HIPAA Law



             


Thursday, March 13, 2008

Connecticut Cracks Down on Illegal Health Insurance Plans

The state of Connecticut cracked down on a number of unlicensed health insurance plans and agents this month. The Insurance Department issued warnings to consumers to check the licensing of any firm before doing business. The targeted illegal heath plans were primarily offered to small businesses through their professional industry associations. The health plans claimed that since they were not fully insured and operated in multiple states Connecticuts strict insurance regulations did not apply to them. CT Insurance Department disagreed and closed the plans. A list of the approximately 40 closed plans is posted on the Departments Web site. Since the affected health plans are offered in multiple states, consumers in other states may soon be dealing with similar actions.

But the news is not all black and white. This crackdown closes the door to some of the few remaining affordable health insurance plans for many Connecticut small businesses. Connecticuts past legislative blunders in regulating health insurance are now costing its residents in sharply higher health insurance premiums. The illegal low-priced health plans are actually quite legal and well accepted in other states. The affected consumers are more likely to be irked by the Big Brother attitude of their government than by the fact that their health plan did not meet all applicable state laws. Most will be unable to find replacement health coverage in the same price range.

Tony Novak, MBA, MT, Online Adviser at MedSave.com suggests that consumers keep in mind the simple principal If it sounds too good to be true, it probably is. There are no bargains or great deals in health insurance. If one health insurance plan costs less than another, that is only because it provides less coverage. Make sure that you know specifically what coverage you are giving up before enrolling in a low cost health insurance plan. As long as a plan is fully insured and the agent is also licensed and insured, then it is OK to save money by choosing a plan that eliminates coverage that you do not need. For example, if you dont need maternity coverage or pre-existing condition coverage, then it is safe to buy a plan that costs only half as much as a health plan that does include this coverage.

Novak emphasizes that these buying guidelines apply to residents of all states, not just Connecticut. Unfortunately, too many small businesses buy the lowest cost health plan they can find without really understanding the reason for the cost difference or the risks they may be taking with the lower cost plan.

MedSave.com also adds that the Connecticut crackdown did not affect any of its health plans. All MedSave.com health plans are fully insured and licensed in the state where they are offered.

But the news is not all black and white. This crackdown closes the door to some of the few remaining affordable health insurance plans for many Connecticut small businesses. Connecticuts past legislative blunders in regulating health insurance are now costing its residents in sharply higher health insurance premiums. The illegal low-priced health plans are actually quite legal and well accepted in other states. The affected consumers are more likely to be irked by the Big Brother attitude of their government than by the fact that their health plan did not meet all applicable state laws. Most will be unable to find replacement health coverage in the same price range.

Tony Novak, MBA, MT, Online Adviser at MedSave.com suggests that consumers keep in mind the simple principal If it sounds too good to be true, it probably is. There are no bargains or great deals in health insurance. If one health insurance plan costs less than another, that is only because it provides less coverage. Make sure that you know specifically what coverage you are giving up before enrolling in a low cost health insurance plan. As long as a plan is fully insured and the agent is also licensed and insured, then it is OK to save money by choosing a plan that eliminates coverage that you do not need. For example, if you dont need maternity coverage or pre-existing condition coverage, then it is safe to buy a plan that costs only half as much as a health plan that does include this coverage.

Novak emphasizes that these buying guidelines apply to residents of all states, not just Connecticut. Unfortunately, too many small businesses buy the lowest cost health plan they can find without really understanding the reason for the cost difference or the risks they may be taking with the lower cost plan.

MedSave.com also adds that the Connecticut crackdown did not affect any of its health plans. All MedSave.com health plans are fully insured and licensed in the state where they are offered.


Tax and Benefits Adviser
Freedom Benefits Association

Labels: , , , , ,

Thursday, March 6, 2008

Health Insurance: The-More-The-Better, Or No-More-HMO?

---------------------------------------------------------- TITLE: Health Insurance: The-More-The-Better, Or No- More-HMO?
AUTHOR: Irina
LENGTH: 571 words
FORMAT: 58 characters per line CONTACT: irbonness@ureach.com --------------------------CUT HERE------------------------

Health Insurance: The-More-The-Better, Or No-More-HMO?

========================================================== The author grants permission to publish this article, in its entirety, electronically or in print, as long as the bylines are included. Other articles by Irina are available from http://www.megaone.com/hbb/savemoney/articles.html ==========================================================

In the movie "John Q," Academy award winner Denzel Washington fights the HMO restrictions to provide the necessary cure for his dying son. When such a lackluster topic like health insurance generates enough drama for a Hollywood movie, you know that something must be seriously wrong...

The problem indeed is severe. Almost 45 million Americans are uninsured and the number continues to rise. Those still insured are frustrated by the double-digit premium increases outpacing all other sectors of the economy. High costs and HMO limitations discourage seeking an immediate medical help. As a result, "little aches" often develop into the life-threatening illnesses and financial disasters for some unfortunate individuals and further escalate already intolerably high health care costs for the rest of us.

To endure the existing health care crisis, we all must recognize one simple fact. There are TWO DIFFERENT LEVELS of health care needs that must be covered with two separate tiers of payment. One level is catastrophic illness - and for that, insurance may still be the answer. Policies that carry a high deductible (say $5,000 a year) are relatively inexpensive, even when the coverage is very high ($1 million or more) or unlimited. That is because most people do not get catastrophic illnesses or injuries.

In fact, most of us only need health maintenance and routine medical procedures that comprise a totally different level of health care needs. For these, the present INSURANCE-based model is not the answer because it is financially incompatible with any efficient HEALTH CARE system.

Everyone knows that the INSURANCE works best when the fewest number of participants actually use it (i.e. make claims). Then the system generates profit, which lowers the premium that, in turn, brings more paying participants. The participants are happy NOT TO USE the insurance, especially if it does not cost them too much. On the contrary, the HEALTH CARE system works best when the most people use it (i.e. get teeth cleaning, checkups and vaccinations).

Fortunately, back in the 1980s, the idea of so-called patient advocacy via health care savings programs was introduced to the U.S. These programs negotiate prices with health care providers on behalf of their members. Since they represent large groups, the resulting discounts are usually the same that the hospitals and physicians give to big insurance companies.

This innovative approach benefits medical providers because they get paid "on the spot" without enormous paperwork and disputes with insurance companies. It also benefits you and me by providing an access to the discounted "insurance rates" without high premiums.

Many of such programs also allow their members to contribute money to medical savings accounts that are tax deductible or not taxable. Monthly membership fee is affordable and no one can be turned down because of a pre- existing condition.

It does not look like the current health care crisis is going to have a Hollywood-style "happy ending". It's up to us to analyze the situation and find the solution... otherwise, the next blockbuster about healthcare may well be a horror movie.

========================================================== About the Author:
Irina helps people save money on healthcare and create steady stream of residual income working from home http://www.megaone.com/hbb/savemoney/ ==========================================================

Irina helps people save money on healthcare and create steady stream of residual income working from home http://www.megaone.com/hbb/savemoney/

Labels: , , , ,

Saturday, March 1, 2008

A Guide To Online Health Insurance Quotes

It is a fact that people in the 25-34 age group often dont have health insurance. This is not because they cant afford it, but is because they think that since they are young and healthy, they dont need insurance. This is most definitely not true. One catastrophic illness or accident could wipe out their financial stability in one moment. Having health insurance protects you from things that would otherwise devastate you financially and make it difficult or impossible to recover from.

Of course, the online health insurance business is a booming one. Getting an online health insurance quote is very easy and requires no obligation or someone coming to your home or office to bother you. If you dont have insurance or you want to supplement your current insurance, going online is a good choice. Online health insurance companies offer a variety of plans for diverse coverage needs, from individuals, to families, to small businesses. You can shop around for the best rate and compare different companies and health insurance plans.

It is a good idea to do a little bit of research on any online health insurance company you re considering. You will want to find out how long they have been in business, how stable their business is, and if they are licensed in your state, which they need to be for you to use their services. The best part about online health insurance is that they must report premiums paid to your state, and this amount is regulated by your state, so you will know that they cant overcharge you and you can rest assured that someone is making sure they arent going to rip you off.

You also need to decide what kind of health care coverage you need. Will you need a prescription card to give you discounts on your prescriptions? Most people do. Will your insurance provide coverage if you are traveling? How about emergency and ambulance coverage? Will you need to have a referral to see a specialist, and can you go to a doctor that is outside of your provider network? It is extremely important to find out about the details of any health insurance plan before you buy.

One thing that is very hot with online insurance health and also with other insurance programs are HSAs. They are health Savings Accounts, and the money you lace in them ca be used for immediate medical expenses, saved for future medical expenses, or invested for medical expenses after retirement. This is just one of many health insurance plan aspects to consider when choosing an online health insurance company. Once you have made your choice based on your needs, sit back and let the online health insurance quotes roll in until you find the one that is best for you.
 

Bob Hett offers great tips and advice regarding all aspects of
the health insurance industry. Get the information you are seeking now by visiting http://www.healthinsurancejournal.info

Labels: , , , , ,

Tuesday, February 5, 2008

The Modern Medical Office: Balancing Success, Technology, and HIPAA

The medical field has always depended on technology for improving patient care. Thanks to advances in technology, administrative functions of healthcare offices have greatly increased their efficiency and customer relations. For example, there is technology that allows doctors to share information with offices across street or across the nation instantly with just a few clicks of the mouse. These advances not only free up hours of paperwork, but also quickly provides information vital to patient?s care.

The Electronic Medical Office & HIPAA A clinic can in the end be more profitable by offering these innovative services. Nearly half of the people interviewed in a Forrester Research study said they would be willing to pay more for online features; such email access to their doctors. (1)

While technology can be tremendously beneficial there are serious cautions that must be heeded. In 2003, the privacy rule of HIPAA was enacted and the rules governing protected health information (PHI) of patients became far more stringent. The rule governs the way in which information is handled. It requires every level of communication and storage of the PHI to be secure and private.(2) Examples of the ways violations occur are:

  • Computer screens visible from waiting room
  • Files left out around the office
  • PHI not disposed of properly, such as securely shredded
  • Records sent to the wrong home or email address

Due to these changes all modes of communication have a heavier burden of responsibility placed upon them since the inclusion of the privacy rule, but none more than electronic transmissions. Keeping the information protected when sending emails, which can be intercepted, can in itself be a daunting task.

HIPAA?s Penalties If an action taken by any employee, whether intentional, unintentional, or simply neglectful leads to improper recipient of PHI, the practice involved could face serious consequences.

  • The civil penalties range from "$100 per incident, up to $25,000 per person, per year, per standard that is violated."(3)
  • The criminal penalties range in three main groups. The first is up to $50,000 and 1 year in prison, moving up to $100,000 and 5 years, or $250,000 and 10 years in prison.

Each tier of the criminal penalties has different qualifications leading up to the knowingly disclosing PHI with the intent for malicious harm. (3)

Keeping Your Practice HIPAA Compliant
It?s important for today?s electronic medical office to have several layers of digital protection. This ensures PHI or any other private information cannot go outside the confines of the practices? systems without the proper digital rights. These rights can be controlled by moderators or even the sender and have the ability to dictate what permissions the receiver may have.

One large step is to protect your practice from accidentally sending information into the wrong hands. This can be done through email anti-theft solutions which encrypts the data sent via email. By using these types of programs, the sender may control not only the security of the file but also subsequent actions that may be carried out by the file?s recipient(s).

email anti-theft programs allow the user to establish who can view, edit, print and forwarding these important health records. Permissions set with email anti-theft software stays with the documents once they?ve left the clinic?s computer.

What Happens if My Practice?s Computer is Stolen?
Email anti-theft software can also protect the data on the computer if the machine is ever misplaced or stolen. This can be done through remote laptop security. All the victim of theft has to do is log into the program and there remotely block access to all protected files on the missing laptop. Without improvement in the means of securing and transmitting their files many practices will continue to commit violations of HIPAA, losing money and patients along the way.

HIPAA Compliance & Patient Trust
It is obvious that one must comply with HIPAA because of the financial penalties that go with noncompliance. There are however, far better reasons for compliance than avoiding punishment.

HIPAA Violations can break the trust between doctors and patients, but compliance along with new technology can strengthen relationships. When patients have new services such as the ability to ask questions to doctors via email the doctors can enhance their trust levels. This is especially important for small practices as interpersonal relationships play key roles for the retention of patients.

The advantages of technology will continue to provide new ways of serving patients. As the digital age comes the computer will increasingly become the focus of record keeping. With an industries like medical & healthcare so dependent on keeping detailed yet secure records, it is going to be ever important to stay current with strong security programs to encrypt and protect files.

  1. Bradford J. Holmes, Eric G. Brown, Elizabeth W. Boehm, Lynne Bishop, "Trends In Healthcare Consumer Technology Adoption" Forrester Research, 15 July 2004.
  2. Title 45 Code of Federal Regulations, Pt 164.
  3. United States Department of Health and Human Services. Protecting the Privacy of Patients' Health Information Summary of the Final Regulation. 2005. http://aspe.hhs.gov/admnsimp/final/pvcfact1.htm
    Michael David is a member of the marketing team at Essential Security Software (ESS), the leading provider of email anti-theft software for small business. He is a regular contributor to http://www.Iwantmyess.com.

Labels: , , , , ,

Monday, February 4, 2008

Medical Billing, HIPAA Compliance, and Role Based Access Control

HIPAA compliance requires special focus and effort as failure to comply carries significant risk of damage and penalties. A practice with multiple separate systems for patient scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. This article presents an integrated approach to HIPAA compliance and outlines key HIPAA terminology, principles, and requirements to help the practice owner to ensure HIPAA compliance by medical billing service and software vendors.

The last decade of the previous century witnessed accelerating proliferation of digital technology in health care, which, along with reduced costs and greater service quality, introduced new and greater risks for accidental disclosure of personal health information.

The Health insurance Portability and Accountability Act (HIPAA) was passed in 1996 by Congress to establish national standards for privacy and security of personal health data. The Privacy Rule, written by the US Department of Health and Human Services took effect on April 14, 2003.

Failure to comply with HIPAA risks accreditation and reputation damage, lawsuits by federal government, financial penalties, ranging from $100 to $250,000, and imprisonment, ranging from one year to ten years.

Protected Health Information (PHI)

The key term of HIPAA is Protected Health Information (PHI), which includes anything that can be used to identify an individual and any information shared with other health care providers or clearinghouses in any media (digital, verbal, recorded voice, faxed, printed, or written). Information that can be used to identify an individual includes:

  1. Name
  2. Dates (except year)
  3. Zip code of more than 3 digits, telephone and fax numbers, email
  4. Social security numbers
  5. Medical record numbers
  6. Health plan numbers
  7. License numbers
  8. Photographs

Information shared with other healthcare providers or clearinghouses

  1. Nursing and physician notes
  2. Billing and other treatment records

Principles of HIPAA

HIPAA intends to allow smooth flow of PHI for healthcare operations subject to patient's consent but prohibit any flow of unauthorized PHI for any other purposes. Healthcare operations include treatment, payment, care quality assessment, competence review training, accreditation, insurance rating, auditing, and legal procedures.

HIPAA promotes fair information practices and requires those with access to PHI to safeguard it. Fair information practices means that a subject must be allowed

  1. Access to PHI,
  2. Correction for errors and completeness, and
  3. Knowledge of others who use PHI

Safeguarding of PHI means that the persons that hold PHI must

  1. Be accountable for own use and disclosure
  2. Have a legal recourse to combat violations

HIPAA Implementation Process

HIPAA implementation begins upon making assumptions about PHI disclosure threat model. The implementation includes both pre-emptive and retroactive controls and involves process, technology, and personnel aspects.

A threat model helps understanding the purpose of HIPAA implementation process. It includes assumptions about

  1. Threat nature (Accidental disclosure by insiders? Access for profit? ),
  2. Source of threat (outsider or insider?),
  3. Means of potential threat (break in, physical intrusion, computer hack, virus?),
  4. Specific kind of data at risk (patient identification, financials, medical?), and
  5. Scale (how many patient records threatened?).

HIPAA process must include clearly stated policy, educational materials and events, clear enforcement means, a schedule for testing of HIPAA compliance, and means for continued transparency about HIPAA compliance. Stated policy typically includes a statement of least privilege data access to complete the job, definition of PHI and incident monitoring and reporting procedures. Educational materials may include case studies, control questions, and a schedule of review seminars for personnel.

Technology Requirements for HIPAA Compliance

Technology implementation of HIPAA proceeds in stages from logical data definition to physical data center to network.

  1. To assure physical data center security, the manager must
    1. Lock data center
    2. Manage access list
    3. Track data center access with closed circuit TV cameras to monitor both internal and external building activities
    4. Protect access to data center with 24 x 7 onsite security
    5. Protect backup data
    6. Test recovery procedure

  2. For network security, the data center must have special facilities for
    1. Secure networking - firewall protection, encrypted data transfer only
    2. Network access monitoring and report auditing

  3. For data security, the manager must have
    1. Individual authentication - individual logins and passwords
    2. Role Based Access Control (see below)
    3. Audit trails - all access to all data fields tracked and recorded
    4. Data discipline - Limited ability to download data

Role Based Access Control (RBAC)

RBAC improves convenience and flexibility of systems management. Greater convenience helps reducing the errors of commission and omission in granting access privileges to users. Greater flexibility helps implement the policy of least privilege, where the users are granted only as much privileges as required for completing their job.

RBAC promotes economies of scale, because the frequency of changes of role definition for a single user is higher than the frequency of changes of role definitions across entire organization. Thus, to make a massive change of privileges for a large number of users with same set of privileges, the administrator only makes changes to the role definition.

Hierarchical RBAC further promotes economies of scale and reduces the likelihood of errors. It allows redefining roles by inheriting privileges assigned to roles in the higher hierarchical level.

RBAC is based on establishing a set of user profiles or roles according to responsibilities. Each role has a predefined set of privileges. The user acquires privileges by receiving membership in the role or assignment of a profile by the administrator.

Every time when the definition of the role changes along with the set of privileges that is required to complete the job associated with the role, the administrator needs only to redefine the privileges of the role. The privileges of all of the users that have this role get redefined automatically.

Similarly, if the role of a single user is changed, the only operation that needs to be performed is the reassignment of the user profile, which will redefine user's access privileges automatically according to the new profile.

Summary

HIPAA compliance requires special practice management attention. A practice with multiple separate systems for scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. An integrated system reduces the complexity of HIPAA implementation. By outsourcing technology to a HIPAA-compliant vendor of vericle-like technology solution on an ASP or SaaS basis, HIPAA management overhead can be eliminated (see companion papers on ASP and SaaS for medical billing).

Yuval Lirov, PhD, author of "Mission Critical Systems Management" (Prentice Hall) , inventor of multiple patents in artificial intelligence and computer security, and CEO of Vericle.com Billing Technologies. Vericle delivers comprehensive practice workflow engine that integrates patient scheduling, electronic medical records (EMR), billing, transcription, and compliance management. By consolidating technology for hundreds of separate billing services, Vericle? tracks payer performance from a single point of control, shares compliance rules globally, and creates massive economies of scale. Yuval invites you to share your knowledge of medical billing and compliance at BillingWiki.com and register to the next webinar on audit risk at ChiroAudit.com.

Labels: , , ,

Saturday, January 19, 2008

HIPAA and privacy guide 101

HIPAA has led to sweeping changes to health care administration and information systems as health care organizations struggle to achieve cost-effective compliance by 2003. The US Congress enacted the Health Insurance Portability and Accountability Act or HIPAA in 1996. The act covered a wide array of issues surrounding the health insurance industry but in particular it required administration simplification, which addressed the issue of security and privacy of health information.

HIPAA is designed to standardize the way all health care organizations electronically exchange sensitive patient data and to protect patients from unauthorized disclosure of their medical records (whether paper or electronic). HIPAA outlined standards to improve the nation's health care system by incorporating electronic data exchange between health care providers. The idea of course was to allow various health providers to access the records of a particular patient. So, when a patient visits a new hospital, the covering doctor can access that patients past record and in so doing provide him with better care. However, as one could envisage, this raised a great number of apprehensions with respect to the privacy and confidentiality of people's medical records. So the legislature created a fundamental list of rules and regulations with which health care providers must comply. And the creation of these rules and regulations gave birth to the industry that is called HIPAA Compliance.

To ensure HIPAA compliance, there are certain key provisions, which need to be followed. For instance, individuals should be able to access their records and request correction of errors. Also, they should be informed about how their personal information will be used. The 'protected health information' (PHI) indicates that the information cannot be used for marketing purposes without the clear consent of the patients in question. People should be able to ask their covered entities (which maintain PHI about them), to ensure that their communications with the patient are confidential. It should be possible for people to file formal privacy-related complaints to the Department of Health and Human Services (HHS) Office for Civil Rights. Covered entities should document their privacy procedures, however, they have discretion on what to include in their privacy procedure. They are required to designate a privacy officer and train their employees. Covered entities can use an individual's information without the individual's consent if the purpose is to provide treatment, obtain payment for services and to perform the non-treatment operational tasks of the provider's business. Some of the agencies, government bodies and individuals who can access the medical records of a person under HIPAA compliance rules are the insurance companies, employers, courts, hospitals, or individual physicians. This is also considered as a downside of the HIPAA Privacy rule because sponsors of a research study; makers of drugs for the particular study and the researchers involved in the study are included in this list.

However, the ultimate objective of HIPAA is to increase the efficiency and effectiveness of health information systems through improvements in electronic health care transactions as well as to maintain the security and privacy of individually identifiable health information.

Mansi gupta recommends that you visit HIPAA and privacy for more information.

Labels: , , , , , ,

Thursday, November 29, 2007

The Need for HIPAA Complaint Medical Billing Software

 

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) includes seven sets of rules that will affect your practice. The Department of Health and Human Services, or DHHS, issues these in the form of the ""Notice of Proposed Rule Making"" or NPRM. Every practice, regardless of size, must comply with HIPAA privacy, security and transactional regulations. Moreover, adherence to all subsequent regulations is also required. This covers most everything in your practice, including your medical billing software.

When you are shopping for medical billing software, ask how and for whom the system was designed, and whether the data will be safe and secure on backed-up, protected, HIPAA-compliant servers accessible only to authorized persons. Look for companies who provide free updates to ensure continued efficiency and HIPAA compliance. The new HIPAA standards require huge changes to how healthcare organizations deal with their patient information, including coding, security, patient record management, reimbursement and care management. HIPAA‘s provisions include stringent codes for the unvarying transfer of electronic data, including routine alterations and billing.

Clearly your approach to HIPAA medical billing software must include a serious investigation of software security. Most computer experts will agree that there is no such thing as absolute computer or software security, so working closely with your HIPAA software providers to help determine data deficiencies is a good idea. HIPAA Complaint Medical Billing Software can be easily expanded to meet future needs, and can be targeted directly to the size and complexity of your practice. Options for new HIPAA compliant software have never been better, as there is unlimited scalability, a wide range of customization choices, and a large selection of useful features that will prevent the patients' privacy from being compromised.

Innovations in the technology of medical billing software have created a new criterion for digital precision. Make certain that the HIPAA compliant medical software packager you chose includes all finalized aspects of HIPAA to guarantee full compliance with HIPAA standards as they relate to the electronic transfer of protected health information. The regulations themselves took effect in February 2003, and affect every medical practice in the United States. Effective April 2005, HIPAA mandates security measures to physically and electronically secure electronic protected health information (PHI) against unauthorized retrieval, reliably store the electronic data, and provide for emergency access to the data.

Since most medical billing software packages are now designed to be HIPAA compliant, it is just a matter of choosing the right software for your practice, and your medical billing software will run as smoothly and efficiently as ever.

Medical Billing Software Info provides comprehensive information about medical insurance billing software, HIPAA compliant medical billing software, easy and free medical billing software, and medical billing software prices and reviews. Medical Billing Software Info is the sister site of Medical Billing Web.

Labels: , , , , , ,