HIPAA Law



             


Thursday, April 23, 2009

Health Insurance ? Not As Straightforward As It Would Seem

Most of the seven million people covered by health insurance in the UK have a policy provided by their company. As such it is a useful benefit, but many of us assume that it will cover any kind of health issue and this is definitely not the case. The insurers exclude a wide variety of possible claims, and this article will explain those in detail.

Health insurance has a very specific purpose ? to get people suffering from short-term, curable health problems straight through to a consultant and to receive top quality private care in top speed time. Essentially, it's about jumping the lengthy NHS queues. However, there are many health problems that don't fit into this narrow band, and as such are not covered by a health insurance policy.

Be aware however that every policy is different, and only be reading your own policy documents will you be able to find out exactly what you are covered for. This article will give you the knowledge you need to understand your policy better.

Defining ? Chronic'

Illnesses and conditions etc fall into two main categories: ?acute' and ?chronic'. Short-term illnesses that can be fixed and cured are called ?acute', for example if you fell and broke your arm, this would be classed as acute. If, however, your problem is either incurable or deemed to be a long-term issue, then it will be classed as ?chronic' and subsequently you will not be able to make a claim.

What counts as ?acute' and what counts as ?chronic' is a hotly disputed issue between insurance companies and their customers. Diabetes and asthma are acknowledged as chronic, long-term conditions that cannot be cured.

The issues become more difficult with certain types of cancer. It often happens that the cancer is considered to be treatable at first, and then the diagnosis is changed at a later time to incurable. In this case, you would only be covered as long as the cancer was diagnosed curable. If the prognosis changes you will lose your cover. Insurance companies are allowed to reclassify an illness from acute to chronic at any time.

What about the long-term
If you need long-term treatment then you're out of luck. However insurers have different ideas on what constitutes long-term, you may be covered for 10 months or up to a year, but it probably won't be for any longer than that. Check your policy for details.

Does preventative medicine count?
Health insurance cannot be used to pay for preventative treatment, although that is another matter of contention. For example, a drug called ?Herceptin' can be used to help women who have ?HER2', a virulent form of breast cancer. The drug has helped reduce the risk of the cancer returning by an average of 50%. Many would call this an essential treatment, but some insurers call it preventative. Legal and General and Axa PPP will not pay for this treatment, however BUPA, Standard Life Healthcare, Norwich Union and WPA will.

Drugs not yet available on the NHS
You might think that it doesn't matter if the drug is available on the NHS, but it relates to the system of drug approval in England and Wales. Before a drug can be used in the NHS, it must be approved by The Institute for Health and Clinical Excellence. The problem is, if it's not approved, the insurance company won't allow you to be treated with it. Huge delays affect the introduction of new drugs into the NHS because The Institute for Health and Clinical Excellence must first ascertain if the benefits of the drug justify the financial costs of adding it to the NHS treatments. As a result, the drug you need may not be approved, and if so, it won't be covered.

Aware of this problem. the Financial Ombudsman issued a compromise which stipulates if the insurer won't cover ?experimental treatments', then it should cover the cost of the approved conventional treatment. The policyholder is then free to undergo the experimental treatment and pay the surplus if it's more expensive.

Pre-existing conditions

A ?pre-existing condition' describes a condition or illness that you suffered from before starting your health insurance policy. You will have to provide details of all these when you fill out your application form. That way the insurer is aware of what they can exclude from your policy. Be sure to be truthful in the application form as the insurer can easily contact your doctor to see your medical history, and they often do ? having requested your approval first. They will also sometimes ask people to undergo a medical examination.

What counts as a pre-existing condition is also a potentially sore subject. If you fell off your horse years ago and fractured an ankle, you may find in later life that it starts playing up again and you need an operation to fix the problem. The insurance company may reject a claim, saying that it's a condition that occurred before the policy began. If that happens, you either pay yourself, or go with the NHS.

Some insurance companies write a moratorium provision into their policies, which allows some respite from a potential long list of pre-existing conditions. For example, you may be covered as long as you have not suffered from the condition for two years, with the condition first taking place in the last five years. These time frames are individual to insurance companies, read the small print first to see if your policy includes a moratorium provision.

The condition or illness is excluded

Health insurance is renewable on a yearly basis and at renewal time, you may find that your policy, and your premiums, have changed ? often not for the better.

If you are undergoing treatment at time of renewal, it's possible that your condition or illness will have become ?excluded' in the renewed policy, and that you will have to cover the cost of the rest of the treatment.

Because medical research is advancing so quickly, and the number of conditions considered treatable is increasing, the goalposts are always shifting as to what is chronic and what is acute.

The insurance companies are usually trying to cover their own backs. More conditions are being classified as acute, so they have to pay out more in claims. At the same time, newly introduced treatments and drugs are often expensive, so that's more expense to the insurer. To cover their losses, the insurers increase the premiums, and introduce some more exclusions. You have to watch out for this as you may renew your policy without realising that some very important details have changed.

So if have Health Insurance, or you are considering signing up to a policy, take this article into account and read the small print so you know exactly what is and isn't covered. And the golden rule: before getting treatment, always double check with your insurer first that it is covered.


About the Author: Safeguard is a uk critical illness insurance website. We provide a huge amount of information based around our products, to read more visit the critical illness information

Labels: , , , ,

Thursday, March 27, 2008

Fortis Health Insurance Is a Name You Can Trust!

Fortis Health Insurance Is a Name You Can Trust!

Fortis health insurance has been a widely recognized name in the insurance since 1892. It has proven itself and won the trust of people around the world. Fortis health insurance is committed to providing the best solutions possible to meet your insurance needs.

There are a great variety of plans available. Fortis short term health insurance is of great use to those who are temporarily uninsured. Students can find Fortis short term health insurance tailored especially for them. From complete coverage to a specific prescription plan, Fortis health insurance will have what you are looking for.

Fortis health insurance is a driving force behind the new Health Savings Accounts, known as HSAs. An HSA works like an IRA, except that the money is used to pay health care costs. The money deposited and the interest earned are tax-deductible, and the money can be withdrawn to pay medical bills, tax-free. This is becoming a very popular method of helping pay for your current medical needs, and safe-guarding for your future.

Fortis health insurance is changing its name to Assurant Health. Rest assured that there will be no change at all in the high quality service and dependability that people around the world have come to expect from Fortis health insurance.


http://www.a1-healthinsurance-4u.com/

Labels: , , , , ,

Tuesday, March 25, 2008

Fortis Health Insurance Is a Name You Can Trust!

Fortis Health Insurance Is a Name You Can Trust!

 by: Mike Yeager

Fortis health insurance has been a widely recognized name in the insurance since 1892. It has proven itself and won the trust of people around the world. Fortis health insurance is committed to providing the best solutions possible to meet your insurance needs.

There are a great variety of plans available. Fortis short term health insurance is of great use to those who are temporarily uninsured. Students can find Fortis short term health insurance tailored especially for them. From complete coverage to a specific prescription plan, Fortis health insurance will have what you are looking for.

Fortis health insurance is a driving force behind the new Health Savings Accounts, known as HSAs. An HSA works like an IRA, except that the money is used to pay health care costs. The money deposited and the interest earned are tax-deductible, and the money can be withdrawn to pay medical bills, tax-free. This is becoming a very popular method of helping pay for your current medical needs, and safe-guarding for your future.

Fortis health insurance is changing its name to Assurant Health. Rest assured that there will be no change at all in the high quality service and dependability that people around the world have come to expect from Fortis health insurance.

Mike Yeager

Publisher

http://www.a1-healthinsurance-4u.com/

Labels: , , , , ,

Tuesday, February 26, 2008

Canadas Aging Baby Boomers: Planning Health Insurance for the Future

The first of Canadas aging baby boomers are poised to turn 65, and with this milestone birthday comes a variety of new health care concerns. In response to these changing medical needs, the Canadian health care system is preparing to handle some 10 million boomers whose reasons for visiting the hospital will range from hearing loss to long-term care. The aging of this Canadian demographic is inevitable, but falling into financial debt in order to pay for these services can be avoided. By thinking ahead to what medical services may be required, individuals are able to customize their health insurance accordingly.

Living in a country like Canada where health care is provided for all is an undeniable luxury. Yet, despite the many benefits of Canadian health care, there are gaps that exist in coverage. These gaps dictate the need for supplementary health insurance. Sadly, there are many instances where people have met with unexpected illness, but there are also many health issues that can be planned for. Aging is one such issue.

Some of the most common services required by seniors include: x-rays for weakening bones, a visit to the podiatrist for any number of foot related issues and testing and fitting hearing aids for hearing loss. Each of these services may be an inevitability for the aging individual, but they may not all be covered by the Canadian government. Provincial health plans vary from province to province with certain provinces offering a proscribed amount of money yearly for various necessities, such as a trip to the podiatrist. A visit to a specialized doctor or the purchase of a hearing aid can be very costly, and with little to no coverage, people are often left with a substantial financial burden. Supplemental health insurance is the best way for seniors to plan for and minimize these costs.

Opting for supplemental health insurance allows you to customize your plan to suit your individual needs. For many seniors, the prospect of spending time in a hospital is not a pleasant one, but with supplemental coverage, a private room in a health care facility can make the stay more comfortable. Not only does health insurance ease the worry that individuals may have concerning their own personal welfare, but it also helps to assuage the fears of family members on whom the burden of long-term care would fall.

As ten million Canadians begin to approach the time in their life when retiring is imminent, it becomes a necessity to plan for whatever eventualities the future might hold. Thinking ahead to answer the various demands of aging helps guarantee a peace of mind for yourself and your family and ensures that you are ready to face the challenge of lifes milestones.

Anna Dorbyk is the editor for Canada Health Insurance and is a graduate student in Communication Studies at Concordia University. For more information on health insurance for Canadians please visit http://www.canada-health-insurance.com/.

Labels: , , , ,

Thursday, January 17, 2008

Overview Of The Health Insurance Portability And Accountability Act (HIPAA)

Congress enacted the Health Insurance Portability and Accountability Act (HIPAA) in 1996. The purpose of this law is to protect private individual health information from being disclosed to anyone without the consent of the individual. Except under unusual circumstances, the consent needs to be in writing.

However, there are some exceptions to the consent provision. The consent provision does not apply in the following situations:

- Treatment
- Billing
- Quality assurance
- Peer review
- Business planning activities
- Staff training
- Required reporting to public health agencies
- Certain emergency situations
- Research studies that have obtained a wavier from the Institutional Review Board (IRB)

Research

Private health information can be used in research studies if it is "de-individualized" so that the identity of the individual cannot be ascertained from the information disclosed. For example, if you were conducting a study of the lung problems suffered by New Yorkers after the 911 terrorist attacks, it would be permissible to identify a patient as, a 50 year old, 5'11', 175 lb., while male from New York City with high blood pressure.

Marketing

Health care providers are prohibited from selling or using their patient or enrollees lists to market products from a third party. However, they can use their list to communicate with or sell their own services to their list members. Great care must be taken to restrict access when using online collaboration, such as an intranet (http://www.trichys.com).

Business Associates

All business associates, vendors or other contractors that use the health care provider's facility must sign a contract stating that they understand and agree to be bound by HIPAA regulations. The health care provider can be held responsible for the actions of the business associate if they did not sign a contract or there was a history of abuse and the health care provider did noting about it.

Individual Rights

Under HIPAA, individuals have the right to:

- Notice of the health provider's privacy practices
- Request restrictions on who is allowed to access their health information
- Access, inspect or copy their personal health information
- Request an accounting of all disclosures of their health information
- Request corrections or amendments to their health information

Health Care Providers Responsibilities

Health care providers are required to:

- Provide security for both paper and electronic individual health information
- Institute a complaint process to investigate complaints
- Train staff on the law

The HIPAA regulations allow for both civil monetary and criminal penalties for violations of the act.

Malcolm Brown is Vice President of Trichys, providers of intranets and extranet solutions for health care and HIPAA compliance (http://www.trichys.com/home/industry-solutions/hipaa.vm).

Labels: , , , ,

Friday, January 11, 2008

HIPAA and Email - How Does Your Practice Deal with Compliance in a Digital Age

The internet has created a new business model for the smaller medical practice, specialty clinic and medical service (e.g. dermatologist, plastic surgeon, physical therapist, psychologist, et. al). More and more, patients are looking to communicate with their healthcare providers as they do in their personal and business lives - via email.

Email as a communication solution for the smaller clinic can be a time-saving resource. It can replace the many phone calls and postal mailings, adding a financial benefit to the smaller clinic.

Does email eliminate the office visit? No nothing can replace the personal face-to-face office visit, but email can be an additional tool clinicians can implement to streamline their practice.

Some healthcare practitioners do however feel that emailing their patients equates to working for free, but some clinics have already adopted charging for email consultations.

At some practices, patients pay a flat rate from $100 to several hundred dollars per year for this type of service. Harvard professor of medicine Dr. Daniel Z Sands, a proponent to a digital clinic, stated "I think it's reasonable to assume that if lawyers and accountants charge for time, then physicians should too. (1)"

Sustainability of Health Information Technology is also on the government's radar. As part of the President's mandate to move the medical field towards a digital clinical setting within the next ten years (2). The National Coordinator for Health IT, Dr. David Brailer, noted the value-added benefit of investing in Healthcare IT:

Information technology supports treatment choices for consumers and enables better and more cost-effective care... Health IT not only adds value to the way people lead their lives, but it gets more out of our investment in healthcare overall. (3)

It is possible for clinics to shift towards a digital medical office while remaining financially solid. Rights management software tools have become a reality for the small and medium business office (4). Small Business Rights Management (SBRM) reflects a shift Rights Management software tools.

SBRM solutions provide clinics and practices of a smaller scale an equal level of user rights management and encryption previously available to larger medical organizations (e.g. state hospitals, large research facilities, university medical networks, etc.).

With any medical advance, the side affects of a solution or cure, must also be considered. While email is beneficial time-wise and financially, there are also cons to using this tool - many HIPAA related. According to the Health Privacy Project's 2005 study, 70% of Americans are concerned that personal health information (PHI) could be disclosed as a result of weak data security (5)

Currently, healthcare organizations are required to provide a disclosure statement when communication is sent to their patients. A sample of a healthcare professional's email disclosure statement may read like this:

Client information gathered by [Clinic or Organization's Name] is protected by Federal Law. If this communication contains any client information, including information which would identify a client, you are prohibited from redisclosing it to any person or organization in any manner, and you are required to maintain it as confidential. Failure to do so is punishable by civil and criminal penalties. If such information has reached you in error, please contact [Clinic or Organization's Name] contact@emailaddress.com

With the advent of phishing, malware, and spyware, the unintended recipient could possibly spread a patients PHI like a virus; using or selling data to any number of damaging sites.

Protecting a patient's PHI is an ingrained concept within the medical profession. Laws and government mandates are take this notion a step further, medical facilities not compliant to protecting their patient's PHI face stiff penalties under HIPAA. PHI includes and is not limited to:

* Patient's address, phone number
* Treating Hospital/Clinic number assigned the patient
* Patient's date of birth/ SSN
* Patients legal next of kin/guardian and their telephone number
* Patient's insurance information (pre-certification/ DSHS/ Medicare)
* Anticipated Admission date and time<

While there are some drawbacks to email, patients want the option of emailing their doctor, pharmacist, therapist or clinic. "People are often more comfortable talking to a computer than they are to a doctor," said Dr. Delbanco, a professor of medicine at the Harvard Medical School and the lead author of an article on doctors and e-mail in the New England Journal of Medicine (6).

Dealing with HIPAA compliance issues can often be frustrating to the small clinical practice. SBRM solutions bridge the gap between staying current with healthcare industry regulations and keeping a small physician practice open. Patient/client information, private communiqu? regarding diagnosis/treatment, and medical billing can stay discreet, only the intended recipient will see this information.

With SBRM solutions; clinics don't have to worry that their email content breaks the Hippocratic Oath's creed of confidentiality by revealing patient's PHI. Healthcare providers can remain both respectful and compliant under HIPAA regarding the patient privacy.

- - - - - - - - - -

End Notes:

1.) Dr. Daniel Z. Sands as quoted in Liz Kowalczyk's article "Is E-Mailing the Future of Doctor-Patient Relations?" The Boston Globe, D2, April 27, 2004, Lexis Nexus - http://www.lexisnexus.com

2.) United States Department of Health and Human Services, "Secretary Leavitt Takes New Steps to Advance Health IT," Press Release on HHS website, June 6, 2005, http://www.os.dhhs.gov/

3.) "Remarks by David Brailer, MD PhD National Coordinator for Health Information Technology HIMSS 2005" February 17, 2005, http://www.himss.org

4.) SBRM on Wikipedia - http://en.wikipedia.org/wiki/Small_Business_Rights_Management

5.) "Majority of Americans Have Privacy Concerns about Electronic Medical Record System," Health Privacy Project (www.heathprivacy.org): http://www.healthprivacy.org/info-url_nocat2303/info-url_nocat_show.htm?doc_id=263085

6.) Anahad O'Connor, "Take Two Aspirin, E-Mail Me Tomorrow," The New York Times, Section F; Column 5; Health & Fitness; 7., 30 September 2005, Lexis Nexis - http://www.lexisnexus.comMs. Veniegas is an alumni of the University of Washington Marilee joined the Marketing team at Essential Security Software, Inc. in 2005. She also serves as one of the ESS site editors for "I Want My ESS!

Labels: , , , ,

Thursday, January 10, 2008

How HIPAA Security Policies Affect Corporate E-mail Systems

TrustAlthough considered by many to be the sole concern of health care providers, the Health Insurance Portability and Accountability Act (HIPAA) affects nearly all companies that regularly transmit or store employee health insurance information. HIPAA was signed into law in 1996 and it's original purpose was to protect employee health and insurance information when workers changed or lost their jobs. As use of the internet became more widespread in the mid-1990s, HIPAA requirements overlapped with the digital revolution and offered direction to organizations needing to exchange healthcare information. HIPAA regulations apply to any establishment that exchanges individually identifiable healthcare information.

Collaboration between healthcare professionals, their colleagues, their patients, and employers has grown progressively more digital, and e-mail has played an ever-increasing role in this communication. In the process of this development, the need for information security and privacy has created an impediment to widespread adoption.

In addition to the usual concerns about privacy and security of e-mail correspondence, even organizations that are not in the heathcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how e-mail containing PHI should be treated in the corporate setting. HIPAA, as it relates to e-mail security, is an enforcement of otherwise well-known best practices that include:


  • Ensuring that e-mail messages containing PHI are kept secure when transmitted over an unprotected link
  • Ensuring that e-mail systems and users are properly authenticated so that PHI does not get into the wrong hands
  • Protecting e-mail servers and message stores where PHI may exist

Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and catch up with other industries of similar size and scope.

The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

Starting April 21, 2005, a new security rule focusing solely on PHI that is stored and transmitted electronically will be enforced as part of HIPAA. The requirements of this rule, which are simply information security best practices, focus on the three cornerstones of a solid information security infrastructure confidentiality, integrity, and availability of information.

The imminent HIPAA regulatory requirements encompass PHI transmission, storage and discoverability. Given the widespread use and importance of e-mail, enforcement of HIPAA encryption policies and the growing demand for secure e-mail solutions, e-mail security has never been more important to the healthcare industry than it is right now.

IronMail significantly contributes to compliance with the HIPAA privacy and security requirements as they relate to protecting PHI that is transmitted and stored via e-mail. Everything from data encryption to firewall and intrusion protection to content filtering is included in the IronMail solution. Once in place, IronMail can be used to protect e-mail going into and out of corporate networks.

As IronMail is a standards-based appliance, it can be integrated into any existing e-mail system seamlessly, without requiring extensive IT staff training, or relying on users to take extra steps to perform e-mail functions.

The IronMail appliance is tailored to help organizations comply with the stringent new guidelines imposed by HIPAA, from security management processes to access control to data integrity.

HIPAA compliance is seen by many organizations as a prohibitively expensive hurdle to overcome. In addition, the growing dependence on e-mail as a mission-critical application requires security and privacy to be a top priority. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence. With IronMail, organizations reduce information complexities as well as associated management costs which can help improve patient relationships, increase the quality of care, and improve the bottom line. E-mail can indeed be safe and secure.

Collaboration between healthcare professionals, their colleagues, their patients, and employers has grown progressively more digital, and e-mail has played an ever-increasing role in this communication. In the process of this development, the need for information security and privacy has created an impediment to widespread adoption.

In addition to the usual concerns about privacy and security of e-mail correspondence, even organizations that are not in the heathcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how e-mail containing PHI should be treated in the corporate setting. HIPAA, as it relates to e-mail security, is an enforcement of otherwise well-known best practices that include:

  • Ensuring that e-mail messages containing PHI are kept secure when transmitted over an unprotected link
  • Ensuring that e-mail systems and users are properly authenticated so that PHI does not get into the wrong hands
  • Protecting e-mail servers and message stores where PHI may exist

Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and catch up with other industries of similar size and scope.

The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

Starting April 21, 2005, a new security rule focusing solely on PHI that is stored and transmitted electronically will be enforced as part of HIPAA. The requirements of this rule, which are simply information security best practices, focus on the three cornerstones of a solid information security infrastructure confidentiality, integrity, and availability of information.

The imminent HIPAA regulatory requirements encompass PHI transmission, storage and discoverability. Given the widespread use and importance of e-mail, enforcement of HIPAA encryption policies and the growing demand for secure e-mail solutions, e-mail security has never been more important to the healthcare industry than it is right now.

IronMail significantly contributes to compliance with the HIPAA privacy and security requirements as they relate to protecting PHI that is transmitted and stored via e-mail. Everything from data encryption to firewall and intrusion protection to content filtering is included in the IronMail solution. Once in place, IronMail can be used to protect e-mail going into and out of corporate networks.

As IronMail is a standards-based appliance, it can be integrated into any existing e-mail system seamlessly, without requiring extensive IT staff training, or relying on users to take extra steps to perform e-mail functions.

The IronMail appliance is tailored to help organizations comply with the stringent new guidelines imposed by HIPAA, from security management processes to access control to data integrity.

HIPAA compliance is seen by many organizations as a prohibitively expensive hurdle to overcome. In addition, the growing dependence on e-mail as a mission-critical application requires security and privacy to be a top priority. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence. With IronMail, organizations reduce information complexities as well as associated management costs which can help improve patient relationships, increase the quality of care, and improve the bottom line. E-mail can indeed be safe and secure.
CipherTrust is the leader in anti-spam and email security. Learn more by downloading our free whitepaper, Contributing to HIPAA Compliance with IronMail or by visiting www.ciphertrust.com.

Labels: , , , ,

Tuesday, January 8, 2008

Alert: New HIPAA Rules Could Affect Your Organization

 Trust Failure to adhere to the new guidelines could cost your company
up to $250,000 per infraction!


On April 21, 2005 (just over three weeks from today), a new Health Insurance Portability and Accountability Act (HIPAA) security rule goes into effect. The requirements of this rule, which are basically information security best practices, focus on the three cornerstones of a solid information security infrastructure: confidentiality, integrity and availability of information.

The imminent HIPAA regulatory requirements encompass transmission, storage and discoverability of Protected Health Information (PHI). Given the widespread use and mission-critical nature of email, enforcement of HIPAA encryption policies and the growing demand for secure email solutions, email security has never been more important to the healthcare industry than it is right now.

Although many assume it applies only to health care providers, HIPAA affects nearly all companies that regularly transmit or store employee health insurance information. HIPAA was signed into law in 1996 by former President Bill Clinton, with the intent of protecting employee health and insurance information when workers changed or lost their jobs. As Internet use became more widespread in the mid-to-late 1990s, HIPAA requirements overlapped with the digital revolution and offered direction to organizations needing to exchange healthcare information.

HIPAA in the Workplace
Collaboration between employers and healthcare professionals has grown increasingly digital, and email has played an ever-increasing role in this communication. However, emails increased importance can lead to severe consequences without proper security and privacy measures implemented.

In addition to the usual concerns about privacy and security of email correspondence, even organizations that are not in the healthcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how email containing PHI should be treated in the corporate setting. HIPAA, as it relates to email security, is an enforcement of otherwise well-known best practices that include:


  • Ensuring that email messages containing PHI are kept secure when transmitted over an unprotected link
  • Ensuring that email systems and users are properly authenticated so that PHI does not get into the wrong hands
  • Protecting email servers and message stores where PHI may exist


Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and catch up with other industries of similar size and scope.

Privacy and Email Security
The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

The clock is ticking its time to get started
Bringing an enterprise into compliance with the rules set by HIPAA can seem like a very daunting task to even the most experienced executives. Nonetheless, the growing dependence on email as a mission-critical application requires that your organization implement comprehensive security and privacy policies and soon. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence.

Despite the immediacy of the new HIPAA security rule, your organization can still achieve compliance. Learn more about how IronMail helps organizations comply with HIPAA by downloading CipherTrusts free whitepaper, "IronMail Compliance Control: Contributing to Corporate Regulatory Compliance". Failure to adhere to the new guidelines could cost your company
up to $250,000 per infraction!


On April 21, 2005 (just over three weeks from today), a new Health Insurance Portability and Accountability Act (HIPAA) security rule goes into effect. The requirements of this rule, which are basically information security best practices, focus on the three cornerstones of a solid information security infrastructure: confidentiality, integrity and availability of information.

The imminent HIPAA regulatory requirements encompass transmission, storage and discoverability of Protected Health Information (PHI). Given the widespread use and mission-critical nature of email, enforcement of HIPAA encryption policies and the growing demand for secure email solutions, email security has never been more important to the healthcare industry than it is right now.

Although many assume it applies only to health care providers, HIPAA affects nearly all companies that regularly transmit or store employee health insurance information. HIPAA was signed into law in 1996 by former President Bill Clinton, with the intent of protecting employee health and insurance information when workers changed or lost their jobs. As Internet use became more widespread in the mid-to-late 1990s, HIPAA requirements overlapped with the digital revolution and offered direction to organizations needing to exchange healthcare information.

HIPAA in the Workplace
Collaboration between employers and healthcare professionals has grown increasingly digital, and email has played an ever-increasing role in this communication. However, emails increased importance can lead to severe consequences without proper security and privacy measures implemented.

In addition to the usual concerns about privacy and security of email correspondence, even organizations that are not in the healthcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how email containing PHI should be treated in the corporate setting. HIPAA, as it relates to email security, is an enforcement of otherwise well-known best practices that include:

  • Ensuring that email messages containing PHI are kept secure when transmitted over an unprotected link
  • Ensuring that email systems and users are properly authenticated so that PHI does not get into the wrong hands
  • Protecting email servers and message stores where PHI may exist


Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and catch up with other industries of similar size and scope.

Privacy and Email Security
The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

The clock is ticking its time to get started
Bringing an enterprise into compliance with the rules set by HIPAA can seem like a very daunting task to even the most experienced executives. Nonetheless, the growing dependence on email as a mission-critical application requires that your organization implement comprehensive security and privacy policies and soon. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence.

Despite the immediacy of the new HIPAA security rule, your organization can still achieve compliance. Learn more about how IronMail helps organizations comply with HIPAA by downloading CipherTrusts free whitepaper, "IronMail Compliance Control: Contributing to Corporate Regulatory Compliance".
CipherTrust is the leader in anti-spam and email security. Learn more by downloading our free whitepaper, IronMail Compliance Control: Contributing to Corporate Regulatory Compliance or by visiting www.ciphertrust.com.

Labels: , , , , , ,

Are you HIPAA Compliant?Matt Sears

By - Matt Sears, Senior Vice President
Athens Benefits Insurance Services, Inc.
A division of The Jenkins Athens Group

HIPAA. Perhaps one of the most significant laws in recent memory; certainly one of the most complex. While this short article won't make anyone an expert, it will, hopefully, demystify this wide ranging set of laws and put you on the path towards compliance.

First, let's answer the question; "What is HIPAA?" HIPAA stands for the Health Insurance Portability and Protection Act of 1996. Although it purports to regulate health insurance, HIPAA provisions extend far beyond insurance. HIPAA introduced broad disclosure and privacy requirements. It also established civil and criminal penalties for each violation (up to $25,000 per person per year in civil penalties and up to $250,000 in criminal fines - along with imprisonment).

Title I of HIPAA deals with portability and special enrollment rights for health plans. Those conditions must have been incorporated into your plans by now (original compliance date was 1997). Title II of HIPAA governs a wide ranging set of conditions called, "Administrative Simplification". For those charged with compliance, the notion that HIPAA simplifies anything qualifies as "dark humor". Administrative simplification attempts to create a uniform system for processing and retention of health information and ensuring the security of that information.

For the purposes of this article, we're only concerned with those portions of the law impacting most employers...privacy. Notably the privacy of personal data defined by HIPAA as "Protected Health Information" or "PHI" - information that is personally identifiable. In the broadest summary possible, key components of HIPAA privacy requirements for a plan sponsor are fairly straightforward:

Generally, the employer (Plan Sponsor) is not a HIPAA "Covered Entity" - the Health Plan is. For fully insured plans, this typically means the health insurer, HMO, EAP provider, etc.
As the Covered Entities, health plans bear the brunt of compliance requirements (your responsibilities become exponentially larger as the quantity of data you receive increases)
Meet with every service provider, or ensure that your broker or consultant has reviewed compliance requirements with each
Use protected health information only for needed administration of the benefit programs (HIPAAspeak: "Treatment, Payment and Health Care Operations)
Collect (and release) only the minimum data required to "do the job" (e.g. enroll an employee, file claims, etc.)
Restrict the data to those persons who absolutely must use it
Establish "firewalls" and safeguards to protect the data (separate locked files, restricted access, password protect systems)
Appoint a Privacy Official (not required for fully insured plans that never receive PHI)
Create a Privacy Policy and distribute a Privacy Notice to participants
"Scrub" personally identifiable data from communications pieces, ID Cards, etc.

HIPAA, like COBRA before it, will continually change as new rules and regulations are released (for example, the U.S. Dept. of HHS has yet to release enforcement rules for HIPAA). Ongoing compliance will require vigilance in remaining up to date on the changing laws. It's vital your broker/consultant proactively work with your organization to review plans, identify problems and provide ongoing education to maximize the performance of your benefit plans.
By - Matt Sears, Senior Vice President
Athens Benefits Insurance Services, Inc.
A division of The Jenkins Athens Group

HIPAA. Perhaps one of the most significant laws in recent memory; certainly one of the most complex. While this short article won't make anyone an expert, it will, hopefully, demystify this wide ranging set of laws and put you on the path towards compliance.

First, let's answer the question; "What is HIPAA?" HIPAA stands for the Health Insurance Portability and Protection Act of 1996. Although it purports to regulate health insurance, HIPAA provisions extend far beyond insurance. HIPAA introduced broad disclosure and privacy requirements. It also established civil and criminal penalties for each violation (up to $25,000 per person per year in civil penalties and up to $250,000 in criminal fines - along with imprisonment).

Title I of HIPAA deals with portability and special enrollment rights for health plans. Those conditions must have been incorporated into your plans by now (original compliance date was 1997). Title II of HIPAA governs a wide ranging set of conditions called, "Administrative Simplification". For those charged with compliance, the notion that HIPAA simplifies anything qualifies as "dark humor". Administrative simplification attempts to create a uniform system for processing and retention of health information and ensuring the security of that information.

For the purposes of this article, we're only concerned with those portions of the law impacting most employers...privacy. Notably the privacy of personal data defined by HIPAA as "Protected Health Information" or "PHI" - information that is personally identifiable. In the broadest summary possible, key components of HIPAA privacy requirements for a plan sponsor are fairly straightforward:

Generally, the employer (Plan Sponsor) is not a HIPAA "Covered Entity" - the Health Plan is. For fully insured plans, this typically means the health insurer, HMO, EAP provider, etc.
As the Covered Entities, health plans bear the brunt of compliance requirements (your responsibilities become exponentially larger as the quantity of data you receive increases)
Meet with every service provider, or ensure that your broker or consultant has reviewed compliance requirements with each
Use protected health information only for needed administration of the benefit programs (HIPAAspeak: "Treatment, Payment and Health Care Operations)
Collect (and release) only the minimum data required to "do the job" (e.g. enroll an employee, file claims, etc.)
Restrict the data to those persons who absolutely must use it
Establish "firewalls" and safeguards to protect the data (separate locked files, restricted access, password protect systems)
Appoint a Privacy Official (not required for fully insured plans that never receive PHI)
Create a Privacy Policy and distribute a Privacy Notice to participants
"Scrub" personally identifiable data from communications pieces, ID Cards, etc.

HIPAA, like COBRA before it, will continually change as new rules and regulations are released (for example, the U.S. Dept. of HHS has yet to release enforcement rules for HIPAA). Ongoing compliance will require vigilance in remaining up to date on the changing laws. It's vital your broker/consultant proactively work with your organization to review plans, identify problems and provide ongoing education to maximize the performance of your benefit plans. Setting-up Your New Computer: How To Move Your Old Files to Your New ComputerSteven PresarYou've got a new computer for your office. It's cleaner, better, faster and you can't wait to start to use it!

However, your satisfaction of making a fresh start with a new computer is tempered by the fact that all of your "stuff" is still on your old computer. Everything that made your old computer YOUR computer: your personal settings, your business files, your company spreadsheets are still loaded on your old computer.

You find yourself with a new computer that's not so great without a whole lot of the useful file information that is still stored on your old computer. How are you going to get all of that information onto your new computer?

The process is called "data migration" and it can be a tedious and time-consuming task for you and your business.

Here are some suggestions to make this data migration go a little easier for you.

CDs

One option is to copy ("burn") everything to recordable CDs.

Blank CDs are cheap, at about $1 apiece, and can hold more than 600 megabytes each. That much storage space should be enough for most small businessess to transfer old data files from one hard drive to a new.

Two drawbacks to the CD method of data transfer are that:

~ It may take a while to burn each CD and
~ That you may not have a recordable CD drive on your old PC.

Recordable CD units are standard on newer PCs but if older computers have a CD unit, it was insatlled as later add-on hardware feature. Thus, depending on the age of your older computer, it may not have a recordable CD drive installed at all. To install a recordable CD drive on your older computer now, may be more of a time-consuming effort when compared with other alternatives to moving your data files.

Portable Drives

Iomega has a pre-packaged solution designed to bridge the gap between old and new computers. They offer a software "moving kit" for individuals who have recently bought a new computer with Microsoft's Windows XP.

The software works with Iomega Zip, Jaz and Peerless drives. It allows individuals to "pack" the files they have on their old computer onto a portable high-capacity disks and then "unpack" the same files onto your new computer.

The transfer software uses Microsoft's "files & settings transfer wizard," a feature included in Windows XP.

After connecting a high-capacity drive to your old computer, you need to download the transfer tool, which primes a disk to prompt you to begin the transfer process the next time it is inserted into a drive. Setting up the disk also requires a CD with the Windows XP operating system.

Keep in mind, software moving kits, have the ability to move everything. Thus, if you are not aware of what files that you are transferring, you may be transferring unneeded problem or virus files to your new computer.

Link Transfers

There are other options if you do not want to shuffle CDs or portable drives.

With the link transfer software option your computers are linked through a serial cable or USB cable. After the software program has been installed on both of your computers (the "source" the old computer and "target" the new computer), you click through a question-and-answer wizard to describe what files you want to transfer. And for transfers on the fly, you can drag and drop folders or files between the two panes in the program representing each computer.

Some link transfer software packages that work with Microsoft's Windows are: PCsync, IntelliMover, PC Relocator, and PC Upgrade Commander.

In each case, the software must be installed on both your old and new computers. The software scans your old computer hard drive, to inventory the folders, subfolder, and files and then you select the data files that you would like to transfer to your new computer.

It sounds like a fairly simple way to handle your data transfer. However, be aware:

~ Generally, these programs want to move all the contents of your old computer to your new computer. That's OK for your data files but moving the program files that run your applications may cause problems because older applications may not be supported by your new computer operating system. Transferring a Windows 95-era program to a computer preloaded with the Windows XP operating system could be a problem because many of those programs haven't been upgraded to run under Windows XP.

~ When you move the full contents of a computer system, everything moves over, including those obscure files that had your old computer running sluggish in its final days.

~ Moving data through a USB cable isn't fast, but it is faster than data transfer through a parallel port.

Choosing a Data Migration Software Package

~ Does the software allow you to pick and choose which files are moved, or does it move EVERYTHING -- even the junk files?

~ How is the data transferred? A wireless network is faster than a USB cable, which is faster than a USB cable, which is faster than a parallel cable. Are you prepared to wait hours or even days for this transfer to take place?

~ If you're using the Internet as a holding place for your data, check your connection and upload speeds. It could take hours to move those files.

~ Consider investing in a high-capacity external hard drive, a plug-and-play device that you'll simply connect to your new computer. The drive, though more expensive, will get far more use than one-time migration software.

Getting Ready for Your Data Migration

~ Get rid of all of your old files. Fill your recycle bin on your old computer with as much as you can. There's nothing worse than bringing useless data to the new computer.

~ Make a software checklist. Is your versions of current program applications compatible with Windows XP? Look on the Web for free Windows XP upgrades to new versions of the programs you need, such as your Palm desktop software.

~ Does your new computer have preloaded software on it? Chances are good the latest Internet browser is already pre-load on your new computer and thus you do not have to transfer the older browser version.

~ Make a list of user names and passwords that are stored in files on your old computer and automatically appear when you visit Web sites. They could be lost in the move, denying you access on your new computer.
Steven Presar is a recognized small business technology coach, Internet publisher, author, speaker, and trainer. He provides personal, home, and computer security solutions at www.ProtectionConnect.com. He provides business software reviews at www.OnlineSoftwareGuide.com. In addition, he publishes articles for starting and running a small business at www.Agora-Business-Center.com. Be sure to sign-up for the SOHO newsletter at the site.

 

Labels: , , , ,

Thursday, January 3, 2008

No Living Will & Power Of Attorney? HIPAA Law Shuts You Out

What do you mean I can't find out about my husband's accident injuries? Why can't we move my mother to the nice nursing-home down the street? The Health Insurance Portability and Accountability Act or HIPAA caused two of my clients to live through these very situations.

A husband and wife were involved in a terrible automobile accident. The husband was seriously injured. His wife wanted to make certain that the needed medical attention was given to her husband. The wife could not get any medical information from her doctor. Even though she was the wife, the new HIPAA law and regulations prevents her from receiving medical information without specific written authorization!

In another case, an elderly widow lady became incapacitated. Her two children wanted to place her in a nursing home so that she would receive adequate care. Even though they had a living will and health-care power of attorney for their mother, they were required to go to court and be appointed her guardians so that they could place their mother in the health care facility.

What is the HIPAA Law all about?

The HIPAA Law in a Nutshell

HIPAA took effect on April 14, 2003.

This legislation applies to virtually every physician, nurse, pharmacist, dentist, and health care provider in the nation. It impacts everyone's access to health care information.

What does this privacy act mean? The regulations stress that health care providers must limit health information to those who are intended to receive it. This means health care information cannot be released to any unauthorized person. This may mean you may not be able to receive medical records for your spouse or parent.

HIPAA Violation Penalties

The penalties for health care providers are staggering. For each disclosure violation, there is a $100 fine. If the violation is knowing, there are criminal penalties of a $50,000 fine and up to one year in prison. If information is provided or obtained under false pretenses, there is $100,000 fine and up to five years in prison. If the wrongful sale, transfer or use of the information was for commercial advantage, there is a $250,000 fine and up to 10 years in prison.

How does this affect you? To ensure an easy transition, you must have the appropriate medical release language to comply with HIPAA in three of your estate planning documents.

Documents to Update

The documents which need to be updated are:

 

  • Your Living Will and Health Care Power of Attorney
  • Your Living Trust
  • Your Durable Power of Attorney

 

What if I do nothing?

You may be forced to sign the doctor's or hospitals forms in a stressful emergency situation. These documents may not reflect your choices and may contain confusing legal and/or medical terminology. Or you may be unable to sign anything and may repeat one of the above scenarios.

If your documents were created before 2003 and have not been amended since, have your attorney review them for HIPAA compliant language. Are you missing some or all of these documents? Make an appointment today!

Visit http://www.stevenallen.com for tips and tools on Wealth Preservation. You can also subscribe to his monthly newsletter Secrets To Wealth Preservation. Steven W. Allen has been an Estate Planning attorney for over 30 years. He is a member of the Arizona Bar Association, National Lawyers Association, National Academy of Elder Law Attorneys and National Speakers Association. He is the author of four books including the most recent You Can’t Take It With You...So How Will You Leave It Behind?. Go to http://www.EstatePlanningDr.com for your 3 free chapters.

Labels: , , , , , ,

Sunday, December 30, 2007

5 Facts About NPI For HIPAA Compliant Electronic Medical Billing Software And Service

The 1996 Health Insurance Portability and Accountability Act (HIPAA) established national privacy and security standards for electronic health care transactions, including a national identifier for providers, health plans and employers. Accordingly, by May 23, 2007, healthcare providers and all health plans and clearinghouses must change both their processes and information systems to implement HIPAA’s National Provider Identifier (NPI) regulations.

Background on the NPI regulation

  • HIPAA mandated regulation
  • Effective nationwide on May 23, 2007
  • The compliance date for health care payers with less than $5 million in annual revenue is May 23, 2008

 

What is the NPI?

  • A unique 10-digit identification number
  • Assigned for life to a provider and de-activated only upon death, retirement, or identity theft
  • Replaces multiple legacy provider identification numbers, including Medicare UPINs, commercial payer IDs and state Medicaid IDs
  • Contains no identifying information related to the provider - randomly generated
  • Independent of key provider information changes, such as practice location or specialty
  • Providers have 30 days to update their NPI record

 

Who is affected by the NPI mandate?

  • Payers
    • Health plans
  • Clearinghouses
  • Providers
    • Organizational providers
    • Individual providers

 

Why is the NPI necessary?

  • NPI delivers two-fold benefits for payers and providers:
    • Simplifies communication and administration
    • Facilitates efficient electronic transmission of certain health information
  • Streamlines detection of billing fraud and abuse
  • Improves debt collection efforts

 

What are the challenges of NPI implementation for payers and providers?

  • Providers and payers must exchange information
  • Technological implementation cost within organizations

 

What should payers and providers do now to prepare for the NPI?

Labels: , , , ,

Thursday, December 27, 2007

7 Steps To NPI For HIPAA-Compliant Electronic Medical Billing Software And Service

The Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) mandated the adoption of standard unique identifiers for health care providers, as well as the adoption of standard unique identifiers for health plans. They become mandatory on May 23, 2007.

The purpose of these provisions is to improve the efficiency and effectiveness of the electronic transmission of health information. The Centers for Medicare & Medicaid Services (CMS) has developed the National Plan and Provider Enumeration System (NPPES) to assign these unique identifiers.

CMS has contracted with Fox Systems, Inc. to serve as the NPI Enumerator. The NPI Enumerator is responsible for dealing with health plans and providers on issues relating to unique identification.

HCFA Timetable

Changes in the HCFA 1500 form to accommodate the NPI number took place January 1, 2007. Until March 30, 2007, using NPI number on the HCFA form is optional but as of April 2, 2007, using NPI becomes mandatory.

Getting an NPI is free - Not Having One Can Be Costly: If you delay applying for your NPI, you risk your cash flow.

 

  1. Enumerate: Enumeration is mandatory for both individual providers and organizations and subparts. When applying for your NPI, CMS urges you to include your legacy identifiers, not only for Medicare but for all payors. If reporting a Medicaid number, include the associated State name. This information is critical for payors in the development of crosswalks to aid in the transition to the NPI.
  2. Update: Make sure to upgrade your software, HIPAA Transactions, CMS1500, UB04, and/or Dental claim form changes.
  3. Communicate: Notify your payers once you have obtained your NPI number. As outlined in the Federal Regulation (The Health Insurance Portability and Accountability Act of 1996 (HIPAA)) you must also share your NPI with other providers, health plans, clearinghouses, and any entity that may need it for billing purposes -- including designation of ordering or referring physician.
  4. Collaborate: Check the readiness of your payment partners (such as health plans, TPAs, clearinghouses, etc...)? Not all payers are ready to accept the NPI number at this time. Use both your existing (legacy) number and the NPI number when submitting electronic claims.
  5. Test: Test transactions well before the deadline. Make sure to test HIPAA Transactions, e.g., 837 Claims, 835 Remittance Advice, and, if you submit paper claims, verify that the data is printed in the correct fields. The new HCFA form has new fields for identifier numbers on lines 17b, 32a and 33a.
  6. Educate: Focus on staff working on insurance verification of eligibility and claim denial or underpayment follow up.
  7. Implement: Once you obtain your NPI, it might take about 120 days to do the remaining wo

    rk to use it. This includes working on your internal billing systems, coordinating with billing services, vendors, and clearinghouses, testing with payers.

    Yuval Lirov, PhD, author of Practicing Profitability - Network Effect for Revenue Cycle Control in Healthcare Clinic and Chiropractic Office: Scheduling, SOAP Notes, Care Plans, Coding, Billing, Collections, and Audit Risk (Affinity Billing) and Mission Critical Systems Management (Prentice Hall), inventor of patents in Artificial Intelligence and Computer Security, and CEO of Vericle.net - Distributed Billing and Practice Management Technologies. Yuval invites you to register to the next webinar on audit risk at BillingPrecision.com

Labels: , , , , , ,

Friday, December 21, 2007

Electronic Medical Billing Software, HIPAA Compliance, and Role Based Access Contro

HIPAA compliance requires special focus and effort as failure to comply carries significant risk of damage and penalties. A practice with multiple separate systems for patient scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. This article presents an integrated approach to HIPAA compliance and outlines key HIPAA terminology, principles, and requirements to help the practice owner to ensure HIPAA compliance by medical billing service and software vendors.

The last decade of the previous century witnessed accelerating proliferation of digital technology in health care, which, along with reduced costs and greater service quality, introduced new and greater risks for accidental disclosure of personal health information.

The Health insurance Portability and Accountability Act (HIPAA) was passed in 1996 by Congress to establish national standards for privacy and security of personal health data. The Privacy Rule, written by the US Department of Health and Human Services took effect on April 14, 2003.

Failure to comply with HIPAA risks accreditation and reputation damage, lawsuits by federal government, financial penalties, ranging from $100 to $250,000, and imprisonment, ranging from one year to ten years.

Protected Health Information (PHI)

The key term of HIPAA is Protected Health Information (PHI), which includes anything that can be used to identify an individual and any information shared with other health care providers or clearinghouses in any media (digital, verbal, recorded voice, faxed, printed, or written). Information that can be used to identify an individual includes:

  1. Name
  2. Dates (except year)
  3. Zip code of more than 3 digits, telephone and fax numbers, email
  4. Social security numbers
  5. Medical record numbers
  6. Health plan numbers
  7. License numbers
  8. Photographs

     

     

 

Information shared with other healthcare providers or clearinghouses

  1. Nursing and physician notes
  2. Billing and other treatment records

     

     

 

Principles of HIPAA

HIPAA intends to allow smooth flow of PHI for healthcare operations subject to patient's consent but prohibit any flow of unauthorized PHI for any other purposes. Healthcare operations include treatment, payment, care quality assessment, competence review training, accreditation, insurance rating, auditing, and legal procedures.

HIPAA promotes fair information practices and requires those with access to PHI to safeguard it. Fair information practices means that a subject must be allowed

  1. Access to PHI,
  2. Correction for errors and completeness, and
  3. Knowledge of others who use PHI

     

     

 

Safeguarding of PHI means that the persons that hold PHI must

  1. Be accountable for own use and disclosure
  2. Have a legal recourse to combat violations

     

     

 

HIPAA Implementation Process

HIPAA implementation begins upon making assumptions about PHI disclosure threat model. The implementation includes both pre-emptive and retroactive controls and involves process, technology, and personnel aspects.

A threat model helps understanding the purpose of HIPAA implementation process. It includes assumptions about

  1. Threat nature (Accidental disclosure by insiders? Access for profit? ),
  2. Source of threat (outsider or insider?),
  3. Means of potential threat (break in, physical intrusion, computer hack, virus?),
  4. Specific kind of data at risk (patient identification, financials, medical?), and
  5. Scale (how many patient records threatened?).

     

     

 

HIPAA process must include clearly stated policy, educational materials and events, clear enforcement means, a schedule for testing of HIPAA compliance, and means for continued transparency about HIPAA compliance. Stated policy typically includes a statement of least privilege data access to complete the job, definition of PHI and incident monitoring and reporting procedures. Educational materials may include case studies, control questions, and a schedule of review seminars for personnel.

Technology Requirements for HIPAA Compliance

Technology implementation of HIPAA proceeds in stages from logical data definition to physical data center to network.

 

     

     

  1. To assure physical data center security, the manager must
    1. Lock data center
    2. Manage access list
    3. Track data center access with closed circuit TV cameras to monitor both internal and external building activities
    4. Protect access to data center with 24 x 7 onsite security
    5. Protect backup data
    6. Test recovery procedure

     

     

  2. For network security, the data center must have special facilities for
    1. Secure networking - firewall protection, encrypted data transfer only
    2. Network access monitoring and report auditing

     

     

  3. For data security, the manager must have
    1. Individual authentication - individual logins and passwords
    2. Role Based Access Control (see below)
    3. Audit trails - all access to all data fields tracked and recorded
    4. Data discipline - Limited ability to download data

     

     

 

Role Based Access Control (RBAC)

RBAC improves convenience and flexibility of systems management. Greater convenience helps reducing the errors of commission and omission in granting access privileges to users. Greater flexibility helps implement the policy of least privilege, where the users are granted only as much privileges as required for completing their job.

RBAC promotes economies of scale, because the frequency of changes of role definition for a single user is higher than the frequency of changes of role definitions across entire organization. Thus, to make a massive change of privileges for a large number of users with same set of privileges, the administrator only makes changes to the role definition.

Hierarchical RBAC further promotes economies of scale and reduces the likelihood of errors. It allows redefining roles by inheriting privileges assigned to roles in the higher hierarchical level.

RBAC is based on establishing a set of user profiles or roles according to responsibilities. Each role has a predefined set of privileges. The user acquires privileges by receiving membership in the role or assignment of a profile by the administrator.

Every time when the definition of the role changes along with the set of privileges that is required to complete the job associated with the role, the administrator needs only to redefine the privileges of the role. The privileges of all of the users that have this role get redefined automatically.

Similarly, if the role of a single user is changed, the only operation that needs to be performed is the reassignment of the user profile, which will redefine user's access privileges automatically according to the new profile.

Summary

HIPAA compliance requires special practice management attention. A practice with multiple separate systems for scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. An integrated system reduces the complexity of HIPAA implementation. By outsourcing technology to a HIPAA-compliant vendor of vericle-like technology solution on an ASP or SaaS basis, HIPAA management overhead can be eliminated (see companion papers on ASP and SaaS for medical billing).

Yuval Lirov, PhD, author of Practicing Profitability - Network Effect for Revenue Cycle Control in Healthcare Clinic and Chiropractic Office: Scheduling, SOAP Notes, Care Plans, Coding, Billing, Collections, and Audit Risk (Affinity Billing) and Mission Critical Systems Management (Prentice Hall), inventor of patents in Artificial Intelligence and Computer Security, and CEO of Vericle.net - Distributed Billing and Practice Management Technologies. Yuval invites you to register to the next webinar on audit risk at BillingPrecision.com

Labels: , , , , ,