Artificial Intelligence in Healthcare
Artificial Intelligence

Asynchronous Telehealth & Patient Privacy

This article provides a basic overview of Artificial Intelligence, Telehealth, Asynchronous Services and HIPAA privacy concerns.  This information is not intended as legal or consulting advice.  Please utilize resources provided within this article for more information.   

Telehealth refers to a collection of methods to enhance health care delivery and education — it’s not a specific service. 

Synchronous telehealth is a virtual interaction between a patient and a provider that takes place in real time, like a video call, audio call, or secure text messaging. It usually results in a provider giving a patient a diagnosis, treatment plan, or prescription, according to Health & Human Services. Synchronous telehealth has been shown to reduce the number of no-show patients, shorten the wait time for patients to see their provider, and increase efficiency in a physician’s practice.  Asynchronous telehealth, on the other hand, is a virtual interaction between a patient and a provider that doesn’t take place in real time.

Telehealth spans four distinct applications:

  • Live Video;
  • Store-and-Forward;
    • Mobile Health (mHealth); and
    • Remote Patient Monitoring (RPM).

Store-and-Forward

Asynchronous telehealth is generally used for patient intake purposes or follow-up care. Store-and-Forward is considered “asynchronous telehealth, a communication between parties that is not live.”  It is a service rendered outside of a real-time or live interaction with a patient.

Within asynchronous telehealth is also called “Store-and-Forward”.  There are two subcategories:

  1. Mobile health (also called mHealth); and
  2. Remote patient monitoring, or RPM.

Mobile health involves using a device such as a smartphone or a wearable device (like an Apple Watch) to support a patient’s health and transmit health data between a patient and their provider.

Remote patient monitoring involves transferring patient data from a medical device, like a blood pressure monitor or a pacemaker, to a provider.

According to https://telehealth.hhs.gov  asynchronous direct-to-patient telehealth can streamline patient workflows by standardizing patient data for later use, flexibility because no scheduling is involved and efficiency through automated patient intake.  Examples include:

  • Messaging or texting between patient and provider with follow-up instructions or confirmations;
  • Patient report sharing;
  • Symptom survey questionnaires;
  • Wound imaging;
  • Images sent for evaluation, X-ray or MRI sharing;
  • Lab results or vital statistics;

Store-and-forward technologies are most commonly used in radiology, pathology, dermatology, ophthalmology and for electronic consultations (eConsults).  eConsult is a web-based system that allows a primary care physician (PCP) and a specialist to securely share health information and discuss patient care.

Although store-and-forward services can increase efficiency, these services are not always reimbursable by private insurers.  Medicaid policies on this issue vary from state to state.


Address HIPAA and Privacy Concerns

Technology considerations

The telehealth platform you use should meet HIPAA requirements.  All telehealth services provided by covered health care providers and health plans must comply with the HIPAA Rules. This means only using technology vendors that comply with the HIPAA Rules and will enter into HIPAA business associate agreements in connection with the provision of their video communication products or other remote communication technologies for telehealth.


HIPAA Telehealth Compliance Resources


Other Telehealth Resources

American Telemedicine Association

Artificial Intelligence -Article posted in the National Library of Medicine

Center for Connected Health Policy (CCHP) and the National Consortium of Telehealth Resource Centers has finalized a Telehealth Definition Framework to help clarify how to accurately use “telehealth” and its key components. 

Centers for Medicare & Medicaid Services (CMS) offers a 17-page PDF:

Center for Connected Health Policy (CCHP) - Medicare and each Medicaid program are different in how they approach and reimburse telehealth delivered services.

E-consults - Telehealth for Emergency Departments -E-consults are communications between providers only. Providers can interact with each other by using phone, video, or a HIPAA-compliant platform that allows two-way communication and can securely share patient records.

E-Consults and Their Outcomes: a Systematic Review

This article is written by members of the AIHC Volunteer Education Committee.  AIHC is a non-profit organization.  We value our members, credentialed professionals and greatly appreciate the talents offered by our member volunteers!

Copyright © February 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Telehealth
Telehealth

Introduction to Telebehavioral Health

Compliance Considerations for Best Outcomes

Written in collaboration with the AIHC Volunteer Education Committee   


Delivering mental health services via telehealth has increased since the COVID-19 pandemic.  Both Federal and State rules are constantly evolving along with the use of Artificial Intelligence, creating a complex environment for compliance considerations.  This article is not intended as legal or consulting advice.  If your practice is currently using a telebehavioral health approach for patient treatment, or if you organization is considering implementing this approach, we hope this article will give some food-for-thought on the topic. Keep in mind coding and documentation is extremely important for psychiatric services – consider registering for the Psychiatric Compliance – coding & documentation short course offered by the American Institute of Healthcare Compliance.

Telemedicine is considered to be under the umbrella of telehealth and refers specifically to clinical services. Telehealth and telemedicine cover similar services, including medical education, remote patient monitoring, patient consultation via videoconferencing, wireless health applications, and transmission of imaging and medical reports.

Behavioral telehealth may also be referred to as telebehavioral health, telemental health, telepsychiatry, or telepsychology. 

Higher rates of use of telehealth are now standard in many practices since the coronavirus disease 2019 (COVID-19) pandemic. Increasing importance on patient satisfaction, providing efficient and quality care, and minimizing costs have also led to higher telehealth implementation.

This increase in telebehavioral health has been especially enjoyed by both patients and providers since the pandemic, but widespread adoption has been hindered by regulatory, legal, and reimbursement barriers.

Individual, one-on-one therapy, is the most common form of behavioral and mental health treatment. Telehealth can be an effective way to deliver individual therapy, as long as your practice carefully considers compliant technology, implementation and reimbursement concerns. Medicare covers many telebehavioral and telemental health services including audio-only services. Most private insurers and Medicaid cover telebehavioral health care, but check for reimbursement restrictions and obtain professional coding and billing guidance to avoid overpayment situations.

Substance use disorders impact a significant number of individuals, families, and communities.  When used in combination with other treatment methods, telebehavioral health interventions can be part of an integrated approach to treating substance use disorders. These interventions can include screening and diagnosis, online counseling, consults for prescriptions, and individual and group talk therapy. Treating substance use disorders via telehealth requires expertise and training in addiction care.

Benefits of Using Advanced Technology

The terms telehealth and telemedicine are often used interchangeably. Telehealth is a subset of e-health and is the use of telecommunications technology in health care delivery, information, and education according to the Health Resources and Services Administration (HRSA).

Telehealth has been used to bring healthcare services to consumers in distant locations, but became a necessity since the 2020 COVID-19 pandemic. Telehealth effectively connects individuals and their healthcare providers when in-person care is not necessary or not possible. Using telehealth services, patients can receive care, consult with a provider, get information about a condition or treatment, arrange for prescriptions, and receive a diagnosis. In the 30 plus years that telehealth has been in-use, it has been consistently shown to be a safe and quality care modality, a convenient option for both patients and the clinicians who care for them, and a secure environment for the collection and transmission of personal health information. In combination, these attributes extend where and how care is delivered for a stronger healthcare system.

Provider Shortages

Given provider shortages around the world, telehealth has a unique and appealing value proposition. It can provide millions of people in both rural and urban areas access to safe, effective, and appropriate care when and where they need it.

Cost-Benefit

Reducing or containing the cost of healthcare is one of the strongest motivators to fund and adopt virtual care technologies. Telehealth reduces the cost of healthcare and increases efficiency with better management of chronic diseases, shared health professional staffing, reduced travel times, and fewer or shorter hospital stays.

Meeting Patient Expectations

Patient utilizing telehealth during the pandemic may continue to expect remote care. Using telehealth technologies reduces travel time and related stresses for the consumer.

Understanding the Technology

Gaining a basic understanding of the technology will help your organization can help the wise professional make informed choices about telehealth purchases. Terminology used for the various forms of telehealth technology are summarized below which applies to both general and behavioral health care use.  Not all forms of technology are recognized as services which can be reimbursed by health insurance.

Chat-Based (Asynchronous) - This approach is online or through a mobile app communication which transmits the patient’s personal health data, vital signs, and other physiologic data or diagnostic images to a healthcare provider to review and deliver a consultation, diagnosis, or treatment plan at a later time.  This is also called “store-and-forward telemedicine.” 

  • Store-and-forward is less commonly reimbursed by Medicare and Medicaid programs.  In many states, the definition of telemedicine and/or telehealth stipulates that the delivery of services must occur in “real time,” automatically excluding store-and-forward as a part of telemedicine and/or telehealth altogether.

Mobile Health (mHealth) - Mobile Health, otherwise known as mHealth utilizes smart devices and can be now used for many specialized aspects of health care that benefit from continuous data collection about a person’s behavior or condition. Smartphones, tablets, smart wearables like iWatch can monitor a variety of factors such as pulse rate, heart rate, and with some, blood sugar levels or quality of expired air. Apps are now available to encourage healthier lifestyles and behaviors by providing heart-rate variability scores, sleep cycles, movement tracking, weight changes, dietary tracking and much more.

Remote Patient Monitoring or RPM - The remote patient monitoring approach supports ongoing condition monitoring and chronic disease management and can be synchronous or asynchronous, depending upon the patient’s needs.  The application of emerging technologies, including artificial intelligence (AI) and machine learning, can enable better disease surveillance and early detection, allow for improved diagnosis, and support personalized medicine. This includes the collection, transmission, evaluation and communication of the patient’s health data to the provider or extended care team from outside a hospital or clinical office.  It involves using personal health technologies including wireless devices, wearable sensors, implanted health monitors, smartphones, and mobile apps.

Virtual Visits (Synchronous)

This approach includes live, synchronous and interactive communication during the encounter between the patient and healthcare provider.  This is accomplished via video, telephone or live chat.

Facing Implementation Challenges

Health care providers should keep risk management strategies in mind and familiarize themselves with potential telehealth legal risks and implications. This will ensure best practices for patient care and to avoid licensure or litigation issues. 

Telehealth faces many legal and regulatory hurdles, including large variations in rules, regulations, and guidelines for practice which contributes to the confusion for providers engaged in the practice of telehealth. Telehealth rules and regulations vary greatly by state.

  • Providers should have awareness of and maintain compliance with state and federal legal requirements while using best practice guidelines to provide patient safety.
  • The lack of multistate licensure presents a barrier to telehealth because providers must obtain and uphold licensure (and the associated medical education and financial obligations) in multiple states.

The Federation of State Medical Boards created the Interstate Medical Licensure Compact to ease portability of licensure and the practice of telemedicine from state to state for physicians and physician assistants.

  • Under the compact, state medical boards would maintain licensure and disciplinary authority of providers. However, they would share information and processes essential to these providers’ licensure and regulations.
  • This compact does not apply to nurse practitioners (NPs) because they are licensed under state boards of nursing and not medicine.
  • Because state regulation and practice authority vary from state to state, NPs face more barriers than physicians or physician assistants.

Compared with face-to-face encounters, telemedicine encounters are more vulnerable to privacy and security risks.  Your telehealth platform should be secure in accordance with several laws, including the:

These laws protect medical information for both face-to-face and telehealth encounters which includes privacy, security, and protection for health information collected by covered entities such as health care plans, health care clearinghouses, and health care providers who use electronic resources for the transmission of health care information.

Only Consider Using HIPAA-Compliant Technology

The HIPAA Rules establish standards to protect patients’ protected health information. All telehealth services provided by covered health care providers and health plans must comply with the HIPAA Rules.

Covered health care providers and health plans must use technology vendors that comply with the HIPAA Rules and will enter into HIPAA business associate agreements in connection with the provision of their video communication products or other remote communication technologies for telehealth.

The Office for Civil Rights (OCR) is the HIPAA enforcement agency.  OCR released guidance on April 12, 2023 to help covered health care providers and health plans understand how they can use remote communication technologies for audio-only telehealth.  This information was published due to the end of the COVID-19 Public Health Emergency (PHE) which began May 12, 2023.

  • Click Here for OCR’s guidance “How the HIPAA Rules Permit Covered Health Care Providers and Health Plans to Use Remote Communication Technologies for Audio-Only Telehealth”

Comply with Consent Requirements

Most states have telehealth specific informed consent requirement in their statute, administrative code and/or Medicaid policies. This requirement can sometimes apply to specific types of professionals when located in law or regulations governing their profession. The requirement for consent is sometimes paired with other requirement such as the need to ensure the same level of care is delivered via telehealth as would be expected in-person. 

Make sure to have your medical/intake forms reviewed by your legal team. Obtaining informed consent with your patient is typically done before the first appointment.  Click Here for the interactive map to research your state, provided by the Center for Connected Health Policy (CCHP), federally designated as the National Telehealth Policy Resource Center.

Another resource is AHRQ resource page “How to Obtain Consent for Telehealth” – providing discussion tips for the before and during the consent periods.

Other Compliance Considerations

Compliance to both Federal and State privacy rules should be at the forefront of any telehealth endeavor, but none so important as those services provided by behavioral health professionals.  Telehealth providers must take responsibility for ensuring compliance with regulations, patient confidentiality, and system security at all times when practicing in a telehealth model.

The practice of telehealth raises many questions regarding malpractice liability including informed consent (addressed in more detail below), practice standards and protocols, supervision requirements for nonphysician providers, and the provision of professional liability insurance coverage.

  • Simply applying existing principles of malpractice liability to telehealth is not straightforward, especially when it is unclear what an appropriate “standard of care” is.
  • Professional liability policies may not include telehealth in the scope of coverage.
    • Providers need to be cognizant of what exactly liability insurance policies cover, especially when providing telehealth services in other states.

In addition to knowledge of legal aspects of telehealth, it is important for providers to be aware of and practice telehealth etiquette. These etiquette standards should be observed when providers are working remotely at home or performing telehealth visits at their practice location. Also follow all clinical standards for care and adhere to practice standards determined by the profession, state regulatory boards, and state law. Reference the CCHP Professional Boards Standards interactive map..

Providers should be appropriately licensed, credentialed, or certified to deliver care and permitted to practice without impermissible influence on their clinical judgement.

The transition to telehealth is an adjustment for patients as well as health care providers. By preparing your patients for remote medical care, you help ensure their comfort and maintain quality care. This includes understanding various fraud and abuse laws.  As telehealth use grows, caution and care should be taken to ensure that the practice of telehealth does not violate federal antikickback and Stark Law statues. These laws prohibit providers from receiving compensation for accepting or making referrals to other facilities or providers where the referring provider has financial interests.

  • Violations to these laws can result in fines, prison time, and/or exclusion from the Medicare and/or Medicaid programs.
  • The Federal Physician Self-Referral Law, also referred to as the Stark Law, prohibits a health care provider (or an immediate family member of a provider) from referring Medicare patients to entities providing designated health services if that provider or the provider’s immediate family member has a financial interest.

When considering potential fraud and abuse scenarios and related risks, a provider needs to keep in mind that each state has its own variations of these laws. A state-by-state analysis is necessary because of variations in statutes and/or regulations.

Advertising for virtual care services should be truthful and non-misleading and demonstrate a commitment to quality healthcare that meets the standard of care and compliance with all applicable state and federal laws.  The use of these telehealth appointments boomed during the pandemic. However, there are concerns about the quality of care patients receive and whether telehealth services are accessible to everyone, according to the September 2022 GAO article “Telehealth in the Pandemic—How Has It Changed Health Care Delivery in Medicaid and Medicare?”  Any website or other promotion of offering behavioral health services via telemedicine or telehealth should be reviewed by legal counsel or your Risk Attorney (free) through your malpractice insurance company.

Free Available Resources

American Telemedicine Association (ATA)

American Psychiatric Association - Telepsychiatry

Arizona Telemedicine Program: How AI Helps Physicians Improve Telehealth Patient Care in Real-Time (June 2023)

Center for Connected Health Policy (CCHP) – nonprofit organization federally designated as the National Telehealth Policy

Resource Center

Government Accountability Office (GAO) - Medicare Telehealth: Actions Needed to Strengthen Oversight and Help Providers

Educate Patients on Privacy and Security Risks

Telehealth.HHS.gov


Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Part 3:  AI & Risk to Empathy, Compassion and Trust in Healthcare

Impact of Artificial Intelligence (AI) on Patient-Centered Care


Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article follows Part 1 - Basics of Artificial Intelligence (AI) and Healthcare Compliance published by AIHC on June 6, 2023 and Part 2 – Who Regulates Healthcare AI?.  AI is advancing rapidly, so we encourage you to reference the new Artificial Intelligence article category for the latest published by AIHC.  The COVID pandemic has proven that patients like telehealth and means other than face-to-face encounters for routine health needs.  But can AI replace the empathy, compassion and trust instilled during a personal encounter with a health care professional?  This article explores recent research on the topic of AI and patient-centered outcomes research.


As AI is integrated into patient care and medical coding, billing and accounts receivable management, will we risk the human connection of empathy and compassion which builds trust in the physician-patient relationship?  I embarked on a short research project to explore this topic and share my findings with AIHC members and affiliates.


Empathy, compassion and trust are fundamental values of a patient-centered, relational model of health care.  As Artificial Intelligence (AI) is advancing the delivery of health care and improving the diagnosis and treatment of our patients, is this promising technology providing greater efficiency and more free time for health-care professionals to focus on the human side of care, including fostering trust relationships and engaging with patients with empathy and compassion?  Or is it freeing time to see more patients to increase the revenue stream?


A June 2023 abstract was posted to the National Institutes of Health (NIH) National Library of Medicine, entitled “Artificial Intelligence in Health: Enhancing a Return to Patient-Centered Communication.”  The authors emphasize concerns around AI in the delivery of health care; concerns related to ethics, privacy, data representation and the potential of eliminating physicians. 


The article states “However, AI cannot replicate a physician's knowledge and understanding of the patient as a person and the conditions in which he or she lives. Therefore, provider-patient communication will be paramount in providing safe and effective health care.”


In April 2023, the NIH posted “The impact of artificial intelligence on the person-centered, doctor-patient relationship: some problems and solutions”.  The authors agree AI is a solution to freeing up of time for doctors and facilitating person-centered doctor-patient relationships. However, “… there is very little concrete evidence on their impact on the doctor-patient relationship or on how to ensure that they are implemented in a way which is beneficial for person-centered care.” 

  • Patient-centered outcomes research (PCOR) compares the impact of two or more preventive, diagnostic, treatment, or health care delivery approaches on health outcomes, including those that are meaningful to patients. 

In light of the given the importance of empathy and compassion in the practice of person-centered care, they conducted a literature review and found that besides empathy and compassion, shared decision-making, and trust relationships emerged as key values.


Using AI tools can have a positive impact on person-centered doctor-patient relationships, according to the article, when:

  1. using AI tools in an assistive role; and
  2. adapting medical education.

“Artificial intelligence and the doctor-patient relationship expanding the paradigm of shared decision making” is a June 2023 NIH article emphasizes how AI based clinical decision support systems (CDSS) are rapidly becoming more prevalent in healthcare, playing an important role in diagnostic and treatment processes. For this reason, AI-based CDSS has an impact on the doctor-patient relationship, shaping their decisions with its suggestions.


The article poses that we may be on the verge of a paradigm shift, where the doctor-patient relationship is no longer a dual relationship, but a triad. AI implementations may instead foster the inappropriate paradigm of paternalism. Understanding how AI relates to doctors and influences doctor-patient communication is essential to promote more ethical medical practice. Both doctors' and patients' autonomy need to be considered in the light of AI.


A successful AI case related to patient-centered outcomes was located on HealthIT.gov, the website for the Office of the National Coordinator for Health Information Technology (ONC).   ONC completed a project in September 2021 “Training Data for Machine Learning to Enhance Patient-Centered Outcomes Research Data Infrastructure.” 


Through this project, ONC in partnership with NIH and the National Institute of Diabetes and Digestive and Kidney Diseases (NIDDK), advanced the application of AI/ML in patient-centered outcomes research (PCOR) by generating high quality training datasets for a chronic kidney disease (CKD) use case – predicting mortality within the first 90 days of dialysis. This case was selected because mortality in the first 90 days of dialysis initiation in ESKD/ESRD patients remains notably high and included joint clinician-patient informed decision making. PCOR researchers can build off the foundational work completed through this project and extend the application of these methods to a wider array of use cases and advance the application of ML to enhance PCOR infrastructure.


Conclusion


Working in health care requires adapting to constant change as technology and software advancements force not only providers, but IT professionals and health care administrators to stay ahead of what is coming.


It is important to be fiscally responsible, however, do we want to live in a world where we can only speak to a machine regarding questions about our medical bills, or discuss our concerns regarding a treatment plan?  Where is the humanity in that?


We must move forward with integrating AI into our lives.  But, moving forward, it is important to re-evaluate whether and how empathy, compassion and trust could be incorporated and practiced within a health-care system where artificial intelligence is increasingly used. Most importantly, society needs to re-examine what kind of health care it ought to promote.


AIHC will continue to post articles related to artificial intelligence with regards to healthcare compliance.  Click Here for additional articles on various HIPAA topics.  Click Here for articles relating to Artificial Intelligence. Visit the AIHC Certifications page with online compliance learning opportunities.

Read More
Healthcare Revenue Cycle Compliance
Billing/RCM

Key Revenue Cycle Trends for 2022 and Beyond

Written by: Melvin Miller, COO




Tech, investments, efficiency, patient experience, underpayment recovery, and coding automation are some of the themes that will drive the revenue cycle market momentum in 2022 and beyond. Coming at the back-end of a long period of adversity due to COVID-19 and an already challenging economic environment for hospitals and healthcare systems, we see a new wave of consolidation, invention, and innovation. In this paper, we discuss some of the trends experienced in health care.


TIGHTENING PROFIT MARGINS – A PANDEMIC RAVAGED REVENUE CYCLE TO BOTTOM OUT.


With hospitals operating on extremely tight margins, projecting cash flow and the ability to extract the maximum out of the revenue cycle is more critical than ever before. This will drive key technology and process innovation as revenue cycle leaders and managers strive to improve business outcomes.


Now, let’s look at the broad trends in each of the major revenue cycle processes.


Patient Access and Experience


Patient experience is now one of the key issues impacting the healthcare industry. There is a huge information deficit in the area of patient payments.


Patients question “How much should I pay from my pocket?” The answer has been surprisingly difficult to find. Patients must get quick and easy access to information about services performed and corresponding charges; the amount expected to be paid by their insurance company; and the out-of-pocket expenses they are expected to bear. It is important to include the aspect of the No Surprises Act, which complicates the situation for both providers and patients.


We anticipate patient access and experience to improve with new technologies that can project the costs they need to bear, improved omnichannel information availability, and improved payment plans. Patient financial services will go through a much-needed overhaul.


Prior-Authorization and Eligibility Verification


While great tech exists for information interchange, prior authorization and eligibility verification tech adoption have lagged because of a lack of standardized documentation and information exchange protocols. With clearinghouses now modernizing, there is new hope for API-driven information exchanges.


Autonomous Coding


Automation tech is seeing increasing adoption, and there is a general perception that coding, billing, and accounts receivable problems will be solved through automation. Artificial Intelligence, Machine Learning, and Robotic Process Automation technologies provide great promise to lower labor costs. Medical coding is becoming data-driven and autonomous with improved standardization through ICD-11 and a better combination of virtual scribing, Universal Medical Language Systems (UMLS), OCR, and natural language processing (NLP). While these are still early days, coding tech is yet to prove effective in finding discharges not fully coded (DNFC) and arresting revenue leakage.


A/R, Denial Management, and Appeals Filing

Accounts Receivable (A/R) status has moved from calls to portals. We see increasing relevance for chatbots using conversational artificial intelligence (AI) in A/R and denial management filing. Data structures can now power customized appeals filing as well.

Focus on the Front-End

Most revenue cycle leaders agree that they need to solve revenue cycle issues in the front-end rather than elongate the cycle and wait to address them in the back end. They recognize that they need to link prior authorization, revenue integrity, clinical documentation improvement, and denial management to accelerate their revenue cycle. The ability to quickly identify denial issues, determine root causes, and develop solutions to reduce these denials through an iterative model that focuses on denial prevention is considered the key to addressing revenue cycle issues.

Underpayment and Analytics

The Hospital revenue cycle is fraught with underpayment issues. Contract analysis and underpayment identification can help arrest underpayments. As the shift to more branded, national healthcare practices happens, performance analytics becomes a critical business function. Practice-specific analytics using standard measures and Key Performance Indicators or KPIs will enable accurate views of performance and drive corrective action.

Unprecedented Financial Activity – Private Equity (PE), IPOs, Mega-mergers, and More

“It’s like Woodstock,” as some revenue cycle dealmakers are saying. The role of private equity in healthcare, in general, and the revenue cycle business, in particular, has increased to an unprecedented level.

  • Entry of the big boys. The big boys, i.e., the large PE firms have made strategic investments in revenue cycle assets.
  • Technology-led investments. Some of the themes that PE firms are investing in include focused revenue cycle service providers and niche technology companies such as autonomous coding, patient experience, prior authorization, and large-scale offshore providers.
  • Investments in revenue cycle aggregators. It seems like if a company’s resume says revenue cycle, it is likely to attract many valuations. Further, larger companies choose to hit the primary market through an initial public offering. We are seeing increasing consolidation of revenue cycle service providers as well.
  • Provider side consolidation. There is an increasing amount of investment in consolidation on the provider side. The push to provide a branded healthcare experience through nationwide chains is driving investments in areas such as urgent care, behavioral/mental health, wellness-focused treatments, home healthcare franchises, etc.

In 2022, we anticipate the continuance of these trends and mega-mergers will be more of a norm than an aberration.

Telehealth Adoption

Spurred on by the pandemic, telehealth adoption is increasing. Not only does this mean a lower cost of care, but it also requires the adoption of new processes for patient monitoring and managing the revenue cycle.

Remote Working

The COVID-19 necessitated revenue cycle team members to adopt work-from-home models. It also required operations managers to be flexible and adopt technologies to monitor revenue cycle performance. We anticipate that hospitals and healthcare systems will look at remote working as the new normal and encourage a significant percentage of their workforce to work remotely.

Labor Shortage and Outsourcing

There is an acute shortage of qualified revenue cycle staff. Many community hospitals are concerned about the community’s response to outsourcing and offshoring strategies they adopt. At this time of rising hospital expenses and reducing revenues due to declining reimbursements, outsourcing, offshoring, and automation can help them contain costs and sustain profitability. If using a U.S. based company that offshores the majority of their work, have you checked with legal counsel regarding how this type of business associate can be held accountable under U.S. laws (such as HIPAA, False Claims Act, etc.)

Conclusion

There has never been a better time to be in healthcare – and these are the most challenging times as well. Both in terms of economic activity and innovation, 2022 is likely to set a scorching pace. Whether you are a healthcare system, revenue cycle services provider, or technology solutions provider, this year will force you to think innovatively, build new delivery frameworks, and create the revenue cycle of the future.

Additional Resources:

_________________________________________________________

Melvin Miller is an experienced Chief Operating Officer with a demonstrated history of working in the healthcare industry for over 15 years, Satish, a.k.a. Melvin, has experience in team building, business development, Healthcare Information Technology (HIT), revenue cycle process training, US. Health Insurance Portability and Accountability Act (HIPAA), and Healthcare Management.
Read More
Telehealth
HIPAA, Telehealth

Audio-Video Telehealth, Mobile Device Management & You

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS


This article addresses how to track telehealth policies while addressing HIPAA compliance and mobile device management as the United States enters into a post-pandemic era. The information is an overview and should not be used as legal or consulting advice. Health care providers need to look toward long-term telehealth policies, ensure compliance and realize there is remaining work to be done. 


Scroll to the end of this article for “Basic Telehealth Terminology” if you are new to telehealth or if you are a mobile device app developer!


Most Providers Utilize Audio-Only Telehealth


More than two-thirds of providers utilizing telehealth use audio-only, according to a recent Telehealth Survey conducted November 2021 through December 2021 by the American Medical Association (AMA). According to this survey, 85% of physician respondents indicate they currently use telehealth. Those reporting a decrease in use since first offering it, now indicate doing a mix of in-person and virtual care. Of physician’s using telehealth, the trend indicates 93% are conducting live, interactive video visits with patients and 69% are doing audio-only visits.  


Considering this survey and other reports on audio-video services, concerns seem to focus on potential overutilization, equity and quality of care. 


A concern expressed to AIHC, by our Compliance and HIPAA Officer members, surrounds mobile devices used by providers and practice managers and the organization’s responsibility to comply with applicable rules, regulations and mobile device policies.


So, how do policies apply? 

 

If your providers use a mobile device to access an organization’s internal network or system, the owner of that network or system’s policies and procedures apply to your use of the mobile device to gain such access. It is your organization’s responsibility to understand and follow the organization’s policies and procedures.


If an organization allows providers and professionals to use mobile devices for work, the organization should have reasonable and appropriate mobile device policies and procedures. The policies and procedures should describe any configuration requirements for mobile devices used by providers and professionals for work. It is your responsibility to understand and follow your organization’s mobile device policies and procedures. But, what about using personally owned mobile devices for work?

  • "Bring Your Own Device" or BYOD refers to using a personally owned mobile device for work. Providers should be reminded to let their organization know when they want to use a personally owned mobile device. Many organizations have centralized security management to make sure mobile devices accessing their internal networks or resources are compliant with their security policies. Centralized security management includes:

o Configuration requirements, such as installing remote disabling on all mobile devices; and


o Management practices, such as setting policy for individual users or a class of users on specific mobile devices.


It is the provider’s responsibility to understand and follow the organization’s mobile device policies and procedures. Registering the provider’s mobile device with the organization allows the organization to control who has access to its network or system and will keep unauthorized persons from accessing its network or systems.

  • Registering these mobile devices with your organization may also help the organization or law enforcement find your mobile device if it is lost or stolen. Providers should be directed to contact their organization’s Privacy Officer or Security Officer to register their mobile device.

Utilizing Step 4 from ONC’s 5-Step Process to Manage Mobile Devices Used by Health Care Providers & Professionals, the list of questions below is a way to take inventory of potential safeguards needed to address risk areas.


Mobile Device Management


 If your organization allows the use of mobile devices, what should the organization do about managing the use of mobile devices?


   o Has the organization identified all the mobile devices that are being used in the organization? How is the organization keeping track of them?


   o Has the organization assigned responsibility to check all mobile devices used for remote access, to find out if selected security/configuration settings are enabled?


   o Should there be a regular review and audit of the mobile devices? 


Misuse of Mobile Devices


 Does the organization have written procedures for addressing misuse of mobile devices?


   o If so, what are the consequences when a mobile device is misused and the incident poses risk of a data breach?


Should the Organization Allow BYOD?


 Is this a policy already in place, where providers are using their own devices?


   o Should the organization let providers and professionals use their personally owned mobile devices within the organization?


 Should providers and professionals be able to connect to the organization’s internal network or system with their personally owned mobile devices, either remotely or on site?


Restrictions on Mobile Device Use


 Does the organization restrict how providers and professionals can use mobile devices?


   o Can providers and professionals use mobile devices to access internal networks or systems, such as an EHR?


   o Are providers and professionals restricted from using mobile devices when they are away from the organization?


   o Can providers and professionals take their mobile devices home?


   o Should the organization allow texting or emailing of health information?


      Is there encryption allowing compliant texting and emailing from the mobile device?


Security/Configuration Settings for Mobile Devices


 Will the organization institute standard configuration and technical controls on all mobile devices used to access internal networks or systems, such as an EHR?


   o If so, is the organization's current mobile device configuration document, including connections to other systems/applications, inside and outside of the firewall.


Information Storage on Mobile Devices


 Are there restrictions on the type of information providers and professionals can store on mobile devices?


   o If so, where and for how long should the data be stored?


 Are providers and professionals allowed to download mobile applications to mobile devices? If so, what type(s) of applications are approved?


Recovery/Deactivation of Mobile Devices


 Does the organization have procedures to wipe or disable a mobile device that is lost or stolen?


 Does the organization have standard procedures to recover mobile devices from providers and professionals when their employment or association with the organization ends?


Mobile Device Training


Training is always a challenge, but if your organization cannot achieve effective training and compliance, you may need to reconsider how telehealth is delivered to your patient population.


 How is the organization training its workforce (management, doctors, nurses, and staff) on policies and procedures?


 How does the organization hold its workforce (management, doctors, nurses, and staff) accountable for non-compliance? 


What Additional Information Should I Know for Compliance?


Covered entities must comply with HIPAA Privacy and Security Rules to protect and secure health information, even when using mobile devices as described above. Taking it a step further, health care leaders are responsible to ensure that mobile device procedures and policies have been developed and properly implemented to protect the health information patients entrust to you.


Make Tracking Audio-Only Policy Easy


A great resource is utilizing the National Telehealth Policy Resource Center called “CCHP,” short for Center for Connected Health Policy. CCHP has been tracking audio-only policies across the country and offers access to state audio-only policies via CCHP’s Policy Finder Tool.


As AIHC advises, another resource is legal advice through your malpractice insurance company. At no additional charge, a risk attorney can be made available to help review which policies impact your type of practice and organization.


Free HIPAA Compliance Resources


Another reliable resource is found at HealthIT.gov, the official website of the Office of the National Coordinator for Health Information Technology, otherwise known as “ONC.” ONC offers basic guidance in these five steps 1) Decide; 2) Assess; 3) Identify; 4) Develop, Document and Implement; and 5) Train entitled “five steps organizations can take to manage mobile devices used by health care providers and professionals.”


Does Your Organization Have a Trained (Certified) HIPAA Privacy/Security Officer?


Your HIPAA Compliance Officer can serve as the best resource to help your organization navigate the telehealth and mobile device compliance issues facing your providers today. AIHC offers an online course covering both privacy and security with the option of certification (proctored and administered online).  The cost of certification is covered in the tuition price. Learn more.


It is highly recommended that mobile health app developers and Managed Service Providers (MSPs) have an in-house HIPAA Compliance Officer contributing input to ensure technology is compliant.


Are You a Mobile Health App Developer?


Integrating protections into your technology to create HIPAA compliant products is necessary for your company to succeed. Health care providers are subject to the HIPAA rules as covered entities to protect identifiable health information when it is created, received, maintained and/or transmitted. These protections are required under Federal and State Privacy, Security and Breach Notification Rules. A few basic resources to reference are:


The Office for Civil Rights (OCR) HIPAA website devotes a webpage under Special Topics entitled “Resources for Mobile Health Apps Developers.”


The Federal Trade Commission (FTC) offers a webpage entitled “Mobile Health Apps Interactive Tool” to help you locate federal laws to follow.


For Beginners - Basic Telehealth Concepts


Telehealth is also referred to as Telemedicine. It is the use of telecommunications technology to provide health care services to persons who are at some distance from the provider. This type of patient encounter involves a spectrum of technologies.


Coverage and payment for telehealth can include consultation, office visits, individual psychotherapy, pharmacologic management and other services delivered via an interactive audio and video telecommunications system.  

  • Providers are located at the distant site; and
  • Patients are located at the originating site.

Provider at the distant site - As stated above, providers are at the “distant site,” referring to where the provider is at time of service. The provider can communicate with the patient using an interactive audio and video telecommunication system that permits real-time communication with the beneficiary.


When telehealth is used, it is considered to be rendered at the physical location of the patient, and therefore a provider typically needs to be licensed in the patient’s state. During the COVID-19 public health emergency (PHE), many states waived this requirement or provided specific exceptions. Click Here for Cross-State Licensing information.


Medicaid programs often restrict the type of providers that can be reimbursed when delivering services via telehealth. During the COVID-19 PHE, the list of providers in Medicare and many state Medicaid programs expanded to include professionals such as occupational and physical therapists and speech-language pathologists. Federally Qualified Healthcare Centers (FQHCs) and Rural Health Clinics (RHCs) were also allowed to provide services in some cases. These policies are temporary and most will expire at the end of the PHE.


I also recommend utilizing the TELEHEALTH.HHS.GOV website for providers – “Getting Started with Telehealth.” This webpage provides many additional links to more resources your organization can use to navigate this complex topic.


Temporary telehealth policies during the PHE were implemented to provide improved access to health care during the COVID-19 pandemic. The federal government has been encouraging providers to use telehealth to conduct virtual appointments and has made the telehealth “rules” more flexible. For instance, audio-only delivery of care has rarely been reimbursed historically. But due to COVID and the PHE, temporary policies allow this modality to deliver some services.


The PHE is reviewed and potentially extended every 90 days. When the PHE ends, coverage for telehealth may change. Monitor these updates by using the CCPH website referenced earlier in this article found at https://www.cchpca.org/.

Read More
Telehealth
Telehealth

How Geriatric Care Will Change in the New Normal

Written by Sophie Johnson




The healthcare industry has been transformed by the pandemic, and one part of healthcare that was thrust into the spotlight over the last 16 months is geriatrics. The Centers for Disease Control and Prevention (CDC) states that older adults were more at risk of coronavirus complications, which put them at a higher likelihood of being hospitalized. This has changed how the healthcare sector has responded to seniors, and it will continue to shape how geriatric healthcare will continue in the new normal.


How COVID Affected Geriatric Care


The elderly were affected more severely by the pandemic because they were already a vulnerable population to begin with. Beyond preventing and treating the virus itself, healthcare centers also had to mitigate the adverse effects of extended isolation for older patients. Other restrictions also prevented seniors from getting the physical activity needed to maintain their health, leading to a faster-deteriorating state.

The beginning of the pandemic presented the greatest challenge for geriatric healthcare workers since there were physical distancing protocols in place. Geriatric care shifted to telehealth to meet the needs of older adults. This presented many challenges, the most pertinent one being how to increase the digital literacy of older people, as it became the main way to access resources and contact persons. As these challenges continued, caregivers and family members have had to give more support to seniors to ensure that their needs would be met and, ultimately, prevent hospitalization.

How Geriatric Care Will Change in the New Normal


The way care has changed during COVID-19 will likely continue into the new normal, but there will certainly be some changes in the preventive measures taken to ensure older adults are resilient, healthy, and safe.

Telehealth will grow

According to Pew Research, only about 40% of people aged 74 to 91 years use the internet. However, this is drastically changing. Doctors are seeing more and more virtual visits from older people as part of their practice. And with the ability to access doctors online becoming much easier now, senior patients may be inclined to make more visits, which will significantly improve their overall health.

One of our previous blogs, How Telehealth Is Being Used to Treat Mental Health, discussed how telehealth has also already improved mental health for older people through online therapy, emergency services, and remote monitoring programs, all of which are likely to become the norm in the new normal.

People will have more than one physician

Older people will likely be seeing teams of doctors rather than just one dedicated physician. It is a more efficient and cost-effective way of accommodating patients and for those patients to have their needs met without long waits. And with easier access to more doctors, seeing several specialists is now easier than before.

Coverage plans will become a priority

Apart from getting vaccinated, the CDC also recommends seniors take extra preventive measures to protect themselves from contracting COVID-19. However, individual efforts such as wearing a mask and a healthy lifestyle may no longer be sufficient, especially for older people who are at risk of suffering from other conditions.

This increased awareness in the new normal will see a rise in older adults investing in medical plans. Fortunately, the healthcare industry has long anticipated this, with many different plans available that cater to specific needs. Kelsey Care Advantage outlines the different packages available, some focusing on dental care while others put a premium on cardiovascular conditions. Older adults may even prefer medical coverage that includes medication and fitness benefits. Being prepared in this manner will allow older people to feel more secure should any health concerns come about in the future, COVID or otherwise.

For additional timely and relevant healthcare related information like this, please check out our other blog articles and access all of our course offerings at AIHC.

Read More
HIPAA Compliance
HIPAA

Healthcare Apps and Data Privacy/Security Risks

Written by Susan Walberg, JD MPA CHC




Healthcare apps have become increasingly prevalent, with people using them for counting steps, monitoring their calories, or linking to various medical devices, to name just a few examples. Since the COVID outbreak, however, and the explosion of telehealth as a healthcare option, these apps have proliferated at an insane rate. As of 2020, there were 325,000 healthcare apps on the market, with more coming all the time.


Whether you are a consumer who uses such apps, or a provider who wants to develop an app for patients to use, it’s important to understand some of the privacy and security risks that may accompany the use of such tools and what to watch out for.


What Are Healthcare Apps?


An ‘app’ is a small program that can be loaded onto a phone or mobile device to perform a specialized function. There are two main types of healthcare apps in terms of privacy and security regulations, and the rules governing them vary accordingly.


The first type are the applications that are used by your healthcare provider. They may be used to store your lab or radiology results or might be integrated with a medical device for tracking/monitoring purposes, such as an electrocardiography device that monitors heart activity. Or they may be used to coordinate your care.


The second type are personal or private healthcare apps, those that an individual can get at an app store to track and manage their diet, exercise, or specific health conditions. There are apps for mental health, diabetes, and, of course, COVID, to name just a few. Many of these apps are free.


Nothing in Life Is Free


First, let’s talk about those ‘free’ apps.


Free apps, how cool is that? Depending on your view, an application that tracks and shares your personal information might not really be ‘free’.


If you go online and look for a free app to help you count calories or manage your diet, for instance, the odds are good that there are advertisements on the app, right? Well, most of those ‘free’ apps, with the ads included, will be sharing your information with the advertisers and perhaps even with other companies, such as the ‘big tech’ companies or other stakeholders or investors.


You may expect this, and you might not care. After all, any online Google search leads to targeted Facebook ads relating to that same subject matter, as many of us have noticed. We may not like it, but we are getting used to the fact that our online activity is not really private.


But when you choose one of those apps, think about what information you are entering, because it is probably not private. How much of your medical information is being collected in order to help you manage your diabetes or exercise program? And do you know where that information might be shared? You may accept the fact that your use of the app is not private, just like your Google searches seem to have a direct pipeline to Facebook. But think about the data collected, because that’s not private either. And that’s not illegal in this situation.


But…But…HIPAA


How can this health information NOT be private? There must be regulations protecting your privacy, especially when it comes to your healthcare information, right? We hear all the time about HIPAA (The Health Insurance Portability and Accountability Act of 1996) and how your health information can’t be shared.


Just to be clear, in a nutshell, HIPAA only applies to those apps that are used and offered by your healthcare provider or insurance company (or some similar organization that is regulated by HIPAA). Those organizations are subject to the HIPAA Privacy and Security regulations (as well as the HITECH and Omnibus laws that followed), so any product they offer in conjunction with their regulated services would typically be subject to the same laws. This does not mean that if your doctor tells you there are apps in the marketplace to monitor your diabetes that they would be subject to HIPAA. But if your insurance company, for instance, offers you a tool as part of your plan that will help you manage a chronic health condition, HIPAA would generally apply. You may not be sure, so it’s important to ask.


If the app is, indeed, regulated under HIPAA, that means that privacy and data security controls must be in place. There should be a privacy/security policy that you can review, and you have specific rights with respect to your information and how it’s used. There are limitations around, for instance, how your data can be used or shared for marketing purposes. It also means that there must be a designated privacy and security ‘official’ who has oversight of compliance with these regulations. A company that provides a healthcare app to physician practices, insurance companies, or similar organizations would be considered a ‘Business Associate’ of that provider or insurance company, which means they are subject to the same requirements. HIPAA does provide a broad range of protections, but they are limited to those specific scenarios.


The reality is that few laws govern the privacy of information you voluntarily share in one of these publicly-available apps, so if you go online and pick an app to track or monitor your own health condition or information…most are not subject to privacy laws.


Apps Provided by Your Physician, Insurance Company, Etc.


The apps used by your doctor’s office or insurance company are subject to much tighter regulation, but also often contain more personal data. Especially with the increased use of telehealth services, provider’s offices are relying on various applications and platforms to facilitate the provision of healthcare services. These apps, and the companies that offer them, are covered under HIPAA as ‘Business Associates’ of the provider or insurance company if the app uses, stores, or transmits patient health information on behalf of the healthcare organization.


Due to COVID, the government has loosened up the privacy regulations in order to allow greater flexibility in providing telehealth services. While this is good news for providers and the patients needing those services, it also means more potential risk to protected health information (PHI). It’s important to keep in mind that, in addition to whatever information you enter online, a telehealth application likely has requested permission to access your calendar, camera, and microphone.


The good news is that, although providers may have been using some of the less secure apps in the beginning of COVID, just out of necessity, those providers who plan to continue providing telehealth services are working to ensure compliance with privacy and security requirements. App developers are busy developing apps to accommodate this changing market, and compliance is a top concern.


Apps as Mobile Devices


There is one type of application which is actually considered by the Food and Drug Administration (FDA) to be a medical device, in addition to being covered under HIPAA (because they are provided in conjunction with healthcare services). Those are the apps that are intended to be used ‘for the diagnosis of disease or other conditions, or the cure, mitigation, treatment, or prevention of disease, or is intended to affect the structure or any function of the body of man’ under section 201(h) of the Food, Drug, and Cosmetic Act. In general, if the purpose or function of the app is to assist in performing a medical device function, it will be treated as a medical device under the FDA. For instance, if the app can be run on a smart phone or other hand-held device and analyzes and interprets EKG waveforms to monitor cardiac irregularities, it would be considered analogous to those software programs that perform the same function and are otherwise regulated as a medical device.


The intent of the FDA is to ensure patient safety related to the use of those devices that could compromise or risk patient health. This oversight is limited to those devices marketed and offered to perform these medical device functions.


Although the FDA purview is not privacy or data security, the FDA jurisdiction is noteworthy in terms of regulatory oversight. For purposes of HIPAA, these devices would typically be subject to the Privacy and Security rules as they are used in conjunction with your provider or insurance company, as discussed above.


How Do You Know if Your Data Is Secure?


Apps in the marketplace that are available to help track health-related information should have a privacy policy, although at the current time it is not required by law for apps that are not considered a medical device or are subject to HIPAA. It is highly recommended that you find those policies and read them, even though some may be lengthy and not written clearly (might be overly technical or legalistic).


Even if the apps have privacy policies, those policies might not be easy to find, and you might discover that the policy does state the ways in which they do share your information. There is no law against the sale or disclosure of data from independent apps to third parties and those apps are being funded somehow (data is valuable). In addition to data sharing, the privacy policy should explain how it safeguards your data. There should be information security measures in place to prevent breaches of your data. And lastly, even if the privacy policy sounds good, the app developer may not necessarily follow their own policies. This is not to say that an app developer is deliberately being deceptive; a developer or their sponsoring company may adopt a policy from another app they are familiar with or may bring in a consultant to write their policy, but the specific terms in the policy aren’t implemented during development. It can happen. And this isn’t limited to app developers; any organization can fall short of following its own policies. Many app developers have a technical or clinical background and may not fully understand the healthcare regulatory framework.


You can also check an app’s automatic settings and look for those that impact privacy, such as location tracking. Beware, though, that in some instances turning those options off will make it more difficult to use the app.


The bottom line here is caveat emptor…buyer beware. Especially if you’re not ‘buying’ and it’s ‘free’.


How Can Data Be Compromised?


Even when providers, insurance companies, and app developers are focused on compliance with the various privacy and security requirements, PHI can still be compromised, but it is less likely. Common mishaps occur in a number of ways:

  • Employee errors. Human errors can occur in any setting. It can be an employee discussing patient information out loud in a non-private setting, clicking on a link that allows a virus or ransomware attack, or accidentally entering an incorrect phone number and sending information to the wrong person. This isn’t limited to technology-related issues but privacy in general.
  • Poor access controls. There needs to be a solid process, that is followed religiously, to ensure that only individuals who need access are given access, and that former employees or business associates are promptly removed when they no longer have a need for access. This also includes business partners who have employees who need access in order to provide services to another company or practice. These employees need their own access, not a universal access that cannot be tracked.
  • Failure to monitor. Any organization that maintains PHI electronically should have a process for routinely reviewing who is accessing sensitive information and following up on any questionable access. Audit trails are part of any good security structure.
  • Failure to securely store data. Not only should data be stored in a secure manner, it should also be consistently destroyed/removed when applicable retention periods have expired.
  • Inadequate encryption.
  • Workstation and device security. Applications should time-out when not in use, rather than rely on users to remember to do so.
  • Failure to conduct a comprehensive risk assessment that includes the various apps and networked devices where PHI is stored or transmitted.
  • Increased remote workers. Employees working from home are more likely to use personal devices that don’t have proper levels of encryption and that are, by definition, less private due to the offsite location. Access is much harder to control and networks may not be secure.

The above issues do not pertain only to apps, but in general to information privacy and security, especially in the new era of increased telehealth services. Those issues are also the types of failures HIPAA was designed to prevent and would likely be considered violations, depending on the specific facts. If you are considering using an app or electronic platform where personal information will be entered, it’s recommended that you ask your provider or insurance company who is offering this tool what their privacy and security policies are. If their organization is using and recommending such a tool, they have almost certainly done the review of privacy and security controls. And if you are a provider considering using an app, or an app developer, the above list is for you. You should have designated ‘privacy and security officials’ who ensure the above risk areas are addressed.


What Are the Risks?


Most people care about the privacy of their health information just because it’s private and not other people’s business. But there are actual risks to consider, which users of these apps should understand:

  • Data is shared with third parties for sales and marketing, increasing the targeting of ads you receive.
  • Even information that is supposedly ‘de-identified’ can include enough information to make users identifiable, and it may be very sensitive information, for instance relating to mental health or substance abuse.
  • Medical identity theft, which can result in someone using your identity to receive free healthcare services or to file fraudulent claims. Healthcare data is valuable for those reasons, which is why it is often targeted by hackers.
  • Additional outside companies, such as Facebook or Google, may acquire the information and build user profiles. Once the information is out there in that environment, there is little control over it and it’s difficult to know who could access it or how it could be used.
  • Your PHI could be acquired by insurance companies or other healthcare companies that could use it against you in underwriting or pricing determinations. Who else would you not want knowing your private information? An employer? The possibilities are frightening, especially considering that once the information is out there, it’s out there. You can’t put the genie back in the bottle.

Conclusion


Telemedicine and the use of online applications has exploded in recent years, particularly in relation to the COVID pandemic and the resulting changes in the delivery of healthcare. The regulatory framework has not necessarily caught up to technology yet, so while HIPAA laws apply to some applications, many that are out there being used by consumers are not regulated in terms of protecting sensitive information. Health information can be bought and sold in the marketplace, it has a value for advertisers, thieves, and others.


For consumers, just be aware of the potential risks before you start using an app; check the app’s privacy and security policies and consider carefully what information you are comfortable exposing. If the app comes from your provider or insurance company, ask about the security controls and how they are protecting your data.


For providers, consider your own liability in terms of recommending an app and make sure your organization has done its due diligence to ensure proper security measures are in place. You should have your own privacy and security experts evaluate the tool before offering it to patients.


For app developers, be aware that technical security isn’t your only concern; you will want to have assistance from someone with healthcare privacy and security regulatory expertise. This will be something that potential clients and investors will be asking about.


Susan Walberg is a healthcare consultant who works with providers and healthcare start-ups. She can be reached at https://www.susanwalberg.com/

Read More