Civil Rights Settlement Highlights Health Industry Discrimination Risks As OCR Prepares To Broaden Requirements

October 27, 2015

Doctors’ Center Hospital, Inc.  (DCI) in the latest health care providers nailed in a U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) enforcement action for allegedly violating Section 504 of the Rehabilitation Act of 1973 (Section 504) by failing to provide auxiliary aids and services for deaf and hard of hearing patients under OCR’s ongoing aggressive campaigned on enforcing federal discrimination laws against health care providers and others covered by its regulations.  OCR’s announcement of the Voluntary Compliance Resolution Agreement with DCI (Agreement) announced today (October 27, 2015) comes with the November 6, 2015 deadline for health care providers and other concerned parties to comment on proposed OCR regulations on Nondiscrimination in Health Programs and Activities, implementing the federal prohibition against sex discrimination in health programs and activities enacted under Section 1557 of the Patient Protection and Affordable Care Act (ACA) and tightening other nondiscrimination requirements that generally apply to health care providers and others covered by OCR’s civil rights rules (covered entities) and various other programs and activities administered by OCR. Health care providers and others covered by these rules should provide meaningful input on the proposed rules even as they work to tighten their compliance and risk management practices to mitigate their exposures.

Section 504 of the Rehabilitation Act of 1973, Title II of the Americans with Disabilities Act (ADA) and Section 1557 of the Patient Protection and Affordable Care Act (ACA) (collectively the “Civil Rights Laws”) together require hospitals, health care providers, clinics, medical practices and other entities who receive Federal financial assistance to provide services to persons with disabilities in a non-discriminatory manner.  As construed by OCR with respect to deaf and hearing impaired individuals and their caregivers, these laws require health care providers offer services or aids need to ensure effective communication in light of the abilities of the individual who is deaf or hard of hearing, the primary method used by the individual to communicate and the complexity and nature of the information being conveyed. Failure to ensure effective communication in such health care settings may lead to misinformation, inappropriate diagnosis and/or delayed or improper medical treatments.

DCI  Discrimination Charge Settlement

The latest in a growing series of Civil Rights Law enforcement actions of these laws against health care providers by OCR, the Agreement announced October 27, 2015 resolves OCR charges stemming from a discrimination complaint made to OCR by an family that charged that one DCI facility, Doctors’ Center Hospital San Juan, Inc. violated Section 504 by failing to provide a sign language interpreter necessary to ensure effective communication during their 10 month old child’s five day hospitalization. OCR investigated the complaint under Section 504, which prohibits covered entities that receive Federal financial assistance from excluding or denying individuals with disabilities an equal opportunity to receive program benefits and services.

While the complaint that resulted in the OCR charges only specifically named its Doctors’ Center Hospital San Juan, Inc., at DCI’s request, the Agreement includes all of DCI facilities in Puerto Rico, which collectively serve an estimated 109,000 patients a year in the San Juan area as well as the northern part of the island of Puerto Rico.  Under the Agreement, DCI, Doctors’ Center Hospital San Juan, Inc. and the Doctors’ Center Hospital Bayamón, Inc. to resolve the complaint agree to take several actions to improve access to appropriate communication services for deaf and hard of hearing individuals including revising its policies and procedures, performing an assessment of the communication needs for deaf and hard of hearing patients and their companions, providing appropriate auxiliary aids and services at no cost, adopting and posting a Notice of Nondiscrimination, creating a Section 504 Grievance Procedure, appointing a Section 504 Coordinator and training all staff on the revised policies and procedures. Read the full Agreement here.

Health Industry’s Already High Civil Rights Enforcement Risks Set To Rise

The DCI Agreement highlights the already significant exposure that health care providers face under OCR’s current Civil Rights Law enforcement practices and comes as OCR is preparing to broaden and expand its existing Civil Rights regulations by adopting proposed changes to its regulations on Nondiscrimination in Health Programs and Activities. The deadline for comment on those proposed regulations is November 6, 2015.

Even before it adopts these proposed changes, health care providers already face significant Civil Rights discrimination risks.  OCR already aggressively investigates and enforces federal Civil Rights Law prohibitions against discrimination based on race, color, national origin, disability, age and sex against covered entities as part of the Obama Administration’s broader civil rights agenda. See. e.g., Health Care Employer’s Discrimination Triggers Medicare, EEOC Prosecutions; Genesis Healthcare Disability HHS OCR Discrimination Settlement Reminder To Use Interpreters, Other Needed Accommodations For Disabled; OCR Settlements Show Health Care & Disabled Housing Providers Face Growing Disability Discrimination Risks. Given the often multimillion dollar penalties and other heavy sanctions that OCR already regularly imposes against a long and ever-growing list of state and other health care, child care, elder care, insurance and other entities for violating its Civil Rights Laws, health care providers and other providers, Medicare and Medicaid Advantage and other insurers, and other covered entities generally will want both to carefully review and comment as appropriate on the proposed rules, as well as review and tighten as advisable their existing practices to reduce the risk of being sanctioned, excluded or both for violation of these nondiscrimination and other civil rights requirements by OCR. In this respect, covered entities will want both to evaluate their risks and responsibilities under the specific rules about Section 1557’s sex discrimination prohibits, as well as changes that more broadly affect the interpretation and enforcement of the nondiscrimination rules enforced by OCR generally.

The author of this article, Cynthia Marcotte Stamer is a practicing attorney and Managing Shareholder of Cynthia Marcotte Stamer, P.C., an attorney practicing as the co-managing member of Stamer│Chadwick │Soefje PLLC, author, pubic speaker, health policy advocate and industry thought leader, has focused on helping health industry and other organizations and their management understand and use the law and process to manage people, process, compliance, operations and risk including significant work with compliance with OCR and other regulatory requirements.

Scribe responsible for leading the American Bar Association (ABA) Joint Committee on Employee Benefits (JCEB) annual agency meeting with HHS Office of Civil Rights for five years, Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Board Certified in Labor & Employment Law, and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 28 years’ experience advising health industry clients about these and other matters.

Ms. Stamer’s experience includes advising and defending hospitals, nursing home, home health, physicians and other health care professionals, rehabilitation and other health care providers and health industry clients to establish and administer compliance and risk management policies and programs in response under CMS, OCR, HHS, FDA, IRS, DOJ, DEA, NIH, licensing, and other regulations; prevent, conduct and investigate, and respond to Board of Medicine, OIG, DOJ, DEA, DOD, DOL, Department of Health, Department of Aging & Disability, IRS, Department of Insurance, and other federal and state regulators; ERISA and private insurance, prompt pay and other reimbursement and contracting; peer review and other quality concerns; and other health care industry investigation, and enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns.

Ms. Stamer also is widely recognized for her regulatory and public policy advocacy, publications, and public speaking on privacy and other compliance, risk management concerns. Her insights on privacy, data security, and other matters have appeared in The Wall Street Journal, Business Insurance, the Dallas Morning News, Spencer Publications, and a host of other publications. She speaks and has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.

Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.

Ms. Stamer also is active in the leadership of a broad range of other professional and civic organizations. For instance, Ms. Stamer serves on the steering committee and as a faculty member of the Southern California ISSA-HIMMS Annual Security Summit and Chaired its 2015 3rd Annual Health Care Privacy Summit.  Ms. Stamer presently serves on an American Bar Association (ABA) Joint Committee on Employee Benefits Council representative; Vice President of the North Texas Healthcare Compliance Professionals Association; Immediate Past Chair of the ABA RPTE Employee Benefits & Other Compensation Committee, its current Welfare Benefit Plans Committee Co-Chair, on its Substantive Groups & Committee and its incoming Defined Contribution Plan Committee Chair and Practice Management Vice Chair; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; current Vice Chair of the ABA TIPS Employee Benefit Committee; the former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division; on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications.  She also previously served as a founding Board Member and President of the Alliance for Healthcare Excellence, as a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early childhood development intervention agency, The Richardson Development Center for Children; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a member of the Board of Directors of the Southwest Benefits Association. For additional information about Ms. Stamer, see here, or the website Stamer ׀ Chadwick ׀ Soefje PLLC.  To contact Ms. Stamer, e-mail her here or telephone (469) 767-8872.

About Solutions Law Press, Inc.™

Solutions Law Press, Inc.™  provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of Ms. Stamer’s publications our other Solutions Law Press, Inc.™ resources such as:


HHS Proposes Stage 3 Meaningful Use EHR Incentive Programs & 2015 Edition Health IT Certification Criteria Rules

March 20, 2015

The U.S. Department of Health and Human Services, Centers for Medicare & Medicaid Services (CMS) and Office of the National Coordinator for Health Information Technology (ONC) on March 20, 2015 announced the release of the Stage 3 notice of proposed rulemaking for the Medicare and Medicaid Electronic Health Records (EHRs) Incentive Programs and 2015 Edition Health IT Certification Criteria which the Agencies believe will improve the way electronic health information is shared and ultimately improve the way care is delivered and experienced.

Under the Health Information Technology for Economic and Clinical Health Act, doctors, health care professionals and hospitals, including critical access hospitals, can qualify for Medicare and Medicaid incentive payments when they adopt and meaningfully use health IT technology certified by ONC. Since the programs began in 2011, more than 433,000 eligible professionals and eligible hospitals have received an incentive payment representing about 60 percent of eligible professionals in either the Medicare or Medicaid programs and about 95 percent of eligible hospitals.

The Meaningful Use Stage 3 proposed rule issued by CMS specifies new criteria that eligible professionals, eligible hospitals, and critical access hospitals must meet to qualify for Medicaid EHR incentive payments. The rule also proposes criteria that providers must meet to avoid Medicare payment adjustments (Medicaid has no payment adjustments) based on program performance beginning in payment year 2018. The rule gives more flexibility and simplifies requirements for providers by focusing on advanced use of electronic health records and eliminating requirements that are no longer relevant.  The Stage 3 proposed rule’s scope is generally limited to the requirements and criteria for meaningful use in 2017 and subsequent years. CMS is considering additional changes to meaningful use beginning in 2015 through separate rulemaking. Learn more here.

The 2015 Edition Health IT Certification Criteria proposed rule aligns with the path toward interoperability – the secure, efficient, and effective sharing and use of health information –identified in ONC’s draft shared Nationwide Interoperability Roadmap. The proposed rule builds on past editions of adopted health IT certification criteria, and includes new and updated IT functionality and provisions that the Agencies believe support the EHR Incentive Programs care improvement, cost reduction, and patient safety across the health system.

“This Stage 3 proposed rule does three things: it helps simplify the meaningful use program, advances the use of health IT toward our vision for improving health delivery, and further aligns the program with other quality and value programs,” said Dr. Patrick Conway, M.D., M.Sc., CMS acting principal deputy administrator and chief medical officer. “And, in an effort to make reporting easier for health care providers, we will be proposing a new meaningful use reporting deadline soon.”

“ONC’s proposed rule will be an integral component in the shared nationwide effort to achieve an interoperable health system,” said Karen DeSalvo, M.D., M.P.H, M.Sc., national coordinator for health IT. “The certification criteria we have proposed in the 2015 Edition will help achieve that vision through provisions that consider the range of health IT users and uses across the care continuum, including those focused on interoperable standards, data portability, improved transparency, privacy and security capabilities, and increased oversight through ONC’s Health IT Certification Program.”

The Stage 3 proposed rule may be viewed here and the comment period ends on May 29, 2015. The 2015 Edition proposed rule may be viewed here and the comment period ends on May 29, 2015. The Draft 2015 Edition Certification Test Procedures may be viewed at HealthIT.gov, and the comment period ends on June 30, 2015.

For More Information Or Assistance

If you need assistance reviewing or responding to these or other health care related risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer, may be able to help. Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Board Certified in Labor & Employment Law, and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 26 years experience advising health industry clients about these and other matters. Her experience includes advising hospitals, nursing home, home health, rehabilitation and other health care providers and health industry clients to establish and administer compliance and risk management policies; prevent, conduct and investigate, and respond to peer review and other quality concerns; and to respond to Board of Medicine, Department of Aging & Disability, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD and other health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns.  The scribe for the American Bar Association (ABA) Joint Committee on Employee Benefits annual agency meeting with the Department of Health & Human Services Office of Civil Rights,  Ms. Stamer has worked extensively with health care providers, health plans, health care clearinghouses, their business associates, employers, banks and other financial institutions, and others on risk management and compliance with HIPAA and other information privacy and data security rules, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns.  Her clients include public and private health care providers, health insurers, health plans, technology and other vendors, and others.  In addition to representing and advising these organizations, she also has conducted training on Privacy & The Pandemic for the Association of State & Territorial Health Plans,  as well as  HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for  Los Angeles County Health Department, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.

A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her insights on these and other related matters appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications.  You can get more information about her health industry experience here. If you need assistance responding to concerns about the matters discussed in this publication or other health care concerns, wish to obtain information about arranging for training or presentations by Ms. Stamer, wish to suggest a topic for a future program or update, or wish to request other information or materials, please contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.

If you or someone else you know would like to receive future updates about developments on these and other concerns from Ms. Stamer, see here.

About Solutions Law Press

Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns.

Other Helpful Resources & Other Information

We hope that this information is useful to you.   If you found these updates of interest, you also be interested in one or more of the following other recent articles published on the Coalition for Responsible Health Care Reform electronic publication available here, our electronic Solutions Law Press Health Care Update publication available here, or our HR & Benefits Update electronic publication available hereYou also can get access to information about how you can arrange for training on “Building Your Family’s Health Care Toolkit,”  using the “PlayForLife” resources to organize low-cost wellness programs in your workplace, school, church or other communities, and other process improvement, compliance and other training and other resources for health care providers, employers, health plans, community leaders and others here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail by creating or updating your profile here. You can reach other recent updates and other informative publications and resources.

Examples of some of these recent health care related publications include:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here. For important information concerning this communication click here.THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2015 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press.  All other rights reserved.


Initial EHR Certification Bodies Named

August 30, 2010

   

The Office of the National Coordinator for Health Information Technology (ONC) today (August 30, 2010) named Certification Commission for Health Information Technology (CCHIT), Chicago, Ill. and the Drummond Group Inc. (DGI), Austin, Texas as the first technology review bodies authorized to test and certify electronic health record (EHR) systems for compliance with the standards and certification criteria that were issued by the U.S. Department of Health and Human Services earlier this year.  The announcement comes less than two months after issuance of final meaningful use rules.  Read more here. 

For More Information or Assistance 

If you need assistance responding to the EHR meaningful use, HITECH and other privacy, or other health industry regulatory, reimbursement or other operational or compliance concerns, please contact the author of this update, attorney Cynthia Marcotte Stamer.  Ms. Stamer has extensive experience advising and assisting health care providers and other health industry clients with licensure, contracting, reimbursement, compliance, public policy, regulatory, staffing, and other operations and risk management matters. Ms. Stamer also regularly publishes and conducts training on these and other compliance, management and operations matters.  You can contact Ms. Stamer to inquire about engaging her services or for information about training or other resources that she provides at (469) 767-8872 or via e-mail here.  To get more information about Ms. Stamer and her health industry experience, see here

Other Recent Developments 

If you found this information of interest, you also may be interested in reviewing some of the following recent Updates available online by clicking on the article title:  

About Solutions Law Press 

Solutions Law Press™ provides health industry and other risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available for review here. If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. For important information concerning this communication click here.  

©2010 Solutions Law Press. All rights reserved.


Southern States Collect Largest Share of $162 Million AARA Fund Meaningful Use Development Grants

March 16, 2010

By Cynthia Marcotte Stamer

Southern states are the big winners among the 16 states and qualified state designated entities (SDEs) to share in the approximately $162 Million in American Recovery and Reinvestment Act of 2009 (ARRA) fund grants to facilitate the development of health information exchange and advance health information technology (health IT) announced by the U.S. Department of Health and Human Services HHS today (March 15, 2010).

Drawn from the $2 billion in funding set aside in ARRA to promote widespread meaningful use of health IT and use of an electronic health record, the following  health information exchange awards seek to facilitate to facilitate non-proprietary health information exchange that adheres to national standards widely perceived as critical to enabling care coordination and improving the quality and efficiency of health care.

The recipients and award amounts of the grants announced today are:

  • Texas Health and Human Services Commission, $28,810,208
  • Florida Agency of Health Care Administration, $20,738,582
  • New Jersey Health Care Facilities Financing Authority, $11,408,594
  • Louisiana Health Care Quality Forum, $10,583,000
  • State of Mississippi, $10,387,000
  • Indiana Health Information Technology, Inc., $10,300,000
  • The Maryland Department of Health and Mental Hygiene, $9,313,924
  • South Carolina Department of Health & Human Services, $9,576,408
  • Iowa Department of Public Health, $8,375,000
  • State of Connecticut Department of Public Health, $7,297,930
  • Nebraska Department of Administrative Services, $6,837,180
  • South Dakota Department of Health, $6,081,750
  • Idaho Health Data Exchange, $5,940,500
  • State of North Dakota, Information Technology Department,  $5,343,733
  • State of Alaska, $4,963,063

Additional information about the state HIE program may be found here.  Other information about other health IT programs funded through ARRA generally can be found at here.

For Assistance With This Opportunity Or Other Health Industry Concerns

If your organization needs advice or assistance with commenting on the AHRO proposal or to respond to other health care quality or other health care matters, consider contacting the author of this article, Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer at (214) 270-2402 or via e-mail here

Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 22 years experience advising health industry clients about these and other matters.    A popular lecturer and widely published author on health industry matters, Ms. Stamer advises hospitals and other health industry clients about responding to and using these and other quality measures and other related concerns.  Ms. Stamer also publishes and speaks extensively on health and managed care industry quality, regulatory, reimbursement, and other operations, risk management and public policy concerns.  Her insights on these and other related matters appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.  

Other Recent Developments & Resources

If you found this information of interest, you also may be interested in reviewing some of the following recent Updates available online by clicking on the article title:

We hope that this information is useful to you.  If you need assistance with auditing or defending these or other health care compliance, risk management, transaction or operation concerns, please contact the author of this update, Curran Tomko Tarski LLP Health Practice Group Chair, Cynthia Marcotte Stamer, at (214) 270‑2402, cstamer@cttlegal.com, Edwin J. Tomko at (214) 270-1405 or another Curran Tomko Tarski LLP Partner of your choice. Ms. Stamer has extensive experience advising clients and writes and speaks extensively on these and other health industry and other internal controls and risk management matters. 

You can review other recent health care and internal controls resources and additional information about the health industry and other experience of Ms. Stamer here.  If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information to cstamer@cttlegal.com.

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.  To unsubscribe, e-mail here.

©2010 Cynthia Marcotte Stamer.  All rights reserved.


HHS Issues Interim Final Requiring Health Care Provider, Health Plans & Other Covered Entities To Give Breach Notifications When Certain Personal Health Information Breached Beginning In September; Register to Participate In September 10th Briefing on New Rules In Person or Via Telephone

August 20, 2009

The U.S. Department of Health and Human Services (HHS) yesterday (August 19, 2009) issued “breach notification” regulations requiring health care providers, health plans and other covered entities (Covered Entities) under the personal health information privacy and security rules of the Health Insurance Portability & Accountability  (HIPAA) to notify affected individuals following a “breach” of “unsecured” protected health information. Scheduled for publication in the Federal Register on August 24, 2009, the new breach notification regulations are part of a series of new rules that implement new electronic personal health information data security and data breach notification requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).  Covered entities must begin complying with the new rules no later than September 24, 2009.

Curran Tomko Tarski, LLP Health Practice leader Cynthia Marcotte Stamer will conduct a briefing on these new protected health information data security and data breach rules on Thursday, September 10, 2009 from Noon to 1:30 P.M. Central Time. For a registration fee of $45.00, registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201.  For more information, e-mail here.

 HITECH Act Data Breach and Unsecured PHI Rules

The new data breach notification rules are part of a series of recent HIPAA enacted under the HITECH Act to strengthen the federal rules requiring HIPAA covered entities to safeguard electronic and certain other protected health information. Enhanced data security and data breach rules added as part of these HITECH Act amendments obligate  covered entities and business associates to provide certain notifications following a breach of “unsecured”  “protected health information” within the meaning of HIPAA, as amended.  “Unsecured protected health information” is defined as protected health information that is not secured through the use of a technology or methodology specified by the HHS Secretary.

The new data breach regulations implement the HITECH Act requirement that Covered Entities and their business associates notify affected individuals, the Secretary of HHS, and in some cases, the media, of a breach and the form, manner, and timing of that notification.  For purposes of the HITECH Act, electronic protected health information is considered “unsecured” unless the covered entity has satisfied certain minimum standards for the protection of that data established pursuant to the HITECH Act.  HHS and the Federal Trade Commission previously issued certain initial guidance concerning the HITECH Act standards for determining when electronic personal health information qualifies as secure.  To help further define when electronic health information is treated as “unsecured” and therefore subject to the breach notification requirements, the data breach rules also update and clarify the previously issued existing HHS guidance specifying encryption and destruction as the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals published earlier this year by HHS to for purposes of determining when protected health information will be considered “unsecured” for purposes of the HITECH Act data breach rules.  Entities subject to the HHS and FTC regulations that secure health information as specified by the guidance through encryption or destruction are relieved from having to notify in the event of a breach of such information.  

The HHS interim final regulations are effective September 24, 2009, which is the date 30 days after the date they will be published on the Federal Register and include a 60-day public comment period. To review the interim final data breach regulations, see here.  To review the HITECH Act Breach Notification Guidance and Request for Information, see here.

For More Information

The author of this article, Curran Tomko and Tarski LLP Health Care Practice Chair Cynthia Marcotte Stamer has extensive experience advising and assisting health care providers, payors and their business associates about HIPAA and other privacy and data security matters, as well as a diverse range of health care policy, regulatory, compliance, risk management and operational concerns. 

Past chair of the American Bar Association Health Law Section Managed Care & Insurance Section, Martindale Hubble AV-rated and recognized in International Who’s Who of Professionals, Ms. Stamer continuously advises health care providers, health care payers and administrators, employers, governments and others about health care, insurance, human resources, privacy and data security, technology, and other legal and operational concerns.  A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer also writes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters.  She currently serves as the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010.  Examples of her other works include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of others.  Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service Privacy Report, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a various other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.  

We hope that this information is useful to you.  If you need assistance monitoring, evaluating or responding to these or other proposed health care or other regulatory reforms or with other health care compliance, risk management, transaction or operation concerns, please contact the author of this update, Curran Tomko Tarski LLP Health Practice Group Chair, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or your other favorite Curran Tomko Tarski LLP Partner.

We also encourage you and others to join the discussion about these and other health care reform proposals and concerns by joining the Coalition for Responsible Health Care Reform Group on Linkedin, registering to receive these updates here.

Other Helpful Resources & Other Information

We hope that this information is useful to you.   If you found these updates of interest, you also be interested in one or more of the following other recent articles published on our electronic Solutions Law Press Health Care Update publication available here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please register to receive this Solutions Law Press Health Care Update here and be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.

©2009 Cynthia Marcotte Stamer.  All rights reserved. 


Comments On Definition of Meaningful Use of EMR For Purposes of HITECH Act Provider Incentives Due June 26

June 16, 2009

Friday, June 26, 2009 at 5:00 p.m. Eastern Time is the deadline to submit comments to the Office of the National Coordinator for Health Information Technology (ONC) on the recommendations about what should be considered the term “meaningful use” of electronic health records (EHRs) presented to the Health Information Technology Policy Committee today (June 16, 2009) available for review here. Comments will be received by the Committee for consideration and further recommendations to the National Coordinator of Health Information Technology on the elements and measures of Meaningful Use of a certified EHR.

The HIT Policy Committee is a Federal Advisory Committee (FACA) to the U.S. Department of Health and Human Services (HHS).  The American Recovery and Reinvestment Act of 2009 (ARRA”) provides for Medicare and Medicaid incentive payments for eligible providers, such as physicians and hospitals, in order to promote the adoption of EHRs.  To receive the incentive payments, providers must demonstrate “meaningful use” of a certified EHR.  Building upon the work of the HIT Policy Committee, HHS anticipates developing a proposed rule that provides greater detail on the incentive programs and “meaningful use.”  HHS expects to issue the proposed rule in late 2009, which will be followed by a comment period.

How OCR decides to define meaningful use of EMR is likely to play a central role in determining how effective provider incentives to use EMR included in ARRA’s HITECH Act provisions work and ultimately influence how effectively those provisions and other OCR efforts to accelerate EMR and other health information technology use to promote health care efficiency and quality work.

For instructions on how to comment or additional information, see here.

For More Information

We hope that this information is useful to you. If you need assistance with EMR or other health care technology, privacy or other health care compliance, risk management, transaction or operation concerns, please contact Curran Tomko Tarski LLP Health Practice Group Chair, Cynthia Marcotte Stamer at (214) 270-2402, CStamer@CTTLegal.com or your other favorite Curan Tomko Tarski LLP Partner.

You can review other recent health care and internal controls resources and additional information about the health industry and other experience of Ms. Stamer here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information to CStamer@CTTLegal.com.


DOJ/HHS Step Up Health Care Fraud Enforcement By Announcing New Interagency Health Care Fraud Prevention and Enforcement Action Team

May 20, 2009

Lead DOJ Health Care Fraud Enforcer Speaks In Dallas Tomorrow

The joint announcement today (May 20, 2009) by the U.S. Departments of Justice (DOJ) and Health & Human Services (HHS) of a new interagency team to combat health care fraud highlights the increasing need for health care providers and health plans to review and tighten their practices for dealing with Medicare and other federal programs to survive scrutiny under federal health care fraud initiatives.   Houston and Detroit are targeted for the attention of a new Strike Force.

Participants attending tomorrow’s Dallas Health Industry Council Southwest Healthcare Transaction Conference will get to hear the latest about these and other federal health care fraud prevention and enforcement activities from one of its key players. The Justice Department’s lead federal health care fraud prosecutor, John “Jay” S. Darden, the U.S. Department of Justice Assistant Chief for Healthcare Fraud is scheduled to provide an update on these and other federal regulatory and enforcement activities affecting health care transactions when he speaks at the Conference tomorrow afternoon at the Omni Mandalay Hotel Dallas at Las Colinas at 1:30 p.m.

Attorney General Eric Holder and Health and Human Services (HHS) Secretary Kathleen Sebelius announced the creation of the Health Care Fraud Prevention and Enforcement Action Team (HEAT), to combat Medicare fraud and the expansion of Strike Force team operations to Detroit and Houston.  Medicare Fraud Strike Forces, currently in operation in South Florida and Los Angeles, fight Medicare fraud on a targeted local level.  Statements made by Secretary Sebelius and Attorney General Holder in connection with the announcement of HEAT and the Strike Force Expansion make clear that the Obama Administration views health care fraud enforcement and prevention as a key element of its efforts to control health care costs.

The HEAT team will include senior officials from DOJ and HHS who will build upon and strengthen existing programs to combat fraud while also investing new resources and technology to prevent fraud, waste and abuse before it happens.  Efforts will include the expansion of joint DOJ-HHS Medicare Fraud Strike Force teams that have been successfully fighting fraud in South Florida and Los Angeles. 

Established in 2007, these Strike Force teams have a proven record of success using a “data-driven” approach to identify unexplainable billing patterns and investigating these providers for possible fraudulent activity.  The Medicare Fraud Strike Force team operating in South Florida has already convicted 146 defendants and secured $186 million in criminal fines and civil recoveries.  After the success of operations in South Florida, the Medicare Fraud Strike Force expanded in May 2008 to phase two in Los Angeles, where 37 defendants have been charged with criminal health care fraud offenses.  To date in the Los Angeles cases, more than $55 million has been ordered in restitution to the Medicare program. 

In addition to health care fraud enforcement and prosecution, HHS and DOJ also view prevention as critical to reforming the system.  Therefore, in addition to investigating and prosecuting fraud, the HEAT team will also focus critical resources on preventing fraud from occurring in the first place.  These efforts are expected to include:

  • Drawing from demonstration projects by the HHS Inspector General and the Centers for Medicare & Medicaid Services (CMS) that have focused on suppliers of durable medical equipment (DME) including increasing site visits to potential suppliers to prevent imposters from posing as legitimate DME providers. 
  • Increasing training for providers on Medicare compliance, offering providers the resources and the knowledge they need to help identify and prevent fraud.
  • Improving data sharing between CMS and law enforcement to help identify patterns that lead to fraud.
  • Strengthening program integrity activities to monitor and ensure Medicare Parts C (Medicare Advantage plans) and D (prescription drug programs) compliance and enforcement.

The Attorney General and the HHS Secretary also called on the American people to visit a new Web site http://www.hhs.gov/stopmedicarefraud or call 1-800-HHS-TIPS (1-800-447-8477) to report suspected Medicare fraud.

The HEAT Team and Strike Force activities are part of a broader emphasis in the enforcement of federal health care fraud laws.  President Obama’s proposed Fiscal Year 2010 budget seeks to further increase funding for fraud prevention and enforcement by investing $311 million — a 50 percent increase from 2009 funding — to strengthen program integrity activities within the Medicare and Medicaid programs.  The Obama Administration anticipates that all combined, the anti-fraud efforts in the President’s budget could save $2.7 billion over five years by improving oversight and stopping fraud in the Medicare and Medicaid programs, including the Medicare Advantage and Medicare prescription drug programs.

For More Information

We hope that this information is useful to you. If you need assistance responding to concerns about the matters discussed in this publication or other health care concerns, wish to obtain information about arranging for training or presentations by Ms. Stamer, wish to suggest a topic for a future program or update, or wish to request other information or materials, please contact Ms. Stamer via telephone at (214) 270-2402 or via e-mail to cstamer@CTTLegal.com.

You can review other recent updates and other publications by Ms. Stamer and other helpful health care resources and additional information about Ms. Stamer and her experience, see Stamer Health Industry Experience. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here or by registering to participate in the Solutions Law Press Health Care Update blog at Health Care Update Blog. For important information concerning this communication click here.    If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.


%d bloggers like this: