Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Monday, December 9, 2013

You Need to Adapt in Order to Survive: How Your Medical Billing Service Can Prosper During the Healthcare Industry Chaos

How Your Company Can Prosper During the
Healthcare Industry Chaos

The healthcare industry is facing a state of complete disorder and confusion: Uncertainty surrounding the implementation of the Affordable Care Act, the looming switch to ICD-10, EHR and "meaningful use" deadlines, hospital acquisitions of physician practices, new HIPAA rules, and Health Insurance Exchanges... the list goes on. It seems like a challenging time for medical billing companies – and it is.
 
The good news is that not only can you prosper, you can bring hope and financial stability to struggling practices and salvage some that would otherwise collapse and shut down (or get swallowed up by a hospital or other acquisition entity). How can you assure your and your clients' continued prosperity and growth?
 
Focus on becoming a full-service revenue cycle management company.
In today's dynamic marketplace, billing companies that do not keep up with the constant changes will be left in the dust by companies that do. You must not only stay current with what is happening in the industry, you need to make alliances with other companies that can provide services to your clients that will help them solve cash-flow challenges beyond just their medical billing. The more services you can offer to your clients, the more you will be perceived as "the expert" who can solve their cash flow problems.

A brief review of the latest issue of Billing will introduce you to vendors that can be valuable to you in assisting your clients with medical coding questions, HIPAA compliance, EHR Meaningful Use attestation, online document management, patient portals, integrated payment channels, patient collections, and other revenue cycle issues. Do not forget that HBMA conferences will introduce you to technology partners that can help you keep up with changes in this dynamic industry.
Make sure you are using a billing system that is fully integrated with an EHR system.
Many outdated, server-based billing systems are trying to patch together a practice management system with one of the new electronic health record systems designed by a different company or on a different platform. The company that developed the practice management (PM) system creates an interface with an EHR system developed by another company. Chaos generally ensues.

If this is the case with your PM system, you are only asking for headaches and a possible loss of clientele. EHR companies are dropping by the wayside every day. Some of them are also server-based. Trying to get them to work together with billing software is like using "bubble gum and bailing wire" and will only lead to ongoing issues in your company. Two different companies, with two groups of programmers, trying to keep all the different parts of both systems running smoothly is almost impossible and can lead to turmoil in your company.

As painful as it may seem now, it may be a good idea to begin looking for a billing system that is totally integrated with an EHR system. That means that it was designed from the ground up by the same programmers in the same company. There are such systems available, and most of them are cloud-based (accessed securely 24/7 through a browser via the Internet).

Anything less than total integration of the two systems could be a disaster waiting to happen. Start your research now and find a system that will take you into the future, especially with any new clients you bring on. And, as part of your due diligence, make sure there is a way to import the data from your current system into the new system (at least the patient demographics). Then, begin to educate your current clients on why they need to start using an EHR, if they are not already, and why they might need to use a system that is fully integrated with your billing system.

Look for a system that has a way to electronically communicate with insurance company databases. You need one that checks for eligibility and automatically imports the patient data directly from the insurance company's database to create new patient charts. This will save you hours of data input and will help you keep employee costs under control. It will also prevent you from submitting claims that are sure to be rejected because the patient was not eligible for the service and it will keep the practice from spending time seeing patients that insurances will not cover. This will increase your revenue for that practice and will eliminate a large number of claim rejections as well.
 
Keep up with changes in the industry.
I can predict the success you are going to have in your business – and in life in general – if you will tell me just two things: the people you associate with and the books (and periodicals) that you read. Do not get bogged down in the details of your billing business. You need to set aside time to attend industry conferences at least once a year and to read industry newsletters and books.

The person who does not read is no better off than the person who cannot read, so set aside time each week to read about our industry and keep up with the constant changes. Change is what life itself is based on, and if you are willing to change along with the industry, you and your clients will prosper.

Do not assume you will have your current clients forever.
You won't. Things change in medical practices: staff turnover, new policies and procedures, new government rules and regulations, competition, updated technology, and the marketplace itself. All these things can cause you to lose a client from time to time. You must always be marketing.

Whether you realize it or not, your competition in this industry is not just other medical billing companies. The practice itself is your biggest competition. All it would take is for a new office manager to come into one of your practices and decide that they would rather not outsource their billing: they think they can do it themselves more efficiently and more economically. You must keep reselling your clients on your efficiencies and on your cost savings versus doing the billing themselves internally. Provide them with revenue reports that delineate what percentage of billed dollars (expected) are actually being collected. Show them you are the expert in this industry by producing and providing to them a professional newsletter with articles that show that you keep up with the changes in the industry. HBMA has a newsletter you can purchase and tailor with your company logo (www.hbma.org). 

Take the practice administrator (or the doctor) to lunch from time to time and show them printed reports that illustrate the revenue collections from both insurance providers and patients. Hold "Lunch 'n Learns" on a regular basis with your clients to bring them up to date on what is happening in the medical industry. Position yourself as the expert. People want to do business with "the expert" in every field.

When you buy a home, you do not want the new real estate agent: you want the guy or gal who has sold 100+ homes. When you look for a CPA, you do not want one who just hung out his or her shingle: you search for one who pays less than double digits of their own taxes and has a number of clients who they service. The same is true of a doctor's office. They want to feel that they are dealing with the company that can bring in every last dime that is due to the practice.

Continue to network with other business people in the community and join your local BNI group or chamber of commerce. Get out once a week and let people know you can solve the cash crunch for doctors and help them build their practices through your contacts.

Set up an automated way of keeping in touch with everyone you come in contact with who is a prospective client. Let them know that you are the only company that they should do business with. When it comes time for them to decide to outsource their billing, you are the only choice that makes sense. People do not buy when you are ready to sell – they buy when they are feeling the pain. Be at the top of their list when they decide it is time for change.

Remind your current doctors and office administrators that you are looking to build your business. Assuming you have done a good job for them, ask them for a referral. You would be surprised as to how many billing company owners never ask their clients for referrals. Do not just ask for the name of someone. Ask your client to pick up the phone and call the other doctor or office administrator and tell them how pleased they are with your billing service and that they think it would be in their interest to meet with you.

You can shrivel up and die in this ever-changing industry, or you can make the choice to grow and prosper, starting right now!
READ MORE - You Need to Adapt in Order to Survive: How Your Medical Billing Service Can Prosper During the Healthcare Industry Chaos

Friday, November 22, 2013

Revenue Cycle Efficiencies and ICD-10

By Rachel V. Rose, JD, MBA from Physicians Practice

According to a Bank of America Merrill Lynch Executive Insight Report, Opportunities From Financial Efficiencies, produced in collaboration with HealthLeaders Media, financial leaders indicated that the "revenue cycle is where they could find the most efficiencies. The revenue cycle has been a focus of the industry for years, but the need for improvement is increasing given the payment model shifts that will come as a result of healthcare reform." (p. 2).

Given the upcoming October 1, 2014, transition to ICD-10, the revenue cycle is being scrutinized more closely than ever in preparation for the greatest impact on healthcare billing since the transition to prospective-payment, diagnosis-related groups (DRGs) in the early 1980s. Currently, physicians and other healthcare providers are considering how to contend with the decrease in claim-submission productivity due to the increased specificity, as well as potential denials and the effect on the revenue cycle.

Given the multiple aspects of ICD-10 transition, which could be focused on, I am going to provide some suggestions in the area of coding and compliance, which I have addressed directly with providers. First, like HIPAA, all entities are required to meet the ICD-10 requirements, regardless of their size. In light of this, coding and compliance policies and procedures should be established based upon state, federal and regulatory agency guidelines. Moreover, private payers may be implementing similar standards, especially those involved with Medicare Part C claims submissions.

For these private payers, state prompt-pay laws may be in effect that will enable providers to collect for untimely billing practices by private payers. Second, educating everyone throughout the revenue cycle proactively will enable efficiencies to be captured now and reduce the cash gap during the October 2014 transition. Third, regular compliance audits, including medical necessity, are critical to reducing adverse outcomes from RAC and ZPIC audits, as well as diverting the billing departments' efforts from clean claims submissions to reactively dealing with legal processes. Finally, the caliber of coders is crucial. It is inadvisable for providers to skimp on coder certification, training, and input. Outsourcing is also an option, but make sure that the appropriate HIPAA and Health Information Technology for Economic and Clinical Health, or HITECH, Act business associate requirements are in place.

In sum, "revenue cycle issues … caused the most anxiety among [the BAML] survey respondents, with 25 percent saying they felt 'very' exposed to potential losses." (Ibid. at p. 5). By being proactive and implementing effective compliance programs, healthcare providers can reduce their anxiety and potentially mitigate significant losses on the revenue cycle.

By Rachel V. Rose, JD, MBA from Physicians Practice
http://www.physicianspractice.com/blog/revenue-cycle-efficiencies-and-icd-10?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=19112013
READ MORE - Revenue Cycle Efficiencies and ICD-10

Thursday, October 31, 2013

New Measures in Pay-for-Performance Programs

Pay for performance, or P4P as it is more commonly known, is not a new concept and some plans have been using this type of initiative with providers for a decade or more. Those providers that participate in Medicare's Physician Quality Reporting System (PQRS) — which uses a combination of incentive payments and payment adjustments to promote reporting of quality information — as well as those participating in large Blues plans, will be most familiar with this model.

The shift What is new is the shift away from P4P as a "bonus" structure and a shift toward an "earning" structure. That is, the extent to which payers are incorporating P4P into their payment strategies means that a portion (or percentage) of providers' revenue is "earned" through meeting P4P targets or measures.  These new models are referred to as "value-based," shifting away from straight fee-for-service payments to some combination of performance- and fee-based compensation, which puts some of the financial risk on providers. The hope is this type of compensation model will improve the quality of care, reduce medical costs over time, and improve patient outcomes. So you can think of the newer P4P models as Pay for outcomes, or P4O.  Under Medicare  The Affordable Care Act expands P4P efforts in hospitals through the establishment of a Hospital Value-Based Purchasing Program begun last year, where hospitals are rewarded for how well they perform on a set of quality measures, as well as on how much they improve in performance relative to a baseline.  The healthcare law also extends the Medicare PQRS program through 2014. However, beginning in 2015 the incentive payments go away, and physicians who do not satisfactorily report quality data will see their payments from Medicare reduced. This marks the real beginning of P4O, in my view, due to the setting of a "quality care" baseline against which the ability to earn will then be tied.

By commercial payers For commercial payers, value-based contracts are springing up around Patient-Centered Medical Homes (PCMHs) and accountable care organizations (ACOs). However, new and negotiated contracts for generalized services — that is, practices that are not technically a PCMH or ACO — are now typically being crafted with P4P/P4O components that allow practices to "earn" additional dollars or year-to-year increases in multi-year contracts through meeting specific measures and targets.  Theses measure are typically HEDIS-based (Healthcare Effectiveness Data and Information Set) which is a widely used set of performance measures developed and maintained by the National Committee for Quality Assurance (NCQA). Many of these measures are focused on high-cost conditions such as heart disease, diabetes, high blood pressure, as well as preventive measures like immunizations and medication management. New and changed measures for 2014 include breast- and cervical-cancer screenings.

 Commercial payers utilizing P4P measures typically have a combination of HEDIS-type "quality" measures as well as "self-reported" measures, where practices can report on items such as EHR implementation and use, and status in achieving NCQA programs such as Patient-Centered Medical Home (PCMH), diabetes, heart/stroke, and back pain recognition programs. In addition to NCQA measures, there is substantial investment underway by the Agency for Healthcare Research and Quality (AHRQ) and other public policy organizations to identify further evidence-based medicine practices that could be used for measurement. And the National Quality Forum (NQF) is leading focused efforts to collect and normalize data, and endorse additional performance measures.

Article By Susanne Madden of physicians Practice http://www.physicianspractice.com/physician-compensation/new-measures-pay-performance-programs?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=31102013
READ MORE - New Measures in Pay-for-Performance Programs

Wednesday, October 30, 2013

Ethics on Ending the Patient-Physician Relationship

Once you accept a patient into your practice, you are under an ethical and legal obligation to provide services to the patient as long as the patient needs them.  There may be times, however, when you may no longer be able to provide care.  It may be that the patient is noncompliant, unreasonably demanding, threatening to you and/or your staff, or otherwise contributing to a breakdown in the patient-physician relationship. Regardless of the situation, you must avoid a claim of "patient abandonment."  Abandonment is a tort, similar to negligence, defined as the termination of a professional relationship between physician and patient at an unreasonable time and without giving the patient the chance to find an equally qualified replacement.
There must be some harm from the abandonment.  The plaintiff must prove that the physician ended the relationship at a critical stage of the patient's treatment without good reason or sufficient notice to allow the patient to find another physician, and the patient was injured as a result.  Usually, expert evidence is required to establish whether termination happened at a critical stage of treatment.
A physician who does not terminate the patient-physician relationship properly may also run afoul of ethical requirements, and find himself before the medical board.  According to the AMA's Council on Ethical and Judicial Affairs, a physician may not discontinue treatment of a patient as long as further treatment is medically indicated, without giving the patient reasonable notice and sufficient opportunity to make alternative arrangements for care.  Further, the patient's failure to pay a bill does not end the relationship, as the relationship is based on a fiduciary rather than a financial responsibility.

According to the AMA's Code of Medical Ethics, Opinion 8.115, you have the option of terminating the patient-physician relationship, but you must give sufficient notice of withdrawal to the patient, relatives, or responsible friends and guardians to allow another physician to be secured.

The Health Care District of Palm Beach County offers this advice regarding the appropriate steps to terminate the patient-physician relationship:

1. Giving the patient written notice, preferably by certified mail, return receipt requested;
2. Providing the patient with a brief explanation for terminating the relationship (this should be a valid reason, for instance non-compliance or failure to keep appointments);
3. Agreeing to continue to provide treatment and access to services for a reasonable period of time, such as 30 days, to allow a patient to secure care from another person (a physician may want to extend the period for emergency services);
4. Providing resources and/or recommendations to help a patient locate another physician of like specialty; and
5. Offering to transfer records to a newly-designated physician upon signed patient authorization to do so.

Following this protocol may be easier in some situations than others.  For example, if a physician has signed a covenant-not-to-compete, chances are the employer will not hand over the patient list upon notice of departure.  In instances such as these, you (in consultation with your attorney) may want to provide a model patient termination letter to the party withholding your patients' addresses, and request that the addresses and letter be merged for distribution to your patients. 
Ideally, you should not be in a contractual arrangement that makes contacting your patients difficult.  However, if you find yourself in this situation, work with an attorney to ensure that appropriate steps are taken.

Article  By Martin Merritt of Physicians Practice http://www.physicianspractice.com/blog/ethics-ending-patient-physician-relationship?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=29102013
READ MORE - Ethics on Ending the Patient-Physician Relationship

Wednesday, September 11, 2013

What Practices Need to Do Now to Prepare for HIPAA Omnibus Changes

The September 23, 2013, deadline for when covered entities such as physician practices must be in compliance with the HIPAA Omnibus Final Rule is quickly approaching. The rule marks the most sweeping changes to the HIPAA Privacy and Security Rules since they were first implemented.

While the final rule brings about many changes, there are three in particular that likely warrant the most attention from practices now. The following column identifies those changes and provides practical guidance to meet the new requirements.

Change 1: The definition of what a "breach" is has been modified.
What it means: Under the old law, a breach was an event that "compromises the security or privacy of the protected health information (PHI) such that the use or disclosure poses a significant risk of financial, reputational or other harm to the affected individual." Under the new rule, the definition of a breach is expanded to include even just the "risk" of impermissible use or disclosure of PHI. For example, if you have patient records on a thumb drive and that drive is lost, if the records are not password-protected or encrypted, that will be considered a breach even if the data is never accessed by anyone. An incident report should be filed with your HIPAA officer. If you lose a laptop but can prove the computer is encrypted and nobody is able to access the information without a secure ID, thus indicating a low probability of the PHI becoming compromised, you will not have committed a breach.
What practices should do: Perform a complete risk assessment in an effort to minimize security holes and prevent possible breaches. Three of the most common causes of breaches are stolen laptops, lost or stolen external hard drives or thumb drives, and sending PHI through unsecured email.
Change 2: The definition of a "business associate" (BA) has been completely reworded.
What it means: A BA is essentially a company or any person who is not a member of the workforce for the covered entity but has access to PHI. This would include contractors and now, under the new rule, subcontractors under the BA. 
What practices should do: Review all BA agreements to see if they need to be revised or replaced. With older agreements, a BA could potentially include a clause that says the BA cannot be held liable for PHI breaches. Now, a BA can be held directly liable. BAs can still try to include the clause to remove themselves and their subcontractors from liability, but a practice would be wise to object to such a request and a BA will lack a strong argument for the clause's inclusion. An example of when a BA might be liable: If an IT company has an off-site data backup and somebody steals the backup device, the BA can be found personally liable for breach of all of the health records on that device. An example of when a subcontractor might be liable: If the IT company were to bring in a subcontractor to run network cable and electric lines in a new service center, that subcontractor would then be considered a BA and potentially liable since it could have access to PHI.Since all BAs are more stringent under the new HIPAA security laws, BAs themselves need to now remain HIPAA compliant.
Change 3: HIPAA audits will happen more frequently, fines will be substantially higher, and auditors will be incentivized to find security problems.
What it means: Periodic HIPAA audits by HHS were already authorized and underway, but covered entities can expect them to happen more frequently once the new rule is enacted.In addition, fines associated with penalties due to HIPAA violations will become significantly higher and essentially without a limit.Finally, auditors will receive what amounts to a "kickback" for each security violation discovered during an audit, which incentivizes auditors to dig deep and find any and all holes. 
What practices should do: The best practice is to perform at least quarterly risk assessments. This will help ensure security hole fixes put in place are working and holding and identify other potential problems. If you can indicate to an auditor that you performed a risk assessment, identified a problem, and have a plan in place to fix it, the auditor is more likely not to consider the problem an issue unless it remains unresolved. Many covered entities rely upon an external company to perform such risk assessments. These companies are not only skilled in identifying security problems and issues often overlooked by covered entity staff members, they have the knowledge and ability to take care of requirements such as creating policies and procedures for administrative safeguards, setting up employee training and changing all IT systems so they have a data backup plan, specific user names, and password policies in place.
Larger organizations may consider hiring someone to handle these responsibilities, but this may be cost prohibitive. For smaller organizations, it's often more cost-effective to hire a company to handle all of these tasks and help ensure year-round compliance.
-
Article By Nelson Gomes and Michael Daly of Physicians Practice http://www.physicianspractice.com/blog/what-practices-need-do-now-prepare-hipaa-omnibus-changes?GUID=2E8F906E-CDE7-43B7-AC93-7066F83372C7&rememberme=1&ts=10092013
READ MORE - What Practices Need to Do Now to Prepare for HIPAA Omnibus Changes

Tuesday, August 27, 2013

Compliance FAQs... How Much is Too Much?

How much information can a biller leave on an answering machine when calling for address or insurance updates?

Answer: Because the biller cannot know for sure who will listen to a message, even when calling a telephone number provided by the patient, it is wise to leave the minimum amount of information necessary to accomplish the reason for the call. Various legal concerns, including the HIPAA Privacy and Security rules, state that confidentiality and privacy laws and debt collection statutes and regulations can be implicated and should be taken into account.

A bare bones message may contain little or no revealing information while still accomplishing the task.

EXAMPLE 1: "This message is for [patient]. We are calling to verify your current mailing address (or insurance information) in order to bill for recent medical services you received. Please contact us at xxx-xxxx during office hours."
Here is another message scenario that gives minimal information.

EXAMPLE 2: "This is Medical Billing Office calling for [patient]. We need to contact you for an updated / corrected mailing address (or insurance information). Please call us at xxx-xxxx at your earliest convenience."
Various factors should be considered in deciding how to draft scripts or instructions for your staff regarding outbound messages.
  • What is the purpose of the call / message?
  • Who is the provider / client? Are they well known in the community?
  • Do they practice in a sensitive specialty, such as family planning, mental health, etc.?
  • Is there a reason you would need to disclose the client's identity or other detailed information at all?
  • What would be the risk if someone other than the patient or a close family member heard the message?
If additional information would be helpful and would not unnecessarily reveal personal health information (PHI) or sensitive information, it can also be included in the message.

EXAMPLE 3: "This message is for [patient]. I am calling for the billing office at [General Hospital Radiology Group]. Please contact our office to update your mailing address (or insurance information)."
 
CMS has published FAQs that are generally related to this question. By analogy, they support the conclusion that a biller may leave a minimum amount of information on an answering machine to solicit a response and gather information to enable proper billing.
The official HIPAA FAQs can be found on the website of the DHHS Office of Civil Rights at www.hhs.gov/ocr/privacy/hipaa/faq/index.html.
 
From the Office of Civil Rights HIPAA website:

May physician offices or pharmacists leave messages for patients at their homes, either on an answering machine or with a family member, to remind them of appointments or to inform them that a prescription is ready? May providers continue to mail appointment or prescription refill reminders to patients' homes?

Answer: Yes. The HIPAA Privacy Rule permits health care providers to communicate with patients regarding their health care. This includes communicating with patients at their homes – either through mail, phone, or in some other manner. In addition, the Rule does not prohibit covered entities from leaving messages for patients on their answering machines. However, to reasonably safeguard the individual's privacy, covered entities should take care to limit the amount of information disclosed on the answering machine. For example, a covered entity might want to consider leaving only its name, number, and other information necessary to confirm an appointment, or ask the individual to call back.

A covered entity also may leave a message with a family member or other person who answers the phone when the patient is not home. The Privacy Rule permits covered entities to disclose limited information to family members, friends, or other persons regarding an individual's care, even when the individual is not present. However, covered entities should use professional judgment to assure that such disclosures are in the best interest of the individual and limit the information disclosed. See 45 CFR 164.510(b)(3).

In situations where a patient has requested that the covered entity communicate with him or her in a confidential manner, such as by alternative means or at an alternative location, the covered entity must accommodate those requests, if reasonable. For example, the Department considers a request to receive mailings from the covered entity in a closed envelope rather than by postcard to be a reasonable request that should be accommodated. Similarly, a request to receive mail from the covered entity at a post office box rather than at home, or to receive calls at the office rather than at home are also considered to be reasonable requests, absent extenuating circumstances. See 45 CFR 164.522(b).
 
 
 
READ MORE - Compliance FAQs... How Much is Too Much?

Saturday, August 24, 2013

What Health Insurance Exchanges Mean for Physicians

Congress enacted the Affordable Care Act (ACA) to provide the means for uninsured Americans to purchase healthcare coverage.  Despite many legal battles and slipped deadlines, the new healthcare insurance exchanges — also known as marketplaces — will begin open enrollment on Oct. 1, 2013. The law provides for three options: one, where states will create and run their own exchanges; two, where they will create a hybrid exchange run by both the state and federal government; and three, where the federal government creates and runs the exchanges for states that have opted out. Coverage through the plans begins on Jan. 1, 2014.

Aside from great reservations expressed by many states, there are a number of unanswered questions where physicians and their practices are concerned. In part because so many states were reticent to fund and undertake the creation of a state-based exchange, progress to date varies widely. As of May 10, 2013, 25 states have been conditionally approved to operate some type of state-based exchange, according to The Center for Consumer Information & Insurance Oversight (CCIO).

And, because each state exchange is unique, the number and type of insurance companies that participate in the exchanges will be singular to each state.

So, what does this mean for physicians and their practices?

Sarah Dash, a faculty member at the Health Policy Institute at Georgetown University, says "fundamentally the exchange plans are just insurance plans. …The market is organized for the purpose of the consumer gaining easier access to those insurance plans. So, to some extent, it is the same thing." Since many people put off seeing the doctor because they are uninsured and can't afford the cost, experts have suggested that there will be a flood of sicker patients once the exchanges provide health insurance. Dash calls it "pent up demand." However, she is not convinced that this will be the case. She points out that the premise of the reform law's "insurance mandate" was to provide a good mix of healthy younger patients with older, potentially sicker patients. Owen Dahl, a practice management consultant based in The Woodlands, Texas, also believes that practices won't be deluged with new patients — but for a different reason. He says people who don't have insurance now are generally those who don't understand how it works and can't afford to pay for it.  "If I've been going to the emergency room for 15 years to get my care, [patients will say] 'Oh look, I've got this insurance, well I'm still going to go to the emergency room,'" says Dahl. He thinks that it will take time for people to change their behavior, which means practices will have plenty of time to prepare for newly insured patients. There is also trepidation among physicians that plans offered on the insurance exchanges will not pay well. As it is nearly impossible to predict reimbursement rates until the exchanges are fully established and patients are enrolled, it is perhaps a wasted effort for practices to dwell on this aspect. Dahl feels that plans offered on the exchanges may behave like managed-care plans. He says that it is likely that exchange plans will be offered by the major payers such as Blue Cross. "As far as the rates are going to be concerned, I think the best-case situation we could expect would be Medicare rates," he says. While that could mean lower revenues for practices, there are other aspects of the reform law which may be to their advantage. Dash says that "the point of the ACA is not to just give people an insurance card. It's to give people an insurance card that they can use. By that I mean, if the cost sharing is too high [in the forms of copays and deductibles], certainly that could be a deterrent."  She argues that through the law, patients will have access to tax subsidies and cost-sharing subsidies that should make it easier for patients to pay their bills. Certainly these changes will bring added administrative burdens to practices, but in many cases, they have already begun to implement new processes and quality improvements required by programs like Patient-Centered Medical Homes. Dahl advises practices "Do not panic." He says that while the business of medicine is most certainly changing, it won't happen overnight. "The important thing is for doctors to think about [the law] and to be prepared for that, but not react," he says.

Article By Erica Sprey - See more at: http://www.physicianspractice.com/blog/what-health-insurance-exchanges-mean-physicians#sthash.oenrJwFk.dpuf
READ MORE - What Health Insurance Exchanges Mean for Physicians

Thursday, August 8, 2013

Public Comment Forum Upcoming Changes: HIPAA Code Conversion for Local Modifier ZS (Medi-Cal, California State Medicaid)

As part of the continuing effort to comply with the federally mandated Health Insurance Portability and Accountability Act (HIPAA), the following change is slated to be effective for dates of service on or after December 1, 2013:
    The Department of Health Care Services (DHCS) will discontinue use of local modifier ZS, which is used to bill for the full professional (26) and technical (TC) components of a procedure.
This article provides information about a public comment forum for this change.
Claim Completion
Providers will be instructed to use one of the following scenarios when submitting a claim for split-billable procedures or services:
    Scenario 1: The facility and physician each bill for their respective component of the service with modifiers 26 or TC.
    Each provider/facility submits their own claim with one line of service and the appropriate modifier (26 or TC) designating the service they provided.
    Scenario 2: Full Fee Billing – The physician bills for both the professional and technical components and subsequently reimburses the facility for the technical component, according to their mutual agreements.
    The physician submits a CMS-1500 claim form and completes two separate claim lines as follows:
    The first line contains the split-billable procedure code and one of the two modifiers (26 or TC). The second line contains the same procedure code and the corresponding modifier (26 or TC).
    Scenario 3: Standard Billing – The facility bills for both the technical and professional components and reimburses the physician for the professional component, according to their mutual agreements.
    The facility submits a UB-04 claim form and completes two separate claim lines as follows:
    The first line contains the split-billable procedure code and one of the two modifiers (26 or TC). The second line contains the same procedure code and the corresponding modifier (26 or TC).
TAR Completion
Providers will be instructed to use one of the following scenarios when submitting a Treatment Authorization Request (TAR) for split-billable procedures or services:
    Scenario 1: One TAR and one provider for both the professional (26) and technical (TC) components of service.
    The TAR must be submitted with two lines of service. The first line must have the CPT-4 code and one of the two modifiers (26 or TC). The second line must have the same CPT-4 code and the corresponding modifier (26 and TC).
    Scenario 2: One TAR and two different providers for the professional (26) and technical (TC) components of service.
    One of the providers submits the TAR on behalf of both providers of the two components of service (26 and TC). Both providers use the same TAR for claim submission. The TAR is submitted with two lines of service. The first line must have the CPT-4 code and one of the two modifiers (26 or TC). The second line must have the same CPT-4 code and the corresponding modifier (26 and TC).
    This is the preferred method for two different providers.
    Scenario 3: Two TARs and two different providers for the professional (26) and technical (TC) components of service.
    Each provider submits their own TAR with one line of service and the appropriate modifier designating the service (26 or TC) they provided or will provide.
Comment Period
Notice is hereby given that DHCS will conduct written public proceedings, during which time any interested person or such person’s duly authorized representative may present statements, arguments or contentions relevant to the action described in this notice.
The comment forum will begin September 15, 2013, and stays open a minimum of 45 days. The proposed changes will be available by clicking the “Public Comment Forum Coming: HIPAA Code Conversion for Local Modifier ZS” line in the NewsFlash area of the Medi-Cal website. This link will direct providers to the “Medi-Cal Comment Forum” where they can view the article. Providers may call the Telephone Service Center (TSC) at 1-800-541-5555 or visit the Medi-Cal website if they have questions or need additional information.

Courtesy of: Dept. of Health Care Services Medi-Cal http://files.medi-cal.ca.gov/pubsdoco/newsroom/newsroom_21767.asp?utm_source=iContact&utm_medium=email&utm_campaign=Medi-Cal%20NewsFlash&utm_content=21767
READ MORE - Public Comment Forum Upcoming Changes: HIPAA Code Conversion for Local Modifier ZS (Medi-Cal, California State Medicaid)

Friday, July 26, 2013

How the New HIPAA Regulations Affect Billing Companies and Their Subcontractors as Business Associates

How the New HIPAA Regulations Affect Billing Companies and Their Subcontractors as Business Associates


Develop an Action Plan for Your Company and Subcontractors

An article by Robert A. Polisky, Esq.,  taken from the May/June issue of HBMA Billing.
       
On January 25, 2013, the Office for Civil Rights of the U.S. Department of Health & Human Services (OCR) published the anticipated final omnibus rule (the Final Rule). This rule created significant changes to the Privacy, Security, Breach Notification, and Enforcement Rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), many of which are required by the Health Information Technology for Economic and Clinical Health Act (HITECH Act). The Final Rule also implements changes to the Genetic Information Nondiscrimination Act of 2008.

The scope of the Final Rule is extensive, and enhances OCR's ability to enforce HIPAA. In the press release announcing the Final Rule, OCR Director Leon Rodriguez proclaimed that the Final Rule "marks the most sweeping changes to the HIPAA Privacy and Security Rules since they were first implemented" and "strengthen[s] the ability of my office to vigorously enforce the HIPAA privacy and security protections…." Individuals and entities affected by the Final Rule must comply with most of its provisions by September 23, 2013.
This article addresses key provisions of the Final Rule applicable to billing companies and their subcontractors, enforcement changes, and recommended action items needed for compliance by billing companies and their subcontractors.

KEY PROVISIONS

Business Associates and Their Subcontractors

Expanded Definition of "Business Associate"
The Final Rule expands the definition of a "business associate" to include any individual or entity that creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity. Companies that code, bill, and/or collect claims on behalf of a health care provider (i.e., a covered entity), are business associates under HIPAA. Notably, the Final Rule includes subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate as business associates themselves. Thus, any subcontractors that a billing company engages to assist in coding, billing, or collections, and any subcontractors that store or transmit any healthcare records on the billing company's behalf, are business associates of the billing company.

Direct Liability
As business associates, the Final Rule requires billing companies and their subcontractors to comply with the Security Rule's administrative, physical, and technical safeguard requirements as well as with the Security Rule's policies and procedures and documentation requirements. These requirements apply to business associates in the same manner as they apply to covered entities, such that billing companies and their subcontractors can be held civilly and criminally liable for violations of these requirements. Similarly, the Final Rule applies certain Privacy Rule requirements to business associates and establishes direct liability of business associates for violations of these requirements. A billing company does not need to provide a notice of privacy practices or designate a privacy official unless the covered entity designated such a responsibility in the billing company's business associate agreement.

Specifically, billing companies and their subcontractors, as business associates, have direct civil and criminal liability exposure for the following items.
  1. impermissible uses and disclosures of PHI
  2. failure to provide breach notification to the covered entity
  3. failure to provide access to a copy of electronic PHI to either the covered entity, the individual, or the individual's designee (whichever is specified in the business associate agreement)
  4. failure to disclose PHI to OCR where required by OCR to investigate or determine the business associate's compliance with HIPAA
  5. failure to provide an accounting of disclosures
  6. failing to enter into business associate agreements with subcontractors that create or receive PHI on the business associate's behalf
  7. failure to comply with the requirements of the Security Rule
Billing companies and their subcontractors also remain contractually liable for all other Privacy Rule obligations that are included in their business associate agreements.
Business Associate Agreements
The Final Rule clarifies that a covered entity is not required to enter into a business associate agreement with a billing company's subcontractor. Rather, the billing company that engaged a subcontractor to perform a function or service involving the use or disclosure of PHI is required to enter into a business associate agreement with the subcontractor. Each business associate agreement in the business associate chain needs to be at least as restrictive as the agreement above it in the chain with respect to permissible uses and disclosures of PHI.
The Final Rule expands the requirements of a business associate agreement by obligating a business associate to comply, where applicable, with the Security Rule with regard to electronic PHI; report breaches of unsecured PHI to the covered entity; and ensure that any subcontractors that create or receive PHI on its behalf agree to the same restrictions and conditions that apply to the business associate with respect to such information.

Transition Period
The Final Rule delays compliance until September 22, 2014 for a covered entity or business associate to enter into a business associate agreement with a business associate or subcontractor if, prior to January 25, 2013, the covered entity or business associate had a business associate agreement with the business associate or subcontractor, as applicable, that complied with HIPAA prior to the Final Rule (unless the business associate agreement was modified or actively renewed between March 26, 2013 and September 23, 2013). In all other cases, covered entities and business associates will need to execute business associate agreements with their business associates and subcontractors no later than September 23, 2013.

Modification To The Breach Notification Rule

Background
Under the HITECH Act, a covered entity is required to notify affected individuals and OCR following discovery of a breach of unsecured PHI; a covered entity also needs to notify the media of a breach involving more than 500 residents of a state or jurisdiction. A business associate, in turn, is required to notify a covered entity following discovery of a breach of unsecured PHI at or by the business associate.
On August 24, 2009, OCR issued an interim final rule implementing the HITECH Act's breach notification provisions ("Breach Notification Interim Rule"). In the Breach Notification Interim Rule, a "breach" is defined as the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that "compromises the security or privacy" of the PHI, with certain exceptions. Moreover, under the Breach Notification Interim Rule, "compromises the security or privacy" of the PHI is defined to mean that an impermissible use or disclosure of PHI poses a significant risk of financial, reputational, or other harm to the individual (the "harm standard").
Revised Definition of "Breach"
The Final Rule significantly revises the definition of "breach" to clarify that an impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised. By replacing the "harm standard" with this "low probability" standard, it is more likely under the Final Rule than under the Breach Notification Interim Rule that covered entities and business associates will determine that an impermissible use or disclosure of PHI "compromises the security or privacy" of the PHI, resulting in many required breach notifications that would not have been required previously.
Modification of Risk Assessment
Under the Final Rule, to determine whether there is a low probability that PHI has been compromised, covered entities and business associates need to conduct a risk assessment that considers at least the following factors:
  • the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
  • the unauthorized person who used the PHI or to whom the disclosure was made;
  • whether the PHI was actually acquired or viewed; and
  • the extent to which the risk to the PHI has been mitigated.
If an evaluation of the above factors, taken together, fails to demonstrate that there is a low probability that PHI has been compromised, breach notification will be required.

Right to Restrict Disclosure to a Health Plan

Under the Final Rule, health care providers, upon request from an individual, must agree to restrict disclosure of PHI about the individual to a health plan if the disclosure would be for the purpose of carrying out payment or healthcare operations, and is not otherwise required by law, or the PHI pertains solely to a healthcare item or service for which the individual, or person acting on the individual's behalf (other than the health plan), has paid the covered entity in full. To avoid payment issues, a health care provider may want to require payment in full at the time of the individual's request for a restriction. Health care providers may request assistance from billing companies to comply with this new restricted disclosure requirement.

ENFORCEMENT

Discretion
The Final Rule gives OCR discretion to use informal means to resolve HIPAA violations. However, OCR is permitted to impose a civil monetary penalty without exhausting informal resolution efforts, especially when the HIPAA violation is due to willful neglect. The Final Rule also allows OCR to coordinate with other law enforcement agencies, such as state attorneys general and the Federal Trade Commission, with respect to pursuing remedies against HIPAA violators.
Tiered Penalty Amounts
Under the HITECH Act, there are four tiers of increasing penalty amounts that correspond to the levels of culpability associated with a HIPAA violation. The minimum fines range between $100 and $50,000 per violation, and are capped at $1.5 million for all violations of the same HIPAA provision during any calendar year (see below table). The lowest category of violation covers situations where the covered entity or business associate did not know, and by exercising reasonable diligence would not have known, of the HIPAA violation. The second lowest category of violation applies to violations due to reasonable cause and not to willful neglect. The third category applies to situations where the violation was due to willful neglect and was corrected within 30 days of when the covered entity or business associate knew, or should have known, of the violation. The fourth category applies to situations where the violation was due to willful neglect and not corrected within 30 days of when the covered entity or business associate knew, or should have known, of the violation.
The Final Rule modifies the definition of "reasonable cause" to mean "an act or omission in which a covered entity or business associate knew, or by exercising reasonable diligence would have known, that the act or omission violated [HIPAA], but in which the covered entity or business associate did not act with willful neglect." The Final Rule keeps the definition of "willful neglect" as the "conscious, intentional failure, or reckless indifference to the obligation to comply" with HIPAA.
Counting Violations
In the preamble to the Final Rule, OCR states that how it counts HIPAA violations for purposes of calculating a civil monetary penalty varies depending on the circumstances surrounding the violation. OCR explains that where multiple individuals are affected by a HIPAA violation (e.g., a breach of unsecured PHI), it is anticipated that the number of identical HIPAA violations would be counted by the number of individuals affected. OCR also explained that, with respect to continuing violations (e.g., a lack of appropriate safeguards for a period of time), it is anticipated that the number of identical HIPAA violations would be counted on a per day basis (i.e., the number of days the covered entity or business associate did not have appropriate safeguards in place to protect the PHI). OCR notes that in many HIPAA breach cases, there would be an impermissible use or disclosure as well as a safeguards violation, for each of which OCR would be entitled to calculate a separate civil monetary penalty. Needless to say, the amount of civil monetary penalties that could be imposed against a billing company or one of its subcontractors for a HIPAA violation can be quite substantial.
Factors Used to Determine a Penalty
The Final Rule lists the following five factors that OCR will consider in determining the amount of a civil monetary penalty.
  1. the nature and extent of the HIPAA violation, including the number of individuals affected and the duration of the violation
  2. the nature and extent of the harm resulting from the violation, including physical, financial, and reputational harm, and any hindrance to an individual's ability to obtain healthcare
  3. the history of prior compliance with HIPAA, including whether the current violation is the same/similar to prior indications of noncompliance by the covered entity or business associate and their attempts to correct that noncompliance
  4. the financial condition of the covered entity or business associate, including any financial difficulties that could have affected compliance and whether a civil monetary penalty could jeopardize the future provision of healthcare
  5. such other matters as justice may require
Agency Liability
The Final Rule makes covered entities and business associates liable for the acts of their business associate agents, regardless of whether the covered entity or business associate knew of the violation or had a compliant business associate agreement in place. According to OCR, the key factor in determining whether an agency relationship exists between a covered entity and its business associate, or between a business associate and its subcontractor, is the principal's right to control the agent's conduct in the course of performing a service on behalf of the principal. OCR observes that a business associate agent's conduct generally is within the scope of agency when its conduct occurs during the performance of the assigned work or incident to such work, regardless of whether the work was done carelessly, a mistake was made in the performance, or the business associate disregarded a covered entity's specific instruction. OCR further observes that, in contrast, a business associate agent's conduct generally is outside the scope of agency when its conduct is solely for its own benefit (or that of a third party), or it pursues a course of conduct not intended to serve any purpose of the covered entity. To protect itself, a billing company's services agreement with a subcontractor should specify that the subcontractor is engaged as an independent contractor, not as an agent, and the billing company does not have the right to control the subcontractor's performance.

RECOMMENDED ACTION ITEMS

Although billing companies and their subcontractors have until September 23, 2013 to fully comply with the Final Rule, they should begin preparing soon in light of the significant number of new or modified compliance obligations. In particular:
  • Covered entities will need to revise, negotiate, and execute business associate agreements with billing companies compliant with the Final Rule by September 23, 2013 to the extent they did not have business associate agreements in place as of January 25, 2013 that were HIPAA compliant. They have until September 22, 2014 to do so to the extent they had business associate agreements in place as of January 25, 2013 that were HIPAA compliant. OCR gives a fair amount of latitude in the content of business associate agreements, so it is important for billing companies to ensure that they are not overcommitting to responsibilities or deadlines that are not required under HIPAA.
  • Billing companies that use subcontractors that create, receive, maintain, or transmit PHI on their behalf will need to draft, negotiate, and execute business associate agreements with them by September 23, 2013. Billing companies will need to ensure that these business associate agreements are at least as stringent as their business associate agreements with covered entities, and enable billing companies to meet deadlines in their business associate agreements with covered entities.
  • Billing companies, including subcontractors, will need to conduct a security risk assessment, implement a written HIPAA security plan, designate a security official, and create certain written HIPAA privacy policies by September 23, 2013 to the extent they have not already done so. OCR has posted guidance on compliance with the HIPAA Security Rule found at www.hhs.gov/ocr/privacy/ hipaa/administrative/securityrule that may be helpful to billing companies and their subcontractors and facilitate their compliance efforts.
  • Billing companies and their subcontractors will need to perform a gap analysis to determine what HIPAA policies and procedures need to be revised to comply with the Final Rule, and then will need to revise them by September 23, 2013 based on the gap analysis.
  • Billing companies and their subcontractors will need to update by September 23, 2013 their breach notification policies and any tools concerning how to conduct a risk assessment to determine whether breach notification is required.
  • Healthcare providers may ask billing companies to implement by September 23, 2013 a method to flag or make a notation in the record with respect to PHI concerning an item or service paid in full by an individual – or person acting on the individual's behalf (other than a health plan) – to ensure that such information is not inadvertently sent to or made accessible to a health plan for payment or healthcare operations purposes, such as audits by the health plan.
  • Billing companies and their subcontractors will need to update their HIPAA training materials and then train their workforce members (i.e., employees, volunteers, trainees, and other persons under their direct control) by September 23, 2013 to comply with HIPAA.
Given the breadth and potential penalties under the Final Rule, billing companies and their subcontractors should review their data flows (i.e., the complete lifecycle of PHI that they create, receive, maintain, or transmit) and then perform an updated risk analysis based on that review, including a risk analysis of mobile devices. Billing companies and their subcontractors will need to determine whether to encrypt these devices in light of the increasing prevalence of large penalties imposed by OCR on entities whose mobile devices, such as laptop computers and smartphones, containing unencrypted PHI have been lost or stolen. Further, covered entities and business associates should consider whether it would be cost-effective for them to purchase HIPAA liability insurance given the risk of substantial penalties for HIPAA violations.

Courtesy of: http://www.hbma.org/news/public-news/n_how-the-new-hipaa-regulations-affect-billing-companies-and-their-subcontractors-as-business-associates
READ MORE - How the New HIPAA Regulations Affect Billing Companies and Their Subcontractors as Business Associates

Wednesday, July 24, 2013

HBMA ICD-10 Readiness Statement published in Wall Street Journal

The HBMA Government Relations Committee, through its spokesperson Holly Louie, took the stage at our nation's capitol to deliver your collective message to the National Committee on Vital and Health Statistics (NCVHS). Holly spoke on behalf of the HBMA (hbma.org) to the NCVHS on ICD-10 Readiness - Learn from Past, Don't Repeat 5010 Mistakes.
 
HBMA testifies before NCVHS on ICD-10 Readiness
 
Learn from Past, Don't Repeat 5010 Mistakes
LAGUNA BEACH, Calif., June 28, 2013 /PRNewswire-USNewswire/ -- Because of its significant role in revenue cycle management, the Healthcare Billing and Management Association (www.hbma.org) was invited recently to participate in discussions with the National Committee on Vital and Health Statistics (NCVHS) Subcommittee on Standards in Washington, D.C. to provide an update on the status of transitioning from ICD-9 CM to ICD-10 CM by the October 1, 2014 effective date.
In testimony before the NCVHS Subcommittee on Standards, Holly Louie, CHBME, Chair of HBMA's ICD-10/5010 Committee presented the association's views on "lessons learned" from the 5010 implementation and how those lessons can and should be applied to avoid problems with ICD-10 implementation. NCVHS is charged with advising the Secretary of Health and Human Services on all HIPAA related matters.
Louie was part of a panel of experts invited. In her testimony, she said, "HBMA believes that we MUST learn from the mistakes that were made in transitioning from 4010 to 5010, and undertake the transition from ICD-9 CM to ICD-10 CM in a way that demonstrates we learned those lessons."
Louie shared HBMA's concern that in order for there to be a successful transition from ICD-9 CM to ICD-10 CM "we must allow the 'lessons learned' from the 4010 to 5010 transition last year to materially inform the implementation of ICD-10 CM." Louie pointed out to the Subcommittee that "the economic stability of America's healthcare reimbursement system will be at risk and could be severely compromised, affecting provider financial viability and patients' access to care."
The Centers for Medicare and Medicaid has already delayed the effective date for ICD-10 CM implementation from October 1, 2013 to October 1, 2014. Speaking about this delay, Louie said, "it is imperative that the time gained by the delay be used wisely in order to ensure that the transition is successful. If we fail to learn the lessons we will merely be delaying the likelihood for payment disruptions and patient access to care problems from 2013 to 2014."
HBMA strongly recommends the following:
   1. While CMS has adopted a definition of "ready" and developed the tools and 
checklists to assist every provider, organization, payor and vendor to
validate they are ready on October 1, 2014, a subsequent announcement by
CMS that they will not perform any external testing is extremely
problematic for the industry. End-to-end testing by all payors, to meet
the definition of "ready" must occur to ensure a smooth ICD-10 CM
implementation. Failure to engage in meaningful end-to-end testing is a
recipe for disaster.

2. CMS must establish period benchmarks that cannot be ignored to assess the
"readiness" status for all facts of the healthcare industry.

3. There must be clear pronouncement that there is no vendor, EHR, coding
assist tool, map, crosswalk or other product that will solve the problem
of excellent medical record documentation and accurate coding.
Physicians and staff must be fully prepared with adequate training to
operate compliantly and not rely on false proclamations of marketed
solutions.

4. Payor policies will be critical to the appropriate adjudication of
claims. Currently, there is a wide variance among payors in stated
policies. It is imperative that policies are published by October 1,
2013 in order to allow adequate time for education and training, data
analysis and other preparations for ICD-10 CM.

5. Any payor that is currently only accepting claims by 4010 format must be
fully 5010 compliant by January 1, 2014 in order to be ICD-10CM ready.
HBMA's expert remarks were made on behalf of the membership with the goal of making this transition as smooth as possible for the entire medical community. To learn more about ICD-10 transition, go to www.hbma.org.
Related Searches: NCVHS, ICD-9, ICD-10, HBMA, HIPAA, Holly Louie, 5010
SOURCE Healthcare Billing & Management Association
/Web site: http://www.hbma.org
READ MORE - HBMA ICD-10 Readiness Statement published in Wall Street Journal