Compliance in Healthcare
Corporate Compliance

The Cobra Effect & Enforcing Compliance Standards

Lessons Learned about Consequences & Incentives

Submitted by the AIHC Education Department    


Introduction   

The Office of Inspector General has released the new General Compliance Program Guidance or “GCPG” in late 2023.  The GCPG is a reference guide for the health care compliance community and other health care stakeholders and provides information about relevant Federal laws, compliance program infrastructure, OIG resources, and other information useful to understanding health care compliance.

The GCPG standardized the seven Elements of a Successful Compliance Program, which differs slightly from the individual compliance guidance documents (CPGs) directed at various segments of the health care industry, such as hospitals, nursing homes, third-party billers, and durable medical equipment suppliers. 

As health care organizations review and update current compliance programs to adapt from the CPG to the newer GCPG, remember to archive previous compliance documents according to effective dates.  If your organization should come under scrutiny, you’ll need to produce how your program was implemented and how if functioned during the time of the potential violation.

One of the seven items, #5 is “Enforcing Standards: Consequences and Incentives.”

Within item #5 are directives from the OIG related to incentives.  The OIG states the following:

“Entities also should develop appropriate incentives to encourage participation in the entity’s compliance program.”

“The compliance officer, Compliance Committee, and other entity leaders should thoughtfully consider the compliance performance or activities they would like to incentivize, both across the entity and within specific departments or positions. Excellent compliance performance or significant contributions to the compliance program could be the basis for additional compensation, significant recognition, or other, smaller forms of encouragement.”

The American Institute of Healthcare Compliance (AIHCTM) has released a 2024 Corporate Compliance Officer training program which is not only based on the new GCPC, but goes beyond to address quality, safety, HIPAA and other high-risk areas.  One of the required reading assignments of this course is provided below to caution health care leaders when implementing incentives.

The Cobra Effect - A Study in Laws of Unintended Consequences

Written by Carl Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCT-CM/PCS, OHCC

A long-term AIHC credentialed member and subject matter expert

EVERY decision or action we make carries unintended consequences.   The “Cobra Effect” is a term coined for a solution that makes a current problem worse based on incentives, rewards and/or punishments exposing chinks in the planning. Perverse Incentives are nearly natural by-products, motivating unscrupulous individuals to game the system to make easy money or cut corners in regulations.

The “Cobra” - In the late 1800s-early 1900s when India was ruled by the British government, there was a problem with venomous cobras invading major cities. The British government decided to take action and offered citizens a bounty to redeem for dead cobras. While this was an effective short-term solution it eventually failed.

Indian citizens started breeding cobras for the cash reward. Cobra breeders killed the majority of the cobras and redeemed them for money while they continued to breed more cobras. The government eventually found out and stopped the financial incentives. The result? The cobra breeders released the snakes onto the streets since the snakes were no longer money makers - which made the cobra problem much worse.  A variant of The Cobra Effect is known commonly as The Hanoi Rat Bounty.

When Hanoi, the capital of Vietnam, was under French colonial rule they discovered their villages had a major rat problem. So, the regime created a bounty program, similar to that of the British cobra bounty, that paid a reward for each rat killed. To get paid, people would provide a severed rat tail and get a little cash. Colonial officials, however, began noticing rats in Hanoi with no tails. The Vietnamese would capture rats, sever the tails, and then release them so they could reproduce more rats, thereby increasing the rat catchers' revenue.

The Cobra Effect is Alive and Well in Health Care

As you can imagine, the cobra effect is alive and well in health care. Whether leaders and policymakers are well intentioned or not health care is so complex, expensive and fraught with policies, laws, rules and regulations they make health care a very difficult maze to navigate. So much complexity in any arena will invite unforeseen consequences. Even well-meaning changes and upgrades to policies can make a previously compliant industry noncompliant.

Has the U.S. Learned from an Iconic Canadian History Lesson?

One of the earliest healthcare cases I know of occurred in Canada. The timeframe varies depending on the author; but it is generally agreed this took place from 1940 through at least 1960. It goes by the unassuming title of “The Duplessis Orphans”. According this article on the Canada’s Human Rights History page, this began in the mid 1940’s and continued into the 1960s when the Quebec government received subsidies from the Canadian federal government for building hospitals, but hardly anything to build orphanages.

  • According to historians, government contributions worked out to be $1.25 a day for orphans, but $2.75 a day for psychiatric patients. So, to get more money from the government, the Catholic Church of Quebec frequently misdiagnosed orphaned children as mentally ill, affecting up to 20,000 people.  This led to 80% of the misdiagnosed children reporting that they underwent a traumatic experience between the ages of 7 and 18, and over 50% said they underwent physical, mental, or sexual abuse.

More Recent History Lessons

An example likely familiar to many was in Forbes’ Aug 26, 2020, in an article entitled Beware Of The "Cobra Effect" In Business. The article states “An example of this was Wells Fargo in 2016. Wells Fargo wanted customers to use more of its products. It added incentives for its employees to sell more products and open more accounts to meet quotas. While the incentives did drive more sales and create more accounts, many of these new opportunities were not authorized by the customers. Instead of enhancing relationships with customers, the decision to offer these incentives influenced employees to act unethically, and it led to customers losing trust in Wells Fargo, as well as to the company simply losing customers.”

A Health Care History Example - Although slightly dated, being before the turbulence of the pandemic, an article appeared in the May 2018 Annals of the American Thoracic Society entitled Unintended Consequences of Quality-of-Care Measures demonstrates how the Cobra Effect is activated by certain moves made by the Centers for Medicare & Medicaid Services (CMS), the single largest payer for health care in the United States.

To begin, the authors use Medicare patients who are diagnosed with aspiration pneumonia:

  • “This study, one of the largest undertaken of aspiration pneumonia, confirms that patients with aspiration pneumonia are older, have more comorbidities, and are more likely to die than with other forms of pneumonia. Aside from its importance as an epidemiologic reference for aspiration pneumonia, this study found an association of hospital coding with quality metrics. Hospitals with the highest rates of coding aspiration pneumonia were much more likely to have low pneumonia mortality rates. Because aspiration pneumonia is excluded from Centers for Medical & Medicaid Services (CMS) pneumonia mortality scores, the implicit conclusion is that a hospital can improve its public rating by coding its oldest and sickest patients with pneumonia as having aspiration pneumonia. The reclassification of pneumonia into another diagnosis has been studied previously.”
  • “When CMS scores are used to reward or punish hospitals, it takes little imagination to realize that a hospital could decide to improve its score by legitimately coding its sickest patients with pneumonia as having aspiration pneumonia. The authors found in this study that hospitals could improve their CMS scores by legitimately recoding patients with pneumonia into sepsis or respiratory failure. The study suggests that recoding patients does improve the scores.”
  • The authors further state “More recently, we have witnessed Campbell’s law in medicine, where a Veterans Affairs hospital in Roseburg, Oregon, reportedly denied care to its sickest patients to improve its quality-of-care ratings. Doctors there were instructed to reclassify congestive heart failure as hypervolemia (an untracked diagnosis), and were instructed to admit veterans only as hospice patients, whose deaths would not be counted against the hospital. These interventions occurred as part of the unintended consequence of measuring and rewarding quality-of-care metrics.”
  • “Hospitals and physicians want to improve the quality of their care. However, it is difficult to quantify care accurately. A high-volume referral hospital or a safety net hospital may have sicker patients and greater mortality in spite of providing better care. We attempt to adjust for this by characterizing and adjusting for these factors, albeit imperfectly. We report the measures of quality to an unsophisticated public, who may make financial decisions on the basis of these data. We penalize based on these imperfect scores, naturally leading to behaviors that optimize the score. Although it seems easy to look down on the hospital administrator or teachers who gamed the system, we should explore what characteristics of the system promote such behavior.”

The Cobra Effect and COVID

In light of the Public Health Emergency (PHE) ending in May, 2023, we find the Cobra effect very active during the PHE. In October 2020, Brigham Young University (BYU) issued the following warning: “Students who…have intentionally exposed themselves or others to [Covid-19] will be immediately suspended from the university and may be permanently dismissed." BYU apparently received credible information that some students were trying to become infected in order to score a bigger paycheck when donating plasma.

Healthy individuals are paid $50 per visit by a plasma donation center near the BYU campus. However, the same donation center offers $100 per visit for those with Covid-19 “convalescent plasma.” Like entrepreneurs seeking to capitalize on a niche market, some students may have seen Covid-19 as an opportunity to apply what they learned in Economics 101 about supply and demand.

After the pandemic had traveled its confusing and massively complex path for some time, studies started coming out showing how and in so many areas from politics to healthcare, the Cobra Effect savagely “bit” around the world. One of the biggest culprits? Some say the COVID-19 lockdowns.

Numerous articles have been published and, to summarize, the findings were that too many political leaders used the lockdowns as a knee jerk reaction to a rapidly spreading and unknown problem. They had never had to deal with anything like COVID before so perhaps the lockdowns were all they could think of. The Cobra Effect struck most places based on one policy: immediate lockdowns. And if anything (even if misreported) came to their attention about the disease gaining speed/victims, the politicians ordered more lockdowns.

Although it is not a formal study, an advisory was published by the State of Ohio on May 5, 2020. In the period of the pandemic to date, the State of Ohio went from a Fiscal Year (FY) state revenue surplus of over $200 million to a deficit of $776.9 million. The Governor had to balance the budget for the next FY (Ohio’s fiscal year ends June 30). Because of the abyss caused by the deficit, the Governor instituted the following reductions:

  • March 23rd directive to freeze hiring, new contracts, pay increases, and promotions at all state agencies, boards, and commissions.
  • Medicaid: Reduction of $210 million
  • K12 Foundation Payment Reduction: $300 million
  • Other Education Budget Line Items Reduced by $55 million
  • Higher Education cut of $110 million
  • All Other Agency budges reduced by $100 million

As an Ohio resident, I can attest the lockdowns were virtually immediate. Even when minimal return-to-work allowances appeared, the slow reopening policy backfired too. There were strict rules governing citizens outside their homes, such as the policy which continued the forced closure of day care centers and schools to remain closed even after parents were allowed to return to work.

Globally and with vastly differing economies and medical systems, the “cobra” struck without mercy, and for the same reason: hip-shoot decisions to lock the populations down far too rapidly. Not only did the lockdowns massively shift and reshape economies and people: the Disaster Risk Reduction study found another enormous problem was the resulting panic buying. People had precious little time but the politicians threatened all manner of punishment against “disobedient” citizens in most states.

Last, but by far not least, politicians in every sector of the globe were forced to contend with a global Cobra Effect result they are wrestling with to this day: civil disobedience.  From defiance to open riots, citizens around the world started pushing back against what are increasingly being viewed as tyrannical moves by political institutions.

So, did the lockdowns actually make COVID cases worse? Maybe, maybe not. Did this affect healthcare? This remains to be seen, because as far as I can find the same entities who disregarded the civilian warning signs then are as willfully defiant now. I believe healthcare, as a profession, is safe.  The media drew light on the suffering of health care workers during the height of the pandemic and because people still trust their doctors and health care professionals. 

The Perverse Incentive or Cobra Effect?

Although the Cobra Effect and Perverse Incentives terms are loosely used together; they actually are different.  A perverse incentive is an incentive that has an unintended and undesirable result that is contrary to the intentions of its designers. The cobra effect is the most direct kind of perverse incentive, typically because the incentive unintentionally rewards people for making the issue worse. Now, let’s take a closer look perverse incentives.

The Oxford Dictionary defines “perversely” as “in a way that shows a deliberate and obstinate desire to behave in an unreasonable or unacceptable manner; “in a manner contrary to what is expected or accepted.”

Perverse incentives arise from real or imagined problems or constraints from honest workers and intimate knowledge of gaming the system for the unscrupulous ones. When any organization’s people do not understand the environment, capabilities, technology and impact of external forces, they can and do make plans which are incomplete. If they do not involve the people who are the experts in the areas of concern the plan may already be doomed or “dead”.

Health Care Examples of Perverse Incentives

  • Physician compensation arrangements incentivizing doctors to order diagnostic tests (result is increased revenue to the organization, increased provider wages but contributes to over utilization and health plans rate hikes).  Also, because physicians are paid for doing things, they are being incentivized to provide services patients might not need.
  • The hospital offers a monetary bonus to workforce members with perfect attendance, resulting in a dramatic reduction of absenteeism.  This is what the company intended, so the incentive worked.  Now, did the hospital set-aside the necessary bonus funds in the budget?

Cobra Effect with a decision tree extension - a self-initiated Perverse Incentive

This is a scenario most of us have experienced or at least can relate.

  • You’re late leaving home for work.  At the end of the street, you can take a right or left to get to work. You decide to take a right (which is a little faster than taking a left) and drive about 50 feet and pow – an accident happens just in front of you!  Lucky you were not on time (it could have been you) – but now you look in the rearview mirror and see that if you had turned left instead, green lights as far as you can see with virtually no traffic.
  • Walking into work, the boss catches you and states your presentation has been moved up to later this morning and must be done ASAP.
  • Irritated, you finish the presentation and, in your hurry, decide to take your anger out on the project, making it sound unnecessarily aggressive.
  • You present later that morning and at least some of the wording irritates the audience. So instead of showing your superiors you have a comprehensive plan with considered solutions, you have now just decreased their confidence in you, and they tell you so.
  • Now you are into damage control and rebuilding your image.

Decisions we make are based on any number of variables (depending on circumstances, knowledge and capabilities): but in the scenario above, we only have ourselves to blame.  The presentation affected more people negatively than just you or your time. Was it you? Was it chance/fate? Where was the perverse part inserted?

Even without more detail we can say it at least began with being late for work (lack of morning time management) and the problem became compounded when the decision was made to take that right at the intersection. Then more poor decisions were made due to controlling your frustration and changing the approach on your presentation, resulting in more trouble.

Stuff happens – but what mitigating factors, if employed, could have produced a better outcome?  Was this an automatic Cobra Effect scenario? Perhaps not. This gets into another gray area, mitigation.

We are already late for work and know it: you still take the right, because it has proven to be faster in the past. The accident still happens. Now what?

  • Call Your Boss - tell s/he you are at the scene of an accident.
  • Get ahead of any impending situation by asking if there is anything pressing.
    • Then you are informed that your presentation is moved up to that morning.
    • Ask if there have been any changes, updates or news you need to be aware of.
  • Use your cell to Email or call others in your immediate circle so they know you are stuck on the road.
  • As soon as you arrive, seek out your boss and let s/he know you arrived.

Now for that presentation. Only the boss knew the presentation was moved.  Pause, collect your thoughts and knowing most of the presentation was done already, modify your approach to meet the tight deadline and present it with passion.  The day may not have gotten easier but it certainly got BETTER: and in the midst of it all, was a successful day.  Your boss will notice your resilience.

This scenario is so minimal it could pass as just another day in the life of: but it shows the results of small decisions and how one failure can snowball into several or many depending on the methodology used to solve it.

Do any of these effects absolutely require a bad actor? No. With getting to work, the problem was we were late: the solution not only made us later; it had a downstream effect of making a poor presentation choice that to this point we were pretty well prepared for.  There may be any number of variables that must be considered and discussed but there are even “sub-variables” which can still take the human element out and produce greater negative outcomes even when the designers of the plan or incentive have only best interests at heart.

Where Do we Go from Here?

Avoid the Fire! Ready, Aim syndrome

If dedicated workers possessing expertise in his/her field are left out of the drafting phase but are given a plan with orders to just “make it happen”, the executors of the plan may, even though they have the best interests of the organization at heart, feel forced to cut corners or disregard some issues in order to be compliant with the plan or policy forced on them. I call this the Fire! Ready, Aim syndrome.

The workers are forced onto a known undesirable track but their superiors will not hear counter arguments. These workers rather than implement the plan fully (compliant), implement the plan arbitrarily (perversely). This plan, whatever it was set up the perverse incentives by not looking at critical elements to ensure compliance. The workers were forced to perversely execute the plan.

The unethical workers are far worse and often cause far more disruption and trouble that are longer lasting and openly invite criminal investigations and prosecutions rather than corrective actions. Although in this scenario the perverse incentive is prewritten in the plan (due to the organizers’ omissions) the perverse incentive is immediately pursued. A workable, compliant result is not even considered.

Reversing or Mitigating the Cobra Effect

Because medical organizations vary so much by size, specialty, state they’re located, and a seeming maze of internal and external policies and personnel we will only cover general but effective ideas. First, in the assumption right now, the Cobra Effect has happened.

First, we need to look at exactly what happened.  I am a Certified Internal Healthcare Fraud Auditor (CIFHA).  If you have such training or experience, I recommend taking an investigative approach.  For the sake of brevity, here are a few questions which can help you start your investigation, such as:

  • Were laws broken?
    • If so, what are the corrective measures (self-reporting) and potential consequences?
  • Was the effect found by an external reviewer or auditor or through an internal whistleblower?
  • Who exactly was responsible for launching the perverse incentive that went so wrong?
  • Were providers/staff/employees affected?
  • Who was involved in both the drawing and execution (Something went big-time wrong and we’ll need to ferret out the details.)

Next you must evaluate the outcome from the initial response to your questions and develop new questions – but you must ask the right questions. If you don’t, every answer will be wrong, and the unknowns become high risk and increasingly dangerous.

Great auditors know this and live by it. So, we must ask not only the right questions: but as many as possible so the outcome will be positive.

Although I haven’t seen the term for a while, you need to use deductive reasoning, meaning we have a known result and must rapidly work backwards to find the root cause(s). If possible, the best starting point is building an investigative element (or team) of people who understand the issue and know what was meant to be accomplished. Although the Cobra Effect typically involves bad actors, this is not absolute: well-intentioned employees who misunderstood or were put under pressure of some form could have made errors affecting the outcome. Any combination of missteps could cause a failure.

You need people dedicated to mission accomplishment who are accurate and effective investigators: and who have your organization’s health and best interests at heart. This team will gather all information and sift through it to determine the causes and produce either an alternate incentive to gain the same ground, or remove the incentive completely.

Add a Fishbone

A very effective tool is the fishbone diagram.   Both the American Society for Quality (ASQ) and Centers for Medicare and Medicaid Services (CMS) recognize this tool’s usefulness in root cause analysis (RCA). To determine shortfalls, omissions or bad actors, your team will need to produce a detailed root cause analysis.

The fishbone allows addition and insertion of critical elements, in this case as the investigation progresses; and it also allows for manipulation of the fish’s segments to better account for where in a process something occurred, and who was responsible for that segment. A great example is below, from the Minnesota Department of Health

Requirements for construction:

1.   Problem Statement. Define a clear problem statement on which all team members agree. Be specific about how and when the problem occurs when a conclusion is reached and agreed upon.

2.   Categorize major elements of the policy or incentive. There is no limit to how many of these “fish ribs” you can use. Use as many as will definitively detail the problem statement.

3.   Brainstorm and build a comprehensive rib cage of Contributing Factors. *NOTE: This is a critical part of the investigation. Investigators must be (1) Unanswerable to the parties who built and sent the policy/incentive into the field. The investigators, like auditors must have the ability to interview individuals at any level and be unaffected by their motivations and safe from accusations or retaliation. Second, investigators must also be able to instill a sense of confidentiality and anonymity in the interviewees: their job is to determine and organize all the facts- not render judgment.

4.   Be the detective. From the moment you begin ask why, who, where, when, what. With the Cobra Effect the central question (which should be repeated by the team constantly), is WHY. For example:

  • Why was this overtime pay bonus started? Answer: Productivity stalled
  • Why has productivity stalled? Answer: Outdated skills/brand new programs were put in our equipment
  • Why were the skills outdated? Why did the new programs go live without proper training? Answer: This department suffered significant budget cuts and funds have not been increased or replaced. There has been no training on the new programs
  • With the budget cuts last year the few people who knew the new programs were downsized.
  • New hires did not fill the void and in X number of cases the few new transferees from department Y were not the right people for the job

5.   The ribs can have “offshoots” or extensions. There is no limit to the number of ribs used to come to the conclusion. Just continually reevaluate to make certain of the conclusion(s)

6.   Causes will expose themselves. Analyze them for repeat offenders which appear consistently not only within categories but between categories.

Avoid the recurring problem of “hyper-compartmentalization”

Many times, a plan will be incompletely drawn up, finalized and thrown into the field without some of the most important people’s input who will be involved in making the plan work: and many times, even those who are responsible for executing the plan get left out.

Employees, sections, departments and even executives do not speak to each other, or are guarded when they do due to being “territorial”. Important people in the manufacturing and execution of the plan go uninformed and only become aware of it when the “final” plan is sent with orders to execute it.

When the report is finalized, the investigating team must meet with all individuals responsible for bringing the policy or incentive to life: but caution must be taken to detail specifics and not pass blame or accusations.

More than likely some aspect involves a breach of compliance so compliance representatives must attend.

Depending on the monetary impact, people from finance may also be required, along with outside experts who can be objective and analyze your findings.

Who else must attend these debriefings should be delegated to the investigation team lead. If the investigation was conducted properly, the lead will have more precise details where the cracks in the plan occurred. Last, there must be someone neutral, and with enough authority to make the final decision and give the order how to proceed without contradiction or argument. If the Cobra Effect was damaging enough this might need to be done by your legal folks.

Mitigation

The investigative executive report details the problems, who was involved and specific findings: mitigation is taking the information from the meetings and either reworking the plan correctly or finding a way to withdraw it without causing further problems. This can be the same meeting as the debriefing: but it must include every party responsible for the plan, policy or incentive from start to finish. An additional party here might be someone who routinely does risk assessments for your organization. The plan failed once: if you plan to go through with it after one costly failure someone needs to evaluate the risks involved in trying again. Someone or even a small team must also be involved as monitors; watching, monitoring, measuring and evaluating each step or series of steps to ensure the failures that occurred before are avoided and thought through.

Last, if there were bad actors involved there must be a means to deal with them immediately and Human Resource experts should be involved. Again, neutrality of investigators is key. Plans must already be in place to deal with them immediately, conclusively and without regard to possible alliances or relationships.

Before the Cobra Strikes

Every action we take carries unintended consequences. Thus far we’ve taken a look at dealing with the Cobra Effect after it has occurred. Now let’s focus on preventing it.

Whereas before you were Sherlock Holmes and worked using deductive reasoning, now you need to use inductive reasoning and realize there will be unintended consequences. The outcome is unknown. Someone has determined this incentive, policy or plan must go forward. Now what? How can you plan for the unknown?

Consider utilizing a reverse fishbone diagram. Rather than the head of the fish being the problem, make the head of the fish the desired outcome. Then draw the spine to the tail and determine who will comprise the ribs. This is an unbeatable way to get input from important elements in the process and will involve parties who typically get left out of decisions. You can even let the different parts make their own diagram with processes: what we can do to facilitate the successful launch of plan at each level. They know best: listen and keep them involved.

Failure Mode and Effects Analysis (FMEA) is an approach offered in the AIHC Certified Healthcare Auditor course.  It is a structured approach to discovering potential failures that may exist within the design of a product or process. Failure modes are the ways in which a process can fail. Effects are the ways that these failures can lead to waste, defects or harmful outcomes.

Another term relevant in healthcare, and particularly to avoiding the Cobra Effect, is the Game Theory, or Gaming Theory. A great simplified definition is given by Brittanica and was updated June 2023 in the article game theory mathematics: “game theory, branch of applied mathematics that provides tools for analyzing situations in which parties, called players, make decisions that are interdependent. This interdependence causes each player to consider the other player’s possible decisions, or strategies, in formulating strategy. A solution to a game describes the optimal decisions of the players, who may have similar, opposed, or mixed interests, and the outcomes that may result from these decisions.”

The importance of using this to prevent the Cobra Effect can hardly be understated. Every party affected by the incentive will have their own view of it: their own expertise: their own loyalties and motivations. Depending on the extent of the incentive/plan/policy these parties may have (in fact or assumed), conflicting goals and motivations.

When I first studied Game Theory, a lot of experts stated Game Theory existed kind of in a vacuum; with parties competing based on, basically, selfish motivations. This has since been proven inaccurate, and rather than motivations many people are driven by rules.

  • For example, rather than saying IT only looks out for itself, we now realize IT is an expertise: and based on their regular work, knowledge and experiences they approach objectives from a more technical aspect.
  • Same with finance: rather than self-serving they tend to approach a goal with initial costs, what the outcome can make money-wise, how much it will cost to maintain, etc. Each segment in the plan lives under rules and constraints: so, in this vein using the term “game” is correct even if the fallout is potentially catastrophic or criminal.

So hopefully when you begin this process integrating Game Theory into your processes, you can see the value all parties bring to make the plan successful. And do not order: ASK. Brainstorm. Make every person and every idea count. In my experience healthcare employees tend to be closer to the military: they are proud of their work, they know their jobs and they see a greater purpose in the work they do and they recognize rank: Administration, Providers-Surgeons and Staff. Use this. Invite people with conflicting goals and abilities. Make certain the lead(s) listen. You may discover competing or conflicting goals may be traced back to conflicting abilities or even non-integrating technology that prevents a certain part of the plan from progressing. If there are competing motivations they can be addressed immediately. Potential bad actors can also be ferreted out at this stage. You may also, through this trust, get people to inform you in advance who the bad actors potentially are.

Realize employees recognize the rank structure. This can dovetail into Game Theory by integrating each stratum, and letting them draw up parts of the plan that directly involve them and their expertise. In over 30 years of working with providers and surgeons I know they’re known as fiercely independent and incisive and they think rapidly on their feet. But they’re also loyal and would far rather have input early, and be asked for their input, than be blindsided by an order to do something they never anticipated.

Building Trust Takes Leadership

Long before worrying about the Cobra Effect, healthcare organizations must build a cohesive people system based on individual value, trust and realization of a common mission. Then, when time comes for execution, no one is surprised; they all agreed to the plan and their part in it, and they realize there will be oversight to ensure the processes and outcome agreed on materialize. The executive section may determine what the need is: but the actual blueprints and construction should occur at the other levels.

Note how I don’t say “know your systems”; or “you’ll need massive data” or something similar. Many people are great with data but it either gets incorrectly manipulated or causes cracks between people. This is a common problem with reporters and sportscasters: they either have more data than experience or they lean heavily on data rather than experience. Data initiates nothing: it produces nothing: and it solves nothing. People do. Data is a tool but it cannot replace the people who do produce it. Data also foresees nothing: your best defense? Correct-people.

A revolutionary thinker was a quality engineer often credited with producing the meteoric rise of the Japanese auto industry after World War II: Dr. W. Edwards Deming. Deming was a reverse thinker (even by many of today’s processes) and believed people were the fundamental driver over data and, yes, incentives. If the Cobra Effect is a negative, unintended outcome, then to my mind Dr. Deming could be called “The Cobra Charmer”. One of his main focal points was why productivity and quality so often suffered unintended consequences. Sound familiar?

In an October 12, 2017 article over Dr. Deming I find the best characterization of him and his importance to Quality. The article appeared in the Quality Assurance Directorate (QAD) blog; QAD being part of the Royal Arsenal, United Kingdom: “Dr. W. Edwards Deming’s outlook on quality was simple but radical. He asserted that organizations that focused on improving quality would automatically reduce costs while those that focused on reducing cost would automatically reduce quality and actually increase costs as a result. He outlined his ideas simply in his theory of management, now known as The Deming Theory of Profound Knowledge.” 

Finally, I leave you with a quote from the great General George S. Patton: “Never tell people how to do things. Tell them what to do and they will surprise you with their ingenuity.”

When an organization lives on and instills trust and realization of the value of different parts, people become above value. Conversing, sharing and involving them will reap unanticipated benefits. As General Patton saw cohesive teams can produce creative ways of problem solving and mission accomplishment. They might even find novel compliant ways of producing the desired results with less effort, or even superior results.

About the Author

Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Telehealth
Telehealth

Introduction to Telebehavioral Health

Compliance Considerations for Best Outcomes

Written in collaboration with the AIHC Volunteer Education Committee   


Delivering mental health services via telehealth has increased since the COVID-19 pandemic.  Both Federal and State rules are constantly evolving along with the use of Artificial Intelligence, creating a complex environment for compliance considerations.  This article is not intended as legal or consulting advice.  If your practice is currently using a telebehavioral health approach for patient treatment, or if you organization is considering implementing this approach, we hope this article will give some food-for-thought on the topic. Keep in mind coding and documentation is extremely important for psychiatric services – consider registering for the Psychiatric Compliance – coding & documentation short course offered by the American Institute of Healthcare Compliance.

Telemedicine is considered to be under the umbrella of telehealth and refers specifically to clinical services. Telehealth and telemedicine cover similar services, including medical education, remote patient monitoring, patient consultation via videoconferencing, wireless health applications, and transmission of imaging and medical reports.

Behavioral telehealth may also be referred to as telebehavioral health, telemental health, telepsychiatry, or telepsychology. 

Higher rates of use of telehealth are now standard in many practices since the coronavirus disease 2019 (COVID-19) pandemic. Increasing importance on patient satisfaction, providing efficient and quality care, and minimizing costs have also led to higher telehealth implementation.

This increase in telebehavioral health has been especially enjoyed by both patients and providers since the pandemic, but widespread adoption has been hindered by regulatory, legal, and reimbursement barriers.

Individual, one-on-one therapy, is the most common form of behavioral and mental health treatment. Telehealth can be an effective way to deliver individual therapy, as long as your practice carefully considers compliant technology, implementation and reimbursement concerns. Medicare covers many telebehavioral and telemental health services including audio-only services. Most private insurers and Medicaid cover telebehavioral health care, but check for reimbursement restrictions and obtain professional coding and billing guidance to avoid overpayment situations.

Substance use disorders impact a significant number of individuals, families, and communities.  When used in combination with other treatment methods, telebehavioral health interventions can be part of an integrated approach to treating substance use disorders. These interventions can include screening and diagnosis, online counseling, consults for prescriptions, and individual and group talk therapy. Treating substance use disorders via telehealth requires expertise and training in addiction care.

Benefits of Using Advanced Technology

The terms telehealth and telemedicine are often used interchangeably. Telehealth is a subset of e-health and is the use of telecommunications technology in health care delivery, information, and education according to the Health Resources and Services Administration (HRSA).

Telehealth has been used to bring healthcare services to consumers in distant locations, but became a necessity since the 2020 COVID-19 pandemic. Telehealth effectively connects individuals and their healthcare providers when in-person care is not necessary or not possible. Using telehealth services, patients can receive care, consult with a provider, get information about a condition or treatment, arrange for prescriptions, and receive a diagnosis. In the 30 plus years that telehealth has been in-use, it has been consistently shown to be a safe and quality care modality, a convenient option for both patients and the clinicians who care for them, and a secure environment for the collection and transmission of personal health information. In combination, these attributes extend where and how care is delivered for a stronger healthcare system.

Provider Shortages

Given provider shortages around the world, telehealth has a unique and appealing value proposition. It can provide millions of people in both rural and urban areas access to safe, effective, and appropriate care when and where they need it.

Cost-Benefit

Reducing or containing the cost of healthcare is one of the strongest motivators to fund and adopt virtual care technologies. Telehealth reduces the cost of healthcare and increases efficiency with better management of chronic diseases, shared health professional staffing, reduced travel times, and fewer or shorter hospital stays.

Meeting Patient Expectations

Patient utilizing telehealth during the pandemic may continue to expect remote care. Using telehealth technologies reduces travel time and related stresses for the consumer.

Understanding the Technology

Gaining a basic understanding of the technology will help your organization can help the wise professional make informed choices about telehealth purchases. Terminology used for the various forms of telehealth technology are summarized below which applies to both general and behavioral health care use.  Not all forms of technology are recognized as services which can be reimbursed by health insurance.

Chat-Based (Asynchronous) - This approach is online or through a mobile app communication which transmits the patient’s personal health data, vital signs, and other physiologic data or diagnostic images to a healthcare provider to review and deliver a consultation, diagnosis, or treatment plan at a later time.  This is also called “store-and-forward telemedicine.” 

  • Store-and-forward is less commonly reimbursed by Medicare and Medicaid programs.  In many states, the definition of telemedicine and/or telehealth stipulates that the delivery of services must occur in “real time,” automatically excluding store-and-forward as a part of telemedicine and/or telehealth altogether.

Mobile Health (mHealth) - Mobile Health, otherwise known as mHealth utilizes smart devices and can be now used for many specialized aspects of health care that benefit from continuous data collection about a person’s behavior or condition. Smartphones, tablets, smart wearables like iWatch can monitor a variety of factors such as pulse rate, heart rate, and with some, blood sugar levels or quality of expired air. Apps are now available to encourage healthier lifestyles and behaviors by providing heart-rate variability scores, sleep cycles, movement tracking, weight changes, dietary tracking and much more.

Remote Patient Monitoring or RPM - The remote patient monitoring approach supports ongoing condition monitoring and chronic disease management and can be synchronous or asynchronous, depending upon the patient’s needs.  The application of emerging technologies, including artificial intelligence (AI) and machine learning, can enable better disease surveillance and early detection, allow for improved diagnosis, and support personalized medicine. This includes the collection, transmission, evaluation and communication of the patient’s health data to the provider or extended care team from outside a hospital or clinical office.  It involves using personal health technologies including wireless devices, wearable sensors, implanted health monitors, smartphones, and mobile apps.

Virtual Visits (Synchronous)

This approach includes live, synchronous and interactive communication during the encounter between the patient and healthcare provider.  This is accomplished via video, telephone or live chat.

Facing Implementation Challenges

Health care providers should keep risk management strategies in mind and familiarize themselves with potential telehealth legal risks and implications. This will ensure best practices for patient care and to avoid licensure or litigation issues. 

Telehealth faces many legal and regulatory hurdles, including large variations in rules, regulations, and guidelines for practice which contributes to the confusion for providers engaged in the practice of telehealth. Telehealth rules and regulations vary greatly by state.

  • Providers should have awareness of and maintain compliance with state and federal legal requirements while using best practice guidelines to provide patient safety.
  • The lack of multistate licensure presents a barrier to telehealth because providers must obtain and uphold licensure (and the associated medical education and financial obligations) in multiple states.

The Federation of State Medical Boards created the Interstate Medical Licensure Compact to ease portability of licensure and the practice of telemedicine from state to state for physicians and physician assistants.

  • Under the compact, state medical boards would maintain licensure and disciplinary authority of providers. However, they would share information and processes essential to these providers’ licensure and regulations.
  • This compact does not apply to nurse practitioners (NPs) because they are licensed under state boards of nursing and not medicine.
  • Because state regulation and practice authority vary from state to state, NPs face more barriers than physicians or physician assistants.

Compared with face-to-face encounters, telemedicine encounters are more vulnerable to privacy and security risks.  Your telehealth platform should be secure in accordance with several laws, including the:

These laws protect medical information for both face-to-face and telehealth encounters which includes privacy, security, and protection for health information collected by covered entities such as health care plans, health care clearinghouses, and health care providers who use electronic resources for the transmission of health care information.

Only Consider Using HIPAA-Compliant Technology

The HIPAA Rules establish standards to protect patients’ protected health information. All telehealth services provided by covered health care providers and health plans must comply with the HIPAA Rules.

Covered health care providers and health plans must use technology vendors that comply with the HIPAA Rules and will enter into HIPAA business associate agreements in connection with the provision of their video communication products or other remote communication technologies for telehealth.

The Office for Civil Rights (OCR) is the HIPAA enforcement agency.  OCR released guidance on April 12, 2023 to help covered health care providers and health plans understand how they can use remote communication technologies for audio-only telehealth.  This information was published due to the end of the COVID-19 Public Health Emergency (PHE) which began May 12, 2023.

  • Click Here for OCR’s guidance “How the HIPAA Rules Permit Covered Health Care Providers and Health Plans to Use Remote Communication Technologies for Audio-Only Telehealth”

Comply with Consent Requirements

Most states have telehealth specific informed consent requirement in their statute, administrative code and/or Medicaid policies. This requirement can sometimes apply to specific types of professionals when located in law or regulations governing their profession. The requirement for consent is sometimes paired with other requirement such as the need to ensure the same level of care is delivered via telehealth as would be expected in-person. 

Make sure to have your medical/intake forms reviewed by your legal team. Obtaining informed consent with your patient is typically done before the first appointment.  Click Here for the interactive map to research your state, provided by the Center for Connected Health Policy (CCHP), federally designated as the National Telehealth Policy Resource Center.

Another resource is AHRQ resource page “How to Obtain Consent for Telehealth” – providing discussion tips for the before and during the consent periods.

Other Compliance Considerations

Compliance to both Federal and State privacy rules should be at the forefront of any telehealth endeavor, but none so important as those services provided by behavioral health professionals.  Telehealth providers must take responsibility for ensuring compliance with regulations, patient confidentiality, and system security at all times when practicing in a telehealth model.

The practice of telehealth raises many questions regarding malpractice liability including informed consent (addressed in more detail below), practice standards and protocols, supervision requirements for nonphysician providers, and the provision of professional liability insurance coverage.

  • Simply applying existing principles of malpractice liability to telehealth is not straightforward, especially when it is unclear what an appropriate “standard of care” is.
  • Professional liability policies may not include telehealth in the scope of coverage.
    • Providers need to be cognizant of what exactly liability insurance policies cover, especially when providing telehealth services in other states.

In addition to knowledge of legal aspects of telehealth, it is important for providers to be aware of and practice telehealth etiquette. These etiquette standards should be observed when providers are working remotely at home or performing telehealth visits at their practice location. Also follow all clinical standards for care and adhere to practice standards determined by the profession, state regulatory boards, and state law. Reference the CCHP Professional Boards Standards interactive map..

Providers should be appropriately licensed, credentialed, or certified to deliver care and permitted to practice without impermissible influence on their clinical judgement.

The transition to telehealth is an adjustment for patients as well as health care providers. By preparing your patients for remote medical care, you help ensure their comfort and maintain quality care. This includes understanding various fraud and abuse laws.  As telehealth use grows, caution and care should be taken to ensure that the practice of telehealth does not violate federal antikickback and Stark Law statues. These laws prohibit providers from receiving compensation for accepting or making referrals to other facilities or providers where the referring provider has financial interests.

  • Violations to these laws can result in fines, prison time, and/or exclusion from the Medicare and/or Medicaid programs.
  • The Federal Physician Self-Referral Law, also referred to as the Stark Law, prohibits a health care provider (or an immediate family member of a provider) from referring Medicare patients to entities providing designated health services if that provider or the provider’s immediate family member has a financial interest.

When considering potential fraud and abuse scenarios and related risks, a provider needs to keep in mind that each state has its own variations of these laws. A state-by-state analysis is necessary because of variations in statutes and/or regulations.

Advertising for virtual care services should be truthful and non-misleading and demonstrate a commitment to quality healthcare that meets the standard of care and compliance with all applicable state and federal laws.  The use of these telehealth appointments boomed during the pandemic. However, there are concerns about the quality of care patients receive and whether telehealth services are accessible to everyone, according to the September 2022 GAO article “Telehealth in the Pandemic—How Has It Changed Health Care Delivery in Medicaid and Medicare?”  Any website or other promotion of offering behavioral health services via telemedicine or telehealth should be reviewed by legal counsel or your Risk Attorney (free) through your malpractice insurance company.

Free Available Resources

American Telemedicine Association (ATA)

American Psychiatric Association - Telepsychiatry

Arizona Telemedicine Program: How AI Helps Physicians Improve Telehealth Patient Care in Real-Time (June 2023)

Center for Connected Health Policy (CCHP) – nonprofit organization federally designated as the National Telehealth Policy

Resource Center

Government Accountability Office (GAO) - Medicare Telehealth: Actions Needed to Strengthen Oversight and Help Providers

Educate Patients on Privacy and Security Risks

Telehealth.HHS.gov


Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Burnout, Boundaries, and Compliance
Leadership

Burnout – A Threat to Our Health Care System?

Written by: AIHC Blogger




The coronavirus disease 2019 (COVID-19) pandemic has generated a substantial increase in the workload of health care professionals leading to physical and mental distress among professionals resulting in an increase in burnout.


Burnout is defined as a work-related syndrome that affects normal life. It is caused by a prolonged response to chronic interpersonal stressors at work. According to an article in the National Library of Medicine entitled “Job Burnout,” burnout is a prolonged response to chronic emotional and interpersonal stressors on the job and is defined by the three dimensions of exhaustion, cynicism, and inefficacy.


A Vicious Cycle - The health care professionals experiencing burnout have a higher tendency to step aside which increases the loss of educated professionals, continuing the cycle of burnout within the profession.


The pandemic exacerbated many of the drivers of physician burnout. Due to COVID-related stress, 1 in 5 physicians intend to leave their current practice within 2 years.


This situation, if not addressed correctly and urgently, is likely to represent a threat to the health care system.


Shortages and maldistribution of health care workers, particularly of certain types of providers such as primary care providers, dentists, psychiatrists, and behavioral health providers, were a major concern even before the pandemic. This pandemic has exacerbated stressors in a health care system in which physician burnout, a response to workplace stress, is already epidemic, as cited by a JAMA article published back in 2018.


According to a recent study in Mayo Clinic Proceedings, burnout rate among physicians in the United States (U.S.) spiked dramatically during the first two years of the COVID-19 pandemic. According to the American Medical Association (AMA), researchers found that 2020 marked the end of a six-year period of decline in the overall rate of work-induced burnout among physicians. However, by the end of 2021, the physician burnout rate spiked to a new height that was greater than previously monitored by researchers, which happens to be after 21 months of the COVID-19 pandemic.


“The new physician burnout research builds on landmark studies conducted at regular intervals between 2011 and 2021 by researchers from the AMA, Mayo Clinic and Stanford Medicine. Together, these studies found the overall prevalence of burnout among U.S. physicians was 62.8% in 2021 compared with 38.2% in 2020, 43.9% in 2017, 54.4% in 2014, and 45.5% in 2011. Each study consistently demonstrated that the overall prevalence of occupational burnout among physicians were higher relative to the U.S. workforce.” 


According to the study published in JAMA Health Forum, Tracking Turnover Among Health Care Workers During the COVID-19 Pandemic, “Employment turnover among nearly all segments of the health care workforce has not yet fully recovered from the COVID-19 pandemic, with turnover rates among long-term care workers and physicians worsening over time.. . . An estimated 1.5 million health care workers lost employment in April 2020 as clinics temporarily closed and hospitals postponed surgeries and other procedures in an effort to limit the spread of the SARS-CoV-2 virus, the study says.”


The complexities of achieving and maintaining a compliant health care organization increases stress and burnout rates among health care administrators. One of the roles of the health care administrator is executive problem-solver. As caregivers burn out, the stress on administration increases.


Reducing burnout and improving a sense of feeling valued may allow health care organizations to better maintain their workforces post pandemic.


Resources

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Addressing Revenue Cycle Labor Shortage With Technology and Outsourcing

Written by: Melvin Miller, COO




The labor shortage is currently one of the biggest issues across industries. Be it restaurants, hospitals, retail, hospitality, and manufacturing – take any sector and you will find that this is perhaps the #1 problem operations managers are facing.


In healthcare, the labor shortage is not limited to clinical roles but extends across administrative functions. Front-office staff, billers, coders, accounts receivable, denial management, and physician credentialing experts are in short supply.


If you look at the revenue cycle, lack of timely filing and follow-ups can increase denials and result in delayed cashflows. When your revenue cycle faces a staffing shortage for core functions, you tend to ignore the optimization functions such as quality assurance and underpayment reviews, which can unlock additional revenue opportunities.


The staffing shortage is aggravating problems for the hospitals, which were impacted already by the pandemic. Over the years, we have seen declining reimbursements necessitating revenue cycle operations to deliver the best financial outcomes, which requires deep healthcare and reimbursement process expertise.


With expert revenue cycle team members already in short supply and the mandate to get all employees vaccinated for COVID-19, hospitals and healthcare systems are losing employees due to resignations and terminations. Due to the shortage of clinical and non-clinical staff, many hospitals are on the verge of closing; in fact, many rural facilities have closed already. Further, the shortage has resulted in a fight for talent, which led to increased salaries and the cost of operations.


In this blog, we look at some of the strategies revenue cycle CFOs are deploying.

  • Cloud-based IT infrastructure

With the need to operate remotely, IT leaders are tasked with making mission-critical EHR and RCM platforms available anytime, anywhere. In most physician practices, the adoption of SaaS-based EMR/RCM solutions is increasing.

  • Process automation

Within both clinical and non-clinical revenue cycle solutions, the application of machine learning, AI, and RPA technologies are enabling revenue cycle leaders to combat the staffing shortage to some degree. Technology and automation can move routine, repeatable, labor-intensive tasks to the machines and reduce manual effort. For instance, claims status automation and the adoption of portals reduce call center workloads. When you free up people from mundane activities, they can focus on higher-value activities and have better job satisfaction.

  • Operational rigor

While all revenue cycle leaders talk about managing tighter operations, few have gone on to invest time and money in implementing workflow systems that help them measure, monitor, and manage the productivity of each employee. Transactional productivity improvements will, in the short term, lead to gains in financial outcomes.

  • Analytics for sustainable transformation

Usually, revenue cycle success boils down to strategic A/R management, i.e., understanding the patterns in denied claims, addressing root causes, strategic touches to claims in higher revenue brackets, and not allowing claims to fall into longer aging buckets. Revenue cycle analytics and adoption of industry-standard reporting can help RCM managers create the focus.

  • Outsourcing

Perhaps the #1 strategy that organizations are looking at is outsourcing, which gives them access to trained, certified labor across the nation. And with offshoring, you also get the benefits of cheaper cost structures. With the outsourcing and offshoring market now nearly two decades old, you can find service providers who have invested in process expertise and technology to help you get access to best-of-the-breed practices.

  • Optimizing costs to collect requires simultaneous implementation of pervasive change strategies

Across the revenue cycle operations, the questions that leaders need to ask are:


o What can you automate?


o What technologies do you need to invest in - workflow automation, analytics,
front-end tech?


o Where will you find the money to invest in new-age technology?


o Does this function need to be done onshore, or can you offshore it? 

  • Cash is king. Leaving revenue on the table is a crime.

Faster cash flow cycles are critical to the survival of healthcare organizations. Address the problems such as revenue leakage and front-end processes sustainably to streamline operations.

  • Change the job content for your employees

Accelerating the adoption of technology and outsourcing can shift the focus of your employees to strategic tasks. The change in job content makes them feel empowered to impact the organization’s revenue cycle outcome, which is more satisfying.

  • Don’t just outsource. Choose your vendor partner well.

Plan along with your vendors, transition and stabilize operations, and then move the goal post for the vendor every quarter.

While you can take the short-term to address your revenue cycle issues, it is time for revenue cycle leaders to implement sustainable solutions. The labor shortage is not going away quickly, and reimbursements will continue to decline. Technology, operational rigor, and outsourcing are the only options you have. Choose well, plan well, and execute in style.

Additional Resources:

  • Medical Billing Wholesalers - https://www.medicalbillingwholesalers.com

    _________________________________________________________

    Melvin Miller is an experienced Chief Operating Officer with a demonstrated history of working in the healthcare industry for over 15 years, Satish, a.k.a. Melvin, has experience in team building, business development, Healthcare Information Technology (HIT), revenue cycle process training, US. Health Insurance Portability and Accountability Act (HIPAA), and Healthcare Management.
Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Key Revenue Cycle Trends for 2022 and Beyond

Written by: Melvin Miller, COO




Tech, investments, efficiency, patient experience, underpayment recovery, and coding automation are some of the themes that will drive the revenue cycle market momentum in 2022 and beyond. Coming at the back-end of a long period of adversity due to COVID-19 and an already challenging economic environment for hospitals and healthcare systems, we see a new wave of consolidation, invention, and innovation. In this paper, we discuss some of the trends experienced in health care.


TIGHTENING PROFIT MARGINS – A PANDEMIC RAVAGED REVENUE CYCLE TO BOTTOM OUT.


With hospitals operating on extremely tight margins, projecting cash flow and the ability to extract the maximum out of the revenue cycle is more critical than ever before. This will drive key technology and process innovation as revenue cycle leaders and managers strive to improve business outcomes.


Now, let’s look at the broad trends in each of the major revenue cycle processes.


Patient Access and Experience


Patient experience is now one of the key issues impacting the healthcare industry. There is a huge information deficit in the area of patient payments.


Patients question “How much should I pay from my pocket?” The answer has been surprisingly difficult to find. Patients must get quick and easy access to information about services performed and corresponding charges; the amount expected to be paid by their insurance company; and the out-of-pocket expenses they are expected to bear. It is important to include the aspect of the No Surprises Act, which complicates the situation for both providers and patients.


We anticipate patient access and experience to improve with new technologies that can project the costs they need to bear, improved omnichannel information availability, and improved payment plans. Patient financial services will go through a much-needed overhaul.


Prior-Authorization and Eligibility Verification


While great tech exists for information interchange, prior authorization and eligibility verification tech adoption have lagged because of a lack of standardized documentation and information exchange protocols. With clearinghouses now modernizing, there is new hope for API-driven information exchanges.


Autonomous Coding


Automation tech is seeing increasing adoption, and there is a general perception that coding, billing, and accounts receivable problems will be solved through automation. Artificial Intelligence, Machine Learning, and Robotic Process Automation technologies provide great promise to lower labor costs. Medical coding is becoming data-driven and autonomous with improved standardization through ICD-11 and a better combination of virtual scribing, Universal Medical Language Systems (UMLS), OCR, and natural language processing (NLP). While these are still early days, coding tech is yet to prove effective in finding discharges not fully coded (DNFC) and arresting revenue leakage.


A/R, Denial Management, and Appeals Filing

Accounts Receivable (A/R) status has moved from calls to portals. We see increasing relevance for chatbots using conversational artificial intelligence (AI) in A/R and denial management filing. Data structures can now power customized appeals filing as well.

Focus on the Front-End

Most revenue cycle leaders agree that they need to solve revenue cycle issues in the front-end rather than elongate the cycle and wait to address them in the back end. They recognize that they need to link prior authorization, revenue integrity, clinical documentation improvement, and denial management to accelerate their revenue cycle. The ability to quickly identify denial issues, determine root causes, and develop solutions to reduce these denials through an iterative model that focuses on denial prevention is considered the key to addressing revenue cycle issues.

Underpayment and Analytics

The Hospital revenue cycle is fraught with underpayment issues. Contract analysis and underpayment identification can help arrest underpayments. As the shift to more branded, national healthcare practices happens, performance analytics becomes a critical business function. Practice-specific analytics using standard measures and Key Performance Indicators or KPIs will enable accurate views of performance and drive corrective action.

Unprecedented Financial Activity – Private Equity (PE), IPOs, Mega-mergers, and More

“It’s like Woodstock,” as some revenue cycle dealmakers are saying. The role of private equity in healthcare, in general, and the revenue cycle business, in particular, has increased to an unprecedented level.

  • Entry of the big boys. The big boys, i.e., the large PE firms have made strategic investments in revenue cycle assets.
  • Technology-led investments. Some of the themes that PE firms are investing in include focused revenue cycle service providers and niche technology companies such as autonomous coding, patient experience, prior authorization, and large-scale offshore providers.
  • Investments in revenue cycle aggregators. It seems like if a company’s resume says revenue cycle, it is likely to attract many valuations. Further, larger companies choose to hit the primary market through an initial public offering. We are seeing increasing consolidation of revenue cycle service providers as well.
  • Provider side consolidation. There is an increasing amount of investment in consolidation on the provider side. The push to provide a branded healthcare experience through nationwide chains is driving investments in areas such as urgent care, behavioral/mental health, wellness-focused treatments, home healthcare franchises, etc.

In 2022, we anticipate the continuance of these trends and mega-mergers will be more of a norm than an aberration.

Telehealth Adoption

Spurred on by the pandemic, telehealth adoption is increasing. Not only does this mean a lower cost of care, but it also requires the adoption of new processes for patient monitoring and managing the revenue cycle.

Remote Working

The COVID-19 necessitated revenue cycle team members to adopt work-from-home models. It also required operations managers to be flexible and adopt technologies to monitor revenue cycle performance. We anticipate that hospitals and healthcare systems will look at remote working as the new normal and encourage a significant percentage of their workforce to work remotely.

Labor Shortage and Outsourcing

There is an acute shortage of qualified revenue cycle staff. Many community hospitals are concerned about the community’s response to outsourcing and offshoring strategies they adopt. At this time of rising hospital expenses and reducing revenues due to declining reimbursements, outsourcing, offshoring, and automation can help them contain costs and sustain profitability. If using a U.S. based company that offshores the majority of their work, have you checked with legal counsel regarding how this type of business associate can be held accountable under U.S. laws (such as HIPAA, False Claims Act, etc.)

Conclusion

There has never been a better time to be in healthcare – and these are the most challenging times as well. Both in terms of economic activity and innovation, 2022 is likely to set a scorching pace. Whether you are a healthcare system, revenue cycle services provider, or technology solutions provider, this year will force you to think innovatively, build new delivery frameworks, and create the revenue cycle of the future.

Additional Resources:

_________________________________________________________

Melvin Miller is an experienced Chief Operating Officer with a demonstrated history of working in the healthcare industry for over 15 years, Satish, a.k.a. Melvin, has experience in team building, business development, Healthcare Information Technology (HIT), revenue cycle process training, US. Health Insurance Portability and Accountability Act (HIPAA), and Healthcare Management.
Read More
General Compliance

Uncompensated Care and DSH (Medicare disproportionate share hospitals)

Written by: Scott Mertie, CHFP, FHFMA, CMPE, CCRS, CHCO, CIFHA (KraftCPAs) and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCSAs (CEO of AIHC)


This article is written for education purposes and should not be considered accounting, consulting or legal advice regarding hospital charity care bad debt and disproportionate share hospitals aka DSH. For more information on filing compliance cost reports, attend the Medicare Cost Report Camp in March 2022 presented by KraftCPAs and sponsored by the American Institute of Healthcare Compliance.


Medicare Uncompensated Care Payments & DSH


Hospitals' charity care and bad debt, together known as uncompensated care, is used to calculate disproportionate-share hospital payments. The Centers for Medicare and Medicaid Services (CMS) distributes a prospectively determined amount of uncompensated care payments to “Medicare disproportionate share hospitals” or better known as “DSH.” This is calculated based on the hospital’s relative share of uncompensated care nationally.

 

As required under law, this amount is equal to an estimate of 75 percent of what otherwise would have been paid as Medicare disproportionate share hospital payments, adjusted for the change in the rate of uninsured people. In this rule, CMS will distribute roughly $8.3 billion in uncompensated care payments for FY 2021, a decrease of approximately $60 million from FY 2020. This estimate of total uncompensated care payments reflects CMS Office of the Actuary’s projections that incorporate the estimated impact of the COVID-19 pandemic.


For FY 2021, CMS will use a single year of data on uncompensated care costs from Worksheet S-10 of hospitals’ FY 2017 cost reports to distribute these funds, in part because CMS has conducted audits of this data. Mindful of the unique challenges facing Indian Health Service and Tribal hospitals and Puerto Rico hospitals, CMS will continue to use data regarding low-income insured days (Medicaid days for FY 2013 and FY 2018 SSI days) to determine the amount of uncompensated care payments for Puerto Rico hospitals and Indian Health Service and Tribal hospitals for FY 2021, similar to the FY 2020 methodology.


Background on the IPPS and LTCH PPS


CMS pays acute care hospitals (with a few exceptions specified in the law) for inpatient stays under the Inpatient Prospective Payment System (IPPS). LTCHs are paid under the Long-Term Care Hospital Prospective Payment System (LTCH PPS). Under these two payment systems, CMS sets base payment rates prospectively for inpatient stays based on the patient’s diagnosis and severity of illness. Subject to certain adjustments, a hospital receives a single payment for the case based on the payment classification assigned at discharge. The classification systems are:

  • IPPS: Medicare Severity Diagnosis-Related Groups (MS-DRGs)
  • LTCH PPS: Medicare Severity Long-Term Care Diagnosis-Related Groups (MS‑LTC‑DRGs).

The law requires CMS to update payment rates for IPPS hospitals annually, and to account for changes in the prices of goods and services used by these hospitals in treating Medicare patients, as well as for other factors. This is known as the hospital “market basket.” The IPPS pays hospitals for services provided to Medicare beneficiaries using a national base payment rate, adjusted for a number of factors that affect hospitals’ costs, including the patient’s condition and the cost of hospital labor in the hospital’s geographic area. Payment rates to LTCHs are typically updated annually according to a separate market basket based on LTCH-specific goods and services.


In 2020, CMS issued a final rule for acute care and long-term care hospitals that ensures access to potentially life-saving diagnostics and therapies by unleashing innovation in medical technology and removing barriers to competition.


On August 2, 2021, the CMS issued the final rule for fiscal year (FY) 2022 Medicare Hospital Inpatient Prospective Payment System (IPPS) and Long-Term Care Hospital (LTCH) Prospective Payment System (PPS). The FY 2022 IPPS and LTCH PPS final rule will be issued in multiple parts. 


The final rule updates Medicare payment policies and rates for operating and capital-related costs of acute care hospitals and for certain hospitals and hospital units excluded from the IPPS for FY 2022. The policies in this IPPS and LTCH PPS final rule build on key priorities to close health care equity gaps and support greater access to life-saving diagnostics and therapies during the COVID-19 public health emergency (PHE) and beyond.


The rule’s provisions seek to:


Sustain hospital readiness to respond to future public health threats;

Enhance the health care workforce in rural and underserved communities; and

Revise scoring, payment and public quality data reporting methods to lessen the adverse impacts of the pandemic and future unplanned events. 


The final rule updates Medicare fee-for-service payment rates and policies for inpatient hospitals and long-term care hospitals for FY 2022. In this final rule, CMS approved 13 technologies that applied for new technology add-on payments for FY 2021. This includes two technologies under the alternative pathway for new medical devices that are part of the FDA Breakthrough Devices Program and five technologies approved under the alternative pathway for products that received FDA Qualified Infectious Disease Product (QIDP) designation. 


Additionally, CMS conditionally approved one technology designated as a QIDP that otherwise meets the alternative pathway criteria but has not yet received FDA approval. After consideration of public comments, CMS also approved six technologies submitted under the traditional new technology add-on payment pathway criteria.


CMS is continuing the new technology add-on payments for 10 of the 18 technologies currently receiving the add-on payment (the remaining 8 technologies will no longer be within their newness period in FY 2021, which includes the Chimeric Antigen Receptor (CAR) T-cell therapies approved for the new technology add-on payment in FY 2019).


In total, 24 technologies are eligible to receive add-on payments for FY 2021. CMS estimates that FY 2021 Medicare spending on new technology add-on payments will be approximately $874 million, nearly a 120% increase over the FY 2020 spending.


CMS is adopting some changes regarding new technology add-on payments for certain antimicrobials for FY 2021:

  • Expansion of alternative new technology add-on payment pathway for antimicrobial products designated by FDA as QIDPs to include products approved under FDA’s Limited Population Pathway for Antibacterial and Antifungal Drugs (LPAD pathway).

o The LPAD pathway encourages the development of safe and effective drug products that address unmet needs of patients with serious bacterial and fungal infections. As is the case for QIDPs, under this policy an antimicrobial drug approved under FDA’s LPAD pathway will be considered new and not substantially similar to an existing technology and will not need to demonstrate that it meets the substantial clinical improvement criterion (the technology will need to meet the cost criterion).

  • CMS is adopting a policy to provide for conditional approval for antimicrobial products that otherwise meet the NTAP alternative pathway criteria but do not receive FDA approval in time for consideration in the final rule. This is to allow eligible antimicrobial products to begin receiving the new technology add-on payment sooner.

o Under this policy, those antimicrobial products that otherwise meet the applicable addon payment criteria will begin receiving the new technology add-on payment, effective for discharges the quarter after the date of FDA marketing authorization instead of waiting until the next fiscal year, provided FDA marketing authorization is received by July 1 of the year for which the applicant applied for new technology add-on payments


Conclusion


CMS estimates total Medicare spending on acute care inpatient hospital services will increase by about $3.5 billion in FY 2021, or 2.7 percent. The Office of Inspector General (OIG) has added reviews of MAC cost report oversight for 2022. This project is described in the OIG January 2022 Work Plan Item. Filing accurate and compliant cost reports should be part of your institution’s risk mitigation program. 


Additional Resources

Read More
General Compliance

Consent and COVID Testing of Employees

Written By: Compliance Blogger




This article addresses COVID testing and consent considerations for:  healthcare organizations, nursing homes and business associates or non-healthcare workplaces. This article is not intended as legal or consulting advice.  Employers are encouraged to collaborate with state, territorial, tribal and local health officials to determine whether and how to implement COVID testing strategies.


SARS-CoV-2 (COVID-19) continues to be a health risk to be mitigated by health care institutions and at the workplace. Employers paying for testing of employees should put procedures in place for rapid notification of results and establish appropriate measures based on testing results, including instructions regarding self-isolation and restrictions on workplace access.


An employer’s testing program (including the implementation of a testing protocol to test employees) may be complex and technical. Certain aspects of the testing program may be more relevant than others to an employee’s decision whether to accept an offered test. Obtain guidance from experts to assist your organization in navigating risk.


Business Associates (non-healthcare organizations)


The Center for Disease Control (CDC) provides guidance for non-healthcare workplaces, which would apply to most business associates who have partnered with a health care institution, such as legal or accounting firms; medical billing companies; IT managed service providers, etc. Workplace-based testing should not be conducted without the employee’s informed consent. Encourage and answer questions during the consent process.


Informed Consent


Informed consent requires disclosure, understanding, and free choice, and is necessary for an employee to act independently and make choices according to their values, goals, and preferences. Consult legal counsel when developing your informed consent form for employees.


To fully support employee decision-making and consent, employers should take the following measures when developing a testing program:

  • Ensure safeguards are in place to protect an employee’s privacy and confidentiality.
  • Provide complete and understandable information about how the employer’s testing program may impact employees’ lives, such as if a positive test result or declination to participate in testing may mean exclusion from work.
  • Explain any parts of the testing program an employee would consider especially important when deciding whether to participate. This involves explaining the key reasons that may guide their decision.
  • Provide information about the testing program in the employee’s preferred language using non-technical terms. Consider obtaining employee input on the readability of the information. Employers can use the CDC tool to create clear messages: https://www.cdc.gov/ccindex/
  • Encourage supervisors and co-workers to avoid pressuring employees to participate in testing.
  • The consent process is active information sharing between an employer or their representative and an employee, in which the employer discloses the information, answers questions to facilitate understanding, and promotes the employee’s free choice.

Disclosures for Non-healthcare Workplace Testing


Individuals tested are required to receive patient fact sheets as part of the test’s emergency use authorization (EUA):

A basic disclosure for COVID-19 should include the following elements to provide information to employees so they understand what is involved when consenting to the test, such as clear information on the manufacturer and name of the test, the type of test, the purpose of the test, the performance specifications of the test, any limitations associated with the test, who will pay for the test, how the test will be performed, how and when they will receive test results, and; how to understand what the results mean, actions associated with negative or positive results, the difference between testing for workplace screening versus for medical diagnosis, who will receive the results, how the results may be used, and any consequences for declining to be tested.


According to the Americans with Disabilities Act (ADA), when employers implement any mandatory testing of employees, it must be “job related and consistent with business necessity.” In the context of the COVID-19 pandemic, the U.S. EEOC notes that testing to determine if an employee has SARS-CoV-2 infection with an “accurate and reliable test” is permissible as a condition to enter the workplace because an employee with the virus will “pose a direct threat to the health of others.” EEOC notes that tests administered by employers which are consistent with current CDC guidance will meet the ADA’s business necessity standard. However, workplace-based testing should not be conducted without the employee’s consent.


Infection Control for Healthcare Facilities


The CDC has made recent changes to infection control guidance for all U.S. settings where healthcare is delivered, including home health. The updated healthcare infection prevention and control (IPC) recommendations as of September 10, 2021 are in response to the COVID-19 vaccination. Consult with legal counsel regarding disclosures and consents appropriate for your organization.


Healthcare Personnel (HCP): HCP refers to all paid and unpaid persons serving in healthcare settings who have the potential for direct or indirect exposure to patients or infectious materials, including body substances (e.g., blood, tissue, and specific body fluids); contaminated medical supplies, devices, and equipment; contaminated environmental surfaces; or contaminated air. HCP include, but are not limited to, emergency medical service personnel, nurses, nursing assistants, home healthcare personnel, physicians, technicians, therapists, phlebotomists, pharmacists, dental healthcare personnel, students and trainees, contractual staff not employed by the healthcare facility, and persons not directly involved in patient care, but who could be exposed to infectious agents that can be transmitted in the healthcare setting (e.g., clerical, dietary, environmental services, laundry, security, engineering and facilities management, administrative, billing, and volunteer personnel).


Healthcare settings refers to places where healthcare is delivered and includes, but is not limited to, acute care facilities, long-term acute-care facilities, inpatient rehabilitation facilities, nursing homes, home healthcare, vehicles where healthcare is delivered (e.g., mobile clinics), and outpatient facilities, such as dialysis centers, physician offices, dental offices, and others.


Source control is the use of respirators, well-fitting facemasks, or well-fitting cloth masks to cover a person’s mouth and nose to prevent spread of respiratory secretions when they are breathing, talking, sneezing, or coughing. Source control devices should not be placed on children under age 2, anyone who cannot wear one safely, such as someone who has a disability or an underlying medical condition that precludes wearing one safely, or anyone who is unconscious, incapacitated, or otherwise unable to remove their source control device without assistance. Face shields alone are not recommended for source control.


IPC Measures


Several of the IPC measures (e.g., use of source control, screening testing) are influenced by levels of SARS-CoV-2 transmission in the community. There are two different indicators in CDC’s COVID-19 Data Tracker which are used to determine the level of SARS-CoV-2 transmission for the county where the healthcare facility is located – Access the COVID Data Tracker:

If the two indicators suggest different transmission levels, the higher level is selected.


Source control and physical distancing (when physical distancing is feasible and will not interfere with provision of care) are recommended for everyone in a healthcare setting. This is particularly important for individuals, regardless of their vaccination status, who live or work in counties with substantial to high community transmission or who have:

  • Not been fully vaccinated; or
  • Suspected or confirmed SARS-CoV-2 infection or other respiratory infection (e.g., those with runny nose, cough, sneeze); or
  • Had close contact (patients and visitors) or a higher-risk exposure (HCP) with someone with SARS-CoV-2 infection for 14 days after their exposure, including those residing or working in areas of a healthcare facility experiencing SARS-CoV-2 transmission (i.e., outbreak); or
  • Moderate to severe immunocompromised; or
  • Otherwise had source control and physical distancing recommended by public health authorities.

Perform SARS-CoV-2 Testing


Anyone with even mild symptoms of COVID-19, regardless of vaccination status, should receive a viral test as soon as possible, according to the CDC recommendation.


Asymptomatic HCP with a higher-risk exposure and patients with close contact with someone with SARS-CoV-2 infection, regardless of vaccination status, should have a series of two viral tests for SARS-CoV-2 infection.

  • In these situations, testing is recommended immediately (but not earlier than 2 days after the exposure) and, if negative, again 5–7 days after the exposure.
  • Note - testing is not recommended for people who have had SARS-CoV-2 infection in the last 90 days if they remain asymptomatic; this is because some people may have detectable virus from their prior infection during this period (additional information is available here). Criteria for use of post-exposure prophylaxis are described elsewhere.

Expanded screening testing of asymptomatic HCP without known exposures was required in nursing homes and could be considered in other settings. It should be conducted as follows:

  • Fully vaccinated HCP may be exempt from expanded screening testing.
  • Guidance for expanded screening testing for nursing homes was described in the Interim Infection Prevention and Control Recommendations to Prevent SARS-CoV-2 Spread in Nursing Homes | CDC but is no longer available.

Performance of pre-procedure or pre-admission viral testing is at the discretion of the facility. The yield of this testing for identifying asymptomatic infection is likely low when performed on vaccinated individuals or those in counties with low or moderate transmission. However, these results might continue to be useful in some situations (e.g., when performing higher risk procedures on unvaccinated people) to inform the type of infection control precautions used (e.g., room assignment/cohorting, or PPE used).


Click Here for more detailed information about infection control guidance.

Read More
Telehealth
Telehealth

How Geriatric Care Will Change in the New Normal

Written by Sophie Johnson




The healthcare industry has been transformed by the pandemic, and one part of healthcare that was thrust into the spotlight over the last 16 months is geriatrics. The Centers for Disease Control and Prevention (CDC) states that older adults were more at risk of coronavirus complications, which put them at a higher likelihood of being hospitalized. This has changed how the healthcare sector has responded to seniors, and it will continue to shape how geriatric healthcare will continue in the new normal.


How COVID Affected Geriatric Care


The elderly were affected more severely by the pandemic because they were already a vulnerable population to begin with. Beyond preventing and treating the virus itself, healthcare centers also had to mitigate the adverse effects of extended isolation for older patients. Other restrictions also prevented seniors from getting the physical activity needed to maintain their health, leading to a faster-deteriorating state.

The beginning of the pandemic presented the greatest challenge for geriatric healthcare workers since there were physical distancing protocols in place. Geriatric care shifted to telehealth to meet the needs of older adults. This presented many challenges, the most pertinent one being how to increase the digital literacy of older people, as it became the main way to access resources and contact persons. As these challenges continued, caregivers and family members have had to give more support to seniors to ensure that their needs would be met and, ultimately, prevent hospitalization.

How Geriatric Care Will Change in the New Normal


The way care has changed during COVID-19 will likely continue into the new normal, but there will certainly be some changes in the preventive measures taken to ensure older adults are resilient, healthy, and safe.

Telehealth will grow

According to Pew Research, only about 40% of people aged 74 to 91 years use the internet. However, this is drastically changing. Doctors are seeing more and more virtual visits from older people as part of their practice. And with the ability to access doctors online becoming much easier now, senior patients may be inclined to make more visits, which will significantly improve their overall health.

One of our previous blogs, How Telehealth Is Being Used to Treat Mental Health, discussed how telehealth has also already improved mental health for older people through online therapy, emergency services, and remote monitoring programs, all of which are likely to become the norm in the new normal.

People will have more than one physician

Older people will likely be seeing teams of doctors rather than just one dedicated physician. It is a more efficient and cost-effective way of accommodating patients and for those patients to have their needs met without long waits. And with easier access to more doctors, seeing several specialists is now easier than before.

Coverage plans will become a priority

Apart from getting vaccinated, the CDC also recommends seniors take extra preventive measures to protect themselves from contracting COVID-19. However, individual efforts such as wearing a mask and a healthy lifestyle may no longer be sufficient, especially for older people who are at risk of suffering from other conditions.

This increased awareness in the new normal will see a rise in older adults investing in medical plans. Fortunately, the healthcare industry has long anticipated this, with many different plans available that cater to specific needs. Kelsey Care Advantage outlines the different packages available, some focusing on dental care while others put a premium on cardiovascular conditions. Older adults may even prefer medical coverage that includes medication and fitness benefits. Being prepared in this manner will allow older people to feel more secure should any health concerns come about in the future, COVID or otherwise.

For additional timely and relevant healthcare related information like this, please check out our other blog articles and access all of our course offerings at AIHC.

Read More
HIPAA Compliance
HIPAA

Healthcare Apps and Data Privacy/Security Risks

Written by Susan Walberg, JD MPA CHC




Healthcare apps have become increasingly prevalent, with people using them for counting steps, monitoring their calories, or linking to various medical devices, to name just a few examples. Since the COVID outbreak, however, and the explosion of telehealth as a healthcare option, these apps have proliferated at an insane rate. As of 2020, there were 325,000 healthcare apps on the market, with more coming all the time.


Whether you are a consumer who uses such apps, or a provider who wants to develop an app for patients to use, it’s important to understand some of the privacy and security risks that may accompany the use of such tools and what to watch out for.


What Are Healthcare Apps?


An ‘app’ is a small program that can be loaded onto a phone or mobile device to perform a specialized function. There are two main types of healthcare apps in terms of privacy and security regulations, and the rules governing them vary accordingly.


The first type are the applications that are used by your healthcare provider. They may be used to store your lab or radiology results or might be integrated with a medical device for tracking/monitoring purposes, such as an electrocardiography device that monitors heart activity. Or they may be used to coordinate your care.


The second type are personal or private healthcare apps, those that an individual can get at an app store to track and manage their diet, exercise, or specific health conditions. There are apps for mental health, diabetes, and, of course, COVID, to name just a few. Many of these apps are free.


Nothing in Life Is Free


First, let’s talk about those ‘free’ apps.


Free apps, how cool is that? Depending on your view, an application that tracks and shares your personal information might not really be ‘free’.


If you go online and look for a free app to help you count calories or manage your diet, for instance, the odds are good that there are advertisements on the app, right? Well, most of those ‘free’ apps, with the ads included, will be sharing your information with the advertisers and perhaps even with other companies, such as the ‘big tech’ companies or other stakeholders or investors.


You may expect this, and you might not care. After all, any online Google search leads to targeted Facebook ads relating to that same subject matter, as many of us have noticed. We may not like it, but we are getting used to the fact that our online activity is not really private.


But when you choose one of those apps, think about what information you are entering, because it is probably not private. How much of your medical information is being collected in order to help you manage your diabetes or exercise program? And do you know where that information might be shared? You may accept the fact that your use of the app is not private, just like your Google searches seem to have a direct pipeline to Facebook. But think about the data collected, because that’s not private either. And that’s not illegal in this situation.


But…But…HIPAA


How can this health information NOT be private? There must be regulations protecting your privacy, especially when it comes to your healthcare information, right? We hear all the time about HIPAA (The Health Insurance Portability and Accountability Act of 1996) and how your health information can’t be shared.


Just to be clear, in a nutshell, HIPAA only applies to those apps that are used and offered by your healthcare provider or insurance company (or some similar organization that is regulated by HIPAA). Those organizations are subject to the HIPAA Privacy and Security regulations (as well as the HITECH and Omnibus laws that followed), so any product they offer in conjunction with their regulated services would typically be subject to the same laws. This does not mean that if your doctor tells you there are apps in the marketplace to monitor your diabetes that they would be subject to HIPAA. But if your insurance company, for instance, offers you a tool as part of your plan that will help you manage a chronic health condition, HIPAA would generally apply. You may not be sure, so it’s important to ask.


If the app is, indeed, regulated under HIPAA, that means that privacy and data security controls must be in place. There should be a privacy/security policy that you can review, and you have specific rights with respect to your information and how it’s used. There are limitations around, for instance, how your data can be used or shared for marketing purposes. It also means that there must be a designated privacy and security ‘official’ who has oversight of compliance with these regulations. A company that provides a healthcare app to physician practices, insurance companies, or similar organizations would be considered a ‘Business Associate’ of that provider or insurance company, which means they are subject to the same requirements. HIPAA does provide a broad range of protections, but they are limited to those specific scenarios.


The reality is that few laws govern the privacy of information you voluntarily share in one of these publicly-available apps, so if you go online and pick an app to track or monitor your own health condition or information…most are not subject to privacy laws.


Apps Provided by Your Physician, Insurance Company, Etc.


The apps used by your doctor’s office or insurance company are subject to much tighter regulation, but also often contain more personal data. Especially with the increased use of telehealth services, provider’s offices are relying on various applications and platforms to facilitate the provision of healthcare services. These apps, and the companies that offer them, are covered under HIPAA as ‘Business Associates’ of the provider or insurance company if the app uses, stores, or transmits patient health information on behalf of the healthcare organization.


Due to COVID, the government has loosened up the privacy regulations in order to allow greater flexibility in providing telehealth services. While this is good news for providers and the patients needing those services, it also means more potential risk to protected health information (PHI). It’s important to keep in mind that, in addition to whatever information you enter online, a telehealth application likely has requested permission to access your calendar, camera, and microphone.


The good news is that, although providers may have been using some of the less secure apps in the beginning of COVID, just out of necessity, those providers who plan to continue providing telehealth services are working to ensure compliance with privacy and security requirements. App developers are busy developing apps to accommodate this changing market, and compliance is a top concern.


Apps as Mobile Devices


There is one type of application which is actually considered by the Food and Drug Administration (FDA) to be a medical device, in addition to being covered under HIPAA (because they are provided in conjunction with healthcare services). Those are the apps that are intended to be used ‘for the diagnosis of disease or other conditions, or the cure, mitigation, treatment, or prevention of disease, or is intended to affect the structure or any function of the body of man’ under section 201(h) of the Food, Drug, and Cosmetic Act. In general, if the purpose or function of the app is to assist in performing a medical device function, it will be treated as a medical device under the FDA. For instance, if the app can be run on a smart phone or other hand-held device and analyzes and interprets EKG waveforms to monitor cardiac irregularities, it would be considered analogous to those software programs that perform the same function and are otherwise regulated as a medical device.


The intent of the FDA is to ensure patient safety related to the use of those devices that could compromise or risk patient health. This oversight is limited to those devices marketed and offered to perform these medical device functions.


Although the FDA purview is not privacy or data security, the FDA jurisdiction is noteworthy in terms of regulatory oversight. For purposes of HIPAA, these devices would typically be subject to the Privacy and Security rules as they are used in conjunction with your provider or insurance company, as discussed above.


How Do You Know if Your Data Is Secure?


Apps in the marketplace that are available to help track health-related information should have a privacy policy, although at the current time it is not required by law for apps that are not considered a medical device or are subject to HIPAA. It is highly recommended that you find those policies and read them, even though some may be lengthy and not written clearly (might be overly technical or legalistic).


Even if the apps have privacy policies, those policies might not be easy to find, and you might discover that the policy does state the ways in which they do share your information. There is no law against the sale or disclosure of data from independent apps to third parties and those apps are being funded somehow (data is valuable). In addition to data sharing, the privacy policy should explain how it safeguards your data. There should be information security measures in place to prevent breaches of your data. And lastly, even if the privacy policy sounds good, the app developer may not necessarily follow their own policies. This is not to say that an app developer is deliberately being deceptive; a developer or their sponsoring company may adopt a policy from another app they are familiar with or may bring in a consultant to write their policy, but the specific terms in the policy aren’t implemented during development. It can happen. And this isn’t limited to app developers; any organization can fall short of following its own policies. Many app developers have a technical or clinical background and may not fully understand the healthcare regulatory framework.


You can also check an app’s automatic settings and look for those that impact privacy, such as location tracking. Beware, though, that in some instances turning those options off will make it more difficult to use the app.


The bottom line here is caveat emptor…buyer beware. Especially if you’re not ‘buying’ and it’s ‘free’.


How Can Data Be Compromised?


Even when providers, insurance companies, and app developers are focused on compliance with the various privacy and security requirements, PHI can still be compromised, but it is less likely. Common mishaps occur in a number of ways:

  • Employee errors. Human errors can occur in any setting. It can be an employee discussing patient information out loud in a non-private setting, clicking on a link that allows a virus or ransomware attack, or accidentally entering an incorrect phone number and sending information to the wrong person. This isn’t limited to technology-related issues but privacy in general.
  • Poor access controls. There needs to be a solid process, that is followed religiously, to ensure that only individuals who need access are given access, and that former employees or business associates are promptly removed when they no longer have a need for access. This also includes business partners who have employees who need access in order to provide services to another company or practice. These employees need their own access, not a universal access that cannot be tracked.
  • Failure to monitor. Any organization that maintains PHI electronically should have a process for routinely reviewing who is accessing sensitive information and following up on any questionable access. Audit trails are part of any good security structure.
  • Failure to securely store data. Not only should data be stored in a secure manner, it should also be consistently destroyed/removed when applicable retention periods have expired.
  • Inadequate encryption.
  • Workstation and device security. Applications should time-out when not in use, rather than rely on users to remember to do so.
  • Failure to conduct a comprehensive risk assessment that includes the various apps and networked devices where PHI is stored or transmitted.
  • Increased remote workers. Employees working from home are more likely to use personal devices that don’t have proper levels of encryption and that are, by definition, less private due to the offsite location. Access is much harder to control and networks may not be secure.

The above issues do not pertain only to apps, but in general to information privacy and security, especially in the new era of increased telehealth services. Those issues are also the types of failures HIPAA was designed to prevent and would likely be considered violations, depending on the specific facts. If you are considering using an app or electronic platform where personal information will be entered, it’s recommended that you ask your provider or insurance company who is offering this tool what their privacy and security policies are. If their organization is using and recommending such a tool, they have almost certainly done the review of privacy and security controls. And if you are a provider considering using an app, or an app developer, the above list is for you. You should have designated ‘privacy and security officials’ who ensure the above risk areas are addressed.


What Are the Risks?


Most people care about the privacy of their health information just because it’s private and not other people’s business. But there are actual risks to consider, which users of these apps should understand:

  • Data is shared with third parties for sales and marketing, increasing the targeting of ads you receive.
  • Even information that is supposedly ‘de-identified’ can include enough information to make users identifiable, and it may be very sensitive information, for instance relating to mental health or substance abuse.
  • Medical identity theft, which can result in someone using your identity to receive free healthcare services or to file fraudulent claims. Healthcare data is valuable for those reasons, which is why it is often targeted by hackers.
  • Additional outside companies, such as Facebook or Google, may acquire the information and build user profiles. Once the information is out there in that environment, there is little control over it and it’s difficult to know who could access it or how it could be used.
  • Your PHI could be acquired by insurance companies or other healthcare companies that could use it against you in underwriting or pricing determinations. Who else would you not want knowing your private information? An employer? The possibilities are frightening, especially considering that once the information is out there, it’s out there. You can’t put the genie back in the bottle.

Conclusion


Telemedicine and the use of online applications has exploded in recent years, particularly in relation to the COVID pandemic and the resulting changes in the delivery of healthcare. The regulatory framework has not necessarily caught up to technology yet, so while HIPAA laws apply to some applications, many that are out there being used by consumers are not regulated in terms of protecting sensitive information. Health information can be bought and sold in the marketplace, it has a value for advertisers, thieves, and others.


For consumers, just be aware of the potential risks before you start using an app; check the app’s privacy and security policies and consider carefully what information you are comfortable exposing. If the app comes from your provider or insurance company, ask about the security controls and how they are protecting your data.


For providers, consider your own liability in terms of recommending an app and make sure your organization has done its due diligence to ensure proper security measures are in place. You should have your own privacy and security experts evaluate the tool before offering it to patients.


For app developers, be aware that technical security isn’t your only concern; you will want to have assistance from someone with healthcare privacy and security regulatory expertise. This will be something that potential clients and investors will be asking about.


Susan Walberg is a healthcare consultant who works with providers and healthcare start-ups. She can be reached at https://www.susanwalberg.com/

Read More