Showing posts with label HIPPA. Show all posts
Showing posts with label HIPPA. Show all posts

Thursday, May 3, 2012

New HIPPA Regulations: What You Should Know

Understanding new HIPPA regulations is a critical challenge for every institution. But with the help of instructional guides and white papers, understanding can come a little easier.

This best practices guide explores ways in which your health care facility can employ the most effective compliance strategies, ensuring not only HIPAA compliance, but secure patient information.


Wednesday, February 23, 2011

Cignet Fined for HIPAA Violation.

The first civil money penalty of $4.3 million has been imposed by HHS on Cignet Health of Prince George’s County, Maryland. HHS and CMS have been very firm that violations will no longer be tolerated. With the enactment of HITECH, this type of penalty seemed inevitable.  An individual’s rights to the privacy of their personal information and access to their own medical records is of utmost importance and while beneficiary protection is a main theme of CMS, it appears HHS is a strong advocate of this as well.

OCR has issued a Notice of Final Determination finding that Cignet violated the Privacy Rule of the Health Insurance Portability and Accountability Act of 1996 (HIPAA). HHS has imposed a civil money penalty (CMP) of $4.3 million for the violations, representing the first CMP issued by the Department for a covered entity’s violations of the HIPAA Privacy Rule.  The CMP is based on the violation categories and increased penalty amounts authorized by Section 13410(d) of the Health Information Technology for Economic and Clinical Health (HITECH) Act.

“Ensuring that Americans’ health information privacy is protected is vital to our health care system and a priority of this Administration. The U.S. Department of Health and Human Services is serious about enforcing individual rights guaranteed by the HIPAA Privacy Rule,” said HHS Secretary Kathleen Sebelius.

In a Notice of Proposed Determination issued Oct. 20, 2010, OCR found that Cignet violated 41 patients’ rights by denying them access to their medical records when requested between September 2008 and October 2009. These patients individually filed complaints with OCR, initiating investigations of each complaint. The HIPAA Privacy Rule requires that a covered entity provide a patient with a copy of their medical records within 30 (and no later than 60) days of the patient’s request. The CMP for these violations is $1.3 million.  

During the investigations, Cignet refused to respond to OCR’s demands to produce the records. Additionally, Cignet failed to cooperate with OCR’s investigations of the complaints and produce the records in response to OCR’s subpoena. OCR filed a petition to enforce its subpoena in United States District Court and obtained a default judgment against Cignet on March 30, 2010. On April 7, 2010, Cignet produced the medical records to OCR, but otherwise made no efforts to resolve the complaints through informal means.

OCR also found that Cignet failed to cooperate with OCR’s investigations on a continuing daily basis from March 17, 2009, to April 7, 2010, and that the failure to cooperate was due to Cignet’s willful neglect to comply with the Privacy Rule. Covered entities are required under law to cooperate with the Department’s investigations. The CMP for these violations is $3 million.

“Covered entities and business associates must uphold their responsibility to provide patients with access to their medical records, and adhere closely to all of HIPAA’s requirements,” said OCR Director Georgina Verdugo.  “The U.S. Department of Health and Human Services will continue to investigate and take action against those organizations that knowingly disregard their obligations under these rules.”
-------------------------------------------------------------------------------------------

Pam Argeris is a thought leader in the Healthcare Industry and possesses extensive, hands-on experience with CMS compliance, and multiple regulatory bodies such as NCQA, JACHO, and DOI. In her role at Merrill Corp., Pam focuses on developing solutions for compliance and quality assurance, delivered in a cost effective manner to improve beneficiary and prospect communications. You can contact Pam at Pamela.Argeris@merrillcorp.com.

Wednesday, January 12, 2011

Mandated Member Communications: A Case Study (Part 2)

Last week, we presented a scenario that, while specific in nature, has commonalities to what a number of organizations in the healthcare communications space may have to deal with when confronted with.the resource-draining, time-consuming process that is the preparation, distributing and reporting of CMS mandated member communications.

A nationally-known insurance company lacked in-house capabilities for managing the creation and distribution of mandated letters for their Medicare members. This resulted in inaccurate mailings, missed deadlines, and poor CMS audit results.

THE SOLUTION:

A web-enabled solution was created that systematically worked with the organization's data and married it to the correct CMS-approved template. The final document was then printed and distributed in one automated process.

This solution provided a chain of custody workflow that was desired by the organization and adhered to all CMS Chapter Two requirements and regulations. Furthermore, the built-in quality assurance processes validated the quality attributes of the letters and delivered 100% integrity management through the utilization of a 2-D bar code driven production process. Additionally, robust tracking – from file creation to delivery point validation, provided detailed, on-demand reports in response to any audit requirements.

This solution effectively transitioned a resource-draining, error-prone process
into a highly efficient, automated data management system. Utilizing HIPAA/PHI
compliant workflows and SAS 70 certified production and mailing facilities, the organization achieved 100% accuracy on all letters managed through this solution. Advanced SLAs provided same day delivery on all files received by 4 a.m., and overall program efficiencies delivered an immediate 20% cost reduction. Additionally, the organization leveraged proactive monitoring of regulatory changes to remain in compliance, at no effort to them.

-------------------------------------------------------------------------------------------

Pam Argeris is a thought leader in the Healthcare Industry and possesses extensive, hands-on experience with CMS compliance, and multiple regulatory bodies such as NCQA, JACHO, and DOI. In her role at Merrill Corp., Pam focuses on developing solutions for compliance and quality assurance, delivered in a cost effective manner to improve beneficiary and prospect communications. Pam can be contacted at Pamela.Argeris@merrillcorp.com.

Friday, November 12, 2010

OPM Shows Little Concern for Privacy

OPM is making waves with their push toward a national database of health insurance customers. OPM’s argument is that such a database would provide "best value for both enrollees and taxpayers.” They also cite the potential efficiency such a system would offer. OPM also claims that the system would be “de-identified,” supposedly protecting individual customers from the healthcare data-mining that plagues the industry.

However, many are not satisfied with OPM’s vague claims. Harley Geiger, policy counsel for the Center for Democracy and Technology, tells Computerworld “[At this point,] there are far too many unknowns about the program for it to be acceptable.” Many questions are raised by the program: Are HIPAA and PHI going to be swirling around cyberspace? Exactly what measures are protecting consumers from data mining?

Most seem to agree that OPM’s notice is entirely too vague to garner any form of support for the new system. OPM’s plans to allow third-parties to access the material, including judicial and research groups, sends up further red-flags.

Until OPM is willing to release more specific information about the program, it is unlikely to be welcomed into the industry. Our concern should be for the protection and safety of consumers and average citizens, not for cost-cutting. If there is even a small potential for someone to profit from selling access of this database to commercial data-miners, then it is unacceptable as a system.

-------------------------------------------------------------------------------------------

Pam Argeris is a thought leader in the Healthcare Industry and possesses extensive, hands-on experience with CMS compliance, and multiple regulatory bodies such as NCQA, JACHO, and DOI. In her role at Merrill Corp., Pam focuses on developing solutions for compliance and quality assurance, delivered in a cost effective manner to improve beneficiary and prospect communications. You can contact Pam at Pamela.Argeris@merrillcorp.com.


Thursday, July 29, 2010

HHS Strengthens Health Information Privacy and Security through New Rules

“To improve the health of individuals and communities, health information must be available to those making critical decisions, including individuals and their caregivers. While health information technology will help America move its health care system forward, the privacy and security of personal health data is at the core of all our work.”

--U.S. Health and Human Services Secretary Kathleen Sebelius

On July 8, Secretary Sebelius announced important new rules to strengthen the Health Insurance Portability and Accountability Act of 1996 (HIPAA), improve the privacy of health information and help all Americans understand their rights and the resources available to safeguard their personal health data.

In short, the proposed rule would strengthen and expand enforcement by:
  • Expanding individuals’ rights to access their information and to restrict certain types of disclosures of protected health information to health plans;
  • Requiring business associates of HIPAA-covered entities to be under most of the same rules as the covered entities;
  • Setting new limitations on the use and disclosure of protected health information for marketing and fundraising; and
  • Prohibiting the sale of protected health information without patient authorization.
“The benefits of health IT can only be fully realized if patients and providers are confident that electronic health information is kept private and secure at all times,” said Georgina Verdugo, Office for Civil Rights director at HHS. “This proposed rule strengthens the privacy and security of health information, and is an integral piece of the administration’s efforts to broaden the use of health information technology in health care today.”

In addition, HHS also launched a privacy website to help visitors easily access information about existing HHS privacy efforts and the policies supporting them. The site emphasizes the deep commitment to privacy in the collection, use and exchange of personally identifiable information. This new resource provides Americans with confidence that their personal information is secure and underscores HHS’ goal of greater openness and transparency in government.

For more information about the new rule, click HERE.

For other HHS Recovery Act programs, click HERE.