Quality
Quality

Coding Integrity and CAC

Why Quality Must Precede Compliance in Healthcare Documentation   

Written by Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE   

Computer-Assisted Coding, better known as “CAC” has become the norm over the past decade, but are we producing compliant, accurate results?  Compliance begins with quality. In the realm of clinical coding, that means ensuring that documentation tells the full story—and that the codes assigned accurately reflect that story. As CAC becomes more widespread, the need for trained human oversight becomes more critical, not less, which is the reason for this article.

Introduction

In today’s fast-paced healthcare environment, coding accuracy is often caught in the crossfire between compliance pressures, productivity demands, and evolving technology. While documentation may be clinically sound, coding associated with documentation can be misaligned or inaccurate, particularly when it is generated by CAC tools.  CAC can trigger regulatory scrutiny, revenue cycle inefficiencies, and reputational risk without verification by an experienced coding first. As a compliance specialist and educator, I contend that quality cannot be compromised for speed or convenience. In fact, quality is the cornerstone of compliance.

Healthcare consultants recently noted that “documentation is often accurate, but the coding is not,” underscoring a critical gap in the way organizations approach their revenue cycle and risk management. This article explores the current landscape of coding discrepancies, the limitations and risks of CAC, and the essential need for robust internal review processes.

The Disconnect Between Documentation and Coding

In many provider organizations, clinical documentation accurately reflects the patient’s story—diagnoses, treatments, and provider decision-making—but coding processes fall short. Coders may misinterpret documentation, overlook nuances, or rely too heavily on automation, leading to miscoded encounters that can have ripple effects across billing, audit, and quality reporting systems. When errors go undetected, the result can be upcoded services, denied claims, compliance violations, and patient safety concerns. According to the Office of Inspector General (OIG), improper payments stemming from inaccurate coding continue to plague the Medicare program, costing billions annually (OIG, 2023).

CAC: A Double-Edged Sword

Computer-assisted coding (CAC) software, designed to improve speed and efficiency, is now a common fixture in health information management. While these systems can process large volumes of data quickly, their reliance on algorithms rather than clinical reasoning poses significant challenges.

Research has shown that CAC tools may struggle to interpret context, such as distinguishing between active and historical conditions, or differentiating provider impressions from definitive diagnoses (AHIMA, 2022). Without skilled human oversight, these limitations result in critical coding inaccuracies. Unfortunately, some healthcare systems mistakenly treat CAC outputs as final codes without sufficient validation.

Quality needs to be the focus to meet compliance standards. CAC should be a tool to enhance human accuracy—not replace it.

Compliance Risks from Coding Discrepancies

Coding discrepancies—particularly those uncorrected in CAC workflows—are not simply operational issues; they are compliance risks. Auditors from CMS, OIG, and commercial payers increasingly target mismatches between documentation and billing codes. These discrepancies may be flagged as potential fraud, waste, or abuse.  Examples of common coding problems that trigger scrutiny include:

  • Upcoding or down coding visits that do not align with documentation
  • Inaccurate diagnosis coding affecting risk adjustment
  • Use of unspecified or non-supported codes
  • Failure to reflect clinical severity accurately

The DOJ's increased enforcement under the False Claims Act often centers on patterns of poor coding oversight. Healthcare entities must demonstrate that they are taking proactive steps to ensure coding integrity.

Quality as a Compliance Imperative

Ensuring the integrity of clinical coding isn’t just about reimbursement—it’s about compliance, patient care quality, and data accuracy. As healthcare moves toward value-based models, accurate coding supports correct risk adjustment, patient attribution, and performance measurement.

Implementing regular coding reviews, especially of CAC-assisted encounters, is a best practice that healthcare experts recommend. These reviews should be multidisciplinary, involving coding professionals, clinicians, and compliance officers. They help:

  • Identify patterns of misinterpretation or misclassification
  • Provide targeted coder education and clinical documentation improvement (CDI)
  • Verify whether CAC algorithms need adjustment or replacement

Quality assurance activities are not optional—they are essential to both ethical billing and regulatory compliance.

Balancing Productivity Pressures with Accuracy

It is well understood that providers are under immense pressure to manage high volumes of patients while fulfilling extensive documentation requirements. These constraints often lead to documentation fatigue and over-reliance on templated language or CAC tools.  However, automation cannot replace clinical judgment or attention to detail. Coders must be trained to spot subtle inconsistencies and to understand that their role is pivotal in compliance integrity. Likewise, providers need CDI support that makes documentation more efficient and accurate—not more burdensome.

Healthcare leaders should prioritize investments in coder training, CDI collaboration, and coding audits rather than shortcutting review processes for the sake of productivity.

Recommendations for Compliance-Driven Coding Integrity

To address the systemic risks tied to coding discrepancies and CAC errors, organizations should implement the following:

  1. Routine Internal Coding Audits: Conduct monthly or quarterly reviews of randomly selected encounters, with particular focus on high-risk services.
  2. Coder & Provider Education: Offer ongoing training on documentation standards, code selection, and regulatory updates.
  3. Review of CAC Outputs: Routinely validate CAC-generated codes against documentation. Never treat CAC outputs as final.
  4. Real-Time Feedback Loops: Encourage communication between CDI specialists, coders, and providers to resolve discrepancies quickly.
  5. Compliance-Focused KPI Tracking: Monitor error rates, denial trends, and audit findings to identify areas needing improvement.

Conclusion

Compliance begins with quality. In the realm of clinical coding, that means ensuring that documentation tells the full story—and that the codes assigned accurately reflect that story. As CAC becomes more widespread, the need for trained human oversight becomes more critical, not less.

Automation cannot replace accountability.

Compliance leaders must treat quality assurance and coding integrity as non-negotiable pillars of risk management. Let us not allow convenience to compromise compliance. Instead, let quality lead the way.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  1. American Health Information Management Association (AHIMA). (2022). The Realities of Computer-Assisted Coding. Retrieved from https://www.ahima.org
  2. Office of Inspector General (OIG). (2023). Medicare Improper Payment Reports. Retrieved from https://oig.hhs.gov
  3. Centers for Medicare & Medicaid Services (CMS). (2024). Evaluation and Management Services Guide. Retrieved from https://www.cms.gov
  4. U.S. Department of Justice. (2023). False Claims Act Settlements and Judgments Exceed $2 Billion in Fiscal Year 2023. Retrieved from https://www.justice.gov/opa/pr

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Compliance in Healthcare
Corporate Compliance

Understanding Whistleblower Protections in Healthcare

Legal Obligations and Compliance Implications  


Written by Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE   

The government’s new whistleblower complaint portal launched in April 2025 emphasizes the importance of complying with regulations related to qui tam suits, OCR investigations and protecting the rights of employees submitting a tip or complaint internally or to authorities. This article illustrates how certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation.

Introduction

Healthcare compliance professionals are often the first line of defense when systems break down. Understanding the interplay between legal protections and organizational ethics is vital—not only to ensure legal compliance, but also to foster environments where staff feel empowered and safe to report misconduct.

Whistleblowers are critical to protecting the integrity of healthcare delivery. When individuals report unsafe care, fraudulent billing, privacy violations, or ethical concerns, they help ensure accountability, uphold regulatory compliance, and safeguard patient welfare. For compliance professionals—particularly those working in environments regulated by Medicare, Medicaid, HIPAA, and federal contracts—it is essential to understand the scope and implications of whistleblower protections under current U.S. law.

This article explores the legal framework that underpins whistleblower protections, including the False Claims Act (FCA), HIPAA Privacy Rule exceptions, and National Defense Authorization Act (NDAA) provisions. It also highlights recent federal developments and compliance best practices to foster a culture of transparency and non-retaliation.

The False Claims Act and Qui Tam Provisions

For compliance departments, the implications of Qui Tam lawsuits extend far beyond financial penalties. They can lead to reputational harm, loss of patient trust, and stricter regulatory scrutiny. Therefore, proactive compliance programs must include regular audits, anonymous reporting options, and a culture that encourages early identification of potential violations.

The False Claims Act (31 U.S.C. §§ 3729–3733) is the federal government’s primary tool for combating fraud against public programs. Healthcare fraud accounts for a significant portion of FCA activity. Under its Qui Tam provision, private citizens—known as “relators”—can file lawsuits on behalf of the government when they have direct knowledge of fraudulent activities, such as billing for services not rendered or providing substandard care reimbursed by federal programs.

When the Department of Justice (DOJ) intervenes in these cases, whistleblowers may receive 15%–30% of recovered funds as a reward. In 2023 alone, the DOJ recovered over $1.8 billion from healthcare-related FCA cases, with whistleblower suits representing the vast majority of those recoveries.

Importantly, the FCA also prohibits retaliation. Section 3730(h) protects whistleblowers from termination, demotion, suspension, or harassment due to lawful acts in furtherance of a Qui Tam action or efforts to stop violations of the FCA.

HIPAA and Whistleblower Disclosures

Healthcare entities must train their workforce on the specific conditions under which PHI disclosures are permissible. Internal policies should not only comply with HIPAA but clarify what constitutes a 'good faith belief' and ensure disclosures are directed to appropriate oversight entities.

While the Health Insurance Portability and Accountability Act (HIPAA) is typically associated with patient privacy, it also contains important exceptions that protect whistleblowers. Under 45 CFR § 164.502(j), a workforce member may disclose protected health information (PHI) if:

  1. They believe in good faith that the covered entity has engaged in conduct that is unlawful or otherwise violates clinical standards; and
  2. The disclosure is made to a healthcare oversight agency, public health authority, law enforcement agency, attorney, or accreditation organization.

This clause is critical for compliance officers to understand, especially when investigating disclosures involving PHI. Any internal policy must clearly explain the scope of permissible disclosures and educate staff on when HIPAA permits these exceptions.

NDAA Protections and the Role of Contractors

The National Defense Authorization Act (NDAA) of 2013 (41 U.S.C. § 4712) expanded whistleblower protections to employees of federal contractors, grantees, and subcontractors, which includes many healthcare providers receiving federal funds. Under this statute, employees are protected from reprisal for reporting gross mismanagement, fraud, abuse of authority, or dangers to public health and safety.

Notably, these protections apply even if the employee discloses information outside of the organization, including to Congress, an Inspector General, or a federal employee responsible for contract oversight.

Compliance officers working with contractors should incorporate NDAA requirements into onboarding and ethics training materials. Additionally, contract language should affirm non-retaliation protections and clarify processes for raising concerns externally.

Recent Developments: HHS Whistleblower Portal and Enforcement

On April 14, 2025, the U.S. Department of Health and Human Services (HHS) launched a new whistleblower complaint portal specifically designed to receive reports of potential harm to children, including medically controversial treatments involving minors.

This new government portal signals increased federal oversight in how healthcare institutions respond to ethical and religious concerns raised by employees and demonstrates the government’s increased commitment to ensuring that providers and institutions uphold safety, informed consent, and respect for medical ethics.

This tool may also be used to identify systemic gaps in institutional policies around consent, safety, and staff protections.

In a notable case publicized by HHS, a hospital faced sanctions for terminating a nurse who refused to participate in a pediatric procedure due to her religious beliefs. HHS concluded that the hospital violated federal conscience protections, highlighting the intersection of whistleblower law, employment rights, and provider conscience protections.

Such scenarios highlight the importance of thorough documentation and timely response by compliance departments. Independent reviews of whistleblower complaints, performed by third-party investigators or ombudspersons, can enhance transparency and fairness in case handling.

Consider a hypothetical but realistic scenario

  • A behavioral health technician reports unsafe restraint practices involving minors in a residential facility.
  • Shortly after filing the internal report, the technician is placed on administrative leave and subsequently terminated.
  • The technician files a complaint under both the FCA and state labor law.
  • The investigation reveals that internal reports were not documented properly, retaliation safeguards were not in place, and training on non-retaliation was outdated.

This case underscores the need for compliance programs to ensure proactive risk mitigation, thorough documentation, and a robust culture of safety and transparency.

The Compliance Officer’s Role: Promoting a Speak-Up Culture

Organizations should periodically evaluate the effectiveness of their whistleblower protection efforts through anonymous staff surveys, incident response audits, and tracking the outcomes of reported concerns. This proactive approach signals to staff that leadership values integrity and transparency.

Certified compliance professionals play a pivotal role in protecting whistleblowers and preventing retaliation. Organizations must go beyond policy documents and invest in cultural and procedural safeguards:

- Establish and communicate clear non-retaliation policies.
- Train all employees and leadership on reporting rights and retaliation indicators.
- Maintain multiple confidential channels for reporting concerns.
- Ensure prompt and fair investigation of all complaints.
- Audit for compliance with whistleblower protection policies.

Conclusion

Ultimately, the goal of any whistleblower protection program is not merely compliance, but the cultivation of an ethical culture that consistently does what is right—even when it is inconvenient or uncomfortable. This requires leadership buy-in, staff empowerment, and a long-term commitment to transparency.

Whistleblower protections are more than legal requirements—they are pillars of ethical healthcare. Laws like the FCA, HIPAA, and NDAA empower individuals to report wrongdoing without fear. Compliance professionals must champion these safeguards, not only to avoid legal liability but to protect patient welfare, support employee integrity, and sustain organizational trust.

As regulatory enforcement intensifies and new federal protections emerge, healthcare organizations must remain vigilant, proactive, and transparent. The call to protect whistleblowers is not just a mandate—it is a moral and professional imperative.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance.  Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References

  • U.S. Department of Health and Human Services (HHS). (2025). New Whistleblower Guidance and Complaint Portal. Retrieved from https://www.hhs.gov/protect-kids
  • 31 U.S.C. §§ 3729–3733, False Claims Act (FCA).
  • 31 U.S.C. § 3730(h), Anti-Retaliation Protections under the FCA.
  • 45 CFR § 164.502(j), Whistleblower Disclosures under the HIPAA Privacy Rule.
  • National Defense Authorization Act (NDAA) of 2013, 41 U.S.C. § 4712.
  • Office for Civil Rights (OCR), HHS. (2025). Press release on hospital investigation, April 14, 2025.
  • American Institute of Healthcare Compliance (AIHC). (2025). Newsblast: New Whistleblower Complaint Portal.

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Part 2: Who Regulates Healthcare AI?

Artificial Intelligence & Regulatory Compliance


Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article follows Part 1 - Basics of Artificial Intelligence (AI) and Healthcare Compliance published by AIHC on June 6, 2023.  AI is advancing rapidly, so we encourage you to reference the new Artificial Intelligence article category for the latest articles.  As stated in Part 1, the Office of the National Coordinator for Health Information Technology (ONC) and the Agency for Healthcare Research and Quality (AHRQ), with support from the Robert Wood Johnson Foundation, turned to an independent group of scientists and academics to consider how AI might shape the future of public health, community health, and healthcare delivery.  The question remains, how will the use of AI be regulated for health care use?


Artificial Intelligence/Machine Learning has gained heightened attention globally.  Augmented Intelligence has been embraced as a concept by physician organizations to underscore that emerging AI systems are designed to aid humans in clinical decision-making, implementation and administration to scale healthcare, according to Act Online Key Terminology for AI in Health.


Although the United States is making progress in developing domestic AI regulation, including with the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the existing laws and regulations that apply to AI systems is still a work-in-progress.  The goals are to protect people from unsafe or ineffective systems. 


So, Who Regulates Healthcare AI?


What seems like a simple question is really a complex situation.  This article only scratches the surface of various regulatory agencies involved in the regulation of AI.  The Health & Human Services (HHS) response to OMB Memorandum 21-06 “Guidance for Regulation of Artificial Intelligence Applications” was drafted in November 2020 and is directed to the heads of all Executive Branch departments and agencies, including independent regulatory agencies.  Much has happened since then.


On April 25, 2023, the Federal Trade Commission (FTC), the Civil Rights Division of the U.S. Department of Justice (DOJ), the Consumer Financial Protection Bureau (CFPB), and the U.S. Equal Employment Opportunity Commission (EEOC) released a joint statement highlighting their commitment to "vigorously use [their] collective authorities to protect individuals" with respect to artificial intelligence and automated systems (AI), which have the potential to negatively impact civil rights, fair competition, consumer protection, and equal opportunity.


The joint statement from the DOJ, FTC, CFPB, and EEOC signifies a growing awareness and concern among federal agencies about the potential risks and challenges posed by AI and automated systems. As AI continues to become more integrated into all aspects of daily life, the importance of addressing potential biases, transparency issues, and flawed design becomes increasingly critical.


Federal Trade Commission (FTC) Raises Concerns


The FTC’s mission is to protect consumers and competition through preventing anticompetitive, deceptive and unfair business practices.  This is achieved through law enforcement, advocacy, and education without unduly burdening legitimate business activity.  The FTC Act’s prohibition on deceptive or unfair conduct can apply if you make, sell, or use a tool that is effectively designed to deceive – even if that’s not its intended or sole purpose. The FTC’s action should help protect healthcare organizations by limiting deceptive or exaggerated promises of what a medical device or AI software can actually do.  It’s not uncommon for advertisers to say that some new-fangled technology makes their product better – perhaps to justify a higher price or influence labor decisions.


On May 18, 2023, the FTC issued a warning that the increasing use of consumers’ biometric information and related technologies, including those powered by machine learning, raises significant consumer privacy and data security concerns and the potential for bias and discrimination. Biometric information refers to data that depict or describe physical, biological, or behavioral traits, characteristics, or measurements of or relating to an identified or identifiable person’s body.


The Federal Drug Administration & AI


The Food & Drug Administration (FDA) released a discussion paper in 2019 and then an action plan on January 21, 2021 regarding Artificial Intelligence and Machine Learning, or AI/ML.  This action plan describes a multi-pronged approach to advance the Agency’s oversight of AI/ML-based medical software.  Then, in April 2023, the FDA is publishing a draft guidance, "Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence/Machine Learning (AI/ML)-Enabled Device Software Functions."

  • This draft guidance proposes a science-based approach to ensuring that AI/ML-enabled devices can be safely, effectively, and rapidly modified, updated, and improved in response to new data.

The approach the FDA is proposing in this draft guidance would put safe and effective advancements in the hands of health care providers and users faster, increasing the pace of medical device innovation in the United States and enabling more personalized medicine.

  • This means, for example, that diagnostic devices could be built to adapt to the data and needs of individual health care facilities and that therapeutic devices could be built to learn and adapt to deliver treatments according to individual users' particular characteristics and needs.

National Institute of Standards and Technology (NIST) AI Risk Management Framework


Released on January 26, 2023, NIST’s AI Risk Management Framework or “AI RMF” which is intended to be used voluntarily to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.  The Framework was developed through a consensus-driven, open, transparent, and collaborative process with the intention to build on, align with, and support AI risk management efforts by others.


Recently NIST launched the Trustworthy and Responsible AI Resource Center (AIRC), which will facilitate implementation of, and international alignment with, the AI RMF.  We recommend watching the introduction video:  https://www.nist.gov/video/introduction-nist-ai-risk-management-framework-ai-rmf-10-explainer-video


For healthcare HIPAA covered entities, NIST is likely a familiar organization to you.  NIST published prior documents related to AI.  The initial draft of the AI RMF was published March 17, 2022 and a second draft on August 18, 2022.


The Health Insurance Portability and Accountability Act (HIPAA)

Public Law 104-191


The Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Privacy and Security Rules (45 C.F.R. Parts 160 and 164, Subparts A, C, and E). One of the ways that OCR carries out this responsibility is to investigate complaints.  As health care organizations evolve with the use of AI, there is increased potential for cyber criminals to exploit vulnerabilities.


At the present, there are two exclusions existing in the HIPAA Privacy Rule that allow Covered Entities to share Protected Health Information (PHI) with device vendors and other organizations without the authorization of the individual(s) to whom the PHI relates. The two exclusions can be found in 45 CFR §164.512(b)(1) and 45 CFR §164.512(i)(1). Respectively, they relate to:

  • Disclosures to vendors regulated by the Federal Drug Administration are permitted by the Privacy Rule for the “purpose of activities related to the quality, safety or effectiveness of such FDA-regulated product or activity”.   The FDA regulates the sale of all medical device products, including personal health devices that transmit data to AI-driven healthcare solutions as described above.
  • PHI can also be disclosed without authorization for research purposes without being de-identified if the disclosure is approved by an Institutional Review Board or Privacy Board. In such circumstances, the disclosed PHI must remain in the possession of the Covered Entity and the disclosure(s) can only be for the purpose of preparatory research (i.e., programming a “Supervised Learning Algorithm”).


Conclusion


Simply stated, a shift to AI calls for new skills.  It warrants increased knowledge of HIPAA privacy, security and anticipating other legal issues surrounding it’s use in healthcare.


Needless to say, it is important to maintain a robust HIPAA program and utilize information from the National Institute of Standards and Technology (NIST) AI Risk Management Framework as mentioned above.


In the context of HIPAA, healthcare data, and AI technologies, AI developers and vendors should consider that HIPAA only provides a federal floor of privacy and security standards. Often, other state and federal laws can apply that pre-empt HIPAA – particularly with regard to healthcare adjacent data – or apply to more organizations than Covered Entities and Business Associates.  Also, many Managed Service Providers (MSP) companies providing services to healthcare organizations should be aware of AI applications and security vulnerabilities.


If your organization plans or is using AI for medical diagnostics, reference the annual joint publication by the U.S. Government Accountability Office (GAO) and the National Academy of Medicine published each September entitled “Technology Assessment – Artificial Intelligence in Health Care – Benefits and Challenges of Machine Learning Technologies for Medical Diagnostics”.   A new publication is posted each year: https://www.gao.gov/products/gao-22-104629


AIHC will continue to post articles related to artificial intelligence with regards to healthcare compliance.  Click Here for additional articles on various HIPAA topics.  Click Here for articles relating to Artificial Intelligence. Visit the AIHC Certifications page with online compliance learning opportunities.

Read More
Release of Information
HIPAA, Release of Information

OCR Enforcement of HIPAA Right of Access and Release of Information (ROI)

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The article addresses the HIPAA Privacy Rule for Covered Entities regarding time limitations to respond to an individual’s request for access of protected health information or “PHI.” This article is not all inclusive and should not be used as legal or consulting advice. Scroll down for hyperlinks to free and low-cost training related to Right of Access & ROI.



What Is HIPAA Right of Access?


The HIPAA Privacy Rule generally provides individuals with a legal, enforceable right to see and receive copies, upon request, of the information in their medical and other health records maintained by their health care providers and health plans. This right is known as the HIPAA Right of Access.


HIPAA Right of Access policies have evolved over the years to ensure that patients have equitable access to their medical records. HIPAA requires covered entities to provide patients with access to their medical records. The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009, helped right of access policies evolve to reflect the growing use of EHR systems.


HIPAA Enforcement


HIPAA compliance it monitored by the Health & Human Services (HHS) enforcement agency, the Office for Civil Rights (OCR). The Office for Civil Rights is responsible for enforcing the Privacy and Security Rules. Enforcement of the Privacy Rule began April 14, 2003, for most HIPAA covered entities. Since 2003, OCR's enforcement activities have obtained significant results that have improved the privacy practices of covered entities. OCR also works in conjunction with the Department of Justice (DOJ) to refer possible criminal violations of HIPAA.


In 2019, the OCR launched the HIPAA Right of Access Initiative to advocate for individuals trying to obtain their health records in a timely manner at a reasonable cost as required by covered entities in the HIPAA Privacy Rule.


Complying With the HIPAA Privacy Right of Access Rule


If your organization is not responding timely to requests for medical records, a complaint to the Office for Civil Rights can trigger an investigation resulting in fines and other consequences, such as being posted on the OCR HIPAA website and a forced Corrective Action Plan.


A dedicated government webpage lists HIPAA News Releases & Bulletins listing OCR cases after investigating organizations which includes Right of Access settlements. Click Here to access this page. https://www.hhs.gov/hipaa/newsroom/index.html


The July 15, 2022, Health & Human Services (HHS) Press Release announces the resolution of eleven investigations and the enforcement actions taken with these eleven organizations related to violations of patient’s rights under HIPAA. In this press release the OCR Director Lisa J. Pino states:


“It should not take a federal investigation before a HIPAA covered entity provides patients, or their personal representatives, with access to their medical records. Health care organizations should take note that there are now 38 enforcement actions in our Right of Access Initiative and understand that OCR is serious about upholding the law and peoples’ fundamental right to timely access to their medical records.”

 

So, how timely must a covered entity be in responding to individuals’ requests for access to their PHI?


This is addressed under 45 CFR 164.524(b)(2) of the HIPAA Privacy Rule regarding access of individuals to protected health information (PHI). Under the HIPAA Privacy Rule, a covered entity must act on an individual’s request for access no later than 30 calendar days after receipt of the request.


If the covered entity is not able to act within this timeframe, the entity may have up to an additional 30 calendar days as long as it provides the individual, within that initial 30-day period, a written statement of the reasons for the delay and date when the entity will complete its action on the request. The 30-day timeline applies regardless of the following circumstances:

  • The PHI that is the subject of the request is maintained by the covered entity or by a business associate on behalf of the covered entity, or the covered entity uses a business associate to fulfill individual requests for access.

o The 30-day clock starts on the date that the covered entity receives a request for access, so any delay in obtaining the necessary information from a business associate or forwarding the request to the business associate for action “uses up” part of the allotted time.


o Alternatively, the 30-day clock starts when, instead of the covered entity, a business associate receives a request directly from an individual because the covered entity instructed the individual through its notice of privacy practices (or otherwise) to submit the access request directly to its business associate for processing. 

  • The covered entity negotiates with the individual on the format of the response. Covered entities that spend significant time before reaching agreement with individuals on format are depleting the 30 days allotted for the response by that amount of time.

  • The PHI that is the subject of the request is old, archived, and/or not otherwise readily accessible.

As noted by OCR, these timelines are outer limits. The government expects that covered entities should be able to respond to requests for access well before these outer limits are reached. However, in cases where a covered entity is aware that an access request may take close to these outer time limits to fulfill, the entity is encouraged to provide the requested information in pieces as it becomes available, if the individual indicates a desire to receive the information in this manner.


Resources to Comply With ROI and Right of Access


Learn more about 45 CFR § 164.524 - Access of individuals to protected health information. Free and reasonably priced training for you and your workforce is listed below:


Right of Access Specialist - Online Course

AIHC HIPAA Compliance Training Videos Free

Legal Information Institute (Cornell Law School) Free

HIPAA Online Privacy Course (Earn 12 AIHC and AHIMA CEUs)

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Update on No Surprises Act 2022

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




As a result of the 2021 Consolidated Appropriations Act, several No Surprises Billing Act regulations went into effect on January 1, 2022, for providers, facilities and air ambulance services. The information below is not legal or consulting advice, but is provided as education and offers links to additional resources.


Starting January 1, 2022, the No Surprises Act protects people covered under group and individual health plans from receiving surprise medical bills when they receive most emergency services, non-emergency services from out-of-network providers at in-network facilities, and services from out-of-network air ambulance service providers.


This article is a follow up to the August 17, 2021, Sending “Surprise” Medical Bills to Patients? Think Again blog post related to the January 1, 2022, implementation of the Interim Final Rule (IFR) of the No Surprises Act. The new law provides consumers with federal protection from unexpected out-of-network medical bills.


Out-of-network charges are common in emergency care, where consumers don’t necessarily have a choice in where they go or who provides their care. These charges can also arise during non-emergency hospitalizations, where multiple providers may be involved in care. Even if a hospital participates in a patient’s insurance plan, specific providers, such as anesthesiologists or radiologists, may not. Consumers may have no idea that they’re getting care from out-of-network providers and no say in it either.


A news release from November 22, 2021, entitled New HHS Report Highlights How the No Surprises Act Will Prevent Surprise Medical Bills Faced by Millions of Americans highlights that millions of Americans with private health insurance experience some kind of surprise medical billing. The report states that surprise medical bills are relatively common among privately-insured patients and can average more than $1,200 for services provided by anesthesiologists, $2,600 for surgical assistants, and $750 for childbirth-related care.


The No Surprises Act establishes an independent dispute resolution process for payment disputes between plans and providers, and provides new dispute resolution opportunities for uninsured and self-pay individuals when they receive a medical bill that is substantially greater than the good faith estimate they got from the provider. These don’t apply to people with coverage through programs like Medicare, Medicaid, Indian Health Services, Veterans Affairs Health Care, or TRICARE. These programs have other protections against high medical bills.


Well, 2022 is here and it is time for EMS, hospitals and other emergency service departments to comply with the No Surprises Act. This can get complicated when meshing this Act with the Emergency Medical Treatment and Labor Act (EMTALA) imposing restrictions on obtaining patient financial or insurance status. The question – how can providers best manage EMTALA, Crisis Standards of Care (CSC), the pandemic and adhere to the new No Surprises Act?


First, it is important to have providers and other staff involved in patient care understand some of the more critical aspects of EMTALA. EMTALA requires Medicare-participating hospitals with emergency departments to screen and treat the emergency medical conditions of patients in a non-discriminatory manner to anyone, regardless of their ability to pay, insurance status, national origin, race, creed or color.


EMTALA is triggered whenever a patient presents to the hospital campus, not just the physical space of the ED but within 250 yards of the hospital. Patients who present to a hospital parking lot, sidewalks, and adjacent medical buildings are mandated to undergo EMTALA screening and stabilization. The provisions of EMTALA apply to all individuals (not just Medicare beneficiaries) who attempt to gain access to a hospital for emergency care.


The Centers for Medicare and Medicaid Services (CMS) defines a dedicated emergency department as “a specially equipped and staffed area of the hospital used a significant portion of the time for initial evaluation and treatment of outpatients for emergency medical conditions.”


EMTALA requires hospitals with emergency departments to provide a medical screening examination to any individual who comes to the emergency department and requests such an examination, and prohibits hospitals with emergency departments from refusing to examine or treat individuals with an emergency medical condition. The term “hospital” includes critical access hospitals.


This means, for example, that hospital-based outpatient clinics not equipped to handle medical emergencies are not obligated under EMTALA and can simply refer patients to a nearby emergency department for care. Typically, outpatient physician offices that do not have resources to stabilize critically ill patients are not required to perform a medical screening examination or stabilization before transferring the patient to an ED. In other words, patients who are part of an outpatient encounter are exempt from these EMTALA regulations. However, the No Surprises Act can still apply to services rendered by your provider.


When a patient has a health insurance Marketplace or individual health plan, the new Act applies as follows (this is a summary):

  • Bans surprise bills for most emergency services, even if rendered out-of-network and without approval beforehand (prior authorization);
  • Bans out-of-network cost-sharing (like out-of-network coinsurance or copayments) for most emergency and some non-emergency services. Patients can’t be charged more than in-network cost-sharing for these services;
  • Bans out-of-network charges and balance bills for certain additional services (like anesthesiology or radiology) furnished by out-of-network providers as part of a patient’s visit to an in-network facility; and
  • Requires that health care providers and facilities give patients an easy-to-understand notice explaining the applicable billing protections, who to contact for concerns that a provider or facility has violated the protections, and that patient consent is required to waive billing protections (i.e., patient must receive notice of and consent to being balance billed by an out-of-network provider).

Patient has no insurance? In most cases, a good faith estimate of how much the care will cost needs to be provided to the self-pay patient prior to rendering such care.


State Billing Laws Still Apply


The No Surprises Act supplements state surprise billing laws; it does not supersede them.


This new Act instead creates a “floor” for consumer protections against surprise bills from out-of-network providers and related higher cost-sharing responsibility for patients. So as a general matter, as long as a state’s surprise billing law provides at least the same level of consumer protections against surprise bills and higher cost-sharing as does the No Surprises Act and its implementing regulations, the state law generally will apply.


For example, if your state operates its own patient-provider dispute resolution process that determines appropriate payment rates for self-pay consumers and Health and Human Services (HHS) has determined that the state’s process meets or exceeds the minimum requirements under the federal patient-provider dispute resolution process, then HHS will defer to the state process and would not accept such disputes into the federal process.


Is Your Organization Prepared?


A violation of the No Surprises Act may result in a state enforcement action or federal civil monetary penalties of up to $10,000 per violation.


Know the plans your organization is in-network with – create a “grid” or listing for reference and keep it updated.


Know your state laws and when Federal laws supersede state rules. Contact your risk attorney through your malpractice insurance company for guidance which is obtained through no additional cost (part of the service you get when paying the insurance premium).


Identify eligible cases. The Act applies to post-stabilization care at out-of-network facilities until a patient can be safely transferred to an in-network facility. Nonparticipating providers and facilities may balance bill for post stabilization services only if all of the following conditions have been met, such as when the attending emergency physician or treating provider determines that the beneficiary, enrollee or participant:

  1. Can travel using non-medical or non-emergency medical transportation to an available participating provider or facility located within a reasonable travel distance, taking into account the individual’s medical condition; and
  2. Is in a condition to receive notice and provide informed consent.
  3. The nonparticipating provider or facility provides the beneficiary, enrollee or participant with a written notice and obtains consent that includes certain content and within a specific timeframe and format outlined in regulation and guidance.
  4. The provider or facility satisfies any additional state law requirements

Make sure revenue cycle workforce members understand EMTALA compliance and can identify out-of-network situations or when the patient is self-pay. 


Implement an efficient and compliant method of providing a good faith estimate. The good faith estimate must include expected charges for the items or services that are reasonably expected to be provided in conjunction with the primary item or service, including items or services that may be provided by other providers and facilities.

  • From January 1, 2022, through December 31, 2022, HHS will exercise its enforcement discretion in situations where a good faith estimate provided to an uninsured (or self-pay) individual does not include expected charges from other providers and facilities that are involved in the individual’s care.

Download the CMS Model Notice and Consent forms.


Your revenue cycle department should have someone already trained to negotiate with out-of-network payers. The first step is to actively negotiate with insurance the highest reimbursement possible since you can no longer balance bill the patient. Are you utilizing Advanced Explanation of Benefits in plain language to provide good faith estimates? Track results – are your processes working? 


Identifying No Balance Billing for Out-of-Network Emergency Service Definitions


Emergency services

With respect to an emergency medical condition, appropriate medical screening including ancillary services, medical examination and treatment required to stabilize the patient, and certain post-stabilization services associated with the emergency medical condition that are covered under the plan or coverage, unless certain notice and consent and other criteria are met.


Emergency medical condition

A medical condition, including a mental health condition or substance use disorder, manifesting itself by acute symptoms of sufficient severity (including severe pain) such that a prudent layperson, who possesses an average knowledge of health and medicine, could reasonably expect the absence of immediate medical attention to result in a condition that places the health of the individual in serious jeopardy, serious impairment to bodily functions, or serious dysfunction of any bodily organ.


Nonparticipating emergency facility

An emergency department of a hospital or an independent freestanding emergency department (or a hospital with respect to post stabilization services) that does not have a contractual relationship directly or indirectly with a group health plan or group or individual health insurance coverage, with respect to the furnishing of an item or service under the plan or coverage.


Nonparticipating provider

Any physician or other health care provider who does not have a contractual relationship directly or indirectly with a group health plan or group or individual health insurance coverage, with respect to the furnishing of an item or service under the plan or coverage.


Participating health care facility

Any health care facility that has a contractual relationship directly or indirectly with a group health plan or health insurance issuer offering group or individual health insurance coverage, with respect to the furnishing of an item or service under the plan or coverage.


Definitions Related to Continuity of Care When Provider Network Status Changes

Continuing care patient - an individual who:

  1. is undergoing a course of treatment for a serious and complex condition from the provider or facility;
  2. is undergoing a course of institutional or inpatient care from the provider or facility;
  3. is scheduled to undergo non-elective surgery from the provider, including receipt of postoperative care with respect to such surgery;
  4. is pregnant and undergoing a course of treatment for the pregnancy from the provider or facility; or
  5. was determined to be terminally ill and is receiving treatment for such illness from the provider or facility.

Serious and complex condition definition:

  1. in the case of an acute illness, a condition that is serious enough to require specialized medical treatment to avoid the reasonable possibility of death or permanent harm; or
  2. in the case of a chronic illness or condition, a condition that

a) is life-threatening, degenerative, potentially disabling or congenital; and

b) requires specialized medical treatment over a prolonged period of time.


Questions?

Send any questions about the provider requirements and provider enforcement to:

provider_enforcement@cms.hhs.gov


Resources

Read More
HIPAA Compliance
HIPAA

Is Sharing EHR Passwords a Problem?

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article addresses the importance of Electronic Health Record (EHR) security to help health care organizations, health plans, clearinghouses (Covered Entities) and their business associates avoid HIPAA violations under the Security Rule Standard § 164.312(a)(1). To obtain more information about mitigating the risk of a HIPAA violation, please consult with legal counsel or a HIPAA Security Consultant. 

 

What If . . .

 

What would happen if you shared your login and password to your online bank account? How about sharing the password to access your credit cards? How would you feel if you knew your doctor shared his/her password to your personal medical records with an unauthorized user? What if someone in medical billing shared his/her password to your account (containing your medical and financial identity) with someone not authorized to access your information?


What If EHR Passwords Are Shared . . .


Electronic health records (EHRs) incorporate a vast amount of patient information and diagnostic data, most of which is considered protected health information. With the advancement of technology, the emergence of advanced cyber threats has escalated, which hinders the privacy and security of health information systems such as EHRs.


As defined by the Center of Medicare and Medicaid Services (CMS), “An electronic health record (EHR) is an electronic version of a patient’s medical history, that is maintained by the provider over time, and may include all of the key administrative clinical data relevant to that person’s care under a particular provider, including demographics, progress notes, problems, medications, vital signs, past medical history, immunizations, laboratory data and radiology reports.”


Because this protected information and data can easily get into the wrong hands, individuals should not share passwords with anyone.  


Is This Really a Problem? Doesn’t Everyone Share Passwords?


Due to the sensitive nature of the information stored within EHRs, several security safeguards have been introduced through the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.


Prevalence of Sharing Access Credentials in Electronic Medical Records

To summarize an abstract published by PMC (Public Med Central) of the U.S. National Institutes of Health’s National Library of Medicine, it was found that to prevent data leakage, many countries have created regulations regarding medical data accessibility. These regulations require a unique user ID for each medical staff member, and this must be protected by a password, which should be kept undisclosed by all means. A survey was conducted with the following results:

  • A total of 299 surveys were gathered.
  • The responses showed that 220 (73.6%) participants reported that they had obtained the password of another medical staff member.
  • Only 171 (57.2%) estimated how many times it happened, with an average estimation of 4.75 episodes. All the residents that took part in the study (45, 15%) had obtained the password of another medical staff member, while 57.5% (38/66) of nurses reported this.

Their conclusion from this study: the use of passwords is doomed because medical staff members share their passwords with one another. Strict regulations requiring each staff member to have a unique user ID might lead to password sharing and to a decrease in data safety. Click Here to access the full study.


Remember to Comply With the 3 Pillars of Securing ePHI


The three pillars to securing protected health information outlined by HIPAA are administrative safeguards, physical safeguards, and technical safeguards. These three pillars are also known as the three security safeguard themes for healthcare. These themes range from techniques regarding the location of computers to the usage of firewall software to protect health information. A brief list of the HIPAA Security Safeguards:

  • Access control (technical safeguard) is a technique that prevents or limits access to an electronic resource. The intent behind access control techniques is to limit access to only authorized parties. The healthcare facility collects, stores, and secures patients’ data, which is very sensitive. This safeguard can take the form of role-based access control, attribute-based access control, and identity-based access control. Role-based refers to a person’s role in the healthcare facility. For instance, when a provider begins working at a healthcare facility, he/she has access to patient data, but only the patient data for his/her patients. If this provider also serves on a certain committee in the hospital, then another set of privileges is created to enable access to committee resources. When other data is accessed, a log is created that is periodically audited. When a front-desk clerk begins working in a facility, he/she has no reason to access clinical data, but may need access to the administrative data such as address and phone number, depending on the role that the person plays in the organization. Other names for this are media controls, entity authentication, encryption, firewall, audit trails, virus checking, and packet filtering.
  • Physical access control (physical safeguard) is a technique that prevents or limits physical access to resources. The intent of this control is similar to the technical safeguard: It limits access to only authorized parties. A patient in a facility will not have access to any clinic or ward except the one he/she is seen in. A front-desk clerk in the optometry clinic will not typically need access to the emergency room, so his/her access card will not open those doors. A provider in a facility will not typically need access to the server room, so his/her access card will not unlock those doors. Other names for this are physical security, (some) workstation security, assigned security responsibility, media controls (access cards), and physical access control.
  • Administrative safeguards are techniques that are not entirely technical or physical, but may contain a piece of each. These safeguards typically take the form of policies, practices, and procedures in the facility to regularly check for vulnerabilities and continually improve the security posture of the organization. Other names for this control are risk analysis and management, system security evaluation, personnel chosen for certain roles, contingency, business continuity, and disaster recovery planning.

When Someone Shares a Password – It Is a HIPAA Violation Under the HIPAA Security Rule – Technical Safeguard Related to Access Controls. 

 

The Security Rule defines access in § 164.304 as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subpart E of this part [the HIPAA Privacy Rule]).” Access controls provide users with rights and/or privileges to access and perform functions using information systems, applications, programs, or files. Access controls should enable authorized users to access the minimum necessary information needed to perform job functions. Rights and/or privileges should be granted to authorized users based on a set of access rules that the covered entity is required to implement as part of § 164.308(a)(4), the Information Access Management standard under the Administrative Safeguards section of the Rule.


Unique User Identification Requirement - § 164.312(a)(2)(i)

 

The Unique User Identification implementation specification states that a covered entity must: “Assign a unique name and/or number for identifying and tracking user identity.”


User identification is a way to identify a specific user of an information system, typically by name and/or number. A unique user identifier allows an entity to track specific user activity when that user is logged into an information system. It enables an entity to hold users accountable for functions performed on information systems with ePHI when logged into those systems using audit trails (addressed toward the end of this article).


Regardless of the technology or information system used, access controls should be appropriate for the role and/or function of the workforce member. For example, even workforce members responsible for monitoring and administering information systems with electronic protected health information or ePHI, such as administrators or super users, must only have access to ePHI as appropriate for their role and/or job function.


Sample questions for covered entities to consider:

  • Does each workforce member have a unique user identifier?
  • What is the current format used for unique user identification?
  • Can the unique user identifier be used to track user activity within information systems that contain ePHI?

So, What Can Happen If We Have Insufficient ePHI Access Controls?

Violating HIPAA law 104-191 can be costly. The HIPAA Security Rule requires covered entities and their business associates to limit access to ePHI to authorized individuals. The failure to implement appropriate ePHI access controls is also one of the most common HIPAA violations and one that has caused financial penalties. 


Financial penalties issued to covered entities for ePHI access control failures include:


Anthem Inc. – $16,000,000 penalty for access control failures and other serious HIPAA violations

OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations

OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations

University of California Los Angeles Health System – $865,500 penalty for the failure to restrict access to medical records

Colorado Medical Center – $111,400 penalty for the failure to terminate access to ePHI after an employee termination and a lack of a business associate agreement

Controlling Access to ePHI: For Whose Eyes Only?


The government HIPAA privacy/security enforcement agency is the Office for Civil Rights (OCR). OCR published the Summer 2021 Cybersecurity Newsletter on July 14, 2021, which states:


The rise in data breaches due to hacking as well as threats to ePHI by malicious insiders highlight the importance of establishing and implementing appropriate policies and procedures regarding these Security Rule requirements. Ensuring that workforce members are only authorized to access the ePHI necessary and that technical controls are in place to restrict access to ePHI can help limit potential unauthorized access to ePHI for both threats.


A recent report of security incidents and data breaches found that 61% of analyzed data breaches in the healthcare sector were perpetrated by external threat actors and 39% by insiders.


Without appropriate authorization policies and procedures and access controls, hackers, workforce members, or anyone with an Internet connection may have impermissible access to the health data, including protected health information (PHI), that HIPAA regulated entities hold. News stories and OCR investigations abound of hackers infiltrating information systems, workforce members impermissibly accessing patients’ health information, and electronic PHI (ePHI) being left on unsecured servers.


Information Access Management and Access Control are two HIPAA Security Rule standards that govern access to ePHI.


Download this newsletter:

Monitor Audit Trails


Audit trails automatically register and record where, when and who accessed the system. They also record what users do when they access the system. This tracks every change in patients’ information and documents it.


Since all the data is logged in the EHR system, it enables users to review the data at regular intervals and flag activities that seem suspicious. Regular reviews can also help correct mistakes caused by human error that could be flagged as a HIPAA violation. An audit trail answers the following:

  • Which patients’ data was accessed?
  • What time was it accessed?
  • Who retrieved the data?
  • Where was the data accessed from?

EHR software can also be set to send notifications to patients when their information is accessed. This way patients can report breaches as soon as they happen.


Conclusion


Create strong policies and procedures, then communicate these rules to your workforce. Enforce compliance through auditing and monitoring. Explain that when an individual allows another to use his/her password to access ePHI, that individual can alter and perform unauthorized functions and not be held accountable. The audit trail points back to the person who is assigned that password. 


Conduct on-going training of your workforce, which needs to include your C-Suite executives (who are not exempt from the rules). To gain the BEST results, conduct additional quarterly training with your front-line managers and supervisors.  Give them tools to incorporate HIPAA training at EVERY department meeting. If you think annual HIPAA training is sufficient, then you simply are not doing enough to protect your patient’s ePHI.


Additional Resources


Weekly HIPAA Podcasts (free) at:

OCR “The Security Rule” on the HHS website:

Train Online in HIPAA Privacy & Security:

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Sending “Surprise” Medical Bills to Patients? Think Again

Written By: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




Government Announces the No Surprises Act to Protect Patients


"Requirements Related to Surprise Billing; Part I" is an interim final rule related to Title I (the No Surprises Act) targeting health care providers with the purpose of restricting excessive out of pocket costs to consumers from surprise billing and balance billing. Balance billing, when a provider charges a patient the remainder of what their insurance does not pay, is currently prohibited in both Medicare and Medicaid. This rule will extend similar protections to Americans insured through employer-sponsored and commercial health plans. 


Most of us love surprises, but not when it comes to devasting surprise medical bills.


Tackling surprise billing has become a government priority, according to the press release made July 1, 2021, from Department of Health and Human Services (DHHS) which states that two-thirds of all bankruptcies filed in the United States are tied to medical expenses. The press release refers to a citation used by DHHS from a report made by CNBC. Researchers estimate that 1 of every 6 emergency room visits and inpatient hospital stays involve care from at least one out-of-network provider, resulting in surprise medical bills.


Surprise billing happens when people get care from providers outside of their health plan's network unknowingly. This can occur in both emergency and non-emergency care situations, but you must agree, we are most vulnerable during circumstances related to emergency medical treatment.


Surprise Billing Curtailed – My Experience in 2021

Case in point:  I was diagnosed with a rare condition and referred to a specialist this year. The first available appointment with the specialist was in 3 months. Finally, during my visit with the specialist (who was worth waiting for, by the way), it was determined that part of my plan of care would include a special form of physical therapy. The specialist placed the order in Epic and instructed me to see a very specific physical therapist highly skilled in treating people with my rare diagnosis. The appointment for therapy was made for me as I left the specialist’s office. When I went home, I logged into my AARP Medicare Advantage UHC plan to find that the therapist was not in network with my insurance; none of the therapists in that clinic were. I called my insurance, got a list of in-network providers, searched to find 3 that offer treatment for my condition, checked each therapy clinic with the Better Business Bureau (BBB) and only selected those with an A+ rating. Then, I called each one and had to leave a voicemail. I finally started therapy within a few days for a $35 copay. If I had not performed my own due-diligence, there would have definitely been out-of-network surprise bills! 


The frustration of working full time, having to wait for 3 months to see the specialist to get a treatment plan, being referred to an out of network therapist and having to lose more time from work to research and locate an in-network provider just added to my stressful situation.


Not everyone has my background as a nurse, coder, compliance officer, documentation specialist and auditor. I can see how many patients would have ended up with huge medical bills because they trusted the doctor to make in-network referrals. And even with my background and experience, if my situation was related to an emergency, I would not have been able to circumvent the “surprise bill” situation.


Implementation of the Interim Final Rule is January 2022

The regulations are generally applicable to group health plans and health insurance issuers for plan and policy years beginning on or after January 1, 2022. The HHS-only regulations that apply to health care providers, facilities, and providers of air ambulance services are applicable beginning on January 1, 2022. Upon implementation of the Interim Final rule, patients will be removed from the billing negotiation process between the insurer and the provider.  Among other provisions, the interim final:

  • Requires certain health care providers and facilities to make publicly available, post on a public website, and provide to individuals a one-page notice about:
    • The requirements and prohibitions applicable to the provider or facility under Public Health Service Act sections 2799B-1 and 2799B-2 and their implementing regulations.
    • Any applicable state balance billing limitations or prohibitions.
    • How to contact appropriate state and federal agencies if someone believes the provider or facility has violated the requirements described in the notice.
  • Bans surprise billing for emergency services.
    • Emergency services, regardless of where they are provided, must be treated on an in-network basis without requirements for prior authorization.
  • Bans high out-of-network cost-sharing for emergency and non-emergency services.
    • Patient cost-sharing, such as co-insurance or a deductible, cannot be higher than if such services were provided by an in-network doctor, and any coinsurance or deductible must be based on in-network provider rates.
  • Bans out-of-network charges for ancillary care (like an anesthesiologist or assistant surgeon) at an in-network facility in all circumstances.
  • Bans other out-of-network charges without advance notice.
    • Health care providers and facilities must provide patients with a plain-language consumer notice explaining that patient consent is required to receive care on an out-of-network basis before that provider can bill at the higher out-of-network rate.

In order to learn important details about this interim final rule Read the Fact Sheet. Also, obtain online, on-demand formal training and get certified in Revenue Cycle Management, which is recommended for all RCM supervisors, billing company managers/owners and chart auditors. Updates on the implementation of this important No Surprises Act is included in the Revenue Cycle Management course as details develop.


Read More
HIPAA Compliance
HIPAA

Cybersecurity Is Not an IT Issue

Why it takes more than technology to defend your organization


Written by J. David Sims, HHS 405(d) Task Group Member and AIHC Board Member




Introduction

This article is reproduced with permission from the HHS 405(d) Task Group Newsletter.  In 2021, the 405(d) Program has grown its reach and continues to pursue its mission of Aligning Healthcare Industry Security Approaches. The 405(d) Program is now able to assist in many of your cybersecurity needs. Whether it is instituting cybersecurity practices using the Health Industry Cybersecurity Practices, better known as “HICP,” or educating your staff on cybersecurity, we are here for you! AIHC is so excited that our talented Board Member, David Sims, is serving on this important task force.


“Dr. Cooper, the computers aren’t working right. They all have a message on the screen about paying to have our data and systems unlocked!”


This was the welcome that Dr. Cooper received on Monday morning from his panicked practice manager, Sherry, as he walked into his practice. No, this would not be a good morning, not at all.


“Sherry, get IT on the phone!” shouted Dr. Cooper as he made his way to every computer and was met with the same ransomware message on each screen. Dr. Cooper had invested a modest amount of money each month to outsource his IT support and security to a local IT firm.


“The IT guys said they can’t log in remotely, so they’ll have to send someone out. It will be an hour or so before anyone can get here,” Sherry explained. In the meantime, patients were starting to fill the lobby for their morning appointments. With no plan of how to respond to such an incident, Sherry instructed her staff to start rescheduling patients and prepared to close the office for the rest of the day. A little while later, Scott from their IT firm arrived. He instantly realized he was walking into a mess. As he walked through the parking lot, he could hear agitated patients complaining about having to reschedule.


Upon entry he noticed another patient expressing concern about their medical records as the front desk person explained that they are experiencing a ransomware attack. Scott quickly assessed the situation and realized that there was nothing he can do to resolve this. Scott turned to Dr. Cooper with a look of dread and began rapidly firing questions:


“Do you have a ransomware response plan?”  “Do you have cyber insurance?”  “Who is handling public relations?”  “Have you called your attorney?”


Dr. Cooper threw up his hands and said, “Wait. So, you’re telling me that you can’t fix this?”


Scott replied, “You have an active ransomware attack happening. Likely, this is going to be a data breach. If so, you are going to have to notify all your patients that have been affected. You may also have to notify the State and HHS and follow State and Federal breach laws. You’ll also need to determine if the media will need to be notified.”


“How could this happen?! We pay you for security!” exclaimed Dr. Cooper, who was sitting down with his head in his hands as he pondered what this will mean for his practice and his patients.


We will leave this true story now and look closer at the question Dr. Cooper asked, “How could this happen?” Afterall, they are indeed paying for cybersecurity and the IT firm is providing good security. So, how then, can this happen?


Like many businesses, this practice did not understand that cybersecurity is not just a function of IT. In fact, there are three areas that must be present for an effective privacy and security program to work. Let’s take a closer look at these three areas.

People

Social engineering, or hacking humans as it is sometimes called, is today’s most successful way to attack an organization. The attacker can bypass all the security that keeps them out if they are able to have someone on the inside let them in. Technology has no way of keeping out the bad guys if the good guys are letting them in through the “employee entrance.”


Your people will either be a security asset or a security liability.


Mostly, people want to do what is right. They want to protect the patients and their employers, but they are often not given the proper tools or training to make them effective security assets.


Organizations should dedicate time and resources to effectively train and test their employees on proper cyber hygiene, privacy and security topics, and incident response. Remember, it’s the people, people.

Processes

A process is the guide that explains to employees how your business does certain things. All too often, a business will either not have processes in place, or they do have them, but nobody knows what they are because they are not trained on them.


It is a guarantee that if your organization has never practiced an incident response, even a table-top exercise, your team will do nearly everything wrong when an actual incident occurs.

Not having an effective, planned response will cost you much more when (not if) disaster strikes. “Failing to plan is planning to fail,” as Ben Franklin said.

Technology

This is the final piece of the cybersecurity trifecta, and yet most people think it is the only piece. This is also the most confusing piece due to its complexity and many other factors. Following a framework or guide, like HICP (Health Industry Cybersecurity Practices), will help organizations understand where their focus should be to properly address the most common threats. Ensure you are devoting enough resources to this area, but understand that technology alone will not properly protect you.

Conclusion

People, processes, and technology. Those are the three areas that must thrive for any organization to have an effective privacy and security program. A cyber incident can happen at a moment’s notice. How well you can recover from it will depend on how prepared you are in advance. In a crisis, people do not rise to the occasion; they fall to their level of preparation.


A resource that can definitely get you started and begin to protect your patients from cyber threats are publications located on the 405(d) Task Force Website.

This publication lays out the top five threats facing the healthcare industry and provides the top 10 practices needed to mitigate them. If you do not have your IT department in house but use a third party, this is a document you can provide to your IT contractor and ask- “Are you doing these things? And if not, why?”


Protecting patients is our number one priority and we all now have to realize that this includes cyber, and using the most up to date practices is paramount to achieving this goal.

Read More
HIPAA Compliance
HIPAA

HIPAA, The Cures Act and Information Blocking Compliance

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS


The patient is at the center of the 21st Century Cures Act. Putting patients in charge of their health records is a key piece of patient control in health care, and patient control is at the center of HHS' work toward a value-based health care system. Patients need more power in their health care, and access to information is key to making that happen.


The Office of the National Coordinator for Health Information Technology (ONC) Cures Act Final Rule implements interoperability requirements outlined in the Cures Act.


HIPAA security requires covered entities to protect health information.  This information blocking practice is allowed except as required by law or as specified by the Secretary of Health and Humans Services as a reasonable and necessary activity.  However, it is likely to interfere with access, exchange and/or use of electronic health information (EHI). 

  • EHI is defined as the electronic protected health information (ePHI) in a designated record set (as defined in the Health Insurance Portability and Accountability Act (HIPAA) regulations) regardless of whether the records are used or maintained by or for a covered entity. The designated record set in a physician’s practice typically includes:
    • Medical records and billing records about individuals;
    • Other records used, in whole or in part, by physicians to make decisions about individuals

Why is this important to you?


All Actors will be subject to ONC’s Information Blocking rules and regulations on April 5, 2021.


For the first 24 months after publication of the Final Rule (currently until August 2, 2022), for the purposes of the information blocking definition, EHI is limited to the data elements represented in the US Core Data for Interoperability (USCDI) V1 standard adopted in the Final Rule.

  • EHR vendors are currently updating their products to support the access, exchange, and use of all data elements in the USCDI. This will take time and, for some smaller EHR vendors, may take several months.
  • After August 2, 2022, the definition of EHI expands to that of ePHI described above. At that time, all physicians will be required to make their patients’ ePHI available for access, exchange, and use.

Penalties - Because there are investigations, penalties and disincentives!  Actors that are subject to the information blocking regulations may be investigated by the HHS Office of Inspector General (OIG) if they are the subject of a claim of information blocking.

Further, actors found to have committed information blocking are subject to penalties:

  • Health IT developers of certified health IT, health information networks, and health information exchanges → Civil monetary penalties (CMPs) up to $1 million per violation
  • Health care providers → Appropriate disincentives to be established by the Secretary

Got Your Attention? 

What is behind the Information Blocking and Need to Comply?


The 21st Century Cures Act (Cures) is a landmark bipartisan health care innovation law enacted in December 2016. Cures includes provisions to promote health information interoperability and prohibit information blocking or “info blocking” by “Actors.”  Actors are considered:

  • Health Care Providers;
  • Health Information Networks (HIN) and Health Information Exchanges (HIE); and
  • Health information technology (IT) developers.

In March 2019, the Office of the National Coordinator for Health Information Technology (ONC) issued a Proposed Rule, 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program. They released a final rule in March 2020 and published it in the Federal Register on May 1, 2020.


What are examples of practices that could constitute information blocking?


Section 4004 of the Cures Act specifies certain practices that could constitute information blocking:

  • Practices that restrict authorized access, exchange, or use under applicable state or federal law of such information for treatment and other permitted purposes under such applicable law, including transitions between certified health information technologies (health IT);
  • Implementing health IT in nonstandard ways that are likely to substantially increase the complexity or burden of accessing, exchanging, or using EHI;
  • Implementing health IT in ways that are likely to—
    • Restrict the access, exchange, or use of EHI with respect to exporting complete information sets or in transitioning between health IT systems; or
    • Lead to fraud, waste, or abuse, or impede innovations and advancements in health information access, exchange, and use, including care delivery enabled by health IT.

Additional examples of practices that could constitute information blocking can be found on the Office of the National Coordinator for Health Information Technology (ONC) website at: https://www.healthit.gov/curesrule/


Ah – there are Exceptions!

What are the information blocking exceptions?


Section 4004 of the Cures Act authorizes the Secretary of HHS to identify reasonable and necessary activities that do not constitute information blocking.  The exceptions support seamless and secure access, exchange, and use of EHI and offer actors certainty that practices that meet the conditions of an exception will not be considered information blocking.


A practice that does not meet the conditions of an exception would not automatically constitute information blocking. Such practices would not have guaranteed protection from civil monetary penalties or appropriate disincentives and would be evaluated on a case-by-case basis to determine whether information blocking has occurred.  Physicians must satisfy ALL applicable conditions of an exception at all relevant times to meet the exception as it relates to the access, exchange, and use of EHI. Each exception is limited to certain practices that clearly advance the aims of ONC’s Final Rule and are tailored to align with the following criteria:

  • Be reasonable and necessary
    These reasonable and necessary practices include providing appropriate protections to prevent harm to patients and others; promoting the privacy and security of EHI; promoting competition and innovation in health IT and its use to provide health care services to consumers, and to develop an efficient means of health care delivery; and allowing system downtime to implement upgrades, repairs, and other changes to health IT.
  • Address significant risk
    The exceptions are intended to address what ONC considers a “significant risk” and that Actors would otherwise avoid engaging in out of concern that such activities could be interpreted as info blocking.
  • Subject to strict conditions
    Each exception is subject to strict conditions to ensure practices are limited to those that are reasonable and necessary.

Exceptions are divided into two classes in the Cures Act Final Rule:

  • Exceptions that involve not fulfilling requests to access, exchange, or use EHI; and
  • Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI.

In the final rule, they have identified eight categories of reasonable and necessary activities that do not constitute information blocking, provided certain conditions are met (referred to as “exceptions”). The information below is a summary.  Go to healthIT.gov for more information.


Exceptions that involve not fulfilling requests to access, exchange, or use EHI


1.   Preventing Harm Exception


It will not be information blocking for an actor to engage in practices that are reasonable and necessary to prevent harm to a patient or another person, provided certain conditions are met.  This exception recognizes that the public interest in protecting patients and other persons against unreasonable risks of harm can justify practices that are likely to interfere with access, exchange, or use of EHI.


Physicians must hold a reasonable belief that the practice will substantially reduce the risk of physical harm to a patient or another natural person and the practice is no broader than necessary to substantially reduce the risk of harm. Practices include:

  • Declining to share data that is corrupt, inaccurate, or erroneous.
  • Declining to share data arising from misidentifying a patient or mismatching a patient’s EHI.
  • Refraining from a disclosure that would endanger life or physical safety of a patient or another person.
    • The licensed provider who made the determination must have done so in the context of a current or prior clinician-patient relationship.

Patients may opt to appeal a physician’s use of the Harm Exception. Physicians must implement their practice in a way that allows for the patient whose EHI is affected to exercise their rights under HIPAA or any federal, state, or tribal law to have the determination reviewed and potentially reversed.


The practice must be consistent with a written organizational policy that is:

  • Based on relevant clinical, technical, other appropriate expertise;
  • Implemented in a consistent and non-discriminatory manner; and
  • Conforms each practice to the conditions in the harm exception.

2.   Privacy Exception


It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI in order to protect an individual’s privacy, provided certain conditions are met.  This exception recognizes that if an actor is permitted to provide access, exchange, or use of EHI under a privacy law, then the actor should provide that access, exchange, or use. However, an actor should not be required to use or disclose EHI in a way that is prohibited under state or federal privacy laws.


Sub-exceptions

  • Unsatisfied legal precondition to the release of EHI

a.  Physicians may withhold EHI if a state or federal privacy law imposes preconditions for providing access, exchange or use of EHI (e.g., a requirement to obtain a patient’s consent before disclosing the EHI), if their practice:


     i.   Is tailored to the applicable precondition;

    ii.   Implemented in consistent and non-discriminatory manner; and

   iii.   Either:

  • Conforms to physician’s written organizational policies; or
  • Is documented by a physician on a case-by-case basis
  • Certified health IT developer not covered by HIPAA
  • Denial of individual’s request for ePHI consistent with the HIPAA Privacy Rule

  • a.  HIPAA covered entity or business associate Actor may deny an individual’s request for EHI under the HIPAA Privacy Rule’s right of access if the Actor’s practice complies with the Privacy Rule’s “unreviewable grounds” for a denial of access.


         i.   Unreviewable grounds under Privacy Rule:

    • Certain requests made by inmates of correctional institutions;
    • Information created or obtained during research that includes treatment if certain conditions are met;
    • Denials permitted by the federal Privacy Act; and
    • Information obtained from non-health care providers pursuant to promises of confidentiality.

    Respecting an individual’s request not to share information


    a.  An Actor may decline to provide access, exchange, or use of EHI if it meets the following requirements intended to align with an individual’s HIPAA Privacy Rule right to request additional restriction:


         i.   Individual requests that the Actor not provide such access, exchange, or use of the EHI without any improper encouragement or inducement of the request by the Actor.


    3.   Security Exception


    It will not be information blocking for an actor to interfere with the access, exchange, or use of EHI in order to protect the security of EHI, provided certain conditions are met.  This exception is intended to cover all legitimate security practices by actors, but does not prescribe a maximum level of security or dictate a one-size-fits-all approach.


    General conditions — A practice is not info blocking if it is:

    • Directly related to safeguarding the confidentiality, integrity, and availability of EHI;
    • Tailored to the specific security risk being addressed; and
    • Implemented in a consistent and non-discriminatory manner.

    Actors and their security-related practices may satisfy proposed exception through:

    • Written organizational policies; or
    • Determinations on a case-by-case basis under particular facts and circumstances.

    A practice must meet both:

    • General conditions; and
    • Either the requirements for organizational policies or case-by-case determinations.

    For practices that do not implement an organizational security policy, an Actor must have decided in each case, based on the particular facts and circumstances, that:

    • The practice is necessary to mitigate the security risk to EHI; and
    • There are no reasonable alternatives to the practice that address the security risk that are less likely to interfere with, prevent, or materially discourage access, exchange, or use of EHI.

    4.   Infeasibility Exception


    It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI due to the infeasibility of the request, provided certain conditions are met.  This exception recognizes that legitimate practical challenges may limit an actor’s ability to comply with requests for access, exchange, or use of EHI. An actor may not have—and may be unable to obtain—the requisite technological capabilities, legal rights, or other means necessary to enable access, exchange, or use.  To receive protection, the practice must meet one of the following conditions:

    • Uncontrollable Events: The Actor cannot fulfil the request for access, exchange, or use of EHI due to a natural or human-made disaster, public health emergency, public safety incident, war, terrorist attack, civil insurrection, strike or other labor unrest, telecommunication or internet service interruption or act of military, civil or regulatory authority.
    • Segmentation*: The Actor cannot fulfil the request for access, exchange, or use of EHI because the Actor cannot unambiguously segment the requested EHI from EHI that:
      • Cannot be made available due to a patient’s preference or because the EHI cannot be made available by law; or
      • May be withheld in accordance with the Preventing Harm Exception.
    • Infeasible Under the Circumstances: The Actor demonstrates, prior to responding to the request, through a contemporaneous written record or other documentation its consistent and non-discriminatory consideration of certain factors that led to its determination that complying with the request would be infeasible under the circumstances.

    * You may need to provide access to information that is not otherwise protected by federal or state privacy law (e.g., HIPAA Patient Right of Access). You should consider speaking with your compliance officer or practice manager about how to handle such situations. For example, you may still be required to print out an office note and hand redact protected information even if you claim the Infeasibility Exception.


    5.   Health IT Performance Exception


    It will not be information blocking for an actor to take reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT's performance for the benefit of the overall performance of the health IT, provided certain conditions are met.


    This exception recognizes that for health IT to perform properly and efficiently, it must be maintained, and in some instances improved, which may require that health IT be taken offline temporarily. Actors should not be deterred from taking reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT’s performance for the benefit of the overall performance of health IT.  An Actor’s practice to maintain or improve health IT performance is not info blocking when the practice meets one of the four following conditions:

    • Maintenance and improvement to health IT (e.g., an EHR upgrade).
    • Consistent with existing service level agreements, where applicable.
    • Practices that prevent harm and comply with Preventing Harm Exception.
    • Security-related practices that comply with Security Exception.

    Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI


    6.   Content and Manner Exception


    This is an important exception for physicians who are limited by their EHR vendor’s ability to access, use, or exchange patient information. Physicians are encouraged to discuss the use of this exception with their EHR vendor.  If the burden on the Actor for fulfilling a request is so significant that the Actor chooses to not fulfil the request at all, the Actor could seek coverage under the Infeasibility Exception.


    It will not be information blocking for an actor to limit the content of its response to a request to access, exchange, or use EHI or the manner in which it fulfills a request to access, exchange, or use EHI, provided certain conditions are met.


    This exception provides clarity and flexibility to actors concerning the required content (i.e., scope of EHI) of an actor’s response to a request to access, exchange, or use EHI and the manner in which the actor may fulfill the request. This exception supports innovation and competition by allowing actors to first attempt to reach and maintain market negotiated terms for the access, exchange, and, use of EHI. This exception applies to practices that involve the Actor responding to a request with limited information and in a manner other than what was requested by the requestor.

    • Content:
      • For 24 months after final rule publication, the Actor must respond with the subset of EHI identified by the USCDI data elements.
      • After that date, the Actor must respond with all EHI in a designated record set (i.e., ePHI).
    • Manner of Response: The Actor must respond either:
      • In the manner requested; or
      • In an alternative manner.

    7.   Fees Exception


    It will not be information blocking for an actor to charge fees, including fees that result in a reasonable profit margin, for accessing, exchanging, or using EHI, provided certain conditions are met. This exception enables actors to charge fees related to the development of technologies and provision of services that enhance interoperability, while not protecting rent seeking, opportunistic fees, and exclusionary practices that interfere with access, exchange, or use of EHI.


    Fees may result in a reasonable profit. The exception excludes certain fees, such as those based on electronic access to EHI by the individual. ONC divided the Fee Exception into three conditions.

    • To qualify for this exception, the Actor’s practice must meet the “Basis of fees condition,” not include any of the fees addressed in the “Excluded fees condition,” and comply with the “Compliance with the Conditions of Certification condition” if the Actor is a health IT developer subject to ONC’s Conditions of Certification (CoC).
    • This exception will most likely be applicable to EHR vendors rather than physicians or other providers.

    8.   Licensing Exception


    It will not be information blocking for an actor to license interoperability elements for EHI to be accessed, exchanged, or used, provided certain conditions are met. This exception allows actors to protect the value of their innovations and charge reasonable royalties in order to earn returns on the investments they have made to develop, maintain, and update those innovations.


    Conclusion

    Information blocking can occur in many forms for both Actors and Patients. Physicians can experience information blocking when trying to access patient records from other providers, connecting their EHR systems to local health information exchanges, migrating from one EHR to another, and linking their EHRs with a clinical data registry.  Patients can also experience information blocking when trying to access their medical records or when sending their records to another provider.


    The new rules regulate EHR vendors, prohibiting them from blocking information. Like physicians, EHR vendors must comply with these regulations now.  Learn more by reviewing the resources provided below.


    Resources

    AIHC HIPAA Compliance Officer Training

    American Medical Association –

    ONC

    Read More
    Compliance in Healthcare
    Corporate Compliance

    Introduction to what Prosecutors Will Consider When Evaluating Your Compliance Program – Updated as of October 2023

    Written by: Compliance blogger

    Read More