HIPAA Law



             


Tuesday, May 20, 2008

Health Insurance - It's Important To Know What's Not Insured!

Around 7 million people in the UK are covered by health insurance, the majority being covered through their employers. The problem is that few have really studied their policy documents and many misunderstand what is covered. And perhaps just as important, what isn't. If you expect health insurance to pay all your health costs, you're mistaken.

Health insurance is designed to provide protection for curable, short-term health problems and allow policyholders to jump the NHS queues to see consultants, be diagnosed, receive surgery or be treated. That sounds fine, but before you buy you need to appreciate the treatments and situations that fall outside the scope of the cover.

But first a word of warning. This article does not relate to any specific policy and the terms and conditions issued by individual insurers do vary. So please ensure you also check your policy documents. After reading this article, you'll know what to look out for!

Sorry - it's a chronic condition

If a condition can be cured and is not a long-term problem, your insurance company will classify it as acute and should meet the cost. If your problem is incurable or it's a problem that, despite appropriate treatment, will be with you for a long time, then your insurance company will classify it as chronic - and no, you won't be covered.

But drawing a firm line between what is acute and what is chronic is fraught with problems, and leads to the biggest area of conflict between insurer and policyholder.

Everyone agrees that diabetes and asthma are chronic conditions as you're likely to suffer from them for the rest of your life. So those sorts of condition are not covered.

Problems arise when the medical team initially considers a patients' illness to be curable, but the condition subsequently deteriorates and the doctors change their mind, it's now become incurable. This can happen especially in the treatment of some types of cancer.

In these circumstances, the condition is initially defined as acute and is therefore insured, but deteriorates and becomes chronic - and outside the terms of cover. This is possible as insurers retain the right to reclassify a condition from acute to chronic during treatment.

Sorry - it's too long term The insurance company will not pay out for long term treatment. But you need to check your policy documents to see how they define "long-term". You can find the situation where a course of drugs extends for say 12 months, but the insurer will only pay for ten months.

Sorry - it's preventative Your insurance is designed to pay for the treatment and cure of conditions when they arise. It is not designed to pay for treatments that are used to prevent an illness.

Again, the problem of definition arises. Sometimes it is arguable whether a treatment is preventative or a cure. Take the drug Herceptin for example. This drug can be used in the early stages of breast cancer. Research shows that Herceptin can halve the incidence of cancer returning for women who have a particularly virulent form of the cancer known as HER2. In this situation, is Herceptin offering a cure or is it a preventative?

Insurance companies are split on the debate. Norwich Union, WPA, BUPA and Standard Life Healthcare will pay for Herceptin for HER2 patients whereas Legal and General and Axa PPP will not.

Sorry - the drug is not approved Two of the main attractions for taking out health insurance are: to jump the queues at the NHS, and to get the latest treatments and drugs. But there's a rider.

Unless the drug has been approved for use by the NHS in England and Wales, by the Institute for Health and Clinical Excellence, your insurer is unlikely to approve its use. The problem is that the Institute's brief is not simply to decide whether a drug works, but to carry out a cost/benefit analysis to ensure that the benefits to the nation outweigh the financial costs of using it in the NHS. Not an easy brief - and one that has placed the Institute under scrutiny for the extended delays in drug approval.

The compromise hit on by the Financial Ombudsman is that if a health policy won't pay for the use of experimental treatments, then it should meet the cost of an approved conventional treatment with the policyholder footing the bill for the balance if the experimental treatment is more expensive.

Sorry - it's a pre-existing condition

The basic principle is that if you are already suffering from a condition when you start a policy, then that condition "pre-exists" the policy and any claims for its treatment are invalid.

For this reason, insurance companies insist you complete an exhaustive questionnaire before they agree to insure you. After all they need a clear picture of your medical condition before they quote. For many applications, the insurer will, with your approval, also write to your GP for specific details of your medical history. They like to have a complete picture.

So lets say some years ago you injured your knee playing football. It appeared to recover but now it turns out that you have a torn cartilage and need an operation. The insurer could argue that this is a pre-existing condition and you have to pay for its' treatment.

Some insurers try to accommodate these grey areas with a moratorium provision within your policy. These provisions typically say that so long as you have been symptom free for two years relating to any condition you've suffered from within the last 5 years, then they will pay for subsequent treatment. Not all policies have these moratorium provisions and the time periods do vary between insurers. You should carefully read your policy.

Sorry - its not covered

Health Insurance is an annual contract - just like your car insurance. So when it comes to renewal, your insurer is at liberty to review not only your premium but also change the conditions on which your cover is provided.

Therefore, if your policy comes up for renewal mid way through a course of treatment, it's possible to find that your new policy no longer covers that particular treatment. This means that you will have to foot the bill for the balance of the treatment.

Furthermore, with ongoing advances in medical research, more and more conditions are becoming treatable. This progress has the effect of shifting back the dividing line between chronic and acute conditions.

This hits the insurers' pocket in two ways. With more conditions being reclassified as acute, the number of claims is increasing. And there's also a trend for new treatments to cost more - Herceptin being a good example. The net result is that the insurers are finding themselves having to pay out far more. This is inevitably passed back to you through increased renewal premiums. And in an attempt to reduce their risk exposure, insurers have a tendency to adjust their definitions and exclusions. This means that you must read your renewal notice closely before you decide to renew.

So when you are considering Health Insurance, be aware that everything is not always black and white. And if you've got insurance and need treatment, always contact your insurer without delay and get them to confirm that your treatment is indeed covered

Labels: , , ,

Tuesday, March 11, 2008

Tales from the Corporate Frontline: The Worth of Health Insurance

This article relates to the Compensation and Benefits Competency, commonly evaluated in employee satisfaction surveys. The questions included in this competency will help your organization determine whether your employees feel they are fairly paid for the work they perform when compared to a similar job at a different company. This competency also queries their feelings regarding the adequacy and quality of their benefits package. A fair and attractive compensation package is critical for hiring and retaining quality employees. A high satisfaction level in this competency requires that your compensation structure and benefits package be fair, balanced, and understood by your present employees.

This article relates to the Compensation and Benefits Competency, commonly evaluated in employee satisfaction surveys. The questions included in this competency will help your organization determine whether your employees feel they are fairly paid for the work they perform when compared to a similar job at a different company. This competency also queries their feelings regarding the adequacy and quality of their benefits package. A fair and attractive compensation package is critical for hiring and retaining quality employees. A high satisfaction level in this competency requires that your compensation structure and benefits package be fair, balanced, and understood by your present employees.

This article, The Worth of Health Insurance, is part of AlphaMeasure's compilation, Tales from the Corporate Frontlines. It focuses specifically on the value of employer provided health insurance to employees in today's workplace and economic climate.

Anonymous Submission:

Large salary increases are rare these days, especially for mid level, mid career employees. Having worked at the same small, family owned business for about ten years now, my fellow employees and I were accustomed to getting about the same raise every year. It never varied very much, and we considered it fair, especially since the business was quite solid and successful with a steady profit stream for the past several years.

That's why we were all so shocked this year when our expected increase amount was cut in half. After the shock faded, the office was abuzz with speculation "the company is going under, that sales rep, Mr. Brown, lost that lucrative account, I knew this would happen, the owners are just getting greedy, they're thinking of selling to a large multinational" - were some of the stories considered.

Finally, our general manager caught wind of the discussions and settled us down for a meeting. He told us that the reason the increases had been cut was that the health insurance program premiums had risen very sharply. The owners decided that rather than require the employees to pay more for the insurance, it would be better to pay the extra premium and give smaller salary increases. He told us that many companies are handling rising premiums in much the same way.

Many employees, myself included, were skeptical. Sure, we told each other. That's a good story. And we picked up where we'd left off with our previous speculations.

That night, I received a phone call. It was my sister, and she was crying. She's a stay- at- home mom, her husband has been downsized, and the family is at the point where it has to pay for health insurance. As my sister tearfully recited the rates she'd been quoted, I was beyond shock. It amounted to a small fortune. After she hung up, I went online to my health insurance provider website. I checked the rate I would pay without my employer contribution. The price difference was far higher than my raise reduction, and the coverage wasn't as good.

Humbled, I went to work the next day and told my coworkers what I'd discovered. We'd all underestimated the worth of a solid benefit plan with good health insurance in today's workplace and economy. Suddenly our salary increase seemed a lot larger.

AlphaMeasure Employee Surveys, Inc. -
This article may be reprinted, provided it is published in its entirety, includes the author bio information, and all links remain active.

Measure. Report. Improve your organization with AlphaMeasure employee surveys.
Josh Greenberg is President of AlphaMeasure, Inc.
AlphaMeasure provides organizations of all sizes a powerful web based method for measuring employee satisfaction, determining employee engagement, and increasing employee retention.

Labels: , , , , ,

Saturday, March 1, 2008

A Guide To Online Health Insurance Quotes

It is a fact that people in the 25-34 age group often dont have health insurance. This is not because they cant afford it, but is because they think that since they are young and healthy, they dont need insurance. This is most definitely not true. One catastrophic illness or accident could wipe out their financial stability in one moment. Having health insurance protects you from things that would otherwise devastate you financially and make it difficult or impossible to recover from.

Of course, the online health insurance business is a booming one. Getting an online health insurance quote is very easy and requires no obligation or someone coming to your home or office to bother you. If you dont have insurance or you want to supplement your current insurance, going online is a good choice. Online health insurance companies offer a variety of plans for diverse coverage needs, from individuals, to families, to small businesses. You can shop around for the best rate and compare different companies and health insurance plans.

It is a good idea to do a little bit of research on any online health insurance company you re considering. You will want to find out how long they have been in business, how stable their business is, and if they are licensed in your state, which they need to be for you to use their services. The best part about online health insurance is that they must report premiums paid to your state, and this amount is regulated by your state, so you will know that they cant overcharge you and you can rest assured that someone is making sure they arent going to rip you off.

You also need to decide what kind of health care coverage you need. Will you need a prescription card to give you discounts on your prescriptions? Most people do. Will your insurance provide coverage if you are traveling? How about emergency and ambulance coverage? Will you need to have a referral to see a specialist, and can you go to a doctor that is outside of your provider network? It is extremely important to find out about the details of any health insurance plan before you buy.

One thing that is very hot with online insurance health and also with other insurance programs are HSAs. They are health Savings Accounts, and the money you lace in them ca be used for immediate medical expenses, saved for future medical expenses, or invested for medical expenses after retirement. This is just one of many health insurance plan aspects to consider when choosing an online health insurance company. Once you have made your choice based on your needs, sit back and let the online health insurance quotes roll in until you find the one that is best for you.
 

Bob Hett offers great tips and advice regarding all aspects of
the health insurance industry. Get the information you are seeking now by visiting http://www.healthinsurancejournal.info

Labels: , , , , ,

Thursday, February 28, 2008

Understanding Health Insurance Coverage: A Primer

Health Insurance Coverage: What are Covered Services?
Health insurance coverage is a contract used to determine medical benefits that are covered, or not covered, between you and your insurance provider. The insurance company, based on a fee that you provide them on a regular basis, promises to pay health insurance coverage on certain items or benefits listed in that contract. These are called covered services. Covered services can include a wide variety of things, such as implements, prescriptions, services (such as massage), checkups, tests and/or research.

Your contract should also list all of the things NOT covered in your health insurance coverage these are items or services that you will need to pay for out of your own pocket, should you require them.

Health Insurance Coverage: What is a Medical Necessity? How is this Different from Covered Services?
Just as it seems, a medical necessity is something that your health professional has deemed a required service/ item that will affect your health negatively should you decide not to purchase it. However, just because your doctor tells you something is a medical necessity does not mean your health insurance actually offers coverage for it.

Since insurance companies decide what health coverage they will and will not provide, you really have no leeway in this area.

Health Insurance Coverage: What Do I Do?
Most doctors try and keep themselves abreast as to what the major insurance companies do, and do not cover when it comes to health coverage. However, there are a LOT of plans out there, so this just isnt enough. So how can you avoid any nasty surprises during an emergency?

Read your health insurance coverage. Youre better off knowing what your health insurance company will, and will not provide coverage for right off the bat. Then, if your doctor decides on a treatment plan that isnt covered, you can ask for alternatives that may be.
If there are questions regarding your health insurance coverage, do not hesitate to contact the insurance company. Questions are good, and they expect them.

Health Insurance Coverage: What Do I Do if Something I Need Isnt Covered?
The gross majority of what your doctor orders for you will be covered in your health insurance plan. If you do get a treatment or supply that isnt covered, you can always challenge the health insurance coverage. You may not be the only one who requires the same type of service, benefit or item so youll end up fighting not just for yourself, but for others in the same situation.

Ask your doctor for their side, and use this in your claim. It may not help in the end, but if your doctor is on your side, you may be able to convince the health insurance company that coverage is required.

For more more information about health insurance coverage please visit http://www.1health-center.com/articles/Health-Insurance-Coverage.php

Labels: , , , , ,

Tuesday, February 26, 2008

Dog Health Insurance

Should you seriously consider buying a dog health insurance policy? Yes, you should. Here's why health insurance for dogs is a good idea:

Dog health insurance saves you money. As with just about all other costs, veterinary expenses have increased rapidly in recent years. Without dog medical insurance (or more accurately, veterinary insurance), you are responsible for paying for everything: routine checkups, preventive procedures, emergency care and disease treatments. That will run into hundreds of dollars. Why not get some help?
Dog Health Insurance: Quick Cost Facts

* Health insurance for your dog, like health insurance for yourself, has annual premiums and deductibles.
* Pet insurance premiums depend on the breed of your dog and the type of policy you decide upon. If you have more than one dog, there is usually a reduced rate after the first policy. Dog health insurance deductibles can vary as well. The average annual deductible is about $100.
* You may choose among different coverage plans which are based on your dogs age, breed, and pre-existing medical conditions. Some policies even consider the dogs lifestyle; for instance, whether your dog is purely a pet or a watchdog, too.

Health Insurance for Dogs: Quick Coverage Facts

* Dog insurance healthcare plans can vary greatly. Some canine health plans are quite comprehensive, covering annual checkups, routine care, vaccinations and other preventive medications, and spaying/neutering, as well as illnesses and accidents. Others only cover unexpected sickness or injuries.
* Dog insurance coverage for emergencies begins immediately on most new dog health plans, with a 30-day waiting period for illness and other claims.
* Your dogs age can affect your dog's health insurance coverage. Typically, policies begin veterinary healthcare coverage when the dog is 6 to 8 weeks old, although some will start when the dog is younger. Similarly, some dog health insurance companies only will cover dogs under 8 years old unless the animal was already insured with them before turning 8.
* Many dog health insurers will not cover your pet if she has a preexisting condition or a terminal illness. Some will insure the dog only if the condition is controlled or stable, usually for 6 months.

With all these options, it is important you check out the various dog health insurance companies, their pet insurance policies and corresponding dog healthcare plans.

In short, if you care about your dog, you should care about his health. If you care about your wallet, you should care about your dog's health insurance coverage, too.

You can read more of Joel Walsh's articles on dog issues such as Dog Health Insurance at: http://www.i-love-dogs.com

Labels: , , , , ,

Thursday, January 24, 2008

HIPAA Compliance

All entities that process health care data must comply with HIPAA. Such entities mainly include healthcare providers and insurance companies. According to the provisions made under this Act, any entity that transmits or stores the private health care information of an individual must comply with certain security regulations.

To ensure smooth compliance with HIPAA, the Department of Health and Human Services (HHS) has the authority to decide which particular codes should be used to identify administrative and medical expenses. This department, as a part of the compliance strategy, can create a safe identification system for clients, insurance carriers and health-care providers. This ID system is a national system.

HHS also has the authority to implement any other procedure necessary to secure private or personal information. Various organizations comply with HIPAA within certain prescribed time limits. Some of them are given 24 months, and those going for small plans can have around 36 months.

Any employer acting as a health care provider must comply with standards set up by HIPAA. There are penalties for non-compliance of HIPAA standards. The rules and regulations for various procedures set up under HIPAA may not be that easy to understand, for an individual. There are several organizations which can help you to comply with HIPAA standards. The help is available online as well as offline. A number of training courses are available for doctors, nurses and anyone else who is interested in learning easy and simple compliance procedures related to HIPAA. These training courses and programs are useful, especially for administrators, physicians and practice managers. Such programs are available online also. A certificate is provided after you complete the program.



HIPAA provides detailed information on HIPAA, HIPAA Compliance, HIPAA Laws, HIPAA Software and more. HIPAA is affliated with Electronic Medical Record Systems.

Labels: , , , , , ,

Thursday, January 17, 2008

Overview Of The Health Insurance Portability And Accountability Act (HIPAA)

Congress enacted the Health Insurance Portability and Accountability Act (HIPAA) in 1996. The purpose of this law is to protect private individual health information from being disclosed to anyone without the consent of the individual. Except under unusual circumstances, the consent needs to be in writing.

However, there are some exceptions to the consent provision. The consent provision does not apply in the following situations:

- Treatment
- Billing
- Quality assurance
- Peer review
- Business planning activities
- Staff training
- Required reporting to public health agencies
- Certain emergency situations
- Research studies that have obtained a wavier from the Institutional Review Board (IRB)

Research

Private health information can be used in research studies if it is "de-individualized" so that the identity of the individual cannot be ascertained from the information disclosed. For example, if you were conducting a study of the lung problems suffered by New Yorkers after the 911 terrorist attacks, it would be permissible to identify a patient as, a 50 year old, 5'11', 175 lb., while male from New York City with high blood pressure.

Marketing

Health care providers are prohibited from selling or using their patient or enrollees lists to market products from a third party. However, they can use their list to communicate with or sell their own services to their list members. Great care must be taken to restrict access when using online collaboration, such as an intranet (http://www.trichys.com).

Business Associates

All business associates, vendors or other contractors that use the health care provider's facility must sign a contract stating that they understand and agree to be bound by HIPAA regulations. The health care provider can be held responsible for the actions of the business associate if they did not sign a contract or there was a history of abuse and the health care provider did noting about it.

Individual Rights

Under HIPAA, individuals have the right to:

- Notice of the health provider's privacy practices
- Request restrictions on who is allowed to access their health information
- Access, inspect or copy their personal health information
- Request an accounting of all disclosures of their health information
- Request corrections or amendments to their health information

Health Care Providers Responsibilities

Health care providers are required to:

- Provide security for both paper and electronic individual health information
- Institute a complaint process to investigate complaints
- Train staff on the law

The HIPAA regulations allow for both civil monetary and criminal penalties for violations of the act.

Malcolm Brown is Vice President of Trichys, providers of intranets and extranet solutions for health care and HIPAA compliance (http://www.trichys.com/home/industry-solutions/hipaa.vm).

Labels: , , , ,

Tuesday, January 8, 2008

Are you HIPAA Compliant?Matt Sears

By - Matt Sears, Senior Vice President
Athens Benefits Insurance Services, Inc.
A division of The Jenkins Athens Group

HIPAA. Perhaps one of the most significant laws in recent memory; certainly one of the most complex. While this short article won't make anyone an expert, it will, hopefully, demystify this wide ranging set of laws and put you on the path towards compliance.

First, let's answer the question; "What is HIPAA?" HIPAA stands for the Health Insurance Portability and Protection Act of 1996. Although it purports to regulate health insurance, HIPAA provisions extend far beyond insurance. HIPAA introduced broad disclosure and privacy requirements. It also established civil and criminal penalties for each violation (up to $25,000 per person per year in civil penalties and up to $250,000 in criminal fines - along with imprisonment).

Title I of HIPAA deals with portability and special enrollment rights for health plans. Those conditions must have been incorporated into your plans by now (original compliance date was 1997). Title II of HIPAA governs a wide ranging set of conditions called, "Administrative Simplification". For those charged with compliance, the notion that HIPAA simplifies anything qualifies as "dark humor". Administrative simplification attempts to create a uniform system for processing and retention of health information and ensuring the security of that information.

For the purposes of this article, we're only concerned with those portions of the law impacting most employers...privacy. Notably the privacy of personal data defined by HIPAA as "Protected Health Information" or "PHI" - information that is personally identifiable. In the broadest summary possible, key components of HIPAA privacy requirements for a plan sponsor are fairly straightforward:

Generally, the employer (Plan Sponsor) is not a HIPAA "Covered Entity" - the Health Plan is. For fully insured plans, this typically means the health insurer, HMO, EAP provider, etc.
As the Covered Entities, health plans bear the brunt of compliance requirements (your responsibilities become exponentially larger as the quantity of data you receive increases)
Meet with every service provider, or ensure that your broker or consultant has reviewed compliance requirements with each
Use protected health information only for needed administration of the benefit programs (HIPAAspeak: "Treatment, Payment and Health Care Operations)
Collect (and release) only the minimum data required to "do the job" (e.g. enroll an employee, file claims, etc.)
Restrict the data to those persons who absolutely must use it
Establish "firewalls" and safeguards to protect the data (separate locked files, restricted access, password protect systems)
Appoint a Privacy Official (not required for fully insured plans that never receive PHI)
Create a Privacy Policy and distribute a Privacy Notice to participants
"Scrub" personally identifiable data from communications pieces, ID Cards, etc.

HIPAA, like COBRA before it, will continually change as new rules and regulations are released (for example, the U.S. Dept. of HHS has yet to release enforcement rules for HIPAA). Ongoing compliance will require vigilance in remaining up to date on the changing laws. It's vital your broker/consultant proactively work with your organization to review plans, identify problems and provide ongoing education to maximize the performance of your benefit plans.
By - Matt Sears, Senior Vice President
Athens Benefits Insurance Services, Inc.
A division of The Jenkins Athens Group

HIPAA. Perhaps one of the most significant laws in recent memory; certainly one of the most complex. While this short article won't make anyone an expert, it will, hopefully, demystify this wide ranging set of laws and put you on the path towards compliance.

First, let's answer the question; "What is HIPAA?" HIPAA stands for the Health Insurance Portability and Protection Act of 1996. Although it purports to regulate health insurance, HIPAA provisions extend far beyond insurance. HIPAA introduced broad disclosure and privacy requirements. It also established civil and criminal penalties for each violation (up to $25,000 per person per year in civil penalties and up to $250,000 in criminal fines - along with imprisonment).

Title I of HIPAA deals with portability and special enrollment rights for health plans. Those conditions must have been incorporated into your plans by now (original compliance date was 1997). Title II of HIPAA governs a wide ranging set of conditions called, "Administrative Simplification". For those charged with compliance, the notion that HIPAA simplifies anything qualifies as "dark humor". Administrative simplification attempts to create a uniform system for processing and retention of health information and ensuring the security of that information.

For the purposes of this article, we're only concerned with those portions of the law impacting most employers...privacy. Notably the privacy of personal data defined by HIPAA as "Protected Health Information" or "PHI" - information that is personally identifiable. In the broadest summary possible, key components of HIPAA privacy requirements for a plan sponsor are fairly straightforward:

Generally, the employer (Plan Sponsor) is not a HIPAA "Covered Entity" - the Health Plan is. For fully insured plans, this typically means the health insurer, HMO, EAP provider, etc.
As the Covered Entities, health plans bear the brunt of compliance requirements (your responsibilities become exponentially larger as the quantity of data you receive increases)
Meet with every service provider, or ensure that your broker or consultant has reviewed compliance requirements with each
Use protected health information only for needed administration of the benefit programs (HIPAAspeak: "Treatment, Payment and Health Care Operations)
Collect (and release) only the minimum data required to "do the job" (e.g. enroll an employee, file claims, etc.)
Restrict the data to those persons who absolutely must use it
Establish "firewalls" and safeguards to protect the data (separate locked files, restricted access, password protect systems)
Appoint a Privacy Official (not required for fully insured plans that never receive PHI)
Create a Privacy Policy and distribute a Privacy Notice to participants
"Scrub" personally identifiable data from communications pieces, ID Cards, etc.

HIPAA, like COBRA before it, will continually change as new rules and regulations are released (for example, the U.S. Dept. of HHS has yet to release enforcement rules for HIPAA). Ongoing compliance will require vigilance in remaining up to date on the changing laws. It's vital your broker/consultant proactively work with your organization to review plans, identify problems and provide ongoing education to maximize the performance of your benefit plans. Setting-up Your New Computer: How To Move Your Old Files to Your New ComputerSteven PresarYou've got a new computer for your office. It's cleaner, better, faster and you can't wait to start to use it!

However, your satisfaction of making a fresh start with a new computer is tempered by the fact that all of your "stuff" is still on your old computer. Everything that made your old computer YOUR computer: your personal settings, your business files, your company spreadsheets are still loaded on your old computer.

You find yourself with a new computer that's not so great without a whole lot of the useful file information that is still stored on your old computer. How are you going to get all of that information onto your new computer?

The process is called "data migration" and it can be a tedious and time-consuming task for you and your business.

Here are some suggestions to make this data migration go a little easier for you.

CDs

One option is to copy ("burn") everything to recordable CDs.

Blank CDs are cheap, at about $1 apiece, and can hold more than 600 megabytes each. That much storage space should be enough for most small businessess to transfer old data files from one hard drive to a new.

Two drawbacks to the CD method of data transfer are that:

~ It may take a while to burn each CD and
~ That you may not have a recordable CD drive on your old PC.

Recordable CD units are standard on newer PCs but if older computers have a CD unit, it was insatlled as later add-on hardware feature. Thus, depending on the age of your older computer, it may not have a recordable CD drive installed at all. To install a recordable CD drive on your older computer now, may be more of a time-consuming effort when compared with other alternatives to moving your data files.

Portable Drives

Iomega has a pre-packaged solution designed to bridge the gap between old and new computers. They offer a software "moving kit" for individuals who have recently bought a new computer with Microsoft's Windows XP.

The software works with Iomega Zip, Jaz and Peerless drives. It allows individuals to "pack" the files they have on their old computer onto a portable high-capacity disks and then "unpack" the same files onto your new computer.

The transfer software uses Microsoft's "files & settings transfer wizard," a feature included in Windows XP.

After connecting a high-capacity drive to your old computer, you need to download the transfer tool, which primes a disk to prompt you to begin the transfer process the next time it is inserted into a drive. Setting up the disk also requires a CD with the Windows XP operating system.

Keep in mind, software moving kits, have the ability to move everything. Thus, if you are not aware of what files that you are transferring, you may be transferring unneeded problem or virus files to your new computer.

Link Transfers

There are other options if you do not want to shuffle CDs or portable drives.

With the link transfer software option your computers are linked through a serial cable or USB cable. After the software program has been installed on both of your computers (the "source" the old computer and "target" the new computer), you click through a question-and-answer wizard to describe what files you want to transfer. And for transfers on the fly, you can drag and drop folders or files between the two panes in the program representing each computer.

Some link transfer software packages that work with Microsoft's Windows are: PCsync, IntelliMover, PC Relocator, and PC Upgrade Commander.

In each case, the software must be installed on both your old and new computers. The software scans your old computer hard drive, to inventory the folders, subfolder, and files and then you select the data files that you would like to transfer to your new computer.

It sounds like a fairly simple way to handle your data transfer. However, be aware:

~ Generally, these programs want to move all the contents of your old computer to your new computer. That's OK for your data files but moving the program files that run your applications may cause problems because older applications may not be supported by your new computer operating system. Transferring a Windows 95-era program to a computer preloaded with the Windows XP operating system could be a problem because many of those programs haven't been upgraded to run under Windows XP.

~ When you move the full contents of a computer system, everything moves over, including those obscure files that had your old computer running sluggish in its final days.

~ Moving data through a USB cable isn't fast, but it is faster than data transfer through a parallel port.

Choosing a Data Migration Software Package

~ Does the software allow you to pick and choose which files are moved, or does it move EVERYTHING -- even the junk files?

~ How is the data transferred? A wireless network is faster than a USB cable, which is faster than a USB cable, which is faster than a parallel cable. Are you prepared to wait hours or even days for this transfer to take place?

~ If you're using the Internet as a holding place for your data, check your connection and upload speeds. It could take hours to move those files.

~ Consider investing in a high-capacity external hard drive, a plug-and-play device that you'll simply connect to your new computer. The drive, though more expensive, will get far more use than one-time migration software.

Getting Ready for Your Data Migration

~ Get rid of all of your old files. Fill your recycle bin on your old computer with as much as you can. There's nothing worse than bringing useless data to the new computer.

~ Make a software checklist. Is your versions of current program applications compatible with Windows XP? Look on the Web for free Windows XP upgrades to new versions of the programs you need, such as your Palm desktop software.

~ Does your new computer have preloaded software on it? Chances are good the latest Internet browser is already pre-load on your new computer and thus you do not have to transfer the older browser version.

~ Make a list of user names and passwords that are stored in files on your old computer and automatically appear when you visit Web sites. They could be lost in the move, denying you access on your new computer.
Steven Presar is a recognized small business technology coach, Internet publisher, author, speaker, and trainer. He provides personal, home, and computer security solutions at www.ProtectionConnect.com. He provides business software reviews at www.OnlineSoftwareGuide.com. In addition, he publishes articles for starting and running a small business at www.Agora-Business-Center.com. Be sure to sign-up for the SOHO newsletter at the site.

 

Labels: , , , ,

Friday, December 21, 2007

Electronic Medical Billing Software, HIPAA Compliance, and Role Based Access Contro

HIPAA compliance requires special focus and effort as failure to comply carries significant risk of damage and penalties. A practice with multiple separate systems for patient scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. This article presents an integrated approach to HIPAA compliance and outlines key HIPAA terminology, principles, and requirements to help the practice owner to ensure HIPAA compliance by medical billing service and software vendors.

The last decade of the previous century witnessed accelerating proliferation of digital technology in health care, which, along with reduced costs and greater service quality, introduced new and greater risks for accidental disclosure of personal health information.

The Health insurance Portability and Accountability Act (HIPAA) was passed in 1996 by Congress to establish national standards for privacy and security of personal health data. The Privacy Rule, written by the US Department of Health and Human Services took effect on April 14, 2003.

Failure to comply with HIPAA risks accreditation and reputation damage, lawsuits by federal government, financial penalties, ranging from $100 to $250,000, and imprisonment, ranging from one year to ten years.

Protected Health Information (PHI)

The key term of HIPAA is Protected Health Information (PHI), which includes anything that can be used to identify an individual and any information shared with other health care providers or clearinghouses in any media (digital, verbal, recorded voice, faxed, printed, or written). Information that can be used to identify an individual includes:

  1. Name
  2. Dates (except year)
  3. Zip code of more than 3 digits, telephone and fax numbers, email
  4. Social security numbers
  5. Medical record numbers
  6. Health plan numbers
  7. License numbers
  8. Photographs

     

     

 

Information shared with other healthcare providers or clearinghouses

  1. Nursing and physician notes
  2. Billing and other treatment records

     

     

 

Principles of HIPAA

HIPAA intends to allow smooth flow of PHI for healthcare operations subject to patient's consent but prohibit any flow of unauthorized PHI for any other purposes. Healthcare operations include treatment, payment, care quality assessment, competence review training, accreditation, insurance rating, auditing, and legal procedures.

HIPAA promotes fair information practices and requires those with access to PHI to safeguard it. Fair information practices means that a subject must be allowed

  1. Access to PHI,
  2. Correction for errors and completeness, and
  3. Knowledge of others who use PHI

     

     

 

Safeguarding of PHI means that the persons that hold PHI must

  1. Be accountable for own use and disclosure
  2. Have a legal recourse to combat violations

     

     

 

HIPAA Implementation Process

HIPAA implementation begins upon making assumptions about PHI disclosure threat model. The implementation includes both pre-emptive and retroactive controls and involves process, technology, and personnel aspects.

A threat model helps understanding the purpose of HIPAA implementation process. It includes assumptions about

  1. Threat nature (Accidental disclosure by insiders? Access for profit? ),
  2. Source of threat (outsider or insider?),
  3. Means of potential threat (break in, physical intrusion, computer hack, virus?),
  4. Specific kind of data at risk (patient identification, financials, medical?), and
  5. Scale (how many patient records threatened?).

     

     

 

HIPAA process must include clearly stated policy, educational materials and events, clear enforcement means, a schedule for testing of HIPAA compliance, and means for continued transparency about HIPAA compliance. Stated policy typically includes a statement of least privilege data access to complete the job, definition of PHI and incident monitoring and reporting procedures. Educational materials may include case studies, control questions, and a schedule of review seminars for personnel.

Technology Requirements for HIPAA Compliance

Technology implementation of HIPAA proceeds in stages from logical data definition to physical data center to network.

 

     

     

  1. To assure physical data center security, the manager must
    1. Lock data center
    2. Manage access list
    3. Track data center access with closed circuit TV cameras to monitor both internal and external building activities
    4. Protect access to data center with 24 x 7 onsite security
    5. Protect backup data
    6. Test recovery procedure

     

     

  2. For network security, the data center must have special facilities for
    1. Secure networking - firewall protection, encrypted data transfer only
    2. Network access monitoring and report auditing

     

     

  3. For data security, the manager must have
    1. Individual authentication - individual logins and passwords
    2. Role Based Access Control (see below)
    3. Audit trails - all access to all data fields tracked and recorded
    4. Data discipline - Limited ability to download data

     

     

 

Role Based Access Control (RBAC)

RBAC improves convenience and flexibility of systems management. Greater convenience helps reducing the errors of commission and omission in granting access privileges to users. Greater flexibility helps implement the policy of least privilege, where the users are granted only as much privileges as required for completing their job.

RBAC promotes economies of scale, because the frequency of changes of role definition for a single user is higher than the frequency of changes of role definitions across entire organization. Thus, to make a massive change of privileges for a large number of users with same set of privileges, the administrator only makes changes to the role definition.

Hierarchical RBAC further promotes economies of scale and reduces the likelihood of errors. It allows redefining roles by inheriting privileges assigned to roles in the higher hierarchical level.

RBAC is based on establishing a set of user profiles or roles according to responsibilities. Each role has a predefined set of privileges. The user acquires privileges by receiving membership in the role or assignment of a profile by the administrator.

Every time when the definition of the role changes along with the set of privileges that is required to complete the job associated with the role, the administrator needs only to redefine the privileges of the role. The privileges of all of the users that have this role get redefined automatically.

Similarly, if the role of a single user is changed, the only operation that needs to be performed is the reassignment of the user profile, which will redefine user's access privileges automatically according to the new profile.

Summary

HIPAA compliance requires special practice management attention. A practice with multiple separate systems for scheduling, electronic medical records, and billing, requires multiple separate HIPAA management efforts. An integrated system reduces the complexity of HIPAA implementation. By outsourcing technology to a HIPAA-compliant vendor of vericle-like technology solution on an ASP or SaaS basis, HIPAA management overhead can be eliminated (see companion papers on ASP and SaaS for medical billing).

Yuval Lirov, PhD, author of Practicing Profitability - Network Effect for Revenue Cycle Control in Healthcare Clinic and Chiropractic Office: Scheduling, SOAP Notes, Care Plans, Coding, Billing, Collections, and Audit Risk (Affinity Billing) and Mission Critical Systems Management (Prentice Hall), inventor of patents in Artificial Intelligence and Computer Security, and CEO of Vericle.net - Distributed Billing and Practice Management Technologies. Yuval invites you to register to the next webinar on audit risk at BillingPrecision.com

Labels: , , , , ,