HIPAA Law



             


Thursday, March 13, 2008

Connecticut Cracks Down on Illegal Health Insurance Plans

The state of Connecticut cracked down on a number of unlicensed health insurance plans and agents this month. The Insurance Department issued warnings to consumers to check the licensing of any firm before doing business. The targeted illegal heath plans were primarily offered to small businesses through their professional industry associations. The health plans claimed that since they were not fully insured and operated in multiple states Connecticuts strict insurance regulations did not apply to them. CT Insurance Department disagreed and closed the plans. A list of the approximately 40 closed plans is posted on the Departments Web site. Since the affected health plans are offered in multiple states, consumers in other states may soon be dealing with similar actions.

But the news is not all black and white. This crackdown closes the door to some of the few remaining affordable health insurance plans for many Connecticut small businesses. Connecticuts past legislative blunders in regulating health insurance are now costing its residents in sharply higher health insurance premiums. The illegal low-priced health plans are actually quite legal and well accepted in other states. The affected consumers are more likely to be irked by the Big Brother attitude of their government than by the fact that their health plan did not meet all applicable state laws. Most will be unable to find replacement health coverage in the same price range.

Tony Novak, MBA, MT, Online Adviser at MedSave.com suggests that consumers keep in mind the simple principal If it sounds too good to be true, it probably is. There are no bargains or great deals in health insurance. If one health insurance plan costs less than another, that is only because it provides less coverage. Make sure that you know specifically what coverage you are giving up before enrolling in a low cost health insurance plan. As long as a plan is fully insured and the agent is also licensed and insured, then it is OK to save money by choosing a plan that eliminates coverage that you do not need. For example, if you dont need maternity coverage or pre-existing condition coverage, then it is safe to buy a plan that costs only half as much as a health plan that does include this coverage.

Novak emphasizes that these buying guidelines apply to residents of all states, not just Connecticut. Unfortunately, too many small businesses buy the lowest cost health plan they can find without really understanding the reason for the cost difference or the risks they may be taking with the lower cost plan.

MedSave.com also adds that the Connecticut crackdown did not affect any of its health plans. All MedSave.com health plans are fully insured and licensed in the state where they are offered.

But the news is not all black and white. This crackdown closes the door to some of the few remaining affordable health insurance plans for many Connecticut small businesses. Connecticuts past legislative blunders in regulating health insurance are now costing its residents in sharply higher health insurance premiums. The illegal low-priced health plans are actually quite legal and well accepted in other states. The affected consumers are more likely to be irked by the Big Brother attitude of their government than by the fact that their health plan did not meet all applicable state laws. Most will be unable to find replacement health coverage in the same price range.

Tony Novak, MBA, MT, Online Adviser at MedSave.com suggests that consumers keep in mind the simple principal If it sounds too good to be true, it probably is. There are no bargains or great deals in health insurance. If one health insurance plan costs less than another, that is only because it provides less coverage. Make sure that you know specifically what coverage you are giving up before enrolling in a low cost health insurance plan. As long as a plan is fully insured and the agent is also licensed and insured, then it is OK to save money by choosing a plan that eliminates coverage that you do not need. For example, if you dont need maternity coverage or pre-existing condition coverage, then it is safe to buy a plan that costs only half as much as a health plan that does include this coverage.

Novak emphasizes that these buying guidelines apply to residents of all states, not just Connecticut. Unfortunately, too many small businesses buy the lowest cost health plan they can find without really understanding the reason for the cost difference or the risks they may be taking with the lower cost plan.

MedSave.com also adds that the Connecticut crackdown did not affect any of its health plans. All MedSave.com health plans are fully insured and licensed in the state where they are offered.


Tax and Benefits Adviser
Freedom Benefits Association

Labels: , , , , ,

Friday, March 7, 2008

Health Insurance for the Self Employed

Health insurance, having enough and being able to afford it, is
one of the most nagging concerns for those who leave corporate
America to run their own business.

Many small businesses have dropped health coverage or reduced it
in the past three years because of rising rates. About 24
million of American small-business employees and their families
are uninsured, according to a study by the Kaiser Family
Foundation.

The Consolidated Omnibus Budget Reconciliation Act (COBRA) is a
federal law that requires employers to allow departing workers
to buy health insurance through the employer's group plan. For
the first 18 months after you leave your employer you may elect
to continue to receive coverage in your employer's group plan at
your expense.

However, the cost of the monthly premiums for COBRA can come as
quite a surprise if you're accustomed to you employer picking up
most of your health insurance tab via pretax paycheck
deductions. COBRA coverage for a family can run $500 a month,
and upwards of $200 a month for an individual.

Depending on which State you live in COBRA may not necessarily
be the best deal for you. Shop around, you may find joining a
short term insurance plan to be less expensive than continuing
your current insurance under COBRA.

One piece of good news for the self-employed - Starting in 2003,
the self-employed health insurance deduction is increased to
100% from the 70% that was deductible in 2002. As a result, if
you work as a consultant, freelance worker, and other
self-employed individual you will be allowed to deduct all of
your health insurance premiums. The self-employed health
insurance deduction is especially valuable because it is an
above the line deduction for Adjusted Gross Income (AGI). This
means that you can take advantage of this deduction even if you
do not you itemize your deductions on your tax return.

Even with health insurance the portion of medical expenses that
has to come out of your pocket can be more than you imagine. If
you have to dip into your retirement savings for certain medical
expenses, distributions from your IRA used for that purpose may
be exempt from the IRS 10 percent early withdrawal penalty.
However, you still will have to pay taxes on the IRA
distribution. Another alternative is to transfer your IRA to a
Self-Employed 401(K) plan and take a loan from that plan. Loans
from a 401(k) plan are tax-free and penalty free as long as the
loans are paid back.

Daniel Lamaute is a retirement plans specialist with Lamaute
Capital. Its website www.investsafe.com covers retirement plans
and other benefits for the self-employed.

Labels: , , , ,

Tuesday, February 26, 2008

Dog Health Insurance

Should you seriously consider buying a dog health insurance policy? Yes, you should. Here's why health insurance for dogs is a good idea:

Dog health insurance saves you money. As with just about all other costs, veterinary expenses have increased rapidly in recent years. Without dog medical insurance (or more accurately, veterinary insurance), you are responsible for paying for everything: routine checkups, preventive procedures, emergency care and disease treatments. That will run into hundreds of dollars. Why not get some help?
Dog Health Insurance: Quick Cost Facts

* Health insurance for your dog, like health insurance for yourself, has annual premiums and deductibles.
* Pet insurance premiums depend on the breed of your dog and the type of policy you decide upon. If you have more than one dog, there is usually a reduced rate after the first policy. Dog health insurance deductibles can vary as well. The average annual deductible is about $100.
* You may choose among different coverage plans which are based on your dogs age, breed, and pre-existing medical conditions. Some policies even consider the dogs lifestyle; for instance, whether your dog is purely a pet or a watchdog, too.

Health Insurance for Dogs: Quick Coverage Facts

* Dog insurance healthcare plans can vary greatly. Some canine health plans are quite comprehensive, covering annual checkups, routine care, vaccinations and other preventive medications, and spaying/neutering, as well as illnesses and accidents. Others only cover unexpected sickness or injuries.
* Dog insurance coverage for emergencies begins immediately on most new dog health plans, with a 30-day waiting period for illness and other claims.
* Your dogs age can affect your dog's health insurance coverage. Typically, policies begin veterinary healthcare coverage when the dog is 6 to 8 weeks old, although some will start when the dog is younger. Similarly, some dog health insurance companies only will cover dogs under 8 years old unless the animal was already insured with them before turning 8.
* Many dog health insurers will not cover your pet if she has a preexisting condition or a terminal illness. Some will insure the dog only if the condition is controlled or stable, usually for 6 months.

With all these options, it is important you check out the various dog health insurance companies, their pet insurance policies and corresponding dog healthcare plans.

In short, if you care about your dog, you should care about his health. If you care about your wallet, you should care about your dog's health insurance coverage, too.

You can read more of Joel Walsh's articles on dog issues such as Dog Health Insurance at: http://www.i-love-dogs.com

Labels: , , , , ,

Wednesday, February 6, 2008

HIPAA And How It Will Affect Your Office

This information is designed to help you better understand HIPAA and to assist your office in becoming HIPAA compliant. The information was obtained from a variety of sources and is not intended to be legal advice. If you are having difficulty understanding any portion of the HIPAA regulations you should consult your legal counsel. First, there are no HIPAA police. No one is going to come into your office to inspect you to see if you are HIPAA compliant. A complaint must be filed in order for any action to be taken.

What is HIPAA?

HIPAA stands for The Health Insurance Portability And Accountability Act. It was enacted by the federal government in 1996 as part of a healthcare reform effort. HIPAA is intended to ensure confidentiality of all patient related health care information. It also intends to simplify the administrative processes of health care, thereby reducing the costs and administrative burdens of health care.

One thing to remember is that the HIPAA Act uses the word ?reasonable? several times. You and your office staff must do whatever reasonable to protect your patient?s privacy. For instance, smaller medical offices do not have to take the same privacy measures as large hospitals do. That would not be reasonable.

Also, there are no ?privacy police.? No one is going to come in and inspect your office randomly. Someone must file a complaint first. The complaints will be handled by the Office of Civil Rights. If someone puts in a complaint, then it will be investigated. The fines are very high, so you will want to be sure that your office has good privacy practices and that they are followed all of the time.

Another thing to keep in mind is that the type of your practice may determine the level of privacy that you need to acquire. For example, patient?s in an optometrist?s office may not be as concerned about people knowing they are there, as opposed to patient?s in a mental health office. There are several different components of HIPAA, each one having its own implementation date.

Section 2: The Privacy Component : implementation date: April 2002

1. You must do everything within reason to protect your patient's privacy.

2. Patient's files and information should be kept in a secure section of your office, a section that is not accessible by other patients.

3. Charts should not be left lying around, open where someone can read it.

4. If you are making a phone call about a patient or to a patient, you need to do it from an area where you cannot be overheard if you will be giving out personal information. For example, if you are calling their insurance company, and you will be saying the patient's first and last name, date of birth, ID#, and/or a diagnosis, then you do not want to do it where others, perhaps in a waiting room, can hear you.

5. If patient's charts are ever removed from the office you need to have a policy in place. For example, you should have a sign out sheet which states the patient's name, date taken, by whom, and then signed back in when the chart is returned.

6. If charts are removed , they should be carried in a case that is marked ?confidential - medical records.? If you were ever involved in an accident, or separated from the bag for any reason, either authorities or medical personel would secure the information for you. Or you would have at least done whatever reasonable to protect that information.

7. If computer screens are in a position that patients can view them, you may want to move them, or get a screen cover. A screen cover makes it so that the computer screen can only be read when directly in front of it. The above are just some things that you will need to consider when becoming HIPAA compliant. Each office will have it?s own areas that need to be reviewed. The above are many of the common areas.

Section 3: Administrative Simplification: compliance date: October 2002

This component requires the standardization of data transmissions, or EDI, and procedure/diagnosis codes.

As for the standardization of procedure/diagnosis codes, this just means that you must use CPT-4 codes for procedure codes and ICD-9 codes for diagnosis codes.

As for the standardization of EDI, that refers to your electronic billing. In order to submit your claims electronically, you must do so in a HIPAA compliant format.

Section 4: Security Component: no implementation date set yet

This component requires that health care professionals, Billing Services, and clearing houses take appropriate security measures to assure that health information pertaining to an individual remains secure and is not accessible by others.

Things to consider:

Where is your fax machine? Is it in a place where only office staff can access incoming faxes? Is it on 24 hours a day? When you are not in the office (after office hours) can anyone else access your fax machine? Whenever you fax personal information about a patient you should use a fax cover sheet with a confidentiality statement. The statement should explain that the following fax contains personal medical information and that if the fax is received by anyone other than the intended party, that the fax should be destroyed and they should notify you that it was received in error.

Do you hire a cleaning person/crew? Are they in the office when you are not? Do they have access to the patient?s personal information? You may want to ask them to sign a confidentiality statement.

Do you rent office space? If yes, does your landlord have access to your office? Do they ever enter your office without you being present? If they do, you may want to ask them to sign a confidentiality statement.

By asking people who have access to your office to sign a confidentiality statement, you are making a reasonable attempt to protect your patient?s privacy. It is not always reasonable to never allow anyone access to areas that contain private information. If those people sign an agreement and then breech that agreement, you would not be held responsible.

If you do any business by email, you will need to use an encryption service. This will ensure that if anyone were to intercept your emails, they would not be able to read them.

Section 5: Privacy Officer

All offices must designate a mandated ?privacy officer.? This person would be responsible for making sure all staff are HIPAA trained and that privacy policies are typed up and followed. They would also be the person that staff members or patients could go to with any concerns or questions about HIPAA compliance. Even if you are a very small practice, you MUST have someone designated as the privacy officer. It may even be the Doctor themself.

Section 6: Release of Patient Information/Consent

You need to have the patient?s written consent in order to release any of their records/information.

(Exception: If request is due to immediate/urgent care of patient.)

You should review your current consent and authorization forms to make sure they are HIPAA compliant. HIPAA requires you to obtain consent for the use and disclosure of information from each of your patients. You may refuse to treat patients who will not sign the consent form.

Section 7: Unique Identifiers: No implementation date set yet

HIPAA will mandate the use of unique identifiers. More to come on this component. Most likely you will have one national provider number, instead of a different provider number for each insurance company.

Section 8: Policies and Procedures Required by HIPAA

1. Identify people on your staff who require access to protected health information.

2. Prevent access to protected health information by unauthorized persons.

3. Ensure that the ?minimum necessary? amount of information is released for routine disclosures (only release information pertaining to what is requested, not the patient?s entire file.)

4. Verify the identity of the requestor of information.

5. Provide patients access to their records, the opportunity to request corrections, and access to and accounting of disclosures.

6. Every office must have written policies regarding privacy practices.

Summary

Evaluate your physical office for potential privacy and security risks. One of the best things that you can do to become ?ready? for HIPAA is to walk through (better yet - have someone else walk through) your office as if you are a patient. Look around at EVERYTHING. What do you see? Do you see any personal patient information, charts in full view? Start right from the front door, and go through every room in your office, especially the rooms that patients have access to. Then continue to do periodic checks to ensure ongoing compliance.

Make sure that you have written policies regarding any privacy practices, such as removing charts from the office, faxing patient information, reviewing any complaints from patients, etc. Also, make sure you designate a ?privacy officer.?

Make sure all staff members are trained regarding HIPAA policies. Remember to train any/all new employees regarding HIPAA policies. You should also review your current HIPAA policies regularly.
Michele Redmond is co-owner of Solutions Medical Billing and has been in business since 1994. She has a bachelor?s degree in Computer Information Science and is responsible for the medical billing for over 50 providers. For more information on medical billing and HIPAA visit her website at http://www.solutions-medical-billing.com

Labels: , , ,

Friday, February 1, 2008

Will HIPAA Sabotage Your Estate Plan

You may have recently noticed that your doctor, other health care providers and pharmacy now ask you to sign a receipt for their "Notice of Privacy Practices".

The reason for this is a new law - - one intended to protect your personal information from identity theft or public disclosure - - which, unfortunately, also dramatically impairs your estate plan in several unforeseen and unintended ways.

The Health Insurance Portability and Accountability Act ("HIPAA") was passed by Congress to provide a secure way for health information to be passed from one health provider to another, or from health providers to insurance companies and to individuals (including the person whose information is involved).

HIPAA strictly limits the disclosure of your medical information by virtually every physician, dentist, psychiatrist, nurse, other health care provider and pharmacist, and imposes fines of up to $250,000 as well as jail time for up to 10 years, in the event any health information is wrongfully disclosed.

Why HIPAA Affects Your Estate Plan

Statistically, there?s better than a 50% chance you?ll someday suffer a serious accident or illness and become unable to handle your financial and medical decisions. In that event, your estate plan documents provide for a successor to take over for you. Your Living Trust and/or your Durable Power of Attorney for Property ("Estate and Personal Planning Uses") take care of your financial decisions. Your "Durable Power of Attorney for Health Care takes care of your health care and treatment decisions.

Your successor decision makers named in your Living Trust or Power of Attorney cannot step in and make decisions for you unless they first have knowledge of your inability to make decisions yourself. If your successor can?t get a confirmation of your condition, he or she may instead have to go to court to declare you "incompetent" - - in what can be an expensive, lengthy and embarrassing conservatorship proceeding. Furthermore, your health care decision makers will urgently need access to your medical information in order to make critical health decisions for you!

Clearly, you would prefer for your successors to have immediate, hassle-free access to your medical records so they may obtain information from your doctor regarding your situation in order to handle your important matters right away. Unfortunately, HIPAA can prevent your successors from getting the medical records and doctor letters they need and force them to go into court!

Sorting out this new law and figuring out how to respond to it has been a huge process for health providers and for us. That?s why you haven?t heard from us, even though the new law became effective in April of 2003. Over the past two years, we have attended numerous continuing education programs, and spent a lot of time doing legal research! Fortunately, the health care providers are only now starting to seriously implement HIPAA, so we haven?t run into any significant problem in getting a client?s medical information so far ? but it will be a real problem in the immediate future!

Isn?t an Authorization to Release Medical

Information Sufficient?

Our policy has always been to thoroughly research new laws and develop practical solutions we feel confident are going to work, rather than to immediately jump in and recommend estate plan changes. For example, we have already seen numerous estate planners advise their clients to merely sign an ?Authorization to Release Medical Information? and tell their clients that?s all they need to take care of the problem ? but that?s wrong!

First of all, HIPAA does not provide one standard ?form? for such authorization. And relying on an authorization form provided by a specific health care provider, a government authority or agency, or even one attorney speaking at a continuing education program may be a big mistake! We have critically examined the exact wording of the law, and almost all forms we?ve see are inadequate!

Many planners creating HIPAA authorizations fail to include certain required disclosures to the signing party and fail to refer to specific terminology of the Act, thereby threatening the validity and acceptance of the authorization by third parties holding your medical information. Worse yet, many authorizations are overly broad and may give others access to your medical information when it?s not yet necessary or appropriate!

Most importantly, very few planners have considered the impact of HIPAA on your other estate plan documents. Your Living Trust, Durable Power of Attorney for Property and Advance Health Care Directive all should be updated to include provisions that will permit your successor trustee or agent to sign a valid authorization on your behalf if you become disabled and your authorization is invalid due to changes in the law, or because it?s too old or simple can?t be located.

These documents also need to provide a set of alternate or back-up procedures if your authorization or the one signed by your successor trustee or agent can?t be properly implemented, even thought it may be valid. For example, your doctor might refuse to honor your authorization because he may question your legal capacity at the time it was signed or he narrowly interprets the kind of information permitted to be released and decides to withhold some important item. Or, because he?s scared off by all the severe penalties, he may refuse to write a letter stating you are incapacitated. If you don?t have a back-up procedure in your estate plan documents to cover these kinds of events, then you may be forced into a court conservatorship!

As if all of this isn?t complicated enough, we also have to consider what may happen if you?re disabled or deceased and one of your successor trustees or agents then becomes incapacitated. How will your documents permit the next named successor to step in immediately if they don?t have a proper Authorization to Release Medical Information from the first successor who can no longer act? We have come up with a practical mechanism to deal with this issue so, again, you can avoid going to court.

You must get all of your documents upgraded, so that your estate plan continues to function smoothly, as intended, should your or one of your successor trustees or agents ever become incapacitated because of illness or accident. This package includes an Authorization to Release Medical Information, an Amendment to your Living Trust for those of you who have a Revocable Living Trust estate plan, a new Power of Attorney for Property and a new Advance Health Care Directive. If you have a Will Package only, you need to have it updated also with a new Authorization to Release Medical Information, Power or Attorney for Property and Health Care Power of Attorney.

Carolina Senior.Com offers South Carolina baby boomers, seniors and retirees, retirement information on investing, financial protection, legal protection, long term care options and more. Perry Fields is a writer for Carolina Senior.com and focuses her writing on South Carolina retirement information.

Labels: , , , , ,

Thursday, December 6, 2007

Alert: New HIPAA Rules Could Affect Your Organization's Email System

On April 21, 2005, a new Health Insurance Portability and Accountability Act (HIPAA) security rule went into effect. The requirements of this rule, which are basically information security best practices, focus on the three cornerstones of a solid information security infrastructure: confidentiality, integrity and availability of information.

The HIPAA regulatory requirements encompass transmission, storage and discoverability of Protected Health Information (PHI). Given the widespread use and mission-critical nature of email, enforcement of HIPAA encryption policies and the growing demand for secure email solutions, email security has never been more important to the healthcare industry than it is right now.

Although many assume it applies only to health care providers, HIPAA affects nearly all companies that regularly transmit or store employee health insurance information. HIPAA was signed into law in 1996 by former President Bill Clinton, with the intent of protecting employee health and insurance information when workers changed or lost their jobs. As Internet use became more widespread in the mid-to-late 1990s, HIPAA requirements overlapped with the digital revolution and offered direction to organizations needing to exchange healthcare information.

HIPAA in the Workplace
Collaboration between employers and healthcare professionals has grown increasingly digital, and email has played an ever-increasing role in this communication. However, email’s increased importance can lead to severe consequences without proper security and privacy measures implemented.

In addition to the usual concerns about privacy and security of email correspondence, even organizations that are not in the healthcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how email containing PHI should be treated in the corporate setting. HIPAA, as it relates to email security, is an enforcement of otherwise well-known best practices that include:

* Ensuring that email messages containing PHI are kept secure when transmitted over an unprotected link

* Ensuring that email systems and users are properly authenticated so that PHI does not get into the wrong hands

* Protecting email servers and message stores where PHI may exist

Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and “catch up” with other industries of similar size and scope.

Privacy and Email Security
The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

The clock is ticking – it’s time to get started
Bringing an enterprise into compliance with the rules set by HIPAA can seem like a very daunting task to even the most experienced executives. Nonetheless, the growing dependence on email as a mission-critical application requires that your organization implement comprehensive security and privacy policies – and soon. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence.

Dr. Paul Judge is a noted scholar and entrepreneur. He is Chief Technology Officer at CipherTrust, the industry's largest provider of enterprise email security solutions. Learn how to make your email system comply with HIPAA regulations by visiting http://www.ciphertrust.com.

Labels: , , , , , ,