HIPAA Law



             


Sunday, March 2, 2008

Where To Find Cheap Health Insurance

Health insurance costs are rising all the time. Many people feel they cannot afford health insurance. Others feel that they dont need it because they are healthy and have never had any major medical problems. This is definitely faulty thinking on their part. As a matter of fact, you do need health insurance, and there are a lot of ways to get affordable health insurance for yourself or your family. Health insurance is protection against the possible health problems that could happen in the future, and you have absolutely no way of knowing what those might be.

For people who are low income, every state has a Medicaid program that they could possible qualify for. The requirements vary form state to state, but all it takes is a trip to your local Division of Family Services office to get an application. You might be surprised at the number of people who would actually qualify for this service that dont think that they would. You will need to fill out the application and provide some documentation about your finances. This program can cover the health insurance needs of the entire family, including dental work, eye care, doctor visits, emergency care, prescriptions and more. For people with children who dont get insurance through their work, this is a very good option to check out. It is free and a fairly painless process, and if you qualify, it could make you like a lot easier.

Another option for cheap health insurance is to look on the Internet. There are a ton of companies that offer all types of health insurance plans, and it is very possible that you could find one that is perfect for your family and fits your pocketbook. The costs vary, so do plenty of research before choosing one or another. It is a smart idea to find out how long the company has been in business, and what kind of reputation they have. Ask for a quote from several sources, and see what kind of a deal they can get for you. Make sure they are also licensed in your state, because it does no good to get insurance if they cant operate in your state.

Still other options include your local insurance agencies. Ask around to find out about the different agents and their policies. Many agents will work very hard to get you an affordable health insurance plan for your family at a cost you can live with. Even if you cant get every type of coverage you want, some is better than none.

Follow up with advertisements for prescription card plans and alternative health care plans. While some of them wont be suited to your needs, there may be one that is perfect for you. An affordable health care insurance plan can be found, but you might have to do some searching.

Bob Hett offers great tips and advice regarding all aspects concerning Health Insurance.
Get the information you are seeking now by visiting http://www.healthinsurancejournal.info

Labels: , , , , , ,

Tuesday, February 5, 2008

The Modern Medical Office: Balancing Success, Technology, and HIPAA

The medical field has always depended on technology for improving patient care. Thanks to advances in technology, administrative functions of healthcare offices have greatly increased their efficiency and customer relations. For example, there is technology that allows doctors to share information with offices across street or across the nation instantly with just a few clicks of the mouse. These advances not only free up hours of paperwork, but also quickly provides information vital to patient?s care.

The Electronic Medical Office & HIPAA A clinic can in the end be more profitable by offering these innovative services. Nearly half of the people interviewed in a Forrester Research study said they would be willing to pay more for online features; such email access to their doctors. (1)

While technology can be tremendously beneficial there are serious cautions that must be heeded. In 2003, the privacy rule of HIPAA was enacted and the rules governing protected health information (PHI) of patients became far more stringent. The rule governs the way in which information is handled. It requires every level of communication and storage of the PHI to be secure and private.(2) Examples of the ways violations occur are:

  • Computer screens visible from waiting room
  • Files left out around the office
  • PHI not disposed of properly, such as securely shredded
  • Records sent to the wrong home or email address

Due to these changes all modes of communication have a heavier burden of responsibility placed upon them since the inclusion of the privacy rule, but none more than electronic transmissions. Keeping the information protected when sending emails, which can be intercepted, can in itself be a daunting task.

HIPAA?s Penalties If an action taken by any employee, whether intentional, unintentional, or simply neglectful leads to improper recipient of PHI, the practice involved could face serious consequences.

  • The civil penalties range from "$100 per incident, up to $25,000 per person, per year, per standard that is violated."(3)
  • The criminal penalties range in three main groups. The first is up to $50,000 and 1 year in prison, moving up to $100,000 and 5 years, or $250,000 and 10 years in prison.

Each tier of the criminal penalties has different qualifications leading up to the knowingly disclosing PHI with the intent for malicious harm. (3)

Keeping Your Practice HIPAA Compliant
It?s important for today?s electronic medical office to have several layers of digital protection. This ensures PHI or any other private information cannot go outside the confines of the practices? systems without the proper digital rights. These rights can be controlled by moderators or even the sender and have the ability to dictate what permissions the receiver may have.

One large step is to protect your practice from accidentally sending information into the wrong hands. This can be done through email anti-theft solutions which encrypts the data sent via email. By using these types of programs, the sender may control not only the security of the file but also subsequent actions that may be carried out by the file?s recipient(s).

email anti-theft programs allow the user to establish who can view, edit, print and forwarding these important health records. Permissions set with email anti-theft software stays with the documents once they?ve left the clinic?s computer.

What Happens if My Practice?s Computer is Stolen?
Email anti-theft software can also protect the data on the computer if the machine is ever misplaced or stolen. This can be done through remote laptop security. All the victim of theft has to do is log into the program and there remotely block access to all protected files on the missing laptop. Without improvement in the means of securing and transmitting their files many practices will continue to commit violations of HIPAA, losing money and patients along the way.

HIPAA Compliance & Patient Trust
It is obvious that one must comply with HIPAA because of the financial penalties that go with noncompliance. There are however, far better reasons for compliance than avoiding punishment.

HIPAA Violations can break the trust between doctors and patients, but compliance along with new technology can strengthen relationships. When patients have new services such as the ability to ask questions to doctors via email the doctors can enhance their trust levels. This is especially important for small practices as interpersonal relationships play key roles for the retention of patients.

The advantages of technology will continue to provide new ways of serving patients. As the digital age comes the computer will increasingly become the focus of record keeping. With an industries like medical & healthcare so dependent on keeping detailed yet secure records, it is going to be ever important to stay current with strong security programs to encrypt and protect files.

  1. Bradford J. Holmes, Eric G. Brown, Elizabeth W. Boehm, Lynne Bishop, "Trends In Healthcare Consumer Technology Adoption" Forrester Research, 15 July 2004.
  2. Title 45 Code of Federal Regulations, Pt 164.
  3. United States Department of Health and Human Services. Protecting the Privacy of Patients' Health Information Summary of the Final Regulation. 2005. http://aspe.hhs.gov/admnsimp/final/pvcfact1.htm
    Michael David is a member of the marketing team at Essential Security Software (ESS), the leading provider of email anti-theft software for small business. He is a regular contributor to http://www.Iwantmyess.com.

Labels: , , , , ,

Sunday, December 30, 2007

5 Facts About NPI For HIPAA Compliant Electronic Medical Billing Software And Service

The 1996 Health Insurance Portability and Accountability Act (HIPAA) established national privacy and security standards for electronic health care transactions, including a national identifier for providers, health plans and employers. Accordingly, by May 23, 2007, healthcare providers and all health plans and clearinghouses must change both their processes and information systems to implement HIPAA’s National Provider Identifier (NPI) regulations.

Background on the NPI regulation

  • HIPAA mandated regulation
  • Effective nationwide on May 23, 2007
  • The compliance date for health care payers with less than $5 million in annual revenue is May 23, 2008

 

What is the NPI?

  • A unique 10-digit identification number
  • Assigned for life to a provider and de-activated only upon death, retirement, or identity theft
  • Replaces multiple legacy provider identification numbers, including Medicare UPINs, commercial payer IDs and state Medicaid IDs
  • Contains no identifying information related to the provider - randomly generated
  • Independent of key provider information changes, such as practice location or specialty
  • Providers have 30 days to update their NPI record

 

Who is affected by the NPI mandate?

  • Payers
    • Health plans
  • Clearinghouses
  • Providers
    • Organizational providers
    • Individual providers

 

Why is the NPI necessary?

  • NPI delivers two-fold benefits for payers and providers:
    • Simplifies communication and administration
    • Facilitates efficient electronic transmission of certain health information
  • Streamlines detection of billing fraud and abuse
  • Improves debt collection efforts

 

What are the challenges of NPI implementation for payers and providers?

  • Providers and payers must exchange information
  • Technological implementation cost within organizations

 

What should payers and providers do now to prepare for the NPI?

Labels: , , , ,

Thursday, December 6, 2007

Alert: New HIPAA Rules Could Affect Your Organization's Email System

On April 21, 2005, a new Health Insurance Portability and Accountability Act (HIPAA) security rule went into effect. The requirements of this rule, which are basically information security best practices, focus on the three cornerstones of a solid information security infrastructure: confidentiality, integrity and availability of information.

The HIPAA regulatory requirements encompass transmission, storage and discoverability of Protected Health Information (PHI). Given the widespread use and mission-critical nature of email, enforcement of HIPAA encryption policies and the growing demand for secure email solutions, email security has never been more important to the healthcare industry than it is right now.

Although many assume it applies only to health care providers, HIPAA affects nearly all companies that regularly transmit or store employee health insurance information. HIPAA was signed into law in 1996 by former President Bill Clinton, with the intent of protecting employee health and insurance information when workers changed or lost their jobs. As Internet use became more widespread in the mid-to-late 1990s, HIPAA requirements overlapped with the digital revolution and offered direction to organizations needing to exchange healthcare information.

HIPAA in the Workplace
Collaboration between employers and healthcare professionals has grown increasingly digital, and email has played an ever-increasing role in this communication. However, email’s increased importance can lead to severe consequences without proper security and privacy measures implemented.

In addition to the usual concerns about privacy and security of email correspondence, even organizations that are not in the healthcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how email containing PHI should be treated in the corporate setting. HIPAA, as it relates to email security, is an enforcement of otherwise well-known best practices that include:

* Ensuring that email messages containing PHI are kept secure when transmitted over an unprotected link

* Ensuring that email systems and users are properly authenticated so that PHI does not get into the wrong hands

* Protecting email servers and message stores where PHI may exist

Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and “catch up” with other industries of similar size and scope.

Privacy and Email Security
The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

The clock is ticking – it’s time to get started
Bringing an enterprise into compliance with the rules set by HIPAA can seem like a very daunting task to even the most experienced executives. Nonetheless, the growing dependence on email as a mission-critical application requires that your organization implement comprehensive security and privacy policies – and soon. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence.

Dr. Paul Judge is a noted scholar and entrepreneur. He is Chief Technology Officer at CipherTrust, the industry's largest provider of enterprise email security solutions. Learn how to make your email system comply with HIPAA regulations by visiting http://www.ciphertrust.com.

Labels: , , , , , ,