HIPAA Law



             


Friday, March 7, 2008

Health Insurance for the Self Employed

Health insurance, having enough and being able to afford it, is
one of the most nagging concerns for those who leave corporate
America to run their own business.

Many small businesses have dropped health coverage or reduced it
in the past three years because of rising rates. About 24
million of American small-business employees and their families
are uninsured, according to a study by the Kaiser Family
Foundation.

The Consolidated Omnibus Budget Reconciliation Act (COBRA) is a
federal law that requires employers to allow departing workers
to buy health insurance through the employer's group plan. For
the first 18 months after you leave your employer you may elect
to continue to receive coverage in your employer's group plan at
your expense.

However, the cost of the monthly premiums for COBRA can come as
quite a surprise if you're accustomed to you employer picking up
most of your health insurance tab via pretax paycheck
deductions. COBRA coverage for a family can run $500 a month,
and upwards of $200 a month for an individual.

Depending on which State you live in COBRA may not necessarily
be the best deal for you. Shop around, you may find joining a
short term insurance plan to be less expensive than continuing
your current insurance under COBRA.

One piece of good news for the self-employed - Starting in 2003,
the self-employed health insurance deduction is increased to
100% from the 70% that was deductible in 2002. As a result, if
you work as a consultant, freelance worker, and other
self-employed individual you will be allowed to deduct all of
your health insurance premiums. The self-employed health
insurance deduction is especially valuable because it is an
above the line deduction for Adjusted Gross Income (AGI). This
means that you can take advantage of this deduction even if you
do not you itemize your deductions on your tax return.

Even with health insurance the portion of medical expenses that
has to come out of your pocket can be more than you imagine. If
you have to dip into your retirement savings for certain medical
expenses, distributions from your IRA used for that purpose may
be exempt from the IRS 10 percent early withdrawal penalty.
However, you still will have to pay taxes on the IRA
distribution. Another alternative is to transfer your IRA to a
Self-Employed 401(K) plan and take a loan from that plan. Loans
from a 401(k) plan are tax-free and penalty free as long as the
loans are paid back.

Daniel Lamaute is a retirement plans specialist with Lamaute
Capital. Its website www.investsafe.com covers retirement plans
and other benefits for the self-employed.

Labels: , , , ,

Sunday, March 2, 2008

Where To Find Cheap Health Insurance

Health insurance costs are rising all the time. Many people feel they cannot afford health insurance. Others feel that they dont need it because they are healthy and have never had any major medical problems. This is definitely faulty thinking on their part. As a matter of fact, you do need health insurance, and there are a lot of ways to get affordable health insurance for yourself or your family. Health insurance is protection against the possible health problems that could happen in the future, and you have absolutely no way of knowing what those might be.

For people who are low income, every state has a Medicaid program that they could possible qualify for. The requirements vary form state to state, but all it takes is a trip to your local Division of Family Services office to get an application. You might be surprised at the number of people who would actually qualify for this service that dont think that they would. You will need to fill out the application and provide some documentation about your finances. This program can cover the health insurance needs of the entire family, including dental work, eye care, doctor visits, emergency care, prescriptions and more. For people with children who dont get insurance through their work, this is a very good option to check out. It is free and a fairly painless process, and if you qualify, it could make you like a lot easier.

Another option for cheap health insurance is to look on the Internet. There are a ton of companies that offer all types of health insurance plans, and it is very possible that you could find one that is perfect for your family and fits your pocketbook. The costs vary, so do plenty of research before choosing one or another. It is a smart idea to find out how long the company has been in business, and what kind of reputation they have. Ask for a quote from several sources, and see what kind of a deal they can get for you. Make sure they are also licensed in your state, because it does no good to get insurance if they cant operate in your state.

Still other options include your local insurance agencies. Ask around to find out about the different agents and their policies. Many agents will work very hard to get you an affordable health insurance plan for your family at a cost you can live with. Even if you cant get every type of coverage you want, some is better than none.

Follow up with advertisements for prescription card plans and alternative health care plans. While some of them wont be suited to your needs, there may be one that is perfect for you. An affordable health care insurance plan can be found, but you might have to do some searching.

Bob Hett offers great tips and advice regarding all aspects concerning Health Insurance.
Get the information you are seeking now by visiting http://www.healthinsurancejournal.info

Labels: , , , , , ,

Monday, February 11, 2008

How to Get NPI - National Provider Number for HIPAA-Compliant Medical Billing in 7 Steps

The Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) mandated the adoption of standard unique identifiers for health care providers, as well as the adoption of standard unique identifiers for health plans. They become mandatory on May 23, 2007.

The purpose of these provisions is to improve the efficiency and effectiveness of the electronic transmission of health information. The Centers for Medicare & Medicaid Services (CMS) has developed the National Plan and Provider Enumeration System (NPPES) to assign these unique identifiers.

CMS has contracted with Fox Systems, Inc. to serve as the NPI Enumerator. The NPI Enumerator is responsible for dealing with health plans and providers on issues relating to unique identification.

HCFA Timetable

Changes in the HCFA 1500 form to accommodate the NPI number took place January 1, 2007. Until March 30, 2007, using NPI number on the HCFA form is optional but as of April 2, 2007, using NPI becomes mandatory.

Getting an NPI is free - Not Having One Can Be Costly: If you delay applying for your NPI, you risk your cash flow.

  1. Enumerate: Enumeration is mandatory for both individual providers and organizations and subparts. When applying for your NPI, CMS urges you to include your legacy identifiers, not only for Medicare but for all payors. If reporting a Medicaid number, include the associated State name. This information is critical for payors in the development of crosswalks to aid in the transition to the NPI.
  2. Update: Make sure to upgrade your software, HIPAA Transactions, CMS1500, UB04, and/or Dental claim form changes.
  3. Communicate: Notify your payers once you have obtained your NPI number. As outlined in the Federal Regulation (The Health Insurance Portability and Accountability Act of 1996 (HIPAA)) you must also share your NPI with other providers, health plans, clearinghouses, and any entity that may need it for billing purposes -- including designation of ordering or referring physician.
  4. Collaborate: Check the readiness of your payment partners (such as health plans, TPAs, clearinghouses, etc...)? Not all payers are ready to accept the NPI number at this time. Use both your existing (legacy) number and the NPI number when submitting electronic claims.
  5. Test: Test transactions well before the deadline. Make sure to test HIPAA Transactions, e.g., 837 Claims, 835 Remittance Advice, and, if you submit paper claims, verify that the data is printed in the correct fields. The new HCFA form has new fields for identifier numbers on lines 17b, 32a and 33a.
  6. Educate: Focus on staff working on insurance verification of eligibility and claim denial or underpayment follow up.
  7. Implement: Once you obtain your NPI, it might take about 120 days to do the remaining work to use it. This includes working on your internal billing systems, coordinating with billing services, vendors, and clearinghouses, testing with payers.
  8. Yuval Lirov, PhD, author of "Mission Critical Systems Management" (Prentice Hall), inventor of patents in Artificial intelligence and Computer Security, and CEO of Vericle.net Billing Technologies and Services. Vericle? unites hundreds of billing services across the nation. Its electronic medical billing software tracks payer performance from a single point of control and shares compliance rules globally. Yuval invites you to register to the next webinar on audit risk at BillingPrecision.com

Labels: , , ,

Thursday, January 10, 2008

How HIPAA Security Policies Affect Corporate E-mail Systems

TrustAlthough considered by many to be the sole concern of health care providers, the Health Insurance Portability and Accountability Act (HIPAA) affects nearly all companies that regularly transmit or store employee health insurance information. HIPAA was signed into law in 1996 and it's original purpose was to protect employee health and insurance information when workers changed or lost their jobs. As use of the internet became more widespread in the mid-1990s, HIPAA requirements overlapped with the digital revolution and offered direction to organizations needing to exchange healthcare information. HIPAA regulations apply to any establishment that exchanges individually identifiable healthcare information.

Collaboration between healthcare professionals, their colleagues, their patients, and employers has grown progressively more digital, and e-mail has played an ever-increasing role in this communication. In the process of this development, the need for information security and privacy has created an impediment to widespread adoption.

In addition to the usual concerns about privacy and security of e-mail correspondence, even organizations that are not in the heathcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how e-mail containing PHI should be treated in the corporate setting. HIPAA, as it relates to e-mail security, is an enforcement of otherwise well-known best practices that include:


  • Ensuring that e-mail messages containing PHI are kept secure when transmitted over an unprotected link
  • Ensuring that e-mail systems and users are properly authenticated so that PHI does not get into the wrong hands
  • Protecting e-mail servers and message stores where PHI may exist

Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and catch up with other industries of similar size and scope.

The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

Starting April 21, 2005, a new security rule focusing solely on PHI that is stored and transmitted electronically will be enforced as part of HIPAA. The requirements of this rule, which are simply information security best practices, focus on the three cornerstones of a solid information security infrastructure confidentiality, integrity, and availability of information.

The imminent HIPAA regulatory requirements encompass PHI transmission, storage and discoverability. Given the widespread use and importance of e-mail, enforcement of HIPAA encryption policies and the growing demand for secure e-mail solutions, e-mail security has never been more important to the healthcare industry than it is right now.

IronMail significantly contributes to compliance with the HIPAA privacy and security requirements as they relate to protecting PHI that is transmitted and stored via e-mail. Everything from data encryption to firewall and intrusion protection to content filtering is included in the IronMail solution. Once in place, IronMail can be used to protect e-mail going into and out of corporate networks.

As IronMail is a standards-based appliance, it can be integrated into any existing e-mail system seamlessly, without requiring extensive IT staff training, or relying on users to take extra steps to perform e-mail functions.

The IronMail appliance is tailored to help organizations comply with the stringent new guidelines imposed by HIPAA, from security management processes to access control to data integrity.

HIPAA compliance is seen by many organizations as a prohibitively expensive hurdle to overcome. In addition, the growing dependence on e-mail as a mission-critical application requires security and privacy to be a top priority. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence. With IronMail, organizations reduce information complexities as well as associated management costs which can help improve patient relationships, increase the quality of care, and improve the bottom line. E-mail can indeed be safe and secure.

Collaboration between healthcare professionals, their colleagues, their patients, and employers has grown progressively more digital, and e-mail has played an ever-increasing role in this communication. In the process of this development, the need for information security and privacy has created an impediment to widespread adoption.

In addition to the usual concerns about privacy and security of e-mail correspondence, even organizations that are not in the heathcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how e-mail containing PHI should be treated in the corporate setting. HIPAA, as it relates to e-mail security, is an enforcement of otherwise well-known best practices that include:

  • Ensuring that e-mail messages containing PHI are kept secure when transmitted over an unprotected link
  • Ensuring that e-mail systems and users are properly authenticated so that PHI does not get into the wrong hands
  • Protecting e-mail servers and message stores where PHI may exist

Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and catch up with other industries of similar size and scope.

The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

Starting April 21, 2005, a new security rule focusing solely on PHI that is stored and transmitted electronically will be enforced as part of HIPAA. The requirements of this rule, which are simply information security best practices, focus on the three cornerstones of a solid information security infrastructure confidentiality, integrity, and availability of information.

The imminent HIPAA regulatory requirements encompass PHI transmission, storage and discoverability. Given the widespread use and importance of e-mail, enforcement of HIPAA encryption policies and the growing demand for secure e-mail solutions, e-mail security has never been more important to the healthcare industry than it is right now.

IronMail significantly contributes to compliance with the HIPAA privacy and security requirements as they relate to protecting PHI that is transmitted and stored via e-mail. Everything from data encryption to firewall and intrusion protection to content filtering is included in the IronMail solution. Once in place, IronMail can be used to protect e-mail going into and out of corporate networks.

As IronMail is a standards-based appliance, it can be integrated into any existing e-mail system seamlessly, without requiring extensive IT staff training, or relying on users to take extra steps to perform e-mail functions.

The IronMail appliance is tailored to help organizations comply with the stringent new guidelines imposed by HIPAA, from security management processes to access control to data integrity.

HIPAA compliance is seen by many organizations as a prohibitively expensive hurdle to overcome. In addition, the growing dependence on e-mail as a mission-critical application requires security and privacy to be a top priority. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence. With IronMail, organizations reduce information complexities as well as associated management costs which can help improve patient relationships, increase the quality of care, and improve the bottom line. E-mail can indeed be safe and secure.
CipherTrust is the leader in anti-spam and email security. Learn more by downloading our free whitepaper, Contributing to HIPAA Compliance with IronMail or by visiting www.ciphertrust.com.

Labels: , , , ,

Sunday, December 30, 2007

5 Facts About NPI For HIPAA Compliant Electronic Medical Billing Software And Service

The 1996 Health Insurance Portability and Accountability Act (HIPAA) established national privacy and security standards for electronic health care transactions, including a national identifier for providers, health plans and employers. Accordingly, by May 23, 2007, healthcare providers and all health plans and clearinghouses must change both their processes and information systems to implement HIPAA’s National Provider Identifier (NPI) regulations.

Background on the NPI regulation

  • HIPAA mandated regulation
  • Effective nationwide on May 23, 2007
  • The compliance date for health care payers with less than $5 million in annual revenue is May 23, 2008

 

What is the NPI?

  • A unique 10-digit identification number
  • Assigned for life to a provider and de-activated only upon death, retirement, or identity theft
  • Replaces multiple legacy provider identification numbers, including Medicare UPINs, commercial payer IDs and state Medicaid IDs
  • Contains no identifying information related to the provider - randomly generated
  • Independent of key provider information changes, such as practice location or specialty
  • Providers have 30 days to update their NPI record

 

Who is affected by the NPI mandate?

  • Payers
    • Health plans
  • Clearinghouses
  • Providers
    • Organizational providers
    • Individual providers

 

Why is the NPI necessary?

  • NPI delivers two-fold benefits for payers and providers:
    • Simplifies communication and administration
    • Facilitates efficient electronic transmission of certain health information
  • Streamlines detection of billing fraud and abuse
  • Improves debt collection efforts

 

What are the challenges of NPI implementation for payers and providers?

  • Providers and payers must exchange information
  • Technological implementation cost within organizations

 

What should payers and providers do now to prepare for the NPI?

Labels: , , , ,

Wednesday, December 19, 2007

HIPAA Products Guide

HIPAA has led to sweeping changes to health care administration and information systems as health care organizations struggle to achieve cost-effective compliance by 2003.All health care entities that process health-related data are required to comply with the U.S. Department of Health and Human Services' (HHS) Health Insurance Portability and Accountability Act of 1996 (HIPAA).

The U.S. Congress designed the Health Insurance Portability and Accountability Act (HIPAA) in 1996. Title I of HIPAA safeguards health insurance coverage for workers and their families when they lose or change their jobs. According to title II of HIPAA, the Administrative Simplification (AS) provisions, necessitates the establishment of national standards for electronic health care transactions and national identifiers for providers, health insurance plans, and employers. The AS provisions also address the security and privacy of health data. The purpose of all these standards is to improve the efficiency and effectiveness of the nation's health care system by encouraging the extensive use of electronic data transactions in health care.

HIPAA is designed to regulate the way all health care organizations electronically exchange sensitive patient data and to protect patients from illegal disclosure of their medical records (whether paper or electronic). It means that if personal information is stored on computer databases, tapes, disks, or transmitted with the assistance of faxes or the Internet, in addition to anything written down or talked about, steps must be taken to ensure a patient’s privacy.

Today a number of HIPAA products and services are being offered both online and offline, such as, online HIPAA training, privacy manuals and template policies, security manuals and template policies, security products, disclosure tracking systems, compliance consulting services, etc. All these products are designed basically to guide you through the formidable transition of HIPAA compliance and help you navigate the complex and tedious regulatory environment created by HIPAA.

The online HIPAA training is a very convenient tool to learn about HIPAA. Moreover, it is available whenever and wherever you have an internet access. The privacy manuals and template policies are the workbooks that will lead you through a careful assessment of your company’s Privacy compliance plan. The security manuals and template policies are those workbooks that will guide you through a careful assessment of your company’s Security compliance plan. The security products include network security scanning and automated online backup. The network security scanning or the HIPAA e-probe beats hackers to the punch by vigilantly probing your Internet connected systems for vulnerabilities before the hackers can find and exploit them.

The automated online backup or the e-backup lets you control the configuration and operation of your entire organization’s backup system from a single location. Monitoring and administration of all backup and recovery tasks are controlled from a single workstation. The disclosure tracking systems are those software programs that are designed and developed to address the requirement of covered entities (health care providers, payers, and clearinghouses) to record the required elements for the patient's right to an accounting of disclosures. The compliance consulting services include onsite consulting services and the business associate certification.

Mansi aggarwal recommends that you visit HIPAA products for more information

 

Labels: , , , , ,