HIPAA Law



             


Monday, March 10, 2008

Caregiver Stress Accounts for 27% Increase in Health Insurance Benefits by South Florida Employees

27% Increase in Health Insurance Benefits by South Florida Employees accounts for Stress as Caregiver to aging parents.

27% Increase in Health Insurance Benefits by South Florida Employees accounts for Stress as Caregiver to aging parents.

The impact of Elder Care issues on corporate America will continue to grow as our elderly population increases:

  • Employees juggling job responsibilities with care giving are a reality in the workplace of today and the future. Workers are torn between the demands of their job and the ability to provide quality care to their relative.
  • One out of three American workers is also managing the care of an older relative.
  • Loss of productivity resulting from time off to care for an aging relative is estimated at $6100 per employee per year.
  • Caregiver stress accounts for a 27% increase in use of company health insurance benefits.

Seventeen percent (17%) of caregivers quit their jobs to provide care for aging family members, and another 15% reduce their work hours to assist their loved ones. This shocking loss of employee productivity is hitting South Florida businesses very hard as more Boomers have senior parents who require caregiving.

To stop this workforce hemorrhaging South Florida companies are looking for methods to provide assistance in caregiving to employees to keep them on the job and productive, while being sensitive to the needs of the employee.

There have been attempts at Corporate Elder Care programs, however few as comprehensive at A Good Daughter, (www.agooddaughter.com) based in Margate. According to Olga Brunner, President, Our Corporate Elder Care program was developed to help employees balance job responsibilities and caregiving. Our Professional Care Managers plan and organize care and services for the employees of Broward and Palm Beach elderly population, affording families a peace of mind that their loved ones will find and secure services such as ongoing supervision of certified home care assistants, home maintenance and care, medication supervision, coordination of medical appointments and representation at these appointments, legal counsel, specialized air travel escorts, and many other services.

While A Good Daughter works with individuals, the Corporate Elder Care program is ideally suited to the mid-sized company with fifty plus employees.

A Good Daughter, Inc.
www.agooddaughter.com
Olga Brunner
800-963-3877

Professional Marketing Firm reaching the Manufacturing Community Worldwide

Labels: , , , , ,

Tuesday, February 5, 2008

The Modern Medical Office: Balancing Success, Technology, and HIPAA

The medical field has always depended on technology for improving patient care. Thanks to advances in technology, administrative functions of healthcare offices have greatly increased their efficiency and customer relations. For example, there is technology that allows doctors to share information with offices across street or across the nation instantly with just a few clicks of the mouse. These advances not only free up hours of paperwork, but also quickly provides information vital to patient?s care.

The Electronic Medical Office & HIPAA A clinic can in the end be more profitable by offering these innovative services. Nearly half of the people interviewed in a Forrester Research study said they would be willing to pay more for online features; such email access to their doctors. (1)

While technology can be tremendously beneficial there are serious cautions that must be heeded. In 2003, the privacy rule of HIPAA was enacted and the rules governing protected health information (PHI) of patients became far more stringent. The rule governs the way in which information is handled. It requires every level of communication and storage of the PHI to be secure and private.(2) Examples of the ways violations occur are:

  • Computer screens visible from waiting room
  • Files left out around the office
  • PHI not disposed of properly, such as securely shredded
  • Records sent to the wrong home or email address

Due to these changes all modes of communication have a heavier burden of responsibility placed upon them since the inclusion of the privacy rule, but none more than electronic transmissions. Keeping the information protected when sending emails, which can be intercepted, can in itself be a daunting task.

HIPAA?s Penalties If an action taken by any employee, whether intentional, unintentional, or simply neglectful leads to improper recipient of PHI, the practice involved could face serious consequences.

  • The civil penalties range from "$100 per incident, up to $25,000 per person, per year, per standard that is violated."(3)
  • The criminal penalties range in three main groups. The first is up to $50,000 and 1 year in prison, moving up to $100,000 and 5 years, or $250,000 and 10 years in prison.

Each tier of the criminal penalties has different qualifications leading up to the knowingly disclosing PHI with the intent for malicious harm. (3)

Keeping Your Practice HIPAA Compliant
It?s important for today?s electronic medical office to have several layers of digital protection. This ensures PHI or any other private information cannot go outside the confines of the practices? systems without the proper digital rights. These rights can be controlled by moderators or even the sender and have the ability to dictate what permissions the receiver may have.

One large step is to protect your practice from accidentally sending information into the wrong hands. This can be done through email anti-theft solutions which encrypts the data sent via email. By using these types of programs, the sender may control not only the security of the file but also subsequent actions that may be carried out by the file?s recipient(s).

email anti-theft programs allow the user to establish who can view, edit, print and forwarding these important health records. Permissions set with email anti-theft software stays with the documents once they?ve left the clinic?s computer.

What Happens if My Practice?s Computer is Stolen?
Email anti-theft software can also protect the data on the computer if the machine is ever misplaced or stolen. This can be done through remote laptop security. All the victim of theft has to do is log into the program and there remotely block access to all protected files on the missing laptop. Without improvement in the means of securing and transmitting their files many practices will continue to commit violations of HIPAA, losing money and patients along the way.

HIPAA Compliance & Patient Trust
It is obvious that one must comply with HIPAA because of the financial penalties that go with noncompliance. There are however, far better reasons for compliance than avoiding punishment.

HIPAA Violations can break the trust between doctors and patients, but compliance along with new technology can strengthen relationships. When patients have new services such as the ability to ask questions to doctors via email the doctors can enhance their trust levels. This is especially important for small practices as interpersonal relationships play key roles for the retention of patients.

The advantages of technology will continue to provide new ways of serving patients. As the digital age comes the computer will increasingly become the focus of record keeping. With an industries like medical & healthcare so dependent on keeping detailed yet secure records, it is going to be ever important to stay current with strong security programs to encrypt and protect files.

  1. Bradford J. Holmes, Eric G. Brown, Elizabeth W. Boehm, Lynne Bishop, "Trends In Healthcare Consumer Technology Adoption" Forrester Research, 15 July 2004.
  2. Title 45 Code of Federal Regulations, Pt 164.
  3. United States Department of Health and Human Services. Protecting the Privacy of Patients' Health Information Summary of the Final Regulation. 2005. http://aspe.hhs.gov/admnsimp/final/pvcfact1.htm
    Michael David is a member of the marketing team at Essential Security Software (ESS), the leading provider of email anti-theft software for small business. He is a regular contributor to http://www.Iwantmyess.com.

Labels: , , , , ,

Monday, February 4, 2008

HIPAA Compliant FTP Hosting

FTP Hosting ? an overview

?File Transfer Protocol?, commonly known as FTP, is a reliable protocol to exchange large volume of digital information from one computer to another. FTP hosting technique has simplified file transfer process over the Internet. FTP hosting comes with two components ? FTP Server and FTP Client. Moreover, each FTP user will get a unique FTP account with user name and password. Irrespective of file type and file size, FTP account holders can upload the files in FTP Server through their FTP account. Similarly, FTP account holders can download copies of the uploaded files from FTP Server.

FTP hosting services provides complete security in file exchange process. Only authorized FTP account holders can view and access the files. Further, you can restrict a FTP account holder to access other FTP accounts. Irrespective of business volume, companies require to transfer files over the Internet. Though it is true that Hyper Text Transfer Protocol (HTTP) provides the facility to share information over the Internet but due to its limitations, FTP became popular across the globe.

FTP Hosting for Health Care Services

In Medical Transcription or other Health Care Services, medical reports are stored and exchanged in digital format. The growing necessity of exchanging large volume of medical reports and files over the Internet allows the Health care Service providers to use File Transfer Protocol as an alternative of Hyper Text Transfer Protocol. After the introduction of Health Insurance Portability & Accountability Act of 1996, extra guidelines are drawn for FTP hosting. All types of Health Care Services, who store and exchange medical files and reports over the Internet will fall under this Act and have to follow HIPAA regulation throughout the business process to ensure quality service and security of digital medical files and reports.

HIPAA

Health Insurance Portability & Accountability Act, commonly known as HIPAA, is a set rule to protect health related electronic information. The effect of HIPAA rules is applied to all types of health care organizations and support services. According to Health Insurance Portability & Accountability Act, all the health care organizations and support services should maintain necessary security measures to protect personal health information.

Medical institutes and support services prepares and stores health information of the patients in digital format. Based on the requirement, these digital reports are exchanged from one computer to another over the Internet. Health Insurance Portability & Accountability Act ensures complete security of digital health information that includes ? secure storage system and secure transmission of digital information over the Internet.

HIPAA Compliant FTP Hosting

The growing importance of Health Insurance Portability & Accountability Act in health care sector has given the birth of HIPAA compliance FTP hosting services. The objective of HIPAA compliance FTP hosting services is to protect unauthorized people from accessing digital heal information or medical report.

Following are some general features of HIPAA compliance FTP hosting service:

  • HIPAA compliance FTP servers are considered as highly secured data centers.
  • The system will automatically generate and run several threads during transferring digital medical files from one location to another. This is known as Multi-thread File Transfer and makes the process faster than normal File Transfer Protocol.
  • HIPAA compliance FTP hosting service comes with 128-bit transfer encryption. Digital files are transferred in the encrypted form. There is also another process ? symmetric or secret key encryption, which encrypt files and upload them in the server with a unique ?key?. The system will store the encrypted data in HIPAA compliance FTP server. Only the authorized person, who has that ?key?, can download the encrypted digital medical report from the server.
  • Like general FTP hosting services, the methods of uploading and downloading digital medical files are user friendly.
  • HIPAA compliance FTP hosting services allow the users to apply FTP services with existing firewalls.
  • Unique user name and password for HIPAA compliance FTP account holders.
  • HIPAA compliance FTP hosting services restrict anonymous FTP account holder from accessing the server.
  • Some HIPAA compliance FTP hosting services provides ultimate security by using ?Intrusion Detection System? and other security tools, which are compatible with all types of operating systems.

Advantages of HIPAA compliance FTP Hosting

The main advantage of HIPAA compliance FTP hosting services is data encryption. HIPAA compliance FTP hosting services will encrypt each data files in separate pieces of data, which are known as ?key?. You have to use the software xTyFTP during the process of uploading medical records in the FTP server. The software will encrypt the digital file in the computer and provide the ?key? to the authorized user decrypt.

HIPAA compliance hosting services will store the encrypted file in the server. However, if any unauthorized user accesses the file from the FTP server, he/she will get the encrypted form and the content will remain hidden without the right ?key?.

Apart from data encryption, which is considered as the core feature of HIPAA regulation, HIPAA compliance FTP hosting service requires secure procedure in data handling and serious maintenance of necessary policies, e.g., restricting unauthorized users from damaging digital information.

Adam is a Network Engineer with "InstantFTPsites.com". You can learn more about "FTP Hosting" services online at http://www.InstantFTPsites.com.

? 2006 InstantFTPsites http://www.InstantFTPsites.com You may reprint this article online and in print provided the links remain live and the content remains unaltered (including the "Author Biography").

Labels: , , , , , , ,

Monday, January 28, 2008

HIPAA Software

The future of your medical practice could greatly depend on how well you comply with HIPAA. As there are complex procedures and you have to keep record of various steps apart from ensuring the security of the information you have access to, most the employers and medical professionals prefer to use HIPAA software.

The software is available online as well as offline, which helps the people concerned with implementing this law. In fact, this software can make the difference between success and failure, for a large number of medical professionals. The HIPAA software helps in removing inefficiency, which causes trouble for many health service providers.

If you plan to run a medical office without sapping too much of your time in dealing with administrative and data management problems, then HIPAA software can be of great help. It provides help in managing almost every aspect of a medical office, such as billing, scheduling, processing of claims, auditing, recording and reserving medical information. It reduces costs as well as the margin of error in managing health care services, and helps in improving the overall productivity of the staff.

Good HIPAA software should ensure that you are complying with all the HIPAA rules and regulations. You must not forget to get your software updated as new rules and regulations are incorporated. A list of such software programs is available on several websites. You can purchase them online. A number of software companies sell HIPAA software.

Do check the performance on trial basis before you pay the full price, as not all software would fulfill your requirement. The choice of software also depends on the type and size of your organization, as well as volume of data that has to be loaded and processed by this software.



HIPAA provides detailed information on HIPAA, HIPAA Compliance, HIPAA Laws, HIPAA Software and more. HIPAA is affliated with Electronic Medical Record Systems.

Labels: , , , ,

Sunday, December 30, 2007

5 Facts About NPI For HIPAA Compliant Electronic Medical Billing Software And Service

The 1996 Health Insurance Portability and Accountability Act (HIPAA) established national privacy and security standards for electronic health care transactions, including a national identifier for providers, health plans and employers. Accordingly, by May 23, 2007, healthcare providers and all health plans and clearinghouses must change both their processes and information systems to implement HIPAA’s National Provider Identifier (NPI) regulations.

Background on the NPI regulation

  • HIPAA mandated regulation
  • Effective nationwide on May 23, 2007
  • The compliance date for health care payers with less than $5 million in annual revenue is May 23, 2008

 

What is the NPI?

  • A unique 10-digit identification number
  • Assigned for life to a provider and de-activated only upon death, retirement, or identity theft
  • Replaces multiple legacy provider identification numbers, including Medicare UPINs, commercial payer IDs and state Medicaid IDs
  • Contains no identifying information related to the provider - randomly generated
  • Independent of key provider information changes, such as practice location or specialty
  • Providers have 30 days to update their NPI record

 

Who is affected by the NPI mandate?

  • Payers
    • Health plans
  • Clearinghouses
  • Providers
    • Organizational providers
    • Individual providers

 

Why is the NPI necessary?

  • NPI delivers two-fold benefits for payers and providers:
    • Simplifies communication and administration
    • Facilitates efficient electronic transmission of certain health information
  • Streamlines detection of billing fraud and abuse
  • Improves debt collection efforts

 

What are the challenges of NPI implementation for payers and providers?

  • Providers and payers must exchange information
  • Technological implementation cost within organizations

 

What should payers and providers do now to prepare for the NPI?

Labels: , , , ,

Thursday, December 27, 2007

7 Steps To NPI For HIPAA-Compliant Electronic Medical Billing Software And Service

The Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) mandated the adoption of standard unique identifiers for health care providers, as well as the adoption of standard unique identifiers for health plans. They become mandatory on May 23, 2007.

The purpose of these provisions is to improve the efficiency and effectiveness of the electronic transmission of health information. The Centers for Medicare & Medicaid Services (CMS) has developed the National Plan and Provider Enumeration System (NPPES) to assign these unique identifiers.

CMS has contracted with Fox Systems, Inc. to serve as the NPI Enumerator. The NPI Enumerator is responsible for dealing with health plans and providers on issues relating to unique identification.

HCFA Timetable

Changes in the HCFA 1500 form to accommodate the NPI number took place January 1, 2007. Until March 30, 2007, using NPI number on the HCFA form is optional but as of April 2, 2007, using NPI becomes mandatory.

Getting an NPI is free - Not Having One Can Be Costly: If you delay applying for your NPI, you risk your cash flow.

 

  1. Enumerate: Enumeration is mandatory for both individual providers and organizations and subparts. When applying for your NPI, CMS urges you to include your legacy identifiers, not only for Medicare but for all payors. If reporting a Medicaid number, include the associated State name. This information is critical for payors in the development of crosswalks to aid in the transition to the NPI.
  2. Update: Make sure to upgrade your software, HIPAA Transactions, CMS1500, UB04, and/or Dental claim form changes.
  3. Communicate: Notify your payers once you have obtained your NPI number. As outlined in the Federal Regulation (The Health Insurance Portability and Accountability Act of 1996 (HIPAA)) you must also share your NPI with other providers, health plans, clearinghouses, and any entity that may need it for billing purposes -- including designation of ordering or referring physician.
  4. Collaborate: Check the readiness of your payment partners (such as health plans, TPAs, clearinghouses, etc...)? Not all payers are ready to accept the NPI number at this time. Use both your existing (legacy) number and the NPI number when submitting electronic claims.
  5. Test: Test transactions well before the deadline. Make sure to test HIPAA Transactions, e.g., 837 Claims, 835 Remittance Advice, and, if you submit paper claims, verify that the data is printed in the correct fields. The new HCFA form has new fields for identifier numbers on lines 17b, 32a and 33a.
  6. Educate: Focus on staff working on insurance verification of eligibility and claim denial or underpayment follow up.
  7. Implement: Once you obtain your NPI, it might take about 120 days to do the remaining wo

    rk to use it. This includes working on your internal billing systems, coordinating with billing services, vendors, and clearinghouses, testing with payers.

    Yuval Lirov, PhD, author of Practicing Profitability - Network Effect for Revenue Cycle Control in Healthcare Clinic and Chiropractic Office: Scheduling, SOAP Notes, Care Plans, Coding, Billing, Collections, and Audit Risk (Affinity Billing) and Mission Critical Systems Management (Prentice Hall), inventor of patents in Artificial Intelligence and Computer Security, and CEO of Vericle.net - Distributed Billing and Practice Management Technologies. Yuval invites you to register to the next webinar on audit risk at BillingPrecision.com

Labels: , , , , , ,

Friday, December 21, 2007

Electronic Medical Billing Software, HIPAA Compliance, and Role Based Access Contro

HIPAA compliance requires special focus and effort as failure to comply carries significant risk of damage and penalties. A practice with multiple separate systems for patient scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. This article presents an integrated approach to HIPAA compliance and outlines key HIPAA terminology, principles, and requirements to help the practice owner to ensure HIPAA compliance by medical billing service and software vendors.

The last decade of the previous century witnessed accelerating proliferation of digital technology in health care, which, along with reduced costs and greater service quality, introduced new and greater risks for accidental disclosure of personal health information.

The Health insurance Portability and Accountability Act (HIPAA) was passed in 1996 by Congress to establish national standards for privacy and security of personal health data. The Privacy Rule, written by the US Department of Health and Human Services took effect on April 14, 2003.

Failure to comply with HIPAA risks accreditation and reputation damage, lawsuits by federal government, financial penalties, ranging from $100 to $250,000, and imprisonment, ranging from one year to ten years.

Protected Health Information (PHI)

The key term of HIPAA is Protected Health Information (PHI), which includes anything that can be used to identify an individual and any information shared with other health care providers or clearinghouses in any media (digital, verbal, recorded voice, faxed, printed, or written). Information that can be used to identify an individual includes:

  1. Name
  2. Dates (except year)
  3. Zip code of more than 3 digits, telephone and fax numbers, email
  4. Social security numbers
  5. Medical record numbers
  6. Health plan numbers
  7. License numbers
  8. Photographs

     

     

 

Information shared with other healthcare providers or clearinghouses

  1. Nursing and physician notes
  2. Billing and other treatment records

     

     

 

Principles of HIPAA

HIPAA intends to allow smooth flow of PHI for healthcare operations subject to patient's consent but prohibit any flow of unauthorized PHI for any other purposes. Healthcare operations include treatment, payment, care quality assessment, competence review training, accreditation, insurance rating, auditing, and legal procedures.

HIPAA promotes fair information practices and requires those with access to PHI to safeguard it. Fair information practices means that a subject must be allowed

  1. Access to PHI,
  2. Correction for errors and completeness, and
  3. Knowledge of others who use PHI

     

     

 

Safeguarding of PHI means that the persons that hold PHI must

  1. Be accountable for own use and disclosure
  2. Have a legal recourse to combat violations

     

     

 

HIPAA Implementation Process

HIPAA implementation begins upon making assumptions about PHI disclosure threat model. The implementation includes both pre-emptive and retroactive controls and involves process, technology, and personnel aspects.

A threat model helps understanding the purpose of HIPAA implementation process. It includes assumptions about

  1. Threat nature (Accidental disclosure by insiders? Access for profit? ),
  2. Source of threat (outsider or insider?),
  3. Means of potential threat (break in, physical intrusion, computer hack, virus?),
  4. Specific kind of data at risk (patient identification, financials, medical?), and
  5. Scale (how many patient records threatened?).

     

     

 

HIPAA process must include clearly stated policy, educational materials and events, clear enforcement means, a schedule for testing of HIPAA compliance, and means for continued transparency about HIPAA compliance. Stated policy typically includes a statement of least privilege data access to complete the job, definition of PHI and incident monitoring and reporting procedures. Educational materials may include case studies, control questions, and a schedule of review seminars for personnel.

Technology Requirements for HIPAA Compliance

Technology implementation of HIPAA proceeds in stages from logical data definition to physical data center to network.

 

     

     

  1. To assure physical data center security, the manager must
    1. Lock data center
    2. Manage access list
    3. Track data center access with closed circuit TV cameras to monitor both internal and external building activities
    4. Protect access to data center with 24 x 7 onsite security
    5. Protect backup data
    6. Test recovery procedure

     

     

  2. For network security, the data center must have special facilities for
    1. Secure networking - firewall protection, encrypted data transfer only
    2. Network access monitoring and report auditing

     

     

  3. For data security, the manager must have
    1. Individual authentication - individual logins and passwords
    2. Role Based Access Control (see below)
    3. Audit trails - all access to all data fields tracked and recorded
    4. Data discipline - Limited ability to download data

     

     

 

Role Based Access Control (RBAC)

RBAC improves convenience and flexibility of systems management. Greater convenience helps reducing the errors of commission and omission in granting access privileges to users. Greater flexibility helps implement the policy of least privilege, where the users are granted only as much privileges as required for completing their job.

RBAC promotes economies of scale, because the frequency of changes of role definition for a single user is higher than the frequency of changes of role definitions across entire organization. Thus, to make a massive change of privileges for a large number of users with same set of privileges, the administrator only makes changes to the role definition.

Hierarchical RBAC further promotes economies of scale and reduces the likelihood of errors. It allows redefining roles by inheriting privileges assigned to roles in the higher hierarchical level.

RBAC is based on establishing a set of user profiles or roles according to responsibilities. Each role has a predefined set of privileges. The user acquires privileges by receiving membership in the role or assignment of a profile by the administrator.

Every time when the definition of the role changes along with the set of privileges that is required to complete the job associated with the role, the administrator needs only to redefine the privileges of the role. The privileges of all of the users that have this role get redefined automatically.

Similarly, if the role of a single user is changed, the only operation that needs to be performed is the reassignment of the user profile, which will redefine user's access privileges automatically according to the new profile.

Summary

HIPAA compliance requires special practice management attention. A practice with multiple separate systems for scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. An integrated system reduces the complexity of HIPAA implementation. By outsourcing technology to a HIPAA-compliant vendor of vericle-like technology solution on an ASP or SaaS basis, HIPAA management overhead can be eliminated (see companion papers on ASP and SaaS for medical billing).

Yuval Lirov, PhD, author of Practicing Profitability - Network Effect for Revenue Cycle Control in Healthcare Clinic and Chiropractic Office: Scheduling, SOAP Notes, Care Plans, Coding, Billing, Collections, and Audit Risk (Affinity Billing) and Mission Critical Systems Management (Prentice Hall), inventor of patents in Artificial Intelligence and Computer Security, and CEO of Vericle.net - Distributed Billing and Practice Management Technologies. Yuval invites you to register to the next webinar on audit risk at BillingPrecision.com

Labels: , , , , ,