HIPAA Compliance
General Compliance, HIPAA

Before PHI Enters a SaaS Workflow

Building a Vendor Evidence Register 

Written by Coco Yang 

Introduction

A clinic can approve a scheduling platform and still miss the place where patient information leaves the approved path. An intake form may pass data to the scheduler, which sends a notification through an email service, creates a record in a customer relationship management system, and copies details into an analytics tool. The vendor review may have covered the scheduling platform. The actual workflow contains four or five services.

That is why a product name and a "HIPAA compliant" statement are not enough to document a SaaS decision. The review needs to identify the exact service, plan, configuration, integrations, users, and data flow. It also needs a record of what each source supports, what it does not support, and what still requires an answer from the vendor.

A vendor evidence register provides that record. It is not a certification score and should not replace legal, privacy, security, procurement, or clinical review. It is a practical way to keep the evidence behind a decision visible before protected health information (PHI) enters a software workflow.

Start With the Workflow, Not the Vendor Name

The first question is not simply, "Does this vendor support HIPAA?" A more useful starting question is, "What will this organization do with this exact service?"

Write down the product edition and paid plan, the features that will be enabled, the people who will have access, and the systems that will send or receive data. Include support tools, exports, backups, browser extensions, mobile applications, application programming interfaces, automation services, and optional artificial intelligence features. Then identify where PHI is expected to be created, received, maintained, or transmitted.

This boundary matters. A vendor may make a business associate agreement (BAA) available only for certain products, plans, customers, or configurations. An integration may be provided by another company. A feature may use a separate sub-processor or different retention setting. HHS guidance on cloud computing advises covered entities and business associates to understand the cloud environment they are using so they can conduct their own risk analysis and enter into appropriate agreements.

A simple workflow sentence helps anchor the review. For example: "Patients submit contact and appointment information through Form A; the data is stored in Scheduler B; staff members access it through managed accounts; appointment reminders are sent through Service C; no PHI is sent to analytics." If the team cannot write that sentence with confidence, it is too early to approve the workflow.

Keep Different Kinds of Evidence Separate

Vendor material often arrives as a mixed folder of contracts, reports, help-center pages, questionnaires, and sales statements. These sources do not answer the same questions.

A BAA is contractual evidence. HHS explains that a business associate contract establishes permitted and required uses and disclosures, requires safeguards, addresses incident reporting, applies restrictions to relevant subcontractors, and covers return or destruction of PHI at termination when feasible. The review still needs to confirm that the agreement applies to the exact legal entity and service being purchased.

A SOC 2 report is security-assurance evidence. It can help a reviewer understand the systems, controls, time period, exceptions, and subservice organizations described in the report. It does not establish that the vendor will sign a BAA, that the intended product is included in the BAA, or that the customer's configuration is appropriate.

Product documentation explains how features work. It may describe access controls, audit logs, retention settings, encryption, data regions, or deletion behavior. Marketing language is a weaker source. It can point the team toward a question, but it should not be treated as proof that a contract, report, or technical control covers the planned workflow.

Keeping these evidence types separate prevents one familiar logo or badge from doing more work than it should.

What to Record

The register does not need to be elaborate. A spreadsheet, ticket, or procurement record can work if it preserves enough context for another reviewer to reconstruct the decision. For each item, record:

  1. The source title, owner, and location.
  2. The date it was retrieved and, when applicable, its effective period or report period.
  3. The legal entity, product, plan, feature, and region it covers.
  4. The conclusion the source supports.
  5. Conditions and limitations stated in the source.
  6. Questions that remain open and the person responsible for resolving them.
  7. The date or event that will trigger another review.

Short conclusions are more useful than broad labels. "Vendor says HIPAA compliant" is difficult to act on. "BAA offered for the Enterprise plan; analytics add-on not named; vendor confirmation pending" tells the next reviewer what is known and where the uncertainty sits.

The same discipline should be used for security evidence. Instead of recording "SOC 2 available," note the report type, review period, system description, relevant exceptions, complementary customer controls, and whether important subservice organizations are included or carved out.

Check the Operational Questions

Contracts and assurance reports are only part of the review. The intended use also depends on routine operational details.

Ask which sub-processors may create, receive, maintain, or transmit PHI. Confirm how administrators and support personnel obtain access, whether that access is logged, and how emergency support is handled. Review default retention, backup retention, deletion timing, export behavior, account termination, and the process for returning or destroying data.

Incident language deserves the same attention. Identify where the vendor describes security incidents and breach notification, who receives notice, and whether the timing and cooperation terms match the organization's requirements. Customer-side safeguards should also be explicit: identity management, multifactor authentication, role design, device controls, logging, staff training, approved integrations, and procedures for offboarding users.

A signed BAA does not configure the product. HHS risk-analysis guidance makes clear that regulated organizations must identify potential risks and vulnerabilities to all electronic PHI they create, receive, maintain, or transmit. The vendor's evidence informs that work; it does not perform the organization's risk analysis for it.

Use Evidence States Instead of a Single Verdict

A binary field labeled "compliant" hides too much. Evidence is often conditional, incomplete, inconsistent, or old. A small set of evidence states makes the record more honest:

  • Supported: the source directly supports the conclusion for the identified scope.
  • Conditional: the conclusion depends on a plan, configuration, contract, location, or customer action.
  • Missing: the needed source has not been obtained.
  • Conflicting: two sources disagree or describe different scopes.
  • Stale: the source no longer reflects the current product, contract, report period, or workflow.

These are evidence states, not compliance determinations. They help the organization route questions to the right owner and avoid treating silence as approval.

Review Again When Something Changes

An annual vendor review is useful, but a change in the workflow can make last month's evidence incomplete. Set event-based review triggers for a new contract or BAA, a plan change, a new integration, a material sub-processor update, revised retention terms, a new artificial intelligence feature, a security incident, or a change in the type of PHI being handled.

The register should also have an owner. Procurement may hold contracts, security may review assurance reports, privacy or compliance may assess uses and disclosures, and the operational team may know the actual configuration. Someone must be responsible for assembling those pieces and recording the final conditions of use.

Conclusion

A SaaS review is easier to defend when another person can see exactly what was reviewed, when it was reviewed, and which workflow the decision covered. Begin with the data path. Separate contractual, assurance, product, and marketing evidence. Record scope and dates. Preserve unresolved questions. Reopen the review when the service or workflow changes.

The purpose of a vendor evidence register is not to produce a universal badge. It is to make the reasoning behind a decision inspectable before PHI enters the workflow. Final decisions should remain with the organization's qualified legal, privacy, security, compliance, procurement, and operational professionals.

About the Author

Coco Yang is the Founder of ComplySaaS, an educational SaaS vendor compliance research project that organizes public HIPAA, BAA, PHI, and SOC 2 signals, source dates, workflow conditions, and verification questions. Her work is limited to documented vendor-research practice; she is not presenting herself as an attorney, auditor, healthcare provider, or compliance certifier. Company website: https://www.complysaas.com/

References

U.S. Department of Health and Human Services. "Guidance on HIPAA & Cloud Computing."

U.S. Department of Health and Human Services. "Business Associate Contracts."

U.S. Department of Health and Human Services. "Guidance on Risk Analysis."

National Institute of Standards and Technology. "SP 800-66 Rev. 2: Implementing the HIPAA Security Rule."

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
General Compliance

The Legal and Ethical Imperative of Explicit Consent in Intimate Medical Procedures

Written by: Shelby Harriel-Hidlebaugh,  M.Ed. and BA  

The medical setting is expected to be a sanctuary of dignity and autonomy. However, sensitive exams and other intimate tasks conducted without consent can leave patients feeling violated. Informed consent is a cornerstone of ethical medical practice. It establishes a foundation of trust between patients and healthcare providers and protects patients’ autonomy over their own bodies. However, intimate medical exams and tasks performed without explicit consent continue to undermine these principles.

 
In order to address concerns about these unauthorized practices, an increasing number of states have passed laws protecting the bodily autonomy of patients. Additionally, the Centers for Medicare & Medicaid Services released revisions and clarifications to the Hospital Interpretive Guidelines for Informed Consent simultaneously with a letter by the Department of Health and Human Services to address medical professionals performing non-consensual intimate exams, particularly on patients under anesthesia.[1] Yet, as bioethicists and others have illustrated, these directives and laws are inadequate.[2]

 
To illustrate this point, a recent study published in October 2024 involving nearly 300 osteopathic medical students, 93.1% of them indicated that they were unaware of whether their state even has statutes regarding explicit consent for performing pelvic exams on anesthetized patients. Approximately 83.5% considered performing a non-consensual pelvic exam under anesthesia akin to sexual assault. Yet, out of those who acknowledged that they had performed pelvic exams, 74% of them either admitted that they did so without explicit consent or declined to answer the question. And this coming after 99.9% of them expressed a correct understanding of what constitutes informed consent.[3]

 
State statutes and institutional policies fail in fully protecting bodily privacy and rights for all patients in medical settings. While unauthorized sensitive exams have been garnering an increasing amount of attention from the media, legislators, bioethicists, and the medical community, far less focus has been placed on tasks such as urinary catheter insertions, gown and underwear removal, groin sanitization, pubic hair removal and other such intimately invasive functions conducted during prep for non-intimate elective surgical procedures.[4] These intimate encounters can result in the same psychological harm caused by non-consensual sensitive exams.[5]  And given that these tasks are performed under anesthesia and without prior disclosure, they raise significant ethical, legal, and institutional concerns. The reliance on patient incapacitation to perform such tasks does not absolve medical professionals of their ethical and legal responsibilities.


This article explores the legal framework surrounding these practices, emphasizing case law, Federal law, and institutional policies while calling for systemic reform to secure equal protection for all patients from all unwanted and non-consensual intimate encounters before, during, and after elective medical procedures. 


Relevant Case Law: Protecting Bodily Privacy


Foundations of Bodily Privacy
According to the American Medical Association’s (AMA) code of ethics, physical privacy is one aspect of patient privacy that medical personnel must protect in all settings as “an expression of respect for patient autonomy and a prerequisite of trust.”[6]


Bodily privacy extends beyond the focus of medical associations and institutions. It is also a fundamental legal principle upheld by multiple judicial rulings. In York v. Story (9th Circuit Court), the court emphasized that the right to privacy over one’s naked body is integral to self-respect and dignity. The decision underscored that any unauthorized exposure or intrusion violates an individual’s constitutional protections.[7]

 
The right to bodily privacy extends into medical settings, as established in Local 567 American Fed. v. Michigan Council 25 (E.D. Mich. 1986). Here, the court affirmed that hospitalization does not negate a person’s right to bodily privacy when it noted that, “It would be a strange doctrine … that would decree that the sanctity of the right of privacy…fully respected in a public restroom, is forfeited by the fact of falling ill and becoming hospitalized.” It further stated that privacy violation—whether by a healthcare provider or another individual—remains significant regardless of gender.[8]

In Backus v. Baptist Medical Center, the court upheld a hospital’s decision to prevent male nurses from being assigned to labor and delivery units. The ruling recognized that intimately invasive tasks such as intimate hair removal performed by unselected individuals could violate patients’ constitutional right to privacy. The judgment further affirmed that such violations are not mitigated by the healthcare professional’s intent or qualifications, placing the patient’s perception, comfort, autonomy, and well-being at the forefront.[9]


Institutional and Judicial Recognition of Psychological Harm in Medical Settings
The Federation of State Medical Boards (FSMB) defines patient harm as “inclusive of physical and emotional harm, resulting distrust in the medical system and avoidance of future medical treatment, and other related effects of trauma.”[10] Further, the National Council of State Boards of Nursing (NCSBN) states that “Sexual boundary violations result in significant and enduring harm to patients.”[11]


Courts have also acknowledged the psychological harm that results from unauthorized intimate medical contact. The ruling in Backus v. Baptist Medical Center highlighted the emotional and psychological toll of privacy violations, underscoring the need for healthcare providers to prioritize patients’ perceptions of dignity and autonomy over institutional convenience or routine practices.[12]


The potential to inflict lifelong psychological harm underscores the importance of consent.


Consent

Standards of Consent
Federal law provides a clear framework for understanding consent as a "freely given agreement to the conduct at issue by a competent person." Importantly, it stipulates that unconscious, incapacitated, or unaware individuals cannot provide valid consent.[13]  Beyond Federal law, state laws and Title IX policies that govern teaching hospitals at associated universities address consent. For example, the University of Iowa’s sexual misconduct policy defines consent as “knowing, voluntary, and clear permission by word or unambiguous action.” This provides a straightforward definition of consent as it applies specifically to intimate areas of the body defined by the policy as “breasts, buttock, groin, or genitals.”[14] The failure to secure explicit consent for intimate tasks—such as gown or underwear removal, pubic hair removal, groin sanitization, or urinary catheterization—contradicts these policies, placing patients at risk of harm and retraumatization.

Implied Consent – A Flawed Justification
Healthcare providers often justify failing to disclose intimate medical tasks by invoking the concept of implied consent, assuming that patients understand and agree to all preparatory procedures associated with a surgery or treatment. However, the invasiveness of manipulating private body parts not directly involved in the procedure renders it unique to the intrusiveness of general procedure. Thus, the implied consent approach undermines the ethical principle of informed consent by creating a significant gap in the important communication process. Patients cannot consent to procedures they are unaware of, and withholding information about intimate tasks denies them the opportunity to make an informed decision with regards to access of their private areas. Without such agreement, intimate functions performed prior to, during, or after non-intimate, elective procedures would theoretically constitute unauthorized and offensive touching regardless of their medical necessity. Legal and institutional definitions of consent for sexual contact directly challenges the medical practice of relying on implied consent for intimate tasks performed without explicit patient knowledge.

 
While the medical community asserts that it is their professional duty to safeguard their patients’ dignity and bodily privacy, assuming that patients have implicitly consented to intimate preparatory tasks for a non-intimate procedure not only denies them the right refuse treatment but also to safeguard their bodily sanctity themselves while simultaneously forcing patients to adhere to the provider’s concept of dignity, rather than allowing patients to assert their own values. Ultimately, when medical personnel subject patients to intimate procedures and tasks to which they have not truly consented, they deny the autonomy and humanity of their patients, which is a core ethical principle of the medical profession.

 
The principle is clear: patients must be fully informed and explicitly agree to visual or physical access of the private areas of their bodies outside a medical emergency.

Sexual Misconduct Concerns and Intimate Procedures and Tasks

The absence of explicit consent for intimate medical tasks parallels behaviors classified as sexual misconduct in other contexts. Under Federal law, non-consensual sexual contact—including contact with genitals, breasts, or other intimate areas—either directly or through clothing is classified as sexual misconduct.[15]

 
State law and universities model their statutes and policies after sexual misconduct Federal laws. So, too, do medical organizations and associations who also address sexual boundary violations. For example, the NCSBN notes that “Clear sexual boundaries are crucial to patient safety” and specifically classifies “Removing a patient’s … clothing, gown or draping without consent, [or] emergent medical necessity” as sexual misconduct.[16] The FSMB bans physical intimate contact “without…explanation of its necessity, and without obtaining informed consent.”[17]

 
FSNB and NCSBN policies also state that sexual misconduct includes behavior that “can have the effect of embarrassing, shaming, humiliating or demeaning the patient.”[18]


Accommodating Vulnerable Populations

Americans with Disabilities Act (ADA)
The ADA extends additional protections to individuals with PTSD and other disabilities, requiring accommodations to prevent retraumatization.[19]  Medical tasks and procedures involving intimate areas without explicit consent can exacerbate psychological harm, particularly for individuals with histories of sexual trauma. Providers – including universities overseeing associated hospitals – who fail to obtain explicit consent for such actions as intimate preparatory tasks denies these patients the opportunity to assert their boundaries, further marginalizing their needs. Thus, they inadvertently violate these legal protections. Comprehensive consent policies that prioritize patient awareness and agreement are essential to fulfilling these obligations.

Recommendations for Reform

Legislative Action

1.  Mandating Explicit Consent

  • Federal and state governments should enact laws requiring explicit consent for all intimate medical tasks, including preparatory steps like gown removal, pubic hair clipping, groin sanitation, urinary catheter insertion and other such procedures.
  • These laws should mandate detailed discussions of these tasks during the informed consent process and require written documentation of patient agreement.

2.  Enforcing Accountability

  • Oversight mechanisms should be strengthened to ensure compliance with consent standards. Medical boards, institutions, facilities, and universities must be held accountable for violations, with penalties such as fines, suspensions, or revocation of licenses.

Institutional Reforms

1.  Revamping Consent Practices

  • Universities and hospitals should revise their informed consent processes to include detailed explanations of intimate preparatory tasks. Patients must be informed of all key aspects of their care and given the opportunity to agree or refuse.

2.  Promoting Transparency in Medical Education

  • Teaching hospitals must disclose the involvement of medical students or residents in procedures – especially those of an intimate nature – and secure explicit patient consent. Transparency is critical to maintaining trust and ethical standards in medical training.

Cultural and Ethical Shift

1.  Prioritizing Patient Autonomy

  • The medical community must prioritize patients’ perceptions of dignity and autonomy, recognizing that intimate medical tasks are not trivial to those being treated.

2. Educating Providers

  • Training programs should emphasize the importance of explicit consent and the ethical implications of intimate medical tasks. Providers must understand the psychological and legal consequences of failing to secure patient agreement

Conclusion

Given the fact that Federal and state law acknowledges and protects the special status attached to individuals’ intimate spaces, medical professionals should comply with these regulations because “patients do not think of their intimate regions in a detached or neutral way.”[20] Case law, Federal law, medical associations, and university and institutional policies converge on the necessity of respecting bodily autonomy and securing explicit consent for medical procedures. Despite these established frameworks, systemic failures in enforcement and the reliance on implied consent perpetuate harmful practices that violate patient rights and erode trust in healthcare institutions. Legislative reforms, institutional accountability, and a cultural shift toward prioritizing the patient’s– rather than the provider’s – notion of dignity are essential to restoring trust, preventing harm, and aligning medical practices with ethical and legal standards.

About the Author

Shelby Harriel-Hidlebaugh has an M.Ed. and BA from the University of Southern Mississippi.  She is a mathematics instructor at Pearl River Community College.  She has a published article on this topic in Voices in Bioethics, November 2023. https://journals.library.columbia.edu/index.php/bioethics/article/view/11927

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved 


[1] CMS Revisions and Clarifications to Hospital Interpretive Guidelines for Informed Consent. April 1, 2024. Retrieved from https://www.cms.gov/files/document/qso-24-10-hospitals.pdf; HHS Letter to the nation’s teaching hospitals and medical schools. April 1, 2024. https://www.hhs.gov/about/news/2024/04/01/letter-to-the-nations-teaching-hospitals-and-medical-schools.html

[2] Neff G. Comply with Privacy Rights to Avoid Unconsented Intimate Exams. American Institute of Healthcare Compliance. November 12, 2024. https://dev-main.aihc-assn.org/comply-with-privacy-rights-to-avoid-unconsented-intimate-exams/; Bruce L. A Pot Ignored Boils On: Sustained Calls for Explicit Consent of Intimate Medical Exams. HEC Forum. 2020 Jun;32(2):125-145. doi: 10.1007/s10730-020-09399-4. PMID: 32152870; PMCID: PMC7223770; Friesen P, Wilson RF, Kim S, Goedken J. Consent for Intimate Exams on Unconscious Patients: Sharpening Legislative Efforts. Hastings Cent Rep. 2022 Jan;52(1):28-31. doi: 10.1002/hast.1337. PMID: 35143067

[3] Rachel Cutting, Varsha Reddy, Sneha Polam, Nicole Neiman, and David Manna (2024). Prevalence of pelvic examinations on anesthetized patients without informed consent. Journal of Osteopathic Medicine. DOI: https://doi.org/10.1515/jom-2024-0058

[4] Harriel - Hidlebaugh, S. (2023). Not Just Non-Consensual Pelvic Exams: The Need for Expressed Consent for All Intimate Tasks for Elective Procedures. Voices in Bioethics, 9. https://doi.org/10.52214/vib.v9i.11927

[5] For patient narratives of bodily privacy violations and their effects, see Medical Patient Modesty, www.patientmodesty.org/modesty.aspx

[6] American Medical Association, “Privacy in Health Care,” Chapter 3.1.1; https://code-medical-ethics.ama-assn.org/ethics-opinions/privacy-health-care

[7] York v. Story, https://casetext.com/case/york-v-story

[8] Local 567 American Fed. v. Michigan Council 25, 635 F. Supp. 1010 (E.D. Mich. 1986). https://law.justia.com/cases/federal/district-courts/FSupp/635/1010/1438741/

[9] Backus v. Baptist Medical Ct., https://casetext.com/case/backus-v-baptist-medical-ctr

[10] Federation of State Medical Boards, “Physician Sexual Misconduct”

[11] National Council of State Boards of Nursing, “Practical Guidelines for Boards of Nursing on Sexual Misconduct Cases,”https://ncsbn.org/public-files/Sexual_Misconduct_Book_web.pdf

[12] Backus v. Baptist Medical Ct., https://casetext.com/case/backus-v-baptist-medical-ctr

[13] https://www.law.cornell.edu/uscode/text/10/920

[14] https://opsmanual.uiowa.edu/community-policies/sexual-harassment-and-sexual-misconduct/prohibited-conduct

[15] Department of Justice, https://uscode.house.gov/view.xhtml?req=(title:18%20section:2246%20edition:prelim)

[16] National Council of State Boards of Nursing, “Practical Guidelines for Boards of Nursing on Sexual Misconduct Cases,” https://ncsbn.org/public-files/Sexual_Misconduct_Book_web.pdf

[17] Federation of State Medical Board, “Physician Sexual Misconduct,” https://www.fsmb.org/siteassets/advocacy/policies/report-of-workgroup-on-sexual-misconduct-adopted-version.pdf

[18] Federation of State Medical Boards, “Physician Sexual Misconduct”; the NCSBN uses very similar language stating that sexual misconduct includes “contact which may reasonably be interpreted as demeaning, humiliating, embarrassing, threatening, or harming a patient.”

[19]  Introduction to the Americans with Disabilities Act, https://www.ada.gov/topics/intro-to-ada/

[20] Bruce L. “A Pot Ignored Boils On”

Read More
General Compliance

Fraudsters Prey on Factors Influencing Health Outcomes

This article addresses various forms of fraud and how criminals’ prey on compromised citizens.  Contributions to this article are made from the American Institute of Healthcare Compliance Volunteer Education Committee’s interview of a law enforcement official.   

There are many factors which can influence our health, and in turn, there are just as many schemes which are actually considered health care fraud.

Social determinants of health (SDoH) are the nonmedical factors that influence health outcomes.  They are the conditions in which people are born, grow, work, live, and age, and the wider set of forces and systems shaping the conditions of daily life. While healthcare providers focus on how to capture SDoH data on patients to improve health outcomes, a counter force may be working in the background which hurts struggling families as they fall victim of fraud schemes.

SNAP Fraud

Food assistance is generally referred to as SNAP or food stamps. States may have their own names.  For example, in California it is known by Cal Fresh.  SNAP stands for Supplemental Nutrition Assistance Program and is the nation’s most important anti-hunger program.  The USDA administers SNAP food assistance through state food stamp programs.  There are directives and policies at state, federal and county levels that encourage healthy eating and lifestyles.  This can help most people to live or become healthy and contribute to positive mental health outcomes.

This government program provides food to low-wage working families, low-income seniors, people with disabilities, and other individuals with low incomes based on a sliding scale.  In 2021, SNAP helped an average of more than 41 million low-income people in the United States afford a nutritionally adequate diet each month.

How this Assistance Works

The Government (taxpayer) loads a debit card and the welfare recipient withdraws the money.  It is intended to provide the basics of food, shelter and clothing.  Policymakers at every level offer incentive and issue public service announcements for shoppers to “shop smart.”

The incentives take many forms. The foods that can be incentivized are fruits, vegetables, dairy and whole grains.  This takes place at small to national retailers, farmers markets and online SNAP retailers.  “Double Up Food Bucks” allows the shopper to buy twice the number of fruits and vegetables with each SNAP dollar.  SNAP participants can even buy seeds and edible plants to grow their own food. This can be a rewarding and empowering experience.

Other incentives include an Amazon membership discount, city bike-share programs, museum and zoo access, discounted YMCA membership and discounted internet access with device options.  Retailers can participate with online purchasing and delivery.  There is a special program that allows elderly, homeless and disabled SNAP recipients to purchase food at SNAP authorized restaurants.  On their own, retailers can offer other discounts and coupons for future purchases.

The debit card system (EBT), that serves welfare receipts, does not have a chip.   All you need is the account and pin number.  Newer EBT account cards may have the CVV code but it’s not required to complete a transaction.  Both of these features can offer verification that the account owner is the person using the card.

EBT Fraud – “It’s a Thing” with Criminal Gangs

Organized Eastern European criminal gangs, largely of Romanian origin, are responsible for ballooning EBT losses.  For just the month of May, 2023, California is reporting 8 million dollars.  The groups are intricate, diversified and organized. Google “EBT account skimming, device, welfare.” It’s a thing.

Gangs Breach UIB Accounts Too

The same groups are or were breaching Unemployment Insurance Benefits (UIB) accounts.  The crooks change their methods and technology frequently.  Compared to what these gangs are doing right now, much of the information easily found on the internet is old.

Most of the hardware, components and software are inexpensive and easily available from Amazon and eBay.  Currently, there are two notable methods.

  • One, the thieves are removing and replacing the keypad on self-checkout areas and sometimes regular register lanes. This type of skimmer captures the account and pin number.  They Bluetooth the data off the device from the parking lot.
  • The second method, at outside bank ATM’s, the crooks insert a thin metal or carbon fiber device into the card slot which reads and records the account number.  They also place a small piece of trim containing a camera and SD card above the terminal to capture the PIN.
    • The skimmer captures the account number and the camera shows the customer entering the PIN.
    • The crook inserts a known card into the ATM slot to show a starting point so they can match up the accounts to the PIN’s. To use the data, they have to retrieve the skimmer and camera.
    • The crooks then take the info and write it onto the magnetic strip of any extra card laying around, old gift cards, hotel room cards, and mailed card offers, etc.  Then they visit an outside ATM with stacks of cards and drain the accounts.

No fresh fruit and vegetables for you, my friend

Food and shelter are growing concerns for even the middle class.  The poor are taking the biggest hit.  Only some of the stolen EBT funds are replaced making both the taxpayer and the welfare recipient victims.

How about the Welfare recipient?  At the county level, they are encouraged to change their PIN monthly which means calling into a phone tree or visiting the local welfare office. Recipients are encouraged to check their account regularly. Most recipients’ benefits are siphoned off by the crooks during the 1st three days of the month. Don’t worry, it's Federal (taxpayer) money.

To report the loss, recipients must fill out form EBT 2259 and face a bit of scrutiny by their case manager.  One would expect some recipients to take advantage of the situation and some do.  Such as, having a friend spend the money or spend it anonymously on the internet and then claim fraud.  Case managers have to make a decision.  If they can’t figure it out, they may defer to county special investigations units (SIU’s).

According to the USDA, replacement benefits cannot exceed the actual amount stolen or the household’s benefit allotment amount for the two months immediately preceding the theft, whichever is lesser.

The USDA goes on to stipulate this can only happen twice per year.

Oh, guess what? The crooks are known to replace skimmers at the same locations the 1st, 2nd and 3rd of the month, EVERY month!

Conclusion

Criminals seem to stay one step ahead, creating more poverty in a situation which is already in crisis.

Rumors abound at adding a chip to the cards in 2024.  While it’s hard to spin this in the news media, especially considering political ambitions, welfare recipients are at a loss at the dinner table.  Millions of those in need are experiencing the stress of making due or going without.

Learn more about SDoH, and how capture and report for reimbursement purposes. The American Institute of Healthcare Compliance (AIHC) is a non-profit health care training organization. Want to volunteer?  Join us – for volunteer opportunities and member discounts.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved


Read More
General Compliance

Medicare Bad Debt: Don’t Leave Money on the Table With Your Cost Report

Written by: Thomas "Trent" Jackson, BS, CCRS




Medicare bad debts present Medicare Part A providers an opportunity to recover reimbursement dollars they otherwise would have missed. Provided that a proper log is kept, total uncollected Medicare co-insurance and/or deductibles can be claimed on the cost report for 65% reimbursement.


Under 42 Code of Federal Regulation (CFR) §413.89 and the Provider Reimbursement Manual (PRM) 15-1 § 308, a bad debt is allowable when it results from deductible and coinsurance amounts for covered services that are uncollectible from Medicare beneficiaries. The Middle-Class Tax Relief and Job Creation Act of 2012 established the current reimbursement rate at 65%.


What is allowable bad debt?

An allowable Medicare bad debt must meet four criteria to be claimed by a facility:

  1. The debt must be related to covered services and derived from deductible and coinsurance amounts.
  2. The provider must be able to establish that reasonable collection efforts were made.
  3. The debt was actually uncollectible when claimed as worthless.
  4. Sound business judgment established that there was no likelihood of recovery at any time in the future.

Undertaking and documenting reasonable collection efforts will satisfy the second requirement, and the completion of those efforts will satisfy the fourth. Then, as long as the amount in question is a deductible or coinsurance amount that was appropriately written off during the period for which the cost report is filed, it is allowed to be claimed.


Reasonable collection efforts required

What constitutes a reasonable collection effort? First and foremost, collection efforts for Medicare beneficiaries must be similar to efforts to collect comparable amounts from non-Medicare patients. Beyond that, the collection policy must include the issuance of a bill on or shortly after discharge of the beneficiary as well as genuine collection efforts such as subsequent billings, collection letters, and phone calls. The regulations also allow for the use of a collection agency in addition to or in lieu of those efforts.


As with many areas of healthcare, the saying “if it was not documented, it did not happen” certainly applies. Any facility looking to claim Medicare bad debt reimbursement will need to maintain supporting documentation for each line on its Medicare bad debt log.


There are a couple of alternate methods to satisfy the second and fourth criteria:

  • If a patient is deemed indigent by provider standards, their debt can be deemed uncollectable without going through reasonable collection efforts. However, the provider must have a codified internal policy to analyze assets, liabilities, expenses, and income of the patient. It must also seek to determine that no other source than the patient would be legally responsible for their debt. Documentation supporting these factors must be contained within the patient’s file.
  • For patients who have Medicare as a primary payer and Medicaid as a secondary payer (commonly referred to as a “crossover”), billing the state Medicaid program for the unpaid amount and documenting its response will satisfy the reasonable collection effort procedures. The account can be added to the Medicare bad debt log upon receipt of the Medicaid program’s remittance advice.

Medicare bad debt is money lost for many Part A Providers, so taking time to explore the cost report reimbursement option could be a valuable decision.

_________________________________________________________

Thomas “Trent” Jackson is a senior associate within Kraft Healthcare Consulting’s Advisory Department. Kraft Healthcare Consulting is an affiliate of KraftCPAs. Trent is also a Certified Cost Reporting Specialist (CCRS) and received his BS in Accounting from Dalton State College. 
Read More
General Compliance

What Can Be Done to Address Elderly Addiction? 

Written by: Tasnova Malek, MD




This article outlines the serious problem of substance abuse and addiction among our elderly. It addresses many reasons an aging population may turn to alcohol and other substances to cope with the multitude of changes involved in getting older. With opioid pain management and the resulting opioid crisis, this subject is important to consider and we are reminded it is important to not only consider the physical health of our elderly population but also their mental health. This article was submitted courtesy of Dr. Malek for educational purpose only and should not be considered consulting or legal advice.



Aging leads to a multitude of changes each person must negotiate. It brings physiological, social, and psychological changes that can lead to the misuse of alcohol or other substances in an attempt to cope. The misuse can lead to delayed diagnosis— and help for the senior.


According to the Administration for Community Living, there were approximately 54 million people aged 65+ in 2019. Of seniors 60 years and older, about 17% live with some form of substance abuse, according to an article published by Michigan State University Extension. Although, alcohol misuse is the most common substance being abused by seniors. This is concerning to the medical community because studies designed to understand how alcohol and drugs impact an aging brain are few and far between.


What is known is that the aging brain is more sensitive to the introduction of chemicals as it struggles to break down and absorb alcohol or drugs. Alcohol metabolizes slower, which allows it to accumulate in the blood quicker, leading to intoxication without someone checking on the senior's consumption.


Memory issues (like forgetting to take or doubling up on medication) may lead to unintentional misuse, while other seniors use meds to cope with loss, declining health, grief, or changes to their living situations, among other issues. In addition, drug use/misuse may impair a senior’s coordination, reaction time, or judgment, aggravating an already risky situation. Some factors that put older adults at risk for substance abuse include:

  • A previous/current mental illness
  • Social isolation
  • Financial concerns due to income changes
  • Resistance to coping with a new living environment

How to Spot Addiction in the Elderly


Health issues are a natural part of the aging process. So, it can be challenging to know if memory issues, reduced focus and low energy are by-products of getting older or symptoms of an undiagnosed substance abuse issue. Consider these warning signs:

  • Sleeping or eating habits that change
  • Moodiness and irritability
  • Erratic behavior
  • Poor hygiene
  • Unexplained bruising

Types of Substance Abuse in the Elderly


Alcohol

Alcohol abuse is the most common type of substance abuse in those over 65 years old, with 10% of seniors reporting that they binge drink, which is defined as five or more drinks on the same occasion for men, and four or more drinks on the same occasion for women.


Prescription Medicine

Because chronic health issues tend to be part of the aging process, older adults are more often prescribed potentially addictive medicines compared to other age groups. And misuse of prescription meds may exacerbate existing mental health conditions.


Opioid Pain Medicines

Persistent pain is typically another challenging condition of growing old. In fact, opioid prescriptions for pain management in older adults increased ninefold from 1995 to 2010.


Illicit Drugs

These may include the use of cocaine, or heroin, among others.


What Can Be Done to Address Elderly Addiction?


Recent data highlights the essential need to screen middle-aged as well as older adults on a regular basis. But it must include health care providers' and administrators’ efforts to develop the tools needed to work with older adults facing a debilitating addiction.


Health care professionals often mistakenly confuse substance abuse symptoms with other conditions that happen as a part of the aging process. As such, research is required to create screening methods that help detect substance abuse in older adults, which often work best with the application of coexisting medical and psychiatric conditions.


The most effective treatment and support for older adults with substance addictive issues are to leverage and coordinate the varying types of services by medical personnel (primary care physicians and addiction specialists, etc.) and community advocacy groups that support the senior community.


How to Treat Substance Use in Older Adults


There are a variety of behavioral therapies and medications that have been successful in treating substance use disorders in older adults. As noted above, there is limited research regarding the most effective model of care, although data suggest that older patients tend to have better outcomes the longer they receive the required care.


The ideal model for addressing elderly addiction includes the following –

  • Regular diagnosis
  • The management of current chronic medical conditions
  • Re-building a network of support professionals
  • Improved medical service access
  • Enhanced case management capabilities
  • Evidence-based training strategies for professionals working with seniors

The Bottom Line


There are many therapies and medications that can be used to successfully treat substance use disorders, in which many seniors respond favorably. It is never too late to choose to quit abusing any kind of substance, which, in time, will improve the future of one’s health and quality of life.

 

Additional Resources:

_________________________________________________________

Tasnova Malek, MD, graduated from Bangladesh Medical College and practiced as a primary care physician for six years in Bangladesh. After moving to the USA, she worked at Emory University Hospital in Pulmonary and Critical Care Medicine and Hospital medicine research. During COVID-19, she worked as a crisis counselor on the Florida Corona Virus Emergency Response Team. Currently, she is working in the National Suicidal Prevention Center and works reviewing articles for Sunshine Behavioral Health. In addition, she has extensive research experience in medicine and psychiatry in the USA.
Read More
General Compliance

Uncompensated Care and DSH (Medicare disproportionate share hospitals)

Written by: Scott Mertie, CHFP, FHFMA, CMPE, CCRS, CHCO, CIFHA (KraftCPAs) and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCSAs (CEO of AIHC)


This article is written for education purposes and should not be considered accounting, consulting or legal advice regarding hospital charity care bad debt and disproportionate share hospitals aka DSH. For more information on filing compliance cost reports, attend the Medicare Cost Report Camp in March 2022 presented by KraftCPAs and sponsored by the American Institute of Healthcare Compliance.


Medicare Uncompensated Care Payments & DSH


Hospitals' charity care and bad debt, together known as uncompensated care, is used to calculate disproportionate-share hospital payments. The Centers for Medicare and Medicaid Services (CMS) distributes a prospectively determined amount of uncompensated care payments to “Medicare disproportionate share hospitals” or better known as “DSH.” This is calculated based on the hospital’s relative share of uncompensated care nationally.

 

As required under law, this amount is equal to an estimate of 75 percent of what otherwise would have been paid as Medicare disproportionate share hospital payments, adjusted for the change in the rate of uninsured people. In this rule, CMS will distribute roughly $8.3 billion in uncompensated care payments for FY 2021, a decrease of approximately $60 million from FY 2020. This estimate of total uncompensated care payments reflects CMS Office of the Actuary’s projections that incorporate the estimated impact of the COVID-19 pandemic.


For FY 2021, CMS will use a single year of data on uncompensated care costs from Worksheet S-10 of hospitals’ FY 2017 cost reports to distribute these funds, in part because CMS has conducted audits of this data. Mindful of the unique challenges facing Indian Health Service and Tribal hospitals and Puerto Rico hospitals, CMS will continue to use data regarding low-income insured days (Medicaid days for FY 2013 and FY 2018 SSI days) to determine the amount of uncompensated care payments for Puerto Rico hospitals and Indian Health Service and Tribal hospitals for FY 2021, similar to the FY 2020 methodology.


Background on the IPPS and LTCH PPS


CMS pays acute care hospitals (with a few exceptions specified in the law) for inpatient stays under the Inpatient Prospective Payment System (IPPS). LTCHs are paid under the Long-Term Care Hospital Prospective Payment System (LTCH PPS). Under these two payment systems, CMS sets base payment rates prospectively for inpatient stays based on the patient’s diagnosis and severity of illness. Subject to certain adjustments, a hospital receives a single payment for the case based on the payment classification assigned at discharge. The classification systems are:

  • IPPS: Medicare Severity Diagnosis-Related Groups (MS-DRGs)
  • LTCH PPS: Medicare Severity Long-Term Care Diagnosis-Related Groups (MS‑LTC‑DRGs).

The law requires CMS to update payment rates for IPPS hospitals annually, and to account for changes in the prices of goods and services used by these hospitals in treating Medicare patients, as well as for other factors. This is known as the hospital “market basket.” The IPPS pays hospitals for services provided to Medicare beneficiaries using a national base payment rate, adjusted for a number of factors that affect hospitals’ costs, including the patient’s condition and the cost of hospital labor in the hospital’s geographic area. Payment rates to LTCHs are typically updated annually according to a separate market basket based on LTCH-specific goods and services.


In 2020, CMS issued a final rule for acute care and long-term care hospitals that ensures access to potentially life-saving diagnostics and therapies by unleashing innovation in medical technology and removing barriers to competition.


On August 2, 2021, the CMS issued the final rule for fiscal year (FY) 2022 Medicare Hospital Inpatient Prospective Payment System (IPPS) and Long-Term Care Hospital (LTCH) Prospective Payment System (PPS). The FY 2022 IPPS and LTCH PPS final rule will be issued in multiple parts. 


The final rule updates Medicare payment policies and rates for operating and capital-related costs of acute care hospitals and for certain hospitals and hospital units excluded from the IPPS for FY 2022. The policies in this IPPS and LTCH PPS final rule build on key priorities to close health care equity gaps and support greater access to life-saving diagnostics and therapies during the COVID-19 public health emergency (PHE) and beyond.


The rule’s provisions seek to:


Sustain hospital readiness to respond to future public health threats;

Enhance the health care workforce in rural and underserved communities; and

Revise scoring, payment and public quality data reporting methods to lessen the adverse impacts of the pandemic and future unplanned events. 


The final rule updates Medicare fee-for-service payment rates and policies for inpatient hospitals and long-term care hospitals for FY 2022. In this final rule, CMS approved 13 technologies that applied for new technology add-on payments for FY 2021. This includes two technologies under the alternative pathway for new medical devices that are part of the FDA Breakthrough Devices Program and five technologies approved under the alternative pathway for products that received FDA Qualified Infectious Disease Product (QIDP) designation. 


Additionally, CMS conditionally approved one technology designated as a QIDP that otherwise meets the alternative pathway criteria but has not yet received FDA approval. After consideration of public comments, CMS also approved six technologies submitted under the traditional new technology add-on payment pathway criteria.


CMS is continuing the new technology add-on payments for 10 of the 18 technologies currently receiving the add-on payment (the remaining 8 technologies will no longer be within their newness period in FY 2021, which includes the Chimeric Antigen Receptor (CAR) T-cell therapies approved for the new technology add-on payment in FY 2019).


In total, 24 technologies are eligible to receive add-on payments for FY 2021. CMS estimates that FY 2021 Medicare spending on new technology add-on payments will be approximately $874 million, nearly a 120% increase over the FY 2020 spending.


CMS is adopting some changes regarding new technology add-on payments for certain antimicrobials for FY 2021:

  • Expansion of alternative new technology add-on payment pathway for antimicrobial products designated by FDA as QIDPs to include products approved under FDA’s Limited Population Pathway for Antibacterial and Antifungal Drugs (LPAD pathway).

o The LPAD pathway encourages the development of safe and effective drug products that address unmet needs of patients with serious bacterial and fungal infections. As is the case for QIDPs, under this policy an antimicrobial drug approved under FDA’s LPAD pathway will be considered new and not substantially similar to an existing technology and will not need to demonstrate that it meets the substantial clinical improvement criterion (the technology will need to meet the cost criterion).

  • CMS is adopting a policy to provide for conditional approval for antimicrobial products that otherwise meet the NTAP alternative pathway criteria but do not receive FDA approval in time for consideration in the final rule. This is to allow eligible antimicrobial products to begin receiving the new technology add-on payment sooner.

o Under this policy, those antimicrobial products that otherwise meet the applicable addon payment criteria will begin receiving the new technology add-on payment, effective for discharges the quarter after the date of FDA marketing authorization instead of waiting until the next fiscal year, provided FDA marketing authorization is received by July 1 of the year for which the applicant applied for new technology add-on payments


Conclusion


CMS estimates total Medicare spending on acute care inpatient hospital services will increase by about $3.5 billion in FY 2021, or 2.7 percent. The Office of Inspector General (OIG) has added reviews of MAC cost report oversight for 2022. This project is described in the OIG January 2022 Work Plan Item. Filing accurate and compliant cost reports should be part of your institution’s risk mitigation program. 


Additional Resources

Read More
General Compliance

Consent and COVID Testing of Employees

Written By: Compliance Blogger




This article addresses COVID testing and consent considerations for:  healthcare organizations, nursing homes and business associates or non-healthcare workplaces. This article is not intended as legal or consulting advice.  Employers are encouraged to collaborate with state, territorial, tribal and local health officials to determine whether and how to implement COVID testing strategies.


SARS-CoV-2 (COVID-19) continues to be a health risk to be mitigated by health care institutions and at the workplace. Employers paying for testing of employees should put procedures in place for rapid notification of results and establish appropriate measures based on testing results, including instructions regarding self-isolation and restrictions on workplace access.


An employer’s testing program (including the implementation of a testing protocol to test employees) may be complex and technical. Certain aspects of the testing program may be more relevant than others to an employee’s decision whether to accept an offered test. Obtain guidance from experts to assist your organization in navigating risk.


Business Associates (non-healthcare organizations)


The Center for Disease Control (CDC) provides guidance for non-healthcare workplaces, which would apply to most business associates who have partnered with a health care institution, such as legal or accounting firms; medical billing companies; IT managed service providers, etc. Workplace-based testing should not be conducted without the employee’s informed consent. Encourage and answer questions during the consent process.


Informed Consent


Informed consent requires disclosure, understanding, and free choice, and is necessary for an employee to act independently and make choices according to their values, goals, and preferences. Consult legal counsel when developing your informed consent form for employees.


To fully support employee decision-making and consent, employers should take the following measures when developing a testing program:

  • Ensure safeguards are in place to protect an employee’s privacy and confidentiality.
  • Provide complete and understandable information about how the employer’s testing program may impact employees’ lives, such as if a positive test result or declination to participate in testing may mean exclusion from work.
  • Explain any parts of the testing program an employee would consider especially important when deciding whether to participate. This involves explaining the key reasons that may guide their decision.
  • Provide information about the testing program in the employee’s preferred language using non-technical terms. Consider obtaining employee input on the readability of the information. Employers can use the CDC tool to create clear messages: https://www.cdc.gov/ccindex/
  • Encourage supervisors and co-workers to avoid pressuring employees to participate in testing.
  • The consent process is active information sharing between an employer or their representative and an employee, in which the employer discloses the information, answers questions to facilitate understanding, and promotes the employee’s free choice.

Disclosures for Non-healthcare Workplace Testing


Individuals tested are required to receive patient fact sheets as part of the test’s emergency use authorization (EUA):

A basic disclosure for COVID-19 should include the following elements to provide information to employees so they understand what is involved when consenting to the test, such as clear information on the manufacturer and name of the test, the type of test, the purpose of the test, the performance specifications of the test, any limitations associated with the test, who will pay for the test, how the test will be performed, how and when they will receive test results, and; how to understand what the results mean, actions associated with negative or positive results, the difference between testing for workplace screening versus for medical diagnosis, who will receive the results, how the results may be used, and any consequences for declining to be tested.


According to the Americans with Disabilities Act (ADA), when employers implement any mandatory testing of employees, it must be “job related and consistent with business necessity.” In the context of the COVID-19 pandemic, the U.S. EEOC notes that testing to determine if an employee has SARS-CoV-2 infection with an “accurate and reliable test” is permissible as a condition to enter the workplace because an employee with the virus will “pose a direct threat to the health of others.” EEOC notes that tests administered by employers which are consistent with current CDC guidance will meet the ADA’s business necessity standard. However, workplace-based testing should not be conducted without the employee’s consent.


Infection Control for Healthcare Facilities


The CDC has made recent changes to infection control guidance for all U.S. settings where healthcare is delivered, including home health. The updated healthcare infection prevention and control (IPC) recommendations as of September 10, 2021 are in response to the COVID-19 vaccination. Consult with legal counsel regarding disclosures and consents appropriate for your organization.


Healthcare Personnel (HCP): HCP refers to all paid and unpaid persons serving in healthcare settings who have the potential for direct or indirect exposure to patients or infectious materials, including body substances (e.g., blood, tissue, and specific body fluids); contaminated medical supplies, devices, and equipment; contaminated environmental surfaces; or contaminated air. HCP include, but are not limited to, emergency medical service personnel, nurses, nursing assistants, home healthcare personnel, physicians, technicians, therapists, phlebotomists, pharmacists, dental healthcare personnel, students and trainees, contractual staff not employed by the healthcare facility, and persons not directly involved in patient care, but who could be exposed to infectious agents that can be transmitted in the healthcare setting (e.g., clerical, dietary, environmental services, laundry, security, engineering and facilities management, administrative, billing, and volunteer personnel).


Healthcare settings refers to places where healthcare is delivered and includes, but is not limited to, acute care facilities, long-term acute-care facilities, inpatient rehabilitation facilities, nursing homes, home healthcare, vehicles where healthcare is delivered (e.g., mobile clinics), and outpatient facilities, such as dialysis centers, physician offices, dental offices, and others.


Source control is the use of respirators, well-fitting facemasks, or well-fitting cloth masks to cover a person’s mouth and nose to prevent spread of respiratory secretions when they are breathing, talking, sneezing, or coughing. Source control devices should not be placed on children under age 2, anyone who cannot wear one safely, such as someone who has a disability or an underlying medical condition that precludes wearing one safely, or anyone who is unconscious, incapacitated, or otherwise unable to remove their source control device without assistance. Face shields alone are not recommended for source control.


IPC Measures


Several of the IPC measures (e.g., use of source control, screening testing) are influenced by levels of SARS-CoV-2 transmission in the community. There are two different indicators in CDC’s COVID-19 Data Tracker which are used to determine the level of SARS-CoV-2 transmission for the county where the healthcare facility is located – Access the COVID Data Tracker:

If the two indicators suggest different transmission levels, the higher level is selected.


Source control and physical distancing (when physical distancing is feasible and will not interfere with provision of care) are recommended for everyone in a healthcare setting. This is particularly important for individuals, regardless of their vaccination status, who live or work in counties with substantial to high community transmission or who have:

  • Not been fully vaccinated; or
  • Suspected or confirmed SARS-CoV-2 infection or other respiratory infection (e.g., those with runny nose, cough, sneeze); or
  • Had close contact (patients and visitors) or a higher-risk exposure (HCP) with someone with SARS-CoV-2 infection for 14 days after their exposure, including those residing or working in areas of a healthcare facility experiencing SARS-CoV-2 transmission (i.e., outbreak); or
  • Moderate to severe immunocompromised; or
  • Otherwise had source control and physical distancing recommended by public health authorities.

Perform SARS-CoV-2 Testing


Anyone with even mild symptoms of COVID-19, regardless of vaccination status, should receive a viral test as soon as possible, according to the CDC recommendation.


Asymptomatic HCP with a higher-risk exposure and patients with close contact with someone with SARS-CoV-2 infection, regardless of vaccination status, should have a series of two viral tests for SARS-CoV-2 infection.

  • In these situations, testing is recommended immediately (but not earlier than 2 days after the exposure) and, if negative, again 5–7 days after the exposure.
  • Note - testing is not recommended for people who have had SARS-CoV-2 infection in the last 90 days if they remain asymptomatic; this is because some people may have detectable virus from their prior infection during this period (additional information is available here). Criteria for use of post-exposure prophylaxis are described elsewhere.

Expanded screening testing of asymptomatic HCP without known exposures was required in nursing homes and could be considered in other settings. It should be conducted as follows:

  • Fully vaccinated HCP may be exempt from expanded screening testing.
  • Guidance for expanded screening testing for nursing homes was described in the Interim Infection Prevention and Control Recommendations to Prevent SARS-CoV-2 Spread in Nursing Homes | CDC but is no longer available.

Performance of pre-procedure or pre-admission viral testing is at the discretion of the facility. The yield of this testing for identifying asymptomatic infection is likely low when performed on vaccinated individuals or those in counties with low or moderate transmission. However, these results might continue to be useful in some situations (e.g., when performing higher risk procedures on unvaccinated people) to inform the type of infection control precautions used (e.g., room assignment/cohorting, or PPE used).


Click Here for more detailed information about infection control guidance.

Read More
General Compliance

Primary Care and SBIRT?

Screening, Brief Intervention, & Referral to Treatment (SBIRT) Services


Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS





Detecting and implementing early intervention for your patients with non-dependent substance use is a critical part of primary care for many clinicians.  Using SBIRT can help you and your patients while getting reimbursed for these important services.


SBIRT is early intervention for individuals with non-dependent substance use to help before the individual requires more extensive or specialized treatment. This approach differs from specialized treatment for those with more severe substance misuse or a Substance Use Disorder (SUD). 


Early intervention is important and when medical records support reimbursement, you can bill for these services.

  • Medicare pays for medically reasonable and necessary SBIRT services in physicians’ offices and outpatient hospital settings.
  • Since January 1, 2020, CMS pays certified OTPs through bundled payments for OUD treatment services under Medicare Part B.
  • The patient’s medical records must support all Medicare claims.
  • States may cover SBIRT as a Medicaid state plan service.

Using SBIRT services can be manageable in primary care settings. You can systematically screen people who may not seek substance use help and offer access to SBIRT treatment services that:

  • Reduce health care costs;
  • Decrease drug and alcohol use severity;
  • Reduce risk of physical trauma; and
  • Reduce the percent of patients who go without specialized treatment.

SBIRT has 3 major components:

  • Screening;
  • Brief Intervention; and
  • Referral to Treatment.

1)  Screening

Screening is a quick, simple method of identifying patients who use substances at at-risk or hazardous levels and who may already have substance use-related disorders. The screening instrument provides specific information and feedback to the patient related to his or her substance use.


The typical screening process involves the use of a brief 1-3 question screen such as the National Institute on Alcohol Abuse and Alcoholism’s single question screen (see below under “Resources”). If a person screens positive, then a longer alcohol or drug use evaluation should be given using a standardized risk assessment tool such as AUDIT or ASSIST (references are under Resources below).


The screening and risk assessment instruments are easily administered and provide patient-reported information about substance use that any healthcare professional can easily score.


2)  Brief Intervention

Brief interventions are typically provided to patients with less severe alcohol or substance use problems who do not need a referral to additional treatment and services. In addition to behavioral health professionals, medical personnel (e.g., doctors, nurses, physician assistants, nurse practitioners) can conduct these interventions and need only minimal training. However, in cases of addiction, more intensive interventions may be needed.

  • How? Brief Intervention is a time-limited, patient-centered strategy that focuses on changing a patient’s behavior by increasing insight and awareness regarding substance use.
  • Depending on severity of use and risk for adverse consequences, a 5–10-minute discussion or a longer 20–30-minute discussion provides the patient with personalized feedback showing concern over drug and/or alcohol use.
  • The topics discussed can include how substances can interact with medications, cause or exacerbate health problems, and/or interfere with personal responsibilities.

3)  Referral to Treatment

In some cases, a more advanced treatment option is necessary and the patient is referred to a higher level of care. This care is often provided at specialized addiction treatment programs. The referral to treatment process consists of:

  • Helping patients access specialized treatment;
  • Selecting treatment facilities; and
  • Facilitating the navigation of any barriers such as cost of treatment or lack of transportation that would hinder them from receiving treatment in a specialty setting.

In order for this process to occur smoothly, primary care providers must initially establish and cultivate relationships with specialty providers, and then share pertinent patient information with the referral provider. Handling the referral process properly and ensuring that the patient receives the necessary care coordination and follow-up support services is critical to the treatment process and to facilitating and maintaining recovery.


Documenting SBIRT Services

Medicare provides documentation guidelines for the patient’s medical record.  The medical record for covered SBIRT services must:

  • Be complete and legible
  • Record start and stop times or total face-to-face time with the patient (because some SBIRT HCPCS codes are time-based)
  • Record the patient’s progress, response to changes in treatment, and diagnosis revision
  • Document the rationale for ordering diagnostic and other ancillary services or ensure it’s easily inferred

For each patient encounter, document:

  • Reason for encounter and relevant history
  • Appropriate health risk factors
  • Physical examination findings and prior diagnostic test results
  • Plan of care
  • Assessment, clinical impression, and diagnosis
  • Past and present diagnoses accessible for treating and consulting physicians
  • Date and legible provider identity
  • Signature on all services provided or ordered

Resources


CMS SBIRT Booklet 2021 (HCPCS codes, Telehealth & SBIRT and Bundled Payment Information)

Psychiatric Compliance - Short Online Course in Documentation & Coding

Screening: AUDIT Questionnaire

Read More