI.Since all BAs are more stringent under the new HIPAA security laws, BAs themselves need to now remain HIPAA compliant.
Change 3: HIPAA audits will happen more frequently, fines will be substantially higher, and auditors will be incentivized to find security problems.
What it means: Periodic HIPAA audits by HHS were already authorized and underway, but covered entities can expect them to happen more frequently once the new rule is enacted.In addition, fines associated with penalties due to HIPAA violations will become significantly higher and essentially without a limit.Finally, auditors will receive what amounts to a "kickback" for each security violation discovered during an audit, which incentivizes auditors to dig deep and find any and all holes.
What practices should do: The best practice is to perform at least quarterly risk assessments. This will help ensure security hole fixes put in place are working and holding and identify other potential problems. If you can indicate to an auditor that you performed a risk assessment, identified a problem, and have a plan in place to fix it, the auditor is more likely not to consider the problem an issue unless it remains unresolved. Many covered entities rely upon an external company to perform such risk assessments. These companies are not only skilled in identifying security problems and issues often overlooked by covered entity staff members, they have the knowledge and ability to take care of requirements such as creating policies and procedures for administrative safeguards, setting up employee training and changing all IT systems so they have a data backup plan, specific user names, and password policies in place.
Larger organizations may consider hiring someone to handle these responsibilities, but this may be cost prohibitive. For smaller organizations, it's often more cost-effective to hire a company to handle all of these tasks and help ensure year-round compliance.
-
Article By Nelson Gomes and Michael Daly of Physicians Practice http://www.physicianspractice.com/blog/what-practices-need-do-now-prepare-hipaa-omnibus-changes?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=10092013
Tuesday, August 27, 2013
Compliance FAQs... How Much is Too Much?
How much information can a biller leave on an answering machine when calling for address or insurance updates?
Answer: Because the biller cannot know for sure who will listen to a message, even when calling a telephone number provided by the patient, it is wise to leave the minimum amount of information necessary to accomplish the reason for the call. Various legal concerns, including the HIPAA Privacy and Security rules, state that confidentiality and privacy laws and debt collection statutes and regulations can be implicated and should be taken into account.
A bare bones message may contain little or no revealing information while still accomplishing the task.
EXAMPLE 1: "This message is for [patient]. We are calling to verify your current mailing address (or insurance information) in order to bill for recent medical services you received. Please contact us at xxx-xxxx during office hours."
Here is another message scenario that gives minimal information.
EXAMPLE 2: "This is Medical Billing Office calling for [patient]. We need to contact you for an updated / corrected mailing address (or insurance information). Please call us at xxx-xxxx at your earliest convenience."
EXAMPLE 2: "This is Medical Billing Office calling for [patient]. We need to contact you for an updated / corrected mailing address (or insurance information). Please call us at xxx-xxxx at your earliest convenience."
Various factors should be considered in deciding how to draft scripts or instructions for your staff regarding outbound messages.
- What is the purpose of the call / message?
- Who is the provider / client? Are they well known in the community?
- Do they practice in a sensitive specialty, such as family planning, mental health, etc.?
- Is there a reason you would need to disclose the client's identity or other detailed information at all?
- What would be the risk if someone other than the patient or a close family member heard the message?
If additional information would be helpful and would not unnecessarily reveal personal health information (PHI) or sensitive information, it can also be included in the message.
EXAMPLE 3: "This message is for [patient]. I am calling for the billing office at [General Hospital Radiology Group]. Please contact our office to update your mailing address (or insurance information)."
CMS has published FAQs that are generally related to this question. By analogy, they support the conclusion that a biller may leave a minimum amount of information on an answering machine to solicit a response and gather information to enable proper billing.
The official HIPAA FAQs can be found on the website of the DHHS Office of Civil Rights at www.hhs.gov/ocr/privacy/hipaa/faq/index.html.
From the Office of Civil Rights HIPAA website:
May physician offices or pharmacists leave messages for patients at their homes, either on an answering machine or with a family member, to remind them of appointments or to inform them that a prescription is ready? May providers continue to mail appointment or prescription refill reminders to patients' homes?
Answer: Yes. The HIPAA Privacy Rule permits health care providers to communicate with patients regarding their health care. This includes communicating with patients at their homes – either through mail, phone, or in some other manner. In addition, the Rule does not prohibit covered entities from leaving messages for patients on their answering machines. However, to reasonably safeguard the individual's privacy, covered entities should take care to limit the amount of information disclosed on the answering machine. For example, a covered entity might want to consider leaving only its name, number, and other information necessary to confirm an appointment, or ask the individual to call back.
A covered entity also may leave a message with a family member or other person who answers the phone when the patient is not home. The Privacy Rule permits covered entities to disclose limited information to family members, friends, or other persons regarding an individual's care, even when the individual is not present. However, covered entities should use professional judgment to assure that such disclosures are in the best interest of the individual and limit the information disclosed. See 45 CFR 164.510(b)(3).
In situations where a patient has requested that the covered entity communicate with him or her in a confidential manner, such as by alternative means or at an alternative location, the covered entity must accommodate those requests, if reasonable. For example, the Department considers a request to receive mailings from the covered entity in a closed envelope rather than by postcard to be a reasonable request that should be accommodated. Similarly, a request to receive mail from the covered entity at a post office box rather than at home, or to receive calls at the office rather than at home are also considered to be reasonable requests, absent extenuating circumstances. See 45 CFR 164.522(b).
A covered entity also may leave a message with a family member or other person who answers the phone when the patient is not home. The Privacy Rule permits covered entities to disclose limited information to family members, friends, or other persons regarding an individual's care, even when the individual is not present. However, covered entities should use professional judgment to assure that such disclosures are in the best interest of the individual and limit the information disclosed. See 45 CFR 164.510(b)(3).
In situations where a patient has requested that the covered entity communicate with him or her in a confidential manner, such as by alternative means or at an alternative location, the covered entity must accommodate those requests, if reasonable. For example, the Department considers a request to receive mailings from the covered entity in a closed envelope rather than by postcard to be a reasonable request that should be accommodated. Similarly, a request to receive mail from the covered entity at a post office box rather than at home, or to receive calls at the office rather than at home are also considered to be reasonable requests, absent extenuating circumstances. See 45 CFR 164.522(b).
Saturday, August 24, 2013
What Health Insurance Exchanges Mean for Physicians
Congress enacted the Affordable Care Act (ACA) to provide the means for uninsured Americans to purchase healthcare coverage. Despite many legal battles and slipped deadlines, the new healthcare insurance exchanges — also known as marketplaces — will begin open enrollment on Oct. 1, 2013. The law provides for three options: one, where states will create and run their own exchanges; two, where they will create a hybrid exchange run by both the state and federal government; and three, where the federal government creates and runs the exchanges for states that have opted out. Coverage through the plans begins on Jan. 1, 2014.
Aside from great reservations expressed by many states, there are a number of unanswered questions where physicians and their practices are concerned. In part because so many states were reticent to fund and undertake the creation of a state-based exchange, progress to date varies widely. As of May 10, 2013, 25 states have been conditionally approved to operate some type of state-based exchange, according to The Center for Consumer Information & Insurance Oversight (CCIO).
And, because each state exchange is unique, the number and type of insurance companies that participate in the exchanges will be singular to each state.
So, what does this mean for physicians and their practices?
Sarah Dash, a faculty member at the Health Policy Institute at Georgetown University, says "fundamentally the exchange plans are just insurance plans. …The market is organized for the purpose of the consumer gaining easier access to those insurance plans. So, to some extent, it is the same thing." Since many people put off seeing the doctor because they are uninsured and can't afford the cost, experts have suggested that there will be a flood of sicker patients once the exchanges provide health insurance. Dash calls it "pent up demand." However, she is not convinced that this will be the case. She points out that the premise of the reform law's "insurance mandate" was to provide a good mix of healthy younger patients with older, potentially sicker patients. Owen Dahl, a practice management consultant based in The Woodlands, Texas, also believes that practices won't be deluged with new patients — but for a different reason. He says people who don't have insurance now are generally those who don't understand how it works and can't afford to pay for it. "If I've been going to the emergency room for 15 years to get my care, [patients will say] 'Oh look, I've got this insurance, well I'm still going to go to the emergency room,'" says Dahl. He thinks that it will take time for people to change their behavior, which means practices will have plenty of time to prepare for newly insured patients. There is also trepidation among physicians that plans offered on the insurance exchanges will not pay well. As it is nearly impossible to predict reimbursement rates until the exchanges are fully established and patients are enrolled, it is perhaps a wasted effort for practices to dwell on this aspect. Dahl feels that plans offered on the exchanges may behave like managed-care plans. He says that it is likely that exchange plans will be offered by the major payers such as Blue Cross. "As far as the rates are going to be concerned, I think the best-case situation we could expect would be Medicare rates," he says. While that could mean lower revenues for practices, there are other aspects of the reform law which may be to their advantage. Dash says that "the point of the ACA is not to just give people an insurance card. It's to give people an insurance card that they can use. By that I mean, if the cost sharing is too high [in the forms of copays and deductibles], certainly that could be a deterrent." She argues that through the law, patients will have access to tax subsidies and cost-sharing subsidies that should make it easier for patients to pay their bills. Certainly these changes will bring added administrative burdens to practices, but in many cases, they have already begun to implement new processes and quality improvements required by programs like Patient-Centered Medical Homes. Dahl advises practices "Do not panic." He says that while the business of medicine is most certainly changing, it won't happen overnight. "The important thing is for doctors to think about [the law] and to be prepared for that, but not react," he says.
Article By Erica Sprey - See more at: http://www.physicianspractice.com/blog/what-health-insurance-exchanges-mean-physicians#sthash.oenrJwFk.dpuf
Aside from great reservations expressed by many states, there are a number of unanswered questions where physicians and their practices are concerned. In part because so many states were reticent to fund and undertake the creation of a state-based exchange, progress to date varies widely. As of May 10, 2013, 25 states have been conditionally approved to operate some type of state-based exchange, according to The Center for Consumer Information & Insurance Oversight (CCIO).
And, because each state exchange is unique, the number and type of insurance companies that participate in the exchanges will be singular to each state.
So, what does this mean for physicians and their practices?
Sarah Dash, a faculty member at the Health Policy Institute at Georgetown University, says "fundamentally the exchange plans are just insurance plans. …The market is organized for the purpose of the consumer gaining easier access to those insurance plans. So, to some extent, it is the same thing." Since many people put off seeing the doctor because they are uninsured and can't afford the cost, experts have suggested that there will be a flood of sicker patients once the exchanges provide health insurance. Dash calls it "pent up demand." However, she is not convinced that this will be the case. She points out that the premise of the reform law's "insurance mandate" was to provide a good mix of healthy younger patients with older, potentially sicker patients. Owen Dahl, a practice management consultant based in The Woodlands, Texas, also believes that practices won't be deluged with new patients — but for a different reason. He says people who don't have insurance now are generally those who don't understand how it works and can't afford to pay for it. "If I've been going to the emergency room for 15 years to get my care, [patients will say] 'Oh look, I've got this insurance, well I'm still going to go to the emergency room,'" says Dahl. He thinks that it will take time for people to change their behavior, which means practices will have plenty of time to prepare for newly insured patients. There is also trepidation among physicians that plans offered on the insurance exchanges will not pay well. As it is nearly impossible to predict reimbursement rates until the exchanges are fully established and patients are enrolled, it is perhaps a wasted effort for practices to dwell on this aspect. Dahl feels that plans offered on the exchanges may behave like managed-care plans. He says that it is likely that exchange plans will be offered by the major payers such as Blue Cross. "As far as the rates are going to be concerned, I think the best-case situation we could expect would be Medicare rates," he says. While that could mean lower revenues for practices, there are other aspects of the reform law which may be to their advantage. Dash says that "the point of the ACA is not to just give people an insurance card. It's to give people an insurance card that they can use. By that I mean, if the cost sharing is too high [in the forms of copays and deductibles], certainly that could be a deterrent." She argues that through the law, patients will have access to tax subsidies and cost-sharing subsidies that should make it easier for patients to pay their bills. Certainly these changes will bring added administrative burdens to practices, but in many cases, they have already begun to implement new processes and quality improvements required by programs like Patient-Centered Medical Homes. Dahl advises practices "Do not panic." He says that while the business of medicine is most certainly changing, it won't happen overnight. "The important thing is for doctors to think about [the law] and to be prepared for that, but not react," he says.
Article By Erica Sprey - See more at: http://www.physicianspractice.com/blog/what-health-insurance-exchanges-mean-physicians#sthash.oenrJwFk.dpuf
Thursday, August 8, 2013
Public Comment Forum Upcoming Changes: HIPAA Code Conversion for Local Modifier ZS (Medi-Cal, California State Medicaid)
As part of the continuing effort to comply with the federally mandated Health Insurance Portability and Accountability Act (HIPAA), the following change is slated to be effective for dates of service on or after December 1, 2013:
Claim Completion
Providers will be instructed to use one of the following scenarios when submitting a claim for split-billable procedures or services:
Providers will be instructed to use one of the following scenarios when submitting a Treatment Authorization Request (TAR) for split-billable procedures or services:
Notice is hereby given that DHCS will conduct written public proceedings, during which time any interested person or such person’s duly authorized representative may present statements, arguments or contentions relevant to the action described in this notice.
The comment forum will begin September 15, 2013, and stays open a minimum of 45 days. The proposed changes will be available by clicking the “Public Comment Forum Coming: HIPAA Code Conversion for Local Modifier ZS” line in the NewsFlash area of the Medi-Cal website. This link will direct providers to the “Medi-Cal Comment Forum” where they can view the article. Providers may call the Telephone Service Center (TSC) at 1-800-541-5555 or visit the Medi-Cal website if they have questions or need additional information.
Courtesy of: Dept. of Health Care Services Medi-Cal http://files.medi-cal.ca.gov/pubsdoco/newsroom/newsroom_21767.asp?utm_source=iContact&utm_medium=email&utm_campaign=Medi-Cal%20NewsFlash&utm_content=21767
- The Department of Health Care Services (DHCS) will discontinue use of local modifier ZS, which is used to bill for the full professional (26) and technical (TC) components of a procedure.
Claim Completion
Providers will be instructed to use one of the following scenarios when submitting a claim for split-billable procedures or services:
- Scenario 1: The facility and physician each bill for their respective component of the service with modifiers 26 or TC.
Each provider/facility submits their own claim with one line of service and the appropriate modifier (26 or TC) designating the service they provided.
- Scenario 2: Full Fee Billing – The physician bills for both the professional and technical components and subsequently reimburses the facility for the technical component, according to their mutual agreements.
The physician submits a CMS-1500 claim form and completes two separate claim lines as follows:
The first line contains the split-billable procedure code and one of the two modifiers (26 or TC). The second line contains the same procedure code and the corresponding modifier (26 or TC).
- Scenario 3: Standard Billing – The facility bills for both the technical and professional components and reimburses the physician for the professional component, according to their mutual agreements.
The facility submits a UB-04 claim form and completes two separate claim lines as follows:
The first line contains the split-billable procedure code and one of the two modifiers (26 or TC). The second line contains the same procedure code and the corresponding modifier (26 or TC).
Providers will be instructed to use one of the following scenarios when submitting a Treatment Authorization Request (TAR) for split-billable procedures or services:
- Scenario 1: One TAR and one provider for both the professional (26) and technical (TC) components of service.
The TAR must be submitted with two lines of service. The first line must have the CPT-4 code and one of the two modifiers (26 or TC). The second line must have the same CPT-4 code and the corresponding modifier (26 and TC).
- Scenario 2: One TAR and two different providers for the professional (26) and technical (TC) components of service.
One of the providers submits the TAR on behalf of both providers of the two components of service (26 and TC). Both providers use the same TAR for claim submission. The TAR is submitted with two lines of service. The first line must have the CPT-4 code and one of the two modifiers (26 or TC). The second line must have the same CPT-4 code and the corresponding modifier (26 and TC).
- This is the preferred method for two different providers.
- Scenario 3: Two TARs and two different providers for the professional (26) and technical (TC) components of service.
Each provider submits their own TAR with one line of service and the appropriate modifier designating the service (26 or TC) they provided or will provide.
Notice is hereby given that DHCS will conduct written public proceedings, during which time any interested person or such person’s duly authorized representative may present statements, arguments or contentions relevant to the action described in this notice.
The comment forum will begin September 15, 2013, and stays open a minimum of 45 days. The proposed changes will be available by clicking the “Public Comment Forum Coming: HIPAA Code Conversion for Local Modifier ZS” line in the NewsFlash area of the Medi-Cal website. This link will direct providers to the “Medi-Cal Comment Forum” where they can view the article. Providers may call the Telephone Service Center (TSC) at 1-800-541-5555 or visit the Medi-Cal website if they have questions or need additional information.
Courtesy of: Dept. of Health Care Services Medi-Cal http://files.medi-cal.ca.gov/pubsdoco/newsroom/newsroom_21767.asp?utm_source=iContact&utm_medium=email&utm_campaign=Medi-Cal%20NewsFlash&utm_content=21767
Friday, July 26, 2013
How the New HIPAA Regulations Affect Billing Companies and Their Subcontractors as Business Associates
How the New HIPAA Regulations Affect Billing Companies and Their Subcontractors as Business Associates
Develop an Action Plan for Your Company and Subcontractors
An article by Robert A. Polisky, Esq., taken from the May/June issue of HBMA Billing.On January 25, 2013, the Office for Civil Rights of the U.S. Department of Health & Human Services (OCR) published the anticipated final omnibus rule (the Final Rule). This rule created significant changes to the Privacy, Security, Breach Notification, and Enforcement Rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), many of which are required by the Health Information Technology for Economic and Clinical Health Act (HITECH Act). The Final Rule also implements changes to the Genetic Information Nondiscrimination Act of 2008.
The scope of the Final Rule is extensive, and enhances OCR's ability to enforce HIPAA. In the press release announcing the Final Rule, OCR Director Leon Rodriguez proclaimed that the Final Rule "marks the most sweeping changes to the HIPAA Privacy and Security Rules since they were first implemented" and "strengthen[s] the ability of my office to vigorously enforce the HIPAA privacy and security protections…." Individuals and entities affected by the Final Rule must comply with most of its provisions by September 23, 2013.
This article addresses key provisions of the Final Rule applicable to billing companies and their subcontractors, enforcement changes, and recommended action items needed for compliance by billing companies and their subcontractors.
KEY PROVISIONS
Business Associates and Their Subcontractors
Expanded Definition of "Business Associate"The Final Rule expands the definition of a "business associate" to include any individual or entity that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity. Companies that code, bill, and/or collect claims on behalf of a health care provider (i.e., a covered entity), are business associates under HIPAA. Notably, the Final Rule includes subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate as business associates themselves. Thus, any subcontractors that a billing company engages to assist in coding, billing, or collections, and any subcontractors that store or transmit any healthcare records on the billing company's behalf, are business associates of the billing company.
Direct Liability
As business associates, the Final Rule requires billing companies and their subcontractors to comply with the Security Rule's administrative, physical, and technical safeguard requirements as well as with the Security Rule's policies and procedures and documentation requirements. These requirements apply to business associates in the same manner as they apply to covered entities, such that billing companies and their subcontractors can be held civilly and criminally liable for violations of these requirements. Similarly, the Final Rule applies certain Privacy Rule requirements to business associates and establishes direct liability of business associates for violations of these requirements. A billing company does not need to provide a notice of privacy practices or designate a privacy official unless the covered entity designated such a responsibility in the billing company's business associate agreement.
Specifically, billing companies and their subcontractors, as business associates, have direct civil and criminal liability exposure for the following items.
- impermissible uses and disclosures of PHI
- failure to provide breach notification to the covered entity
- failure to provide access to a copy of electronic PHI to either the covered entity, the individual, or the individual's designee (whichever is specified in the business associate agreement)
- failure to disclose PHI to OCR where required by OCR to investigate or determine the business associate's compliance with HIPAA
- failure to provide an accounting of disclosures
- failing to enter into business associate agreements with subcontractors that create or receive PHI on the business associate's behalf
- failure to comply with the requirements of the Security Rule
Business Associate Agreements
The Final Rule clarifies that a covered entity is not required to enter into a business associate agreement with a billing company's subcontractor. Rather, the billing company that engaged a subcontractor to perform a function or service involving the use or disclosure of PHI is required to enter into a business associate agreement with the subcontractor. Each business associate agreement in the business associate chain needs to be at least as restrictive as the agreement above it in the chain with respect to permissible uses and disclosures of PHI.
The Final Rule expands the requirements of a business associate agreement by obligating a business associate to comply, where applicable, with the Security Rule with regard to electronic PHI; report breaches of unsecured PHI to the covered entity; and ensure that any subcontractors that create or receive PHI on its behalf agree to the same restrictions and conditions that apply to the business associate with respect to such information.
Transition Period
The Final Rule delays compliance until September 22, 2014 for a covered entity or business associate to enter into a business associate agreement with a business associate or subcontractor if, prior to January 25, 2013, the covered entity or business associate had a business associate agreement with the business associate or subcontractor, as applicable, that complied with HIPAA prior to the Final Rule (unless the business associate agreement was modified or actively renewed between March 26, 2013 and September 23, 2013). In all other cases, covered entities and business associates will need to execute business associate agreements with their business associates and subcontractors no later than September 23, 2013.
Modification To The Breach Notification Rule
BackgroundUnder the HITECH Act, a covered entity is required to notify affected individuals and OCR following discovery of a breach of unsecured PHI; a covered entity also needs to notify the media of a breach involving more than 500 residents of a state or jurisdiction. A business associate, in turn, is required to notify a covered entity following discovery of a breach of unsecured PHI at or by the business associate.
On August 24, 2009, OCR issued an interim final rule implementing the HITECH Act's breach notification provisions ("Breach Notification Interim Rule"). In the Breach Notification Interim Rule, a "breach" is defined as the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that "compromises the security or privacy" of the PHI, with certain exceptions. Moreover, under the Breach Notification Interim Rule, "compromises the security or privacy" of the PHI is defined to mean that an impermissible use or disclosure of PHI poses a significant risk of financial, reputational, or other harm to the individual (the "harm standard").
Revised Definition of "Breach"
The Final Rule significantly revises the definition of "breach" to clarify that an impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised. By replacing the "harm standard" with this "low probability" standard, it is more likely under the Final Rule than under the Breach Notification Interim Rule that covered entities and business associates will determine that an impermissible use or disclosure of PHI "compromises the security or privacy" of the PHI, resulting in many required breach notifications that would not have been required previously.
Modification of Risk Assessment
Under the Final Rule, to determine whether there is a low probability that PHI has been compromised, covered entities and business associates need to conduct a risk assessment that considers at least the following factors:
- the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
- the unauthorized person who used the PHI or to whom the disclosure was made;
- whether the PHI was actually acquired or viewed; and
- the extent to which the risk to the PHI has been mitigated.
Right to Restrict Disclosure to a Health Plan
Under the Final Rule, health care providers, upon request from an individual, must agree to restrict disclosure of PHI about the individual to a health plan if the disclosure would be for the purpose of carrying out payment or healthcare operations, and is not otherwise required by law, or the PHI pertains solely to a healthcare item or service for which the individual, or person acting on the individual's behalf (other than the health plan), has paid the covered entity in full. To avoid payment issues, a health care provider may want to require payment in full at the time of the individual's request for a restriction. Health care providers may request assistance from billing companies to comply with this new restricted disclosure requirement.ENFORCEMENT
DiscretionThe Final Rule gives OCR discretion to use informal means to resolve HIPAA violations. However, OCR is permitted to impose a civil monetary penalty without exhausting informal resolution efforts, especially when the HIPAA violation is due to willful neglect. The Final Rule also allows OCR to coordinate with other law enforcement agencies, such as state attorneys general and the Federal Trade Commission, with respect to pursuing remedies against HIPAA violators.
Tiered Penalty Amounts
Under the HITECH Act, there are four tiers of increasing penalty amounts that correspond to the levels of culpability associated with a HIPAA violation. The minimum fines range between $100 and $50,000 per violation, and are capped at $1.5 million for all violations of the same HIPAA provision during any calendar year (see below table). The lowest category of violation covers situations where the covered entity or business associate did not know, and by exercising reasonable diligence would not have known, of the HIPAA violation. The second lowest category of violation applies to violations due to reasonable cause and not to willful neglect. The third category applies to situations where the violation was due to willful neglect and was corrected within 30 days of when the covered entity or business associate knew, or should have known, of the violation. The fourth category applies to situations where the violation was due to willful neglect and not corrected within 30 days of when the covered entity or business associate knew, or should have known, of the violation.
The Final Rule modifies the definition of "reasonable cause" to mean "an act or omission in which a covered entity or business associate knew, or by exercising reasonable diligence would have known, that the act or omission violated [HIPAA], but in which the covered entity or business associate did not act with willful neglect." The Final Rule keeps the definition of "willful neglect" as the "conscious, intentional failure, or reckless indifference to the obligation to comply" with HIPAA.
Counting Violations
In the preamble to the Final Rule, OCR states that how it counts HIPAA violations for purposes of calculating a civil monetary penalty varies depending on the circumstances surrounding the violation. OCR explains that where multiple individuals are affected by a HIPAA violation (e.g., a breach of unsecured PHI), it is anticipated that the number of identical HIPAA violations would be counted by the number of individuals affected. OCR also explained that, with respect to continuing violations (e.g., a lack of appropriate safeguards for a period of time), it is anticipated that the number of identical HIPAA violations would be counted on a per day basis (i.e., the number of days the covered entity or business associate did not have appropriate safeguards in place to protect the PHI). OCR notes that in many HIPAA breach cases, there would be an impermissible use or disclosure as well as a safeguards violation, for each of which OCR would be entitled to calculate a separate civil monetary penalty. Needless to say, the amount of civil monetary penalties that could be imposed against a billing company or one of its subcontractors for a HIPAA violation can be quite substantial.
Factors Used to Determine a Penalty
The Final Rule lists the following five factors that OCR will consider in determining the amount of a civil monetary penalty.
- the nature and extent of the HIPAA violation, including the number of individuals affected and the duration of the violation
- the nature and extent of the harm resulting from the violation, including physical, financial, and reputational harm, and any hindrance to an individual's ability to obtain healthcare
- the history of prior compliance with HIPAA, including whether the current violation is the same/similar to prior indications of noncompliance by the covered entity or business associate and their attempts to correct that noncompliance
- the financial condition of the covered entity or business associate, including any financial difficulties that could have affected compliance and whether a civil monetary penalty could jeopardize the future provision of healthcare
- such other matters as justice may require
The Final Rule makes covered entities and business associates liable for the acts of their business associate agents, regardless of whether the covered entity or business associate knew of the violation or had a compliant business associate agreement in place. According to OCR, the key factor in determining whether an agency relationship exists between a covered entity and its business associate, or between a business associate and its subcontractor, is the principal's right to control the agent's conduct in the course of performing a service on behalf of the principal. OCR observes that a business associate agent's conduct generally is within the scope of agency when its conduct occurs during the performance of the assigned work or incident to such work, regardless of whether the work was done carelessly, a mistake was made in the performance, or the business associate disregarded a covered entity's specific instruction. OCR further observes that, in contrast, a business associate agent's conduct generally is outside the scope of agency when its conduct is solely for its own benefit (or that of a third party), or it pursues a course of conduct not intended to serve any purpose of the covered entity. To protect itself, a billing company's services agreement with a subcontractor should specify that the subcontractor is engaged as an independent contractor, not as an agent, and the billing company does not have the right to control the subcontractor's performance.
RECOMMENDED ACTION ITEMS
Although billing companies and their subcontractors have until September 23, 2013 to fully comply with the Final Rule, they should begin preparing soon in light of the significant number of new or modified compliance obligations. In particular:- Covered entities will need to revise, negotiate, and execute business associate agreements with billing companies compliant with the Final Rule by September 23, 2013 to the extent they did not have business associate agreements in place as of January 25, 2013 that were HIPAA compliant. They have until September 22, 2014 to do so to the extent they had business associate agreements in place as of January 25, 2013 that were HIPAA compliant. OCR gives a fair amount of latitude in the content of business associate agreements, so it is important for billing companies to ensure that they are not overcommitting to responsibilities or deadlines that are not required under HIPAA.
- Billing companies that use subcontractors that create, receive, maintain, or transmit PHI on their behalf will need to draft, negotiate, and execute business associate agreements with them by September 23, 2013. Billing companies will need to ensure that these business associate agreements are at least as stringent as their business associate agreements with covered entities, and enable billing companies to meet deadlines in their business associate agreements with covered entities.
- Billing companies, including subcontractors, will need to conduct a security risk assessment, implement a written HIPAA security plan, designate a security official, and create certain written HIPAA privacy policies by September 23, 2013 to the extent they have not already done so. OCR has posted guidance on compliance with the HIPAA Security Rule found at www.hhs.gov/ocr/privacy/ hipaa/administrative/securityrule that may be helpful to billing companies and their subcontractors and facilitate their compliance efforts.
- Billing companies and their subcontractors will need to perform a gap analysis to determine what HIPAA policies and procedures need to be revised to comply with the Final Rule, and then will need to revise them by September 23, 2013 based on the gap analysis.
- Billing companies and their subcontractors will need to update by September 23, 2013 their breach notification policies and any tools concerning how to conduct a risk assessment to determine whether breach notification is required.
- Healthcare providers may ask billing companies to implement by September 23, 2013 a method to flag or make a notation in the record with respect to PHI concerning an item or service paid in full by an individual – or person acting on the individual's behalf (other than a health plan) – to ensure that such information is not inadvertently sent to or made accessible to a health plan for payment or healthcare operations purposes, such as audits by the health plan.
- Billing companies and their subcontractors will need to update their HIPAA training materials and then train their workforce members (i.e., employees, volunteers, trainees, and other persons under their direct control) by September 23, 2013 to comply with HIPAA.
Courtesy of: http://www.hbma.org/news/public-news/n_how-the-new-hipaa-regulations-affect-billing-companies-and-their-subcontractors-as-business-associates
Wednesday, July 24, 2013
HBMA ICD-10 Readiness Statement published in Wall Street Journal
The HBMA Government Relations Committee, through its spokesperson
Holly Louie, took the stage at our nation's capitol to deliver your collective
message to the National Committee on Vital and Health Statistics (NCVHS).
Holly spoke on behalf of the HBMA (hbma.org) to the NCVHS on ICD-10 Readiness -
Learn from Past, Don't Repeat 5010 Mistakes.
In testimony before the NCVHS Subcommittee on Standards, Holly Louie, CHBME,
Chair of HBMA's ICD-10/5010 Committee presented the association's views on
"lessons learned" from the 5010 implementation and how those lessons can and
should be applied to avoid problems with ICD-10 implementation. NCVHS is charged
with advising the Secretary of Health and Human Services on all HIPAA related
matters.
Louie was part of a panel of experts invited. In her testimony, she said,
"HBMA believes that we MUST learn from the mistakes that were made in
transitioning from 4010 to 5010, and undertake the transition from ICD-9 CM to
ICD-10 CM in a way that demonstrates we learned those lessons."
Louie shared HBMA's concern that in order for there to be a successful
transition from ICD-9 CM to ICD-10 CM "we must allow the 'lessons learned' from
the 4010 to 5010 transition last year to materially inform the implementation of
ICD-10 CM." Louie pointed out to the Subcommittee that "the economic stability
of America's healthcare reimbursement system will be at risk and could be
severely compromised, affecting provider financial viability and patients'
access to care."
The Centers for Medicare and Medicaid has already delayed the effective date
for ICD-10 CM implementation from October 1, 2013 to October 1, 2014. Speaking
about this delay, Louie said, "it is imperative that the time gained by the
delay be used wisely in order to ensure that the transition is successful. If we
fail to learn the lessons we will merely be delaying the likelihood for payment
disruptions and patient access to care problems from 2013 to 2014."
HBMA strongly recommends the following:
HBMA's expert remarks were made on behalf of the membership with the goal of
making this transition as smooth as possible for the entire medical community.
To learn more about ICD-10 transition, go to www.hbma.org.
Related Searches: NCVHS, ICD-9, ICD-10, HBMA, HIPAA, Holly Louie, 5010
SOURCE Healthcare Billing & Management Association
/Web site: http://www.hbma.org
HBMA testifies before NCVHS on ICD-10 Readiness
Learn from Past, Don't Repeat 5010 Mistakes
LAGUNA BEACH, Calif., June 28, 2013 /PRNewswire-USNewswire/ -- Because of its
significant role in revenue cycle management, the Healthcare Billing and
Management Association (www.hbma.org) was invited recently to participate in
discussions with the National Committee on Vital and Health Statistics (NCVHS)
Subcommittee on Standards in Washington, D.C. to provide an update on the status
of transitioning from ICD-9 CM to ICD-10 CM by the October 1, 2014 effective
date. 1. While CMS has adopted a definition of "ready" and developed the tools and
checklists to assist every provider, organization, payor and vendor to
validate they are ready on October 1, 2014, a subsequent announcement by
CMS that they will not perform any external testing is extremely
problematic for the industry. End-to-end testing by all payors, to meet
the definition of "ready" must occur to ensure a smooth ICD-10 CM
implementation. Failure to engage in meaningful end-to-end testing is a
recipe for disaster.
2. CMS must establish period benchmarks that cannot be ignored to assess the
"readiness" status for all facts of the healthcare industry.
3. There must be clear pronouncement that there is no vendor, EHR, coding
assist tool, map, crosswalk or other product that will solve the problem
of excellent medical record documentation and accurate coding.
Physicians and staff must be fully prepared with adequate training to
operate compliantly and not rely on false proclamations of marketed
solutions.
4. Payor policies will be critical to the appropriate adjudication of
claims. Currently, there is a wide variance among payors in stated
policies. It is imperative that policies are published by October 1,
2013 in order to allow adequate time for education and training, data
analysis and other preparations for ICD-10 CM.
5. Any payor that is currently only accepting claims by 4010 format must be
fully 5010 compliant by January 1, 2014 in order to be ICD-10CM ready.
Subscribe to:
Posts (Atom)