UHG Shares Resumption Timeline For Products Disrupted By Cyberattack

March 25, 2024

UnitedHealthcare Group (UHG) plans to resume certain key health benefit and payment function this week that it turned off in response to a February 21, 2024 cyberattack. 

Health care providers and their billing and other service providers may find these updates helpful to their efforts to respond with ongoing payment and other disruptions as well as to fulfill their own Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules, state contract, prompt pay and other duties to health care providers or other responsibilities in response to disruptions created by UHG’s Blackcat1234 ransomware attack subsidiary Change Healthcare.

UHG Attack

On February 21, 2024, a ransomware attack executed by the Blackcat1234 ransomware group took control of and shut down the payment, revenue cycle management and related tools and systems of UHG Subsidiary Change Healthcare. Well-known for stealing sensitive data and demanding ransom for not publishing it, and other public and private cybersecurity monitoring and tracking organizations have warned heath care and other system operators to guard against Blackcat1234 and related ransomware attack risks since at least 2022.  See, e.g., #StopRansomware: ALPHV Blackcat | CISA.

The Choice Health shutdown resulting from the Blackcat1234 ransomware attack has created widespread disruptions to key care authorization, billing and other pharmacy, provider and other plan and provider transactions within health care and health benefit systems nationwide due to the widespread use of the Choice Health tools.  Among other things:

Due to the widespread use of the Change Healthcare tools and systems as a financial clearinghouse for connecting pharmacy benefit managers, health care providers, and other key plays and health plans throughout the health care and health benefits industry, the attack has and continues to disrupt key billing, care-authorization, payment and other transactions between health care payers and pharmacies, physicians and other health care providers and health care payers and their partners across the health care industry.  

The resulting shutdown and disruption to electronic payment and medical claims systems incorporating the compromised Change Healthcare tools create various legal and operational headaches for many health plans and other health care payers by preventing or obstructing the submission and processing of health care claims and other transactions between health care providers and health plans.  

While UHG works to remediate and restore the operability and security of the Choice Health tools and systems, health plans, and insurers, their fiduciaries, plan sponsors, and fiduciaries should take timely and prudent steps in response to the breach and resulting disruptions to mitigate the exposure of their health plans, and themselves under HIPAA and ERISA. See Manage Health Plan HIPAA, ERISA & Other Exposures From Change Healthcare Ransomware Attack.

Timeline

In its Product Restoration Timeline posted on a UHG website, UhG projects the following timeline for restoration of the following systems:

Week of 3/25
  • Eligibility Processing: Processes real-time transactions
  • Clearance: Benefits verification and authorization determination
  • MedRX: Pharmacy electronic claims for medical
  • Reimbursement Manager: Claim pricing
  • Coverage Insight: Coverage discovery
Week of 4/1
  • Clinical Exchange: Provider workflow enabling electronic prescribing, ordering and resulting integrated into EHR’s
  • Payer Connectivity Services  (PCS): EDI validation and editing
  • Hosted Payer Services  (HPS): Payer hosting service for eligibility responses to providers
  • Acuity / Pulse: Acuity provides revenue cycle analytics for users of Clearance and Assurance; Pulse provides RCM KPI benchmarks for institutional claims utilizing Assurance client data
Week of 4/8
  • Risk Manager: Supports clients in managing value-based payment contracts.
  • Health QX: Retrospective episode-base payment models

No Guarantees

The UHG website warns these dates are projections based on available information. Products will go through a phased reconnection process, including launch, testing and scaled reconnection. The timeline may change as UHG learns more.

Unlisted Services

The Timeline currently does not list all products and services. The UHG website states that the absence of a product from the schedule does not mean that product is more than three weeks away from resumption. Rather, it means that UHG does not yet have line of sight to the week that it expects to restore it. UHG plans to provide updated information as those timelines become clear.

For specific product updates, UHG invites interested persons to subscribe to the products of interest here.

Restoration Webinars

UHG also has shared the following series of webinary providing more information about its restoration efforts:

Other Assistance

UHG also has announced the availability of finding assistance for providers adversely impacted by payment disruptions relating to the attack.

Health care providers can watch a video to learn more about this program and the process check eligibility on the UHG website.

For Additional Information

We hope this update is helpful. Solutions Law Press, Inc. invites you to receive future updates by registering on  here and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations GroupHR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.

If you need have questions or need assistance with this or other cybersecurity, health, benefit, payroll, investment or other data, systems or other privacy or security related risk management, compliance, enforcement or management concerns, to inquire about arranging for compliance audit or training, or need legal representation on other matters,  contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297

About the Author 

Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 35 plus years of employee benefit, managed care and other health and insurance industry, workforce and other management work, public policy leadership and advocacy, coaching, teachings, and publications.

A Fellow in the American College of Employee Benefit Counsel, Co-Chair of the American Bar Association (“ABA”) International Section Life Sciences and Health Committee and Vice-Chair Elect of its International Employment Law Committee, Chair-Elect of the ABA TIPS Section Medicine & Law Committee, Past Chair of the ABA Managed Care & Insurance Interest Group, Scribe for the ABA JCEB Annual Agency Meeting with HHS-OCR, past chair of the ABA RPTE Employee Benefits & Other Compensation Group and current co-Chair of its Welfare Benefit Committee, and Chair of the ABA Intellectual Property Section Law Practice Management Committee, Ms. Stamer is most widely recognized for her decades of pragmatic, leading-edge work, scholarship and thought leadership on heath benefit and other healthcare and life science, managed care and insurance and other workforce and staffing, employee benefits, safety, contracting, quality assurance, compliance and risk management, and other legal, public policy and operational concerns in the healthcare and life sciences, employee benefits, managed care and insurance, technology and other related industries. She speaks and publishes extensively on these and other related compliance issues.

Ms. Stamer’s work throughout her career has focused heavily on working with health care and managed care, life sciences, health and other employee benefit plan, insurance and financial services and other public and private organizations and their technology, data, and other service providers and advisors domestically and internationally with legal and operational compliance and risk management, performance and workforce management, regulatory and public policy and other legal and operational concerns. Author of a multitude of highly regarded publications on HIPAA and other medical record and data privacy and scribe for the ABA JCEB Annual Meeting with the HHS Office of Civil Rights, her experience includes extensive involvement throughout her career in advising health care and life sciences and other clients about preventing, investigating and defending EEOC, DOJ, OFCCP and other Civil Rights Act, Section 1557 and other HHS, HUD, banking, and other federal and state discrimination investigations, audits, lawsuits and other enforcement actions as well as advocacy before Congress and regulators regarding federal and state equal opportunity, equity and other laws. 

For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here

About Solutions Laws Press, Inc.™

Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested in reviewing some of our other Solutions Law Press, Inc.™ resources available here

IMPORTANT NOTICE ABOUT THIS COMMUNICATION

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.

NOTICE: These statements and materials are for general informational and educational purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstances at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author and Solutions Law Press, Inc.™ reserve the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules make it highly likely that subsequent developments could impact the currency and completeness of this discussion. The author and Solutions Law Press, Inc.™ disclaim, and have no responsibility to provide any update or otherwise notify anyone of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication. Readers acknowledge and agree to the conditions of this Notice as a condition of their access to this publication. 

Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.

©2024 Cynthia Marcotte Stamer. Limited non-exclusive right to republish granted to Solutions Law Press, Inc.™


eBay Paying $59 Million to Settle Controlled Substances Act Allegations About Website Pill Press Sales

January 31, 2024

The U.S. Department of Justice announced today that e-commerce company eBay Inc. will pay $59 million and enhance its compliance program to settle charges it violated the Controlled Substances Act (CSA) in connection with the use of its platform to sell thousands of pill presses and encapsulating machines. The fourth largest CSA settlement in history, it reaffirms the continuing Justice Department war on fentanyl and other illegal opiate distribution.

Criminals can use pill presses and encapsulating machines to manufacture illegal drugs. When used with a mold, stamp, or die mimicking commonly prescribed controlled substances, pill presses are capable of producing counterfeit pills that appear indistinguishable from legitimate pharmaceutical drugs, including pills that are sometimes laced with fentanyl. The Justice Department says counterfeit pills laced with fentanyl are a significant contributor to the deadly overdose epidemic.

The CSA regulates certain pharmaceutical manufacturing equipment, including pill presses and encapsulating machines, by requiring identity verification of purchasers, record-keeping, and reporting to the Drug Enforcement Administration (DEA). These requirements seek to prevent individuals from obtaining these machines to use for illegal purposes and to allow the government to trace the machines to the end user. Associate Attorney General Vanita Gupta, Chair of the Justice Department’s Opioid Epidemic Civil Litigation Task Force says the Justice Department is committed to using all available enforcement measures to ensure that companies involved in selling the equipment that makes it possible to create these dangerous pills comply with the Controlled Substances Act.”

The Justice Department has successfully prosecuted many of eBay’s pill press buyers for trafficking illegal counterfeit pills. The Justice Department alleges eBay violations of the CSA requirements for thousands of pill presses and encapsulating machines sold through its website, including high-capacity pill presses capable of producing thousands of pills per hour. The Justice Department investigation further found that hundreds of eBay’s pill press buyers also purchased counterfeit molds, stamps, or dies, allowing them to produce pills that mimicked the products of legitimate pharmaceutical companies,

Justice Department officials say eBay made it easy for individuals across the country to use its website to obtain the type of dangerous machines that are often used to make counterfeit pills.and that some of these machines were even sold to individuals who were later convicted of drug related crimes.

U.S. Attorney Henry C. Leventis for the Middle District of Tennessee says today’s settlement holds eBay accountable for its compliance lapses and serves as a reminder to other e-commerce companies that the Justice Department will enforce these requirements, and will help keep these items out of the hands of criminals moving forward.

In addition to the large monetary settlement, eBay also has agreed to maintain and enhance its compliance program with respect to its prohibited and restricted items policy as it pertains to sales of pill presses, counterfeit molds, stamps, and dies, and encapsulating machines.

Coupled with other high profile prosecutions and settlements of nationwide pharmacies, physicians and others, the eBay settlement alerts all parties connected with the manufacture, prescription, distribution and sale of opiates and other controlled substances to use care to ensure the defensibility of their actions.

For More Information

We hope this update is helpful. For more information about these or other health or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297

Solutions Law Press, Inc. invites you to receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations GroupHR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.

About the Author

Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 35 plus years of health industry and other management work, public policy leadership and advocacy, coaching, teachings, and publications.

A Fellow in the American College of Employee Benefit Counsel, Co-Chair of the American Bar Association (“ABA”) International Section Life Sciences and Health Committee and Vice-Chair Elect of its International Employment Law Committee, Chair-Elect of the ABA TIPS Section Medicine & Law Committee, Past Chair of the ABA Managed Care & Insurance Interest Group, Scribe for the ABA JCEB Annual Agency Meeting with HHS-OCR, past chair of the ABA RPTE Employee Benefits & Other Compensation Group and current co-Chair of its Welfare Benefit Committee, and Chair of the ABA Intellectual Property Section Law Practice Management Committee, Ms. Stamer is most widely recognized for her decades of pragmatic, leading-edge work, scholarship and thought leadership on heath benefit and other healthcare and life science, managed care and insurance and other workforce and staffing, employee benefits, safety, contracting, quality assurance, compliance and risk management, and other legal, public policy and operational concerns in the healthcare and life sciences, employee benefits, managed care and insurance, technology and other related industries. She speaks and publishes extensively on these and other related compliance issues.

Ms. Stamer’s work throughout her career has focused heavily on working with health care and managed care, life sciences, health and other employee benefit plan, insurance and financial services and other public and private organizations and their technology, data, and other service providers and advisors domestically and internationally with legal and operational compliance and risk management, performance and workforce management, regulatory and public policy and other legal and operational concerns. Author of a multitude of highly regarded publications on HIPAA and other medical record and data privacy and scribe for the ABA JCEB Annual Meeting with the HHS Office of Civil Rights, her experience includes extensive involvement throughout her career in advising health care and life sciences and other clients about preventing, investigating and defending EEOC, DOJ, OFCCP and other Civil Rights Act, Section 1557 and other HHS, HUD, banking, and other federal and state discrimination investigations, audits, lawsuits and other enforcement actions as well as advocacy before Congress and regulators regarding federal and state equal opportunity, equity and other laws. 

For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here

About Solutions Law Press, Inc.™

Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested in reviewing some of our other Solutions Law Press, Inc.™ resources available here such as:

IMPORTANT NOTICE ABOUT THIS COMMUNICATION

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.

NOTICE: These statements and materials are for general informational and educational purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstances at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author and Solutions Law Press, Inc.™ reserve the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules make it highly likely that subsequent developments could impact the currency and completeness of this discussion. The author and Solutions Law Press, Inc.™ disclaim, and have no responsibility to provide any update or otherwise notify anyone of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication. Readers acknowledge and agree to the conditions of this Notice as a condition of their access to this publication. 

Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.

©2024 Cynthia Marcotte Stamer. Limited non-exclusive right to republish granted to Solutions Law Press, Inc.™


Banner Health Pays $1.25 Million To Settle Cybersecurity Breach Impacting Nearly 3 Million Individuals

February 3, 2023

Phoenix-based nonprofit health system Banner Health and its affiliates (“Banner Health”) paid $1.25 million and agreed to take corrective actions to resolve its exposure to potentially much greater Health Insurance Portability and Accountability Act (HIPAA) Security Rule civil monetary penalty exposure for a 2016 cyber hacking breach that compromised the personal health information of 2.81 million consumers. OCR used its February 2 announcement of the Banner Health settlement to warn health care providers, health plans, health care clearinghouses (“covered entities”) and business associates covered by HIPAA to guard their own systems containing protected health information against breach by cyber hacking.

Banner Health Settlement

Banner Health is one of the largest non-profit health systems in the country, with over 50,000 employees and operating in six states. Banner Health is the largest employer in Arizona and one of the largest in northern Colorado.

In November 2016, OCR initiated an investigation of Banner Health following the receipt of a breach report stating that a threat actor had gained unauthorized access to electronic protected health information, potentially affecting millions.  The hacker accessed protected health information that included patient names, physician names, dates of birth, addresses, Social Security numbers, clinical details, dates of service, claims information, lab results, medications, diagnoses and conditions, and health insurance information.

OCR’s investigation found evidence of long-term, pervasive noncompliance with the HIPAA Security Rule across Banner Health’s organization, a serious concern given the size of this covered entity. Organizations must be proactive in their efforts to regularly monitor system activity for hacking incidents and have measures in place to sufficiently safeguard patient information from risk across their entire network.

The potential violations OCR identified specifically included:

  • A lack of an analysis to determine risks and vulnerabilities of electronic protected health information across the organization;
  • Insufficient monitoring of its health information systems’ activity to protect against a cyber-attack;
  • Failure to implement an authentication process to safeguard its electronic protected health information; and
  • Failure to have security measures in place to protect electronic protected health information from unauthorized access when it was being transmitted electronically.

Under the Resolution Agreement and Corrective Action Plan negotiated to resolve these potential violations, Banner Health paid $1,250,000 to OCR. Banner Health also agreed to implement a corrective action plan, which identifies steps Banner Health will take to resolve these potential violations of the HIPAA Security Rule and protect the security of electronic patient health information that will be monitored for two years by OCR to ensure compliance with the HIPAA Security Rule. Under the corrective action plan, Banner has agreed to take the following steps:

  • Conduct an accurate and thorough risk analysis to determine risks and vulnerabilities to electronic patient/system data across the organization
  • Develop and implement a risk management plan to address identified risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI
  • Develop, implement, and distribute policies and procedures for a risk analysis and risk management plan, the regular review of activity within their information systems, an authentication process to provide safeguards to data and records, and security measures to protect electronic protected health information from unauthorized access when it is being transmitted electronically, and
  • Report to HHS within thirty (30) days when workforce members fail to comply with the HIPAA Security Rule.

OCR Warns Other HIPAA-Covered Entities

In the health care sector, hacking is now the greatest threat to the privacy and security of protected health information. OCR’s announcement of the settlement reports 74 percent (74%) of the breaches reported to OCR in 2021 involved hacking/IT incidents.

The announcement also notes OCR offers an array of resources to help health care organizations bolster their cybersecurity posture and comply with the HIPAA Rules,

The settlement and OCR’s announcement warn other covered entities and business associates to use these and other necessary resources to protect their systems with protected health information from cyber hacking and other breaches.

In conjunction with reminding other covered entities of these resources, the settlement announcement quotes OCR Director Melanie Fontes Rainer as a warning, “Hackers continue to threaten the privacy and security of patient information held by health care organizations, including our nation’s hospitals, … It is imperative that hospitals and other covered entities and business associates be vigilant in taking robust steps to protect their systems, data, and records, and this begins with understanding their risks, and taking action to prevent, respond to and combat such cyber-attacks. … Cyber security is on all of us, and we must take steps to protect our health care systems from these attacks.”

OCR’s enforcement record confirms these are not idyl threats. Breaches of the Security or Breach Notification Rules often result in significant civil monetary penalty assessments or negotiated settlements to mitigate civil liability exposures arising out of such breaches. See e.g., Clinical Laboratory Pays $25,000 To Settle Potential HIPAA Security Rule Violations (May 25, 2021); Health Insurer Pays $5.1 Million to Settle Data Breach Affecting Over 9.3 Million People (January 15, 2021); Aetna Pays $1,000,000 to Settle Three HIPAA Breaches(October 28, 2020); Health Insurer Pays $6.85 Million to Settle Data Breach Affecting Over 10.4 Million People (September 25, 2020); HIPAA Business Associate Pays $2.3 Million to Settle Breach Affecting Protected Health Information of Over 6 million Individual – (September 23, 2020); Lifespan Pays $1,040,000 to OCR to Settle Unencrypted Stolen Laptop Breach (July 27, 2020); Small Health Care Provider Fails to Implement Multiple HIPAA Security Rule Requirements (July 23, 2020).

Alerts issued by OCR regarding heightened security risks in recent months and a growing tide of highly publicized breaches send a strong warning to other covered entities and their business associates to reconfirm the adequacy of their own HIPAA privacy, security, breach notification and other procedures and protections by among other things:

  • Reviewing and monitoring on a documented, ongoing basis the adequacy and susceptibilities of existing practices, policies, safeguards of their own organizations, as well as their business associates and their vendors within the scope of attorney-client privilege taking into consideration data available from OCR, data regarding known or potential susceptibilities within their own operations as well as in the media, and other developments to determine if additional steps are necessary or advisable.
  • Updating policies, privacy and other notices, practices, procedures, training and other practices as needed to promote compliance and defensibility.
  • Renegotiating and enhancing service provider agreements to detail the specific compliance, audit, oversight and reporting rights, workforce and vendor credentialing and access control, indemnification, insurance, cooperation and other rights and responsibilities of all entities and individuals that use, access or disclose, or provide systems, software or other services or tools that could impact on security; to clarify the respective rights, procedures and responsibilities of each party in regards to compliance audits, investigation, breach reporting, and mitigation; and other relevant matters.
  • Verifying and tightening technological and other tracking, documentation and safeguards and controls to the use, access and disclosure of protected health information and systems.
  • Conducting well-documented training as necessary to ensure that members of the workforce of each covered entity and business associate understand and are prepared to comply with the expanded requirements of HIPAA, understand their responsibilities and appropriate procedures for reporting and investigating potential breaches or other compliance concerns, and understand as well as are prepared to follow appropriate procedures for reporting and responding to suspected 
    violations or other indicia of potential security concerns.
  • Tracking and reviewing on a systemized, well-documented basis actual and near-miss security threats to evaluate, document decision-making and make timely adjustments to policies, practices, training, safeguards and other compliance components as necessary to identify and resolve risks.
  • Establishing and providing well-documented monitoring of compliance that includes board-level oversight and reporting at least quarterly and sooner in response to potential threat indicators.
  • Establishing and providing well-documented timely investigation and redress of reported 
    violations or other compliance concerns.
  • Establishing contingency plans for responding in the event of a breach. 
  • Establishing a well-documented process for monitoring and updating policies, practices and other efforts in response to changes in risks, practices and requirements.
  • Preparing and maintaining a well-documented record of compliance, risk, investigation and other security activities.
  • Pursuing other appropriate strategies to enhance the covered entity’s ability to demonstrate its compliance commitment both on paper and in operation.

Because of susceptibilities in systems, software and other vendors of business associates, suppliers and other third parties, covered entities and their business associates should use care to assess and manage business associate and other vendor-associated risks and compliance as well as tighten business associate and other service agreements to promote the improved cooperation, coordination, management and oversight required to comply with the new breach notification and other HIPAA requirements by specifically mapping out these details.

Beyond these HIPAA exposures, breaches and other HIPAA noncompliance carries other liability risks. Leaders of covered entities or their business associates also are cautioned that while HIPAA itself does not generally create any private right of action for victims of breach under HIPAA, breaches may create substantial liability for their organizations or increasingly, organizational leaders. For instance, the Department of Health & Human Services has warned health care providers participating in Medicare or other federal programs and Medicare Advantage health plans that HIPAA compliance is a program term of participation.

Health care providers and health insurers can face liability under state data privacy and breach, negligence or other statutory or common laws. In addition, physicians and other licensed parties may face professional discipline or other professional liability for breaches violating statutory or ethical standards.

Health plans also face a myriad of other exposures from failing to use appropriate cyber safeguards. Plan fiduciaries of employment-based health plans covered by the Employee Retirement Income Security Act (“ERISA”) risk liability under ERISA’s fiduciary responsibility rules. The Department of Labor Employee Benefit Security Administration (“EBSA”) now audits the adequacy of the cybersecurity and other HIPAA compliance of health plans and their third-party administrators and other business associates as part of EBSA’s oversight and enforcement of ERISA. Department of Labor Assistant Secretary for EBSA Lisa Gomez confirmed audit and enforcement of cybersecurity obligations is a key priority in EBSA’s current work plan in her February 4, 2023 comments to the American Bar Association.

Meanwhile, the Securities and Exchange Commission has indicated that it plans to pursue enforcement against leaders of public health care or other public companies that fail to use appropriate care to ensure their organizations comply with privacy and data security obligations.

Furthermore, appropriate cyber security practices also may be advisable elements for organizations to include in their Federal Sentencing Guideline Compliance Programs to mitigate potential organization liability risks under federal electronic crime and related laws.

In the face of these risks and warnings, all covered entities and their business associates should reassess and confirm the adequacy of their and their business associates’ cyber security defenses and breach response preparations.

More Information

We hope this update is helpful. For more information about these or other health or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297.  

Solutions Law Press, Inc. invites you to receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy. 

About the Author

Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely-known for 35 plus years of health industry and other management work, public policy leadership and advocacy, coaching, teachings, and publications.

A Fellow in the American College of Employee Benefit Counsel, Chair of the American Bar Association (“ABA”) International Section Life Sciences and Health Committee, Chair-Elect of the ABA TIPS Section Medicine & Law Committee, Past Chair of the ABA Managed Care & Insurance Interest Group, Scribe for the ABA JCEB Annual Agency Meeting with HHS-OCR, past chair of the ABA RPTE Employee Benefits & Other Compensation Group and current co-Chair of its Welfare Benefit Committee, Ms. Stamer is most widely recognized for her decades of pragmatic, leading-edge work, scholarship and thought leadership on health and managed care and employer benefits legal, public policy and operational concerns in the healthcare, employer benefits, and insurance and financial services industries. She speaks and publishes extensively on HIPAA and other related compliance issues.

Ms. Stamer’s work throughout her career has focused heavily on working with health care and managed care, health and other employee benefit plan, insurance and financial services and other public and private organizations and their technology, data, and other service providers and advisors domestically and internationally with legal and operational compliance and risk management, performance and workforce management, regulatory and public policy and other legal and operational concerns.

For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here

About Solutions Law Press, Inc.™

Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested in reviewing some of our other Solutions Law Press, Inc.™ resources available here such as:

IMPORTANT NOTICE ABOUT THIS COMMUNICATION

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.

NOTICE: These statements and materials are for general informational and educational purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstances at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author and Solutions Law Press, Inc.™ reserve the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules make it highly likely that subsequent developments could impact the currency and completeness of this discussion. The author and Solutions Law Press, Inc.™ disclaim, and have no responsibility to provide any update or otherwise notify anyone of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication. Readers acknowledge and agree to the conditions of this Notice as a condition of their access to this publication. 

Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.

©2023 Cynthia Marcotte Stamer. Limited non-exclusive right to republish granted to Solutions Law Press, Inc.™


Biden-Harris Administration to Expand Vaccination Requirements for Health Care and Many Other Employers

September 9, 2021

All Medicare and Medicaid certified health care facilities, and a broad range of other employers must prepare to meet impending new federal COVID-19 vaccine mandates announced by the Biden-Harris Administration today.

According to today’s announcements all healthcare facilities participating in Medicare or Medicaid or employing 100 or more employees will be required to ensure all staff are vaccinated against COVID-19.

The Biden-Harris Administration says the new health industry COVID-19 vaccine mandates will be implemented through emergency regulations to be issued in October.

According to today’s announcement, the Centers for Medicare & Medicaid Service (“CMS”) in collaboration with the Centers for Disease Control (“CDC”) is developing an Interim Final Rule with Comment Period that will be issued in October that will extend vaccine mandates originally announced last month for all Medicare and Medicaid participating nursing home workers to include hospitals, dialysis facilities, ambulatory surgical settings, and home health agencies, among others, as a condition for participating in the Medicare and Medicaid programs. See .

The announcement of the vaccine mandates for healthcare workers coincides with the Biden-Harris Administration’s announcement of sweeping new vaccine mandates for all government workers, government contractors and employers employing more than 100 employees.

The two mandates will force most health care facilities to impose mask mandates for all staff in order to meet the requirement all staff be vaccinated.

CMS and CDC say the decision was based on the continued and growing spread of the virus in health care settings, especially in parts of the U.S. with higher incidence of COVID-19. They claim the action will protect patients of the 50,000 providers and over 17 million health care workers in Medicare and Medicaid certified facilities.

According to the CDC, nursing homes with an overall staff vaccination rate of 75% or lower experience higher rates of preventable COVID infection. In CMS’s review of available data, the agency is seeing lower staff vaccination rates among hospital and End Stage Renal Disease (ESRD) facilities. To combat this issue, CMS is using its authority to establish vaccine requirements for all providers and suppliers that participate in the Medicare and Medicaid programs. Vaccinations have proven to reduce the risk of severe illness and death from COVID-19 and are effective against the Delta variant.

In it’s announcement of the impending vaccination requirements, CDC urged health care facilities to prepare now to meet the new mandate in October. CMS expects certified Medicare and Medicaid facilities to act in the best interest of patients and staff by complying with new COVID-19 vaccination requirements.

CDC also urged any health care workers employed in these facilities who are not currently vaccinated are urged to begin the process immediately and facilities to use all available resources to support employee vaccinations, including employee education and clinics, as they work to meet new federal requirements.

While legal challenges to the mandate requirements are likely, most facilities that have not already adopted vaccine mandates are expected to adopt these mandates rather than risk losing eligibility for Medicare and Medicaid reimbursement and other sanctions.

Beyondprogram disqualification and attendant financial pressures, announcement of the new vaccine mandates adds vaccination to the list of safety safeguards that healthcare facilities as employers can expect to be required to enforce as part of the occupational safety rules of the Occupational Safety and Health Administration (”OSHA”).

OSHA already is sanctioning employers for violating COVID-19 related OSHA requirements. For instance, OSHA nailed Lakewood Resource and Referral Center Inc., dba Center for Education Medicine and Dentistry (CHEMED) with heavy fines for allegedly violating applicable COVID-19 safety guidelines in January, 2021.

In a July 23, 2021 citation letter, OSH proposes to fine CHEMED $273,064.00 for willfully violating OSHA by not providing a medical evaluation to determine each employee’s ability to use a N95 respirator, before the employee was fit tested or required to use the respirator in the workplace to protect against SARS-CoV-2 virus while testing suspected COVID-19 individuals.

In addition to the proposed fine, the citation also orders CHEMED to take a series of corrective actions and to post notices in the workplace informing workers of the violation. 

Along with the CHEMED citation, OSH also cited a staffing agency contracted to provide nursing staffing to CHEMED, Homecare Therapies for also failing to conduct medical evaluations and fit tests. It received two violations and a proposed fine of $13,653.

In the face of these potential consequences, most covered health care facilities and other employers impacted by the mandate are likely to implement mandates unless and until these requirements are struct down by the courts or withdrawn.

Assuming the Administration follows appropriate procedures to adopt the rules, most legal commentators do not expect the legal challenges opposing the mandate orders to be successful in the courts particularly after the Supreme Court refused to overturn or hear arguments for overturning a unanimous decision of a three-judge panel of the United States Court of Appeals for the Seventh Circuit in Klassen v. Trustees of Indiana University that refused to enjoin a vaccine mandate imposed by Indiana University as a condition of student or staff in person participation in classes or other activities.

While most healthcare and other covered businesses are not expected to challenge the rules, compliance us likely to trigger backlash from some unvaccinated workers strongly opposed to becoming vaccinated. Employers may find that some employees will resign their employment or take other tactics to avoid becoming vaccinated. Even those who elect to become vaccinated to retain their employment are likely to express opposition and dissatisfaction that could create liability exposures for the employers if it becomes a basis for retaliation claim.

Employers in Texas and certain other states that have adopted rules restricting or prohibiting vaccine, mask or other mandates also may face challenges based on the state rules.

In light of these and other uncertainties and challenges, Healthcare and Other or Employers generally should seek legal advice and assistance from legal counsel experienced with the relevant health care, labor and employment, privacy and other concerns.

More Information

This article is republished by permission of the author, Cynthia Marcotte Stamer.  To review the original work, see here.

Solutions Law Press, Inc. invites you to receive future updates by registering here and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations GroupHR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here. For specific information about the these or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297.

About the Author

Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years working as an on demand, special project, consulting, general counsel or other basis with domestic and international business, charitable, community and government organizations of all types, sizes and industries and their leaders on labor and employment and other workforce compliance, performance management, internal controls and governance, compensation and benefits, regulatory compliance, investigations and audits, change management and restructuring, disaster preparedness and response and other operational, risk management and tactical concerns.

Most widely recognized for her work with health care, life sciences, insurance and data and technology organizations, she also has worked extensively with health plan and insurance, employee benefits, financial, transportation, manufacturing, energy, real estate, accounting and other services, public and private academic and other education, hospitality, charitable, civic and other business, government and community organizations. and their leaders.

Ms. Stamer has extensive experience advising, representing, defending, and training domestic and international public and private business, charitable, community and governmental organizations and their leaders, employers, employee benefit plans, their fiduciaries and service providers, insurers, and others has published and spoken extensively on these concerns. As part of these involvements, she has worked, published and spoken extensively on these and other human resources, employee benefits, compensation, worker classification and other workforce and other services; insurance; health care; workers’ compensation and occupational disease; business reengineering, disaster and distress; and many other performance, risk management, compliance, public policy and regulatory affairs, and other operational concerns. 

A former lead advisor to the Government of Bolivia on its pension  project, Ms. Stamer also has worked internationally and domestically as an advisor to business, community and government leaders on these and other legislative, regulatory and other legislative and regulatory design, drafting, interpretation and enforcement, as well as regularly advises and represents organizations on the design, administration and defense of workforce, employee benefit and compensation, safety, discipline, reengineering, regulatory and operational compliance and other management practices and actions.

Ms. Stamer also serves in leadership of a broad range of professional and civic organizations and provides insights and thought leadership through her extensive publications, public speaking and volunteer service with a diverse range of organizations including as Chair of the American Bar Association (“ABA”) Intellectual Property Section Law Practice Management Committee, Vice Chair of the International Section Life Sciences and Health Committee, Past ABA RPTE Employee Benefits & Other Compensation Group Chair and Council Representative and current Welfare Benefit Committee Co-Chair, Past Chair of the ABA Managed Care & Insurance Interest Group, past Region IV Chair and national Society of Human Resources Management Consultant Forum Board Member,  past Texas Association of Business BACPAC Chair, Regional Chair and Dallas Chapter Chair, former Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation and many others.

For more information about these concerns or Ms. Stamer’s work, experience, involvements, other publications, or programs, see www.cynthiastamer.com,  on  Facebook, on LinkedIn or Twitter or e-mail here.

About Solutions Law Press, Inc.™

Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns.

©2021 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™


Fresenius Medical Care Pays $3.5 Million HIPAA Settlement

February 2, 2018

Fresenius Medical Care North America (FMCNA) is paying $3.5 million to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and adopting a comprehensive corrective action plan, under a voluntary resolution agreement that settles FMCNA exposures to OCR for violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules OCR asserts it found from an investigation it conducted into five separate HIPAA breach reports FMCNA filed in January 21, 2017.

Widespread publicity and fallout from data breaches involving Equifax, Blue Cross, the Internal Revenue Service and many other giant organizations have ramped up public awareness and government concern about health care and other data security.  The resulting pressure is adding additional fuel to the already substantial concern of OCR and other agencies about compliance with HIPAA and other data security and breach laws.  Like the $2.3 million HIPAA resolution agreement OCR announced with now bankrupt radiation oncology and cancer care provider 21st Century Oncology, Inc. (21CO) earlier this year,  see, e.g., $23M Penalty Small Part of 21st Century’s Data Breach Fallout; Offers Data Breach Lessons For Other Businesses, the growing list of OCR resolution agreements and other enforcement actions against FMCNA, 21CO and other covered entities and other legal and market fallout that covered entities and other organizations experience following the announcement of breaches or other security deficiencies make the case for why HIPAA-covered health care providers, health plans, health care clearinghouses and their business associates (covered entities) must prioritize HIPAA compliance and other medical and other data security protection, privacy and risk management a top priority in 2018.

HIPAA Privacy, Security & Breach Notification Rule Responsibilities & Risks

The Privacy Rule requires that health plans, health care providers, health care clearinghouses (covered entities) and their vendors that qualify as “business associates” under HIPAA comply with detailed requirements concerning the protection, use, access, destruction and disclosure of protected health information.  As part of these requirements, covered entities and their business associates must adopt, administer and enforce detailed policies and practices, assess, monitor and maintain the security of electronic protected health information (ePHI) and other protected health information, provide notices of privacy practices and breaches of “unsecured” ePHI, afford individuals that are the subject of protected health information certain rights and comply with other requirements as specified by the Privacy, Security and Breach Notification Rules.  In addition, covered entities and business associates also must enter into a written and signed business associate agreement that contains the elements specified in Privacy Rule § 164.504(e) before the business associate creates, uses, accesses or discloses PHI of the covered entity. Furthermore, the Privacy Rule includes extensive documentation and keeping requirements require that covered entities and BAs maintain copies of these BAAs for a minimum of six years and to provide that documentation to OCR upon demand.

Violations of the Privacy Rule can carry stiff civil or even criminal penalties.  Pursuant to amendments to HIPAA enacted as part of the HITECH Act, civil penalties typically do not apply to violations punished under the criminal penalty rules of HIPAA set forth in Social Security Act , 42 U.S.C § 1320d-6 (Section 1177).

Resolution Agreements like the $3.2 million FMCNA resolution agreement allow covered entities and business associates to resolve potentially substantially larger civil monetary penalty liabilities that OCR can impose under the civil enforcement provisions of HIPAA.  As amended by the HITECH Act, the civil enforcement provisions of HIPAA empower OCR to impose Civil Monetary Penalties on both covered entities and BAs for violations of any of the requirements of the Privacy or Security Rules.  The penalty ranges for civil violations depends upon the circumstances associated with the violations and are subject to upward adjustment for inflation.  As most recently adjusted here effective September 6, 2016,  the following currently are the progressively increasing Civil Monetary Penalty tiers:

  • A minimum penalty of $100 and a maximum penalty of $50,000 per violation, for violations which the CE or BA “did not know, and by exercising reasonable diligence would not have known” about using “the business care and prudence expected from a person seeking to satisfy a legal requirement under similar circumstances;”
  • A minimum penalty of $1,000 and a maximum penalty of $50,000 per violation, for violations for “reasonable cause” which do not rise to the level of “willful neglect” where “reasonable cause” means the “circumstances that would make it unreasonable for the covered entity, despite the exercise of ordinary business care and prudence, to comply with the violated Privacy Rule requirement;”
  • A minimum penalty of $10,000 and a maximum penalty of $50,000 per violation, for violations attributed to “willful neglect,” defined as “the conscious, intentional failure or reckless indifference to the obligation to comply” with the requirement or prohibition; and
  • A minimum penalty of $50,000 and a maximum penalty of $1.5 million per violation, for violations attributed to “willful neglect” not remedied within 30 days of the date that the covered entity or BA knew or should have known of the violation.

For continuing violations such as failing to implement a required BAA, OCR can treat each day  of noncompliance as a separate violation.  However, sanctions under each of these tiers generally are subject to a maximum penalty of $1,500,000 for violations of identical requirements or prohibitions during a calendar year.  For violations such as the failure to implement and maintain a required BAA where more than one covered entity bears responsibility for the violation, OCR an impose Civil Monetary Penalties against each culpable party. OCR considers a variety of mitigating and aggravating facts and circumstances when arriving at the amount of the penalty within each of these applicable tiers to impose.

In addition to these potential civil liability exposures, however, covered entities, their business associates and other individuals or organizations that wrongfully use, access or disclose electronic or other protected health information also can face civil liability under various circumstances.  The criminal enforcement provisions of HIPAA authorize the Justice Department to prosecute a person who knowingly in violation of the Privacy Rule (1) uses or causes to be used a unique health identifier; (2) obtains individually identifiable health information relating to an individual; or (3) discloses individually identifiable health information to another person, punishable by the following criminal sanctions and penalties:

  • A fine of up to $50,000, imprisoned not more than 1 year, or both;
  • If the offense is committed under false pretenses, a fine of up to $100,000, imprisonment of not more than 5 years, or both; and
  • If the offense is committed with intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm, a fine of up to $250,000, imprisoned not more than 10 years, or both.

Because HIPAA Privacy Rule criminal violations are Class A Misdemeanors or felonies, Covered Entities and business associates should include HIPAA compliance in their Federal Sentencing Guideline Compliance Programs and practices and need to be concerned both about criminal exposure for their own direct violations, as well as imputed organizational liability for violations committed by their employees or agents under the Federal Sentencing Guidelines, particularly where their failure to implement or administer these required compliance policies and practices or failure to properly investigate or redress potential violations enables, perpetuates or covers up the criminal breach.

Fresenius Breach, Charges & Settlement Agreement Illustrate Civil Exposures

The FMCNA resolution agreement is another example of a growing list of resolution agreements various HIPAA covered entities have entered into to resolve their exposure to potentially greater liability should OCR assess civil monetary penalties under HIPAA’s civil sanction scheme.

The breach reports filed on January 21, 2017 reported five separate breach incidents occurring between February 23, 2012 and July 18, 2012 implicating the electronic protected health information (ePHI) of five separate FMCNA owned covered entities (FMCNA covered entities):  Bio-Medical Applications of Florida, Inc. d/b/a Fresenius Medical Care Duval Facility in Jacksonville, Florida (FMC Duval Facility); Bio-Medical Applications of Alabama, Inc. d/b/a Fresenius Medical Care Magnolia Grove in Semmes, Alabama (FMC Magnolia Grove Facility); Renal Dimensions, LLC d/b/a Fresenius Medical Care Ak-Chin in Maricopa, Arizona (FMC Ak-Chin Facility); Fresenius Vascular Care Augusta, LLC (FVC Augusta); and WSKC Dialysis Services, Inc. d/b/a Fresenius Medical Care Blue Island Dialysis (FMC Blue Island Facility).

OCR concluded its investigation showed the breaches resulted because FMCNA failed to conduct an accurate and thorough risk analysis of potential risks and vulnerabilities to the confidentiality, integrity, and availability of all of its ePHI.  OCR also concluded:

  • The FMCNA covered entities impermissibly disclosed the ePHI of patients by providing unauthorized access for a purpose not permitted by the Privacy Rule.
  • FMC Ak-Chin failed to implement policies and procedures to address security incidents.
  • FMC Magnolia Grove failed to implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain ePHI into and out of a facility; and the movement of these items within the facility.
  • FMC Duval and FMC Blue Island failed to implement policies and procedures to safeguard their facilities and equipment therein from unauthorized access, tampering, and theft, when it was reasonable and appropriate to do so under the circumstances.
  • FMC Magnolia Grove and FVC Augusta failed to implement a mechanism to encrypt and decrypt ePHI, when it was reasonable and appropriate to do so under the circumstances.

In addition to a $3.5 million monetary settlement, a corrective action plan requires the FMCNA covered entities to complete a risk analysis and risk management plan, revise policies and procedures on device and media controls as well as facility access controls, develop an encryption report, and educate its workforce on policies and procedures.

 

HIPAA Enforcement A Growing Risk

Covered entities, their business associates and members of their workforce need to recognize that the FMCNA and other resolution agreements are part of a growing trend, rather than isolated incidents of enforcement.

While civil monetary penalty enforcement remains much more common than criminal prosecution, covered entities, their business associates and members of their workforce must understand that HIPAA enforcement and resulting liability is growing.

While Department of Justice federal criminal prosecutions and convictions under HIPAA remain relatively rare, they occur and are growing.  See e.g.,  Former Hospital Employee Sentenced for HIPAA Violations (Texas man sentenced to 18 months in federal prison for obtaining protected health information with the intent to use it for personal gain); Three Life Sentences Imposed On Man Following Convictions For Drug Trafficking, Kidnapping, Using Firearms and HIPAA Violations (drug king pin gets multiple 10 year consecutive prison terms for unauthorized access to private health information in violation of HIPAA; his health care worker friend sentenced for accessing electronic medical files and reporting information to him); Former Therapist Charged In HIPAA Case; Hefty Prison Sentence in ID Theft Case (former assisted living facility worker gets 37 months in prison after pleading guilty to wrongful disclosure of HIPAA protected information and other charges); Hefty Prison Sentence in ID Theft Case (former medical supply company owner sentenced to 12 years for HIPAA violations and fraud).  While the harshest sentences tend to be associated with health care fraud or other criminal conduct, lighter criminal sentences are imposed against defendants in other cases as well. See e.g., Sentencing In S.C. Medicaid Breach Case (former South Carolina state employee sentenced to three years’ probation, plus community service, for sending personal information about more than 228,000 Medicaid recipients to his personal e-mail account.); HIPAA Violation Leads To Prison Term (former UCLA Healthcare System surgeon gets four months in prison after admitting he illegally read private electronic medical records of celebrities and others.)

While criminal enforcement of HIPAA remains relatively rare and OCR to date only actually has assessed HIPAA civil monetary penalties against certain Covered Entities for violating HIPAA in a couple isolated instances, the growing list of multi-million dollar resolution payments that FMCNA and other covered entities caught violating HIPAA make clear that HIPAA enforcement is both meaningful and growing.   See e.g., Learn From Children’s New $3.2M+ HIPAA CMP For “Knowing” Violation of HIPAA Security Rules ($3.2 million Children’s Medical Center HIPAA Civil Monetary Penalty); 1st HIPAA Privacy Civil Penalty of $4.3 Million Signals CMS Serious About HIPAA Enforcement;  $400K HIPAA Settlement Shows Need To Conduct Timely & Appropriate Risk Assessments$5.5M Memorial HIPAA Resolution Agreement Shows Need To Audit.  For more examples, also see here.

Coming on the heels of  an already lengthy and growing list of OCR high dollar HIPAA enforcement actions, the FMCNA and other resolution agreements and civil monetary penalties these and other announced enforcement actions clearly reflect that OCR takes HIPAA compliance seriously and stands ready to impose substantial penalties when it finds violations in connection with breach notice investigations.  Viewed in the context of these and other enforcement actions, the FMCNA Resolution Agreement and others clearly reflect the time for complacency in HIPAA compliance and leniency in HIPAA HIPAA enforcement are passed.  Rather, these and other enforcement actions make clear why health care providers, health plans, healthcare clearinghouses and their business associates must make HIPAA compliance a priority now.

Covered entities and business associates also should recognize their potential responsibilities and risks for breaches or other improper conduct concerning patient or other sensitive personal financial information, trade secrets or other data under a wide range of laws beyond HIPAA and its state law equivalents.  As documented by the media coverage of the legal and business woes of Alteryx, eBay, Paypal owner TIO Networks, Uber, Equifax and a long list of other previously trusted prominent businesses have and continue to incur from data breaches within their organizations, health care or other covered entities experiencing breaches often also face FTC or other government investigations and enforcement under the Fair and Accurate Credit Transactions Act (FACTA) and other federal or state identity theft, data privacy and security, electronic crimes and other rules as well as business losses and disruptions; civil litigation from breach victims, shareholders and investors, and business partners as well as OCR, FTC, and state data security regulation enforcement.  Amid this growing concern, OCR has indicated that it intends to continue to diligently both seek to support and encourage voluntary compliance by covered entities and their business associates and  investigate and enforce HIPAA against HIPAA covered entities and their business associates that fail to adequately safeguard PHI and ePHI in accordance with HIPAA. In the face of these growing risks and liabilities, covered entities and their business leaders face a strong imperative to clean up and maintain their HIPAA compliance and other data security to minimize their exposure to similar consequences.

In light of these rises, leaders, investors, insurers, lenders and others involved with covered entities and their business associates should take steps to verify that the covered entities and their business associates not only maintain compliance with HIPAA, but also comply with data security, privacy and other information protection requirements arising under other laws, regulations, and contracts, as well as the practical business risks that typically follow the announcement of a breach.  Considering these risks, covered entities and their business associates must recognize and take meaningful, documented action to verify their existing compliance and ongoing oversight to ensure their organizations can demonstrate appropriate action to maintain appropriate practices, insurance and other safeguards to prevent, respond to and mitigate exposures in the event of a breach of protected health information or other sensitive data.

In response to these growing risks and concerns, covered entities and their business associates should ensure that they have conducted, and maintain and are ready to produce appropriate policies and procedures backed up by a well documented, up-to-date industry wide risk assessment of their organization’s susceptibility to breaches or other misuse of electronic or other protected health information.  The starting point of these efforts should be to adopt and enforce updated written policies, procedures, technical and physical safeguards, processes and training to prevent the improper use, access, destruction or disclosure of patient PHI.  Processes also should create, retain and be designed to cost effectively track, capture, and retain both all protected health information, its use, access, protection, destruction and disclosure, and the requisite supportive documentation supporting the appropriateness of those action to position the organization  cost-effectively and quickly to fulfill required accounting, reporting and other needs in the event of a data breach, audit, participant inquiry or other event.

As part of this process, covered entities and business associates should start by reviewing and updating their policies, HIPAA audits and assessments and other documentation and processes.  In doing so, they must use care to look outside the four corners of their Privacy Policies and core operating systems to ensure that their policies, practices, oversight and training address all protected health information within their operations on an entity wide basis. This entity-wide assessment should include both communications and requests for information normally addressed to the Privacy Officer as well as requests and communications that could arise in the course of media or other public relations, practice transition, workforce communication and other operations not typically under the direct oversight and management of the Privacy Officer.

In connection with these efforts, the enforcement actions make clear that Covered Entities and business associates should adopt, implement and monitor PHI privacy, and security on an entity wide basis.  These efforts should include both general policies, practices and procedures as well as specifically tailored policies, processes and training to protect PHI and preserve HIPAA compliance throughout their organization  as well as the business associate agreements and other processes to provide for HIPAA compliance with respect to protected health information created, used, accessed or disclosed to business associates or others not part of their direct workforce or operating outside the core boundaries of their facilities.

Covered entities and their business associates also must recognize and design their compliance efforts and documentation recognizing that HIPAA compliance is a living process, which require both constant diligence about changes in systems or other events that may require reevaluation or adjustments, whether from changes in software, systems or processes or external threats.

Because the cost of responding to and investigating breaches or other compliance concern can be quite burdensome, covered entities and their business associates also generally will want to pursue options to plan for and minimize potential expenses in the design and administration of their programs as well as to minimize and cover the potentially extraordinary costs of breach or other compliance investigation and results that commonly arise following a breach or other compliance event.  As a part of this planning, covered entities and their business associates also generally will want to add consideration of changes to federal tax rules on the deductibility of compliance penalty and other related compliance expenditures.

While the Internal Revenue Code traditionally has prohibited businesses and individuals from deducting penalties, fines and other expenditures arising from violations of federal or state laws under Section 162(f) of the Internal Revenue Code, Section 13306 of the Tax Cuts and Jobs Creation Act creates a new exception for amounts  (other than amounts paid or incurred any amount paid or incurred as reimbursement to the government or entity for the costs of any investigation or litigation) that a taxpayer establishes meet the following requirements:

  • Constitute restitution (including remediation of property) for damage or harm which was or may be caused by the violation of any law or the potential violation of any law, or
  • Are paid to come into compliance with any law which was violated or otherwise involved in the investigation or inquiry into a violation or potential violation of any law;
  • Are identified as restitution or as an amount paid to come into compliance with such law, as the case may be, in the court order or settlement agreement, and
  • In the case of any amount of restitution for failure to pay any tax imposed under this title in the same manner as if such amount were such tax, would have been allowed as a deduction under this chapter if it had been timely paid.

Because the true effect of these modifications will be impacted by implementing regulations and a number of other special conditions and rules may impact the deductibility of these payments and the reporting obligations attached to their payment, covered entities will want to consult with legal counsel about these rules and monitor their implementation to understand their potential implications on compliance expenditures and penalties.

About The Author

Repeatedly recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, a Fellow in the American College of Employee Benefit Council, the American Bar Foundation and the Texas Bar Foundation and board certified in labor and employment law by the Texas Board of Legal Specialization, Cynthia Marcotte Stamer is a practicing attorney, management consultant, author, public policy advocate and lecturer widely known for health and managed care, employee benefits, insurance and financial services, data and technology and other management work, public policy leadership and advocacy, coaching, teachings, and publications. Nationally recognized for her work, experience, leadership and publications on HIPAA and other medical privacy and data use and security, FACTA, GLB, trade secrets and other privacy and data security concerns, Ms. Stamer has worked extensively with clients and the government on cybersecurity, technology and processes and other issues involved in the use and management of medical, insurance and other financial, workforce, trade secrets and other sensitive data and information throughout her career.  Scribe or co-scribe of the ABA Joint Committee on Employee Benefits Agency meeting with OCR since 2011 and author of a multitude of highly regarded publications on HIPAA and other health care, insurance, financial and other privacy and data security, Ms. Stamer is widely known for her extensive and leading edge experience, advising, representing, training and coaching health care providers, health plans, healthcare clearinghouses, business associates, their information technology and other solutions providers and vendors, and others on HIPAA and other privacy, data security and cybersecurity design, documentation, administration, audit and oversight, business associate and other data and technology contracting, breach investigation and response, and other related concerns including extensive involvement representing clients in dealings with OCR and other Health & Human Services, Federal Trade Commission, Department of Labor, Department of Treasury, state health, insurance and attorneys’ general, Congress and state legislators and other federal officials.

Ms. Stamer also has an extensive contributes her leadership and insights with other professionals, industry leaders and lawmakers.    Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.  You can get more information about her HIPAA and other experience here. For additional information about Ms. Stamer, see here, e-mail her here or telephone Ms. Stamer at (214) 452-8297.

About Solutions Law Press, Inc.™

Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here including:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.

NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.

Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.

©2018 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.


Bankrupt Oncology Provider’s $2.3M Settlement Payment & Other HIPAA Breach Consequences Shows Why To Prioritize HIPAA Compliance In 2018

December 29, 2017

The just-announced agreement $2.3 million (Resolution Amount) settlement by now bankrupt radiation oncology and cancer care provider 21st Century Oncology, Inc. (21CO)  is paying to settle Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules violation charges and other continuing post-breach fallout that helped push 21CO to file for Chapter 11 bankruptcy protection demonstrates again why HIPAA-covered health care providers, health plans, health care clearinghouses and their business associates (covered entities) must make HIPAA compliance and risk management a high priority in 2018.

Distinctive as the first HIPAA resolution agreement requiring bankruptcy court approval  and for the bankruptcy court’s order including a direction to the covered entity’s cyber liability insurer to pay the Resolution Payment and other investigation defense expenses, the 21CO resolution agreement resolves potential civil monetary penalty exposures the Fort Myers, Florida based provider of cancer care services and radiation oncology could have faced from the Department of Health & Human Services Office of Civil Rights (OCR) charges it violated HIPAA’s Privacy and Security Rules arising from the hacking and misappropriation of records containing sensitive electronic protected health information (ePHI) of up to 2,213597 individuals.

When their own 2018 HIPAA or other compliance investigation activities or planning HIPAA compliance and risk management activities, covered entities and their business associates and their leaders should use 21CO’s painful post-breach lessons experience to minimize their own HIPAA breach exposures, as well as consider how amendments to Internal Revenue Code Section 162(f) might impact the tax deductibility of certain compliance expenditures.

 21CO HIPAA Breaches & Fallout

The OCR charges against 21CO arose from an OCR investigation commenced after the Federal Bureau of Investigation (FBI) notified 21CO on November 13, 2015 and a second time on December 13, 2015 than unauthorized third-party illegally obtained 21CO sensitive patient information and produced 21CO patient files purchased by a FBI informant.  As part of its internal investigation, 21CO hired a third party forensic auditing firm in November 2015. 21CO determined that the attacker may have accessed 21CO’s network SQL database as early as October 3, 2015, through Remote Desktop Protocol from an Exchange Server within 21CO’s network. 21CO determined that it is possible that 2,213,597 individuals may have been affected by the impermissible access to their names, social security numbers, physicians’ names, diagnoses, treatment and insurance information.

Although it knew of the breaches in November and December, 2015, 21CO delayed notifying patients of the data breach for more than three months after the FBI notified it of the breaches before it sent HIPAA or other breach notifications about the data breach to patients or notified investors in March, 2016. Its March 4, 2016 Securities and Exchange Commission 8-K on Data Security Incident (Breach 8-K) states 21CO delayed notification at the request of the FBI to avoid interfering in the criminal investigation of the breach.

When announcing the breach, 21CO provided all individuals affected by the breach with a free one-year subscription to the Experian ProtectMyID fraud protection service. At that time, 21CO said it had no evidence that any patient information actually had been misused.  However victims of the breach subsequently are claiming being victimized by a variety of scams since the breach in news reports and lawsuits about the breach.

At the time of the breach and its March 4, 2016 announcement of the breach, 21CO already was working to resolve other compliance issues.  On December 16, 2015, 21CO announced that a 21CO  subsidiary had agreed to pay $19.75 million to the United States and $528,000 in attorneys’ fees and costs and comply with a corporate integrity agreement related to a qui tam action in which it was accused of making false claims to Medicare and other federal health programs. See 21CO 8-K Re: Entry into a Material Definitive Agreement (December 22, 2015).  Among other things, the corporate integrity agreement required by that settlement required 21CO to appoint a compliance officer and take other steps to maintain compliance with federal health care laws.  In addition, five days after releasing the March 4, 2017 Breach 8-K, 21CO notified investors that its subsidiary, 21st Century Oncology, Inc. (“21C”), had agreed to pay $37.4 million to settle health care fraud law charges relating to billing and other protocols of certain staff in the utilization of state-of-the-art radiation dose calculation system used by radiation oncologists called GAMMA.  See 21CO 8-K Re: GAMMA Settlement March 9, 2016 ;  See also United States Settles False Claims Act Allegations Against 21st Century Oncology for $34.7 Million.

As the breeches impacted more than 500 individuals, 21CO’s HIPAA breaches were considered large breaches for purposes of the Breach Notification Rules.  It is the policy of OCR to investigate all large breach notifications filed under the HIPAA Breach Notification Rules.

Based on OCR’s subsequent investigation into these breaches, OCR found:

  • 21CO impermissibly disclosed certain PHI of 2,213,597 of its patients in violation of 45 C.F.R. § 164.502(a);
  • 21CO failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information (ePHI) held by 21CO in violation of 45 C.F.R. § 164.308(a)(1)(ii)(A);
  • 21CO failed to implement certain security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with 45 C.F.R. § 164.306(A) in violation of 45 C.F.R. § 164.308(a)(1)(ii)(B);
  •  21CO failed to implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports as required by 45 C.F.R. §164.308(a)(1)(ii)(D);
  • 21CO disclosed protected health information to a third-party vendors, acting as its business associates, without obtaining satisfactory assurances in the form of a written business associate agreement in violation of HIPAA’s business associate rule requirements under 45 C.F.R. §§ 164.502(e) and 164.308(b)(3).

The Resolution Agreement settles potential charges and exposures to potentially much higher civil monetary penalties that 21CO could have faced had OCR successfully prosecuted charges against 21CO for the breaches.   In return for OCR’s agreement not to further pursue charges or penalties relating to the breach investigation, the Resolution Agreement requires that 21CO pay OCR a $2.3 million Resolution Amount and implement to OCR’s satisfaction a corrective action plan that among other things requires that 21CO complete  the following corrective actions to the satisfaction of OCR:

  • To complete a risk analysis and risk management plan;
  • To revise its HIPAA policies and procedures regarding information system activity review to require the regular review of audit logs, access reports, and security incident tracking reports pursuant to 45 C.F.R. § 164.308(a)(1)(ii)(D);
  • To revise its policies and procedures regarding access establishment and modification and termination pursuant to 45 C.F.R. § 164.308(a)(4)(ii)(C) and 45 C.F.R. § 164.308(a)(3)(ii)(C) to include protocols for access to 21CO’s e-PHI by affiliated physicians, their practices, and their employees.
  • To distribute its policies to and educate its workforce on the updated and other HIPAA policies and procedures;
  • To provide OCR with an accounting of 21CO’s business associates that includes names of business associates, a description of services provided, a description of the business associate’s handling of 21CO’s PHI, the date services began and copies of the actual business associate agreement with each business associate; and
  • Submit an internal monitoring plan to OCR.

In addition to  the OCR investigation that lead to the new HIPAA resolution agreement announced by OCR on December 28, 2017, 21CO experienced other fallout following its March 4, 2016 public disclosure of the breach.  Not surprisingly, the breach notification led to a multitude of class-action civil lawsuits by breach victims and shareholders.  See, e.g., 16 Data Breach Class Action Lawsuits Filed Against 21st Century Oncology Consolidated; 21st Century Oncology data breach prompts multiple lawsuits.  Reports of spoofing and other misleading contacts made to 21CO patients following the breach prompted the Federal Trade Commission (FTC) to issue a specific notice alerting victims about potential false breach notifications and other misleading contacts.  See April 4, 2016 FTC Announcement Re: 21st Century Oncology breach exposes patients’ info.

These and other developments also had significant consequences on 21CO’s financial status and leadership.  By March 31, 2015, 21CO notified the SEC and investors that it needed added time to complete its financial statements.  Subsequent SEC filings document its restatement of financial statements, the departure of board members and other leaders,  default on credit terms, and ultimately its filing for Chapter 11 bankruptcy protection in the United States Bankruptcy Court for the Southern District of New York on May 25, 2017.

Insurer Funding $2.3 Million Settlement Payment For Bankrupt 21CO

The 21CO resolution agreement required bankruptcy court approval,  Funds for payment of the required $2.3 million resolution payment and other charges associated with the investigation apparently are being provided in part from breach liability insurance coverage provided under a policy issued by Beazley Insurance, as the Bankruptcy Court order directs Beazley Breach Response Policy No. W140E2150301 to make immediate payment to the OCR of the resolution amount and the payment of fees incurred by 21CO in connection with regulatory defense issues.

Settlements Highlight Growing Risks Of Noncompliance, Lack Data Security

One of a growing multitude of multimillion dollar HIPAA resolution agreements to avoid HIPAA civil monetary sanctions that OCR already has announced, the 21CO resolution agreement announcement also comes when a steady stream of reports of massive data breaches at Alteryx, eBay, Paypal owner TIO Networks, Uber, Equifax and a long list of other previously trusted prominent businesses are stoking government and public awareness and concern over health care and other data privacy and cybersecurity.  Beyond their potential HIPAA enforcement exposures, health care or other covered entities experiencing breaches often also face FTC or other government investigations and enforcement under the Fair and Accurate Credit Transactions Act (FACTA) and other federal or state identity theft, data privacy and security, electronic crimes and other rules as well as business losses and disruptions; civil litigation from breach victims, shareholders and investors, and business partners as well as OCR, FTC, and state data security regulation enforcement.  Amid this growing concern, OCR has indicated that it intends to continue to diligently both seek to support and encourage voluntary compliance by covered entities and their business associates and  investigate and enforce HIPAA against HIPAA covered entities and their business associates that fail to adequately safeguard PHI and ePHI in accordance with HIPAA. In the face of these growing risks and liabilities, covered entities and their business leaders face a strong imperative to clean up and maintain their HIPAA compliance and other data security to minimize their exposure to similar consequences.

In light of these rises, leaders, investors, insurers, lenders and others involved with covered entities and their business associates should take steps to verify that the covered entities and their business associates not only maintain compliance with HIPAA, but also maintain appropriate practices, insurance and other safeguards to prevent, respond to and mitigate exposures in the event of a breach of protected health information or other sensitive data.

As a part of this planning, covered entities and their business associates also generally will want to add consideration of changes to federal tax rules on the deductibility of compliance penalty and other related compliance expenditures.  While the Internal Revenue Code traditionally has prohibited businesses and individuals from deducting penalties, fines and other expenditures arising from violations of federal or state laws under Section 162(f) of the Internal Revenue Code, Section 13306 of the Tax Cuts and Jobs Creation Act creates a new exception for amounts  (other than amounts paid or incurred any amount paid or incurred as reimbursement to the government or entity for the costs of any investigation or litigation) that a taxpayer establishes meet the following requirements:

  • Constitute restitution (including remediation of property) for damage or harm which was or may be caused by the violation of any law or the potential violation of any law, or
  • Are paid to come into compliance with any law which was violated or otherwise involved in the investigation or inquiry into a violation or potential violation of any law;
  • Are identified as restitution or as an amount paid to come into compliance with such law, as the case may be, in the court order or settlement agreement, and
  • In the case of any amount of restitution for failure to pay any tax imposed under this title in the same manner as if such amount were such tax, would have been allowed as a deduction under this chapter if it had been timely paid.

Because the true effect of these modifications will be impacted by implementing regulations and a number of other special conditions and rules may impact the deductibility of these payments and the reporting obligations attached to their payment, covered entities will want to consult with legal counsel about these rules and monitor their implementation to understand their potential implications on compliance expenditures and penalties.

About The Author

Repeatedly recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, a Fellow in the American College of Employee Benefit Council, the American Bar Foundation and the Texas Bar Foundation and board certified in labor and employment law by the Texas Board of Legal Specialization, Cynthia Marcotte Stamer is a practicing attorney, management consultant, author, public policy advocate and lecturer widely known for health and managed care, employee benefits, insurance and financial services, data and technology and other management work, public policy leadership and advocacy, coaching, teachings, and publications. Nationally recognized for her work, experience, leadership and publications on HIPAA and other medical privacy and data use and security, FACTA, GLB, trade secrets and other privacy and data security concerns, Ms. Stamer has worked extensively with clients and the government on cybersecurity, technology and processes and other issues involved in the use and management of medical, insurance and other financial, workforce, trade secrets and other sensitive data and information throughout her career.  Scribe or co-scribe of the ABA Joint Committee on Employee Benefits Agency meeting with OCR since 2011 and author of a multitude of highly regarded publications on HIPAA and other health care, insurance, financial and other privacy and data security, Ms. Stamer is widely known for her extensive and leading edge experience, advising, representing, training and coaching health care providers, health plans, healthcare clearinghouses, business associates, their information technology and other solutions providers and vendors, and others on HIPAA and other privacy, data security and cybersecurity design, documentation, administration, audit and oversight, business associate and other data and technology contracting, breach investigation and response, and other related concerns including extensive involvement representing clients in dealings with OCR and other Health & Human Services, Federal Trade Commission, Department of Labor, Department of Treasury, state health, insurance and attorneys’ general, Congress and state legislators and other federal officials.

Ms. Stamer also has an extensive contributes her leadership and insights with other professionals, industry leaders and lawmakers.    Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.  You can get more information about her HIPAA and other experience here. For additional information about Ms. Stamer, see here, e-mail her here or telephone Ms. Stamer at (214) 452-8297.

About Solutions Law Press, Inc.™

Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here including:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.

NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.

Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.

©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.


Health Care Org’s ERISA Health Plan Reimbursement Opportunities & Compliance Obligations Free 9/15 Study Group Topic

September 9, 2015

Solutions Law Press, Inc. is happy to share information about this upcoming free health industry study group meeting on 9/15/2015 in Irving, Texas.

NORTH TEXAS HEALTHCARE COMPLIANCE PROFESSIONALS ASSOCIATION

Invites Members and Guests to Our Next Group Luncheon

Employee Benefit Security Administration Insights On Healthcare Organization’s Health & Other Employee Benefit Plan Rights & Responsibilities Under Employee Retirement Income Security Act

Featuring

Kristi Gotcher

U.S. Department of Labor Employee Benefit Security Administration Investigator

Tuesday, September 15, 2015

11:30 a.m. to 1:30 p.m.

DFW Hospital Council Offices

250 Decker Drive

Irving, Texas

RSVP here  by Noon on September 14, 2015

Space Limited!  Register Early To Reserve Your Spot To Participate!

 

Please share this invitation with others who might be interested in this topic or other NTHCPA events!

The North Texas Healthcare Compliance Professionals Association (NTHCPA) invites members and other interested health care compliance professionals to join us on Tuesday, September 15, 2015 from 11:30 a.m. to 1:30 p.m. for our Study Group Luncheon featuring a program on “Employee Benefit Security Administration Insights On Healthcare Organization’s Health & Other Employee Benefit Plan Rights & Responsibilities Under Employee Retirement Income Security Act” from U.S. Department of Labor Employee Benefit Security Administration (EBSA) Investigator Kristi Gotcher.

The health and other employee benefit plan rules of the Employee Retirement Income Security Act (ERISA) generally offer important protections and create significant compliance challenges for health care organizations and providers.  On one hand, health care providers generally rely heavily on their or their patient’s ability to obtain health benefits promised under employer or union-sponsored health plans covering their patients to help reimbursement provider charges.  Meanwhile, health care providers and their leaders also can incur significant liability for failing to comply with ERISA’s rules when establishing and maintaining health or other employee benefit programs for their own employees.  Drawing on her involvement as investigator with the Department of Labor agency primarily responsible for both interpreting and enforcing ERISA’s rules, EBSA Ms. Gotcher will share key updates and insights on both how ERISA and the EBSA can help patients and providers enforce benefit rights under ERISA-covered health plans and key health and highlight employee benefit compliance responsibilities that health care organizations and their leaders need to ensure that their own health and other employee benefit programs meet to avoid violating ERISA.

About the Speaker

Kristi A. Gotcher is an Investigator with the United States Department of Labor, Employee Benefits Security Administration (EBSA) in the Dallas Regional Office.   Kristi began working for EBSA in the Dallas Regional Office in November 2007 as a Benefits Advisor.  She earned her Bachelor of Arts in Social Political Relations from St. Edwards University and a J.D. from Texas Wesleyan University School of Law (now Texas A&M University School of Law).  Ms. Gotcher is licensed to practice law in the State of Texas.

Registration & Meeting Details

The meeting scheduled from 11:30 a.m. to 1:30 p.m. on Tuesday, September 15, 2015 at the DFW Hospital Council Offices located at 250 Decker Drive, Irving Texas.  Participants who timely R.S.V.P. will enjoy a complimentary luncheon. Networking and lunch service will begin at 11:30. Our program will begin at Noon.

NTHCPA encourages members and other interested health care compliance professionals to register early to reserve their spot to participate and to share this invitation with others in the industry who might benefit from participation.

There is no charge to participate in the meeting.  However space is limited and available only on a first come, first serve basis.  To ensure your spot and help us to arrange for adequate space and refreshments for this meeting, R.S.V.P. here as soon as possible and no later than Noon on September 14, 2015.  Walk in guests will be accommodated on a space-available basis only.

Thanks To Meeting Underwriter Stamer ׀ Chadwick ׀ Soefje, PLLC

NTHCPA and its members extend our thanks to Cynthia Marcotte Stamer, P.C. and the other members of Stamer ׀ Chadwick ׀ Soefje PLLC for underwriting this month’s study group luncheon and other support of NTHCPA.

A boutique firm of exceptionally experienced and skilled “big-firm” lawyers committed to changing the way law firms serve their clients, Stamer │Chadwick │Soefje, PLLC delivers sophisticated legal advice and innovative solutions to the most challenging and complex problems. Simply put, Stamer │Chadwick │Soefje, PLLC attorneys are “Solutions Lawyers™.”

Stamer │Chadwick │Soefje, PLLC attorneys deliver sophisticated legal advice and innovative solutions to the most challenging and complex problems. Stamer │Chadwick │Soefje, PLLC attorneys possess the breadth of experience to respond to the unique legal and operational challenges health industry and other clients face and help guide them toward pragmatic resolutions that make sense for them. “Solutions Lawyers™ possess the breadth of experience to respond to the unique challenges our corporate and individual clients face and help guide them toward pragmatic resolutions that make sense for them.

Founded by nationally-known, healthcare and labor & employment attorney Cynthia Marcotte Stamer; labor & employment attorney Robert G. Chadwick; and professional liability and civil litigation attorney Timothy B. Soefje, Stamer │Chadwick │Soefje, PLLC focuses on advising and representing businesses and professionals nationally in the areas of healthcare, cyber liability, ERISA, employee benefits, labor & employment, corporate and commercial litigation, professional liability, construction litigation, and insurance defense.  All three attorneys are rated AV® Preeminent™ by Martindale-Hubbell® Peer Review Ratings™ Ms. Stamer and Mr. Chadwick are both Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, are Fellows in the American Bar Foundation, and recognized as “Top Lawyers” in Labor and Employment Law.  Ms. Stamer also has received recognition as a “Top” attorney in health care and employee benefits law and is a Fellow in the American College of Employee Benefit Council.

Ms. Stamer more than 28 years’ experience advising and representing health industry and employee benefit clients on a wide range of legal, public policy, management and operational concerns as well as extensive leadership and management experience serving in on the board of health industry nonprofit organizations. Nationally recognized for her legal work, advocacy, publications, writings and presentations on health industry concerns, Ms. Stamer provides legal and management advice, training and coaching, defense, public policy and regulatory advocacy to health industry and other clients on health and other regulatory and operational compliance, federal and state public policy and enforcement, managed care and other contracting, reimbursement, fraud, quality, employment, staffing and other workforce, benefits, licensing, credentialing and peer review, safety, disaster preparedness and response, HIPAA and other privacy and data security, corporate governance, investigations and internal controls, and a host of other health industry compliance and risk management and other legal and operational concerns. In addition to her legal experience, Ms. Stamer also contributes her experience and talents to serving in a number of health industry and other civil and professional groups.  Among other things, Ms. Stamer serves as Vice President of the NTHCPA, the RPTE representative to the American Bar Association (ABA) Joint Committee on Employee Benefits Council and scrivener for its annual agency meeting with the Office of Civil Rights, the ABA International Section Life Sciences and Health Law Committee Vice President of Policy, RPTE Liaison to the ABA Health Care Coordinating Counsel, TIPS Employee Benefit Committee Vice Chair, Founder and Executive Director of the Project COPE:  The Coalition on Patient Empowerment, and National Physicians Council for Healthcare Policy.  She also previously served as President and Founding Board Member of the Alliance for Health Care Excellence and its Health Care Heroes and Patient Empowerment Programs, as RPTE Employee Benefits & Other Compensation Group Chair and Welfare Benefit Committee Vice Chair, Exempt Organizations Coordinator of the Gulf States Area TEGE Council, Board President and Audit Committee Chair of the Richardson Development Center for Children ECI Agency, National Kidney Foundation of North Texas Board Audit Committee Chair, the United Way of North Texas Long Range Planning Committee.  She also has and continues to serve in the leadership of many other civic and professional boards, seminar faculties, editorial advisory boards and publishes and speaks extensively on health industry and employee benefit related concerns.

Mr. Chadwick has extensive experience advising and defending health industry and other clients on OSHA and other occupational health and safety, employee benefits, compensation and other labor and employment  concerns as well as defending boards and other management leaders against management liability claims.

Mr. Soefje has extensive experience advising and representing health industry clients and professionals on medical malpractice, officers and directors liability and other professional liability, errors and omissions, construction defect and other litigation and disputes.

For additional information, contact Ms. Stamer cstamer@solutionslawyer.net

About the NTHCPA

NTHCPA exists to champion ethical practice and compliance standards and to provide the necessary resources for ethics and compliance Professionals and others in North Texas who share these principles.  The vision of NTHCPA is to be a pre-eminent compliance and ethics group promoting lasting success and integrity of organizations within North Texas.

About Solutions Law Press

Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns.

Other Helpful Resources & Other Information

We hope that this information is useful to you.   If you found these updates of interest, you also be interested in one or more of the following other recent articles published on the Coalition for Responsible Health Care Reform electronic publication available here, our electronic Solutions Law Press Health Care Update publication available here, or our HR & Benefits Update electronic publication available hereYou also can get access to information about how you can arrange for training on “Building Your Family’s Health Care Toolkit,”  using the “PlayForLife” resources to organize low-cost wellness programs in your workplace, school, church or other communities, and other process improvement, compliance and other training and other resources for health care providers, employers, health plans, community leaders and others here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail by creating or updating your profile here. You can reach other recent updates and other informative publications and resources.

Examples of some of these recent health care related publications include:


Check Defensibility Of Policies & Practices Given New HHS/DOJ Joint Disability Law Technical Assistance

August 10, 2015

Child welfare agencies, health care providers and their contactors and other service providers should evaluate the adequacy and defensibility of their existing practices for accommodating and providing other services to individuals with disabilities and their families in light of the new joint technical assistance to state and local child welfare agencies and courts on the requirements of Title II of the Americans with Disabilities Act (ADA) and Section 504 of the Rehabilitation Act jointly announced by the Departments of Health & Human Services (HHS) and the Justice (DOJ) under a new HHS/DOJ partnership intended to help child welfare agencies protect the welfare of children and ensure compliance with nondiscrimination laws announced here August 10, 2015.

Federal child welfare and discrimination laws generally prohibit discrimination on the basis of disability, and require providers of government programs, services, and activities to make reasonable modifications to their policies and practices when necessary to avoid discrimination on the basis of disability, unless such modifications would fundamentally alter the nature of the program or the services.  The new joint technical assistance addresses disability discrimination complaints that HHS and DOJ say the agencies have received from parents who have had their children taken away or otherwise have not been given equal opportunities to become foster or adoptive parents.

The technical assistance provides an overview of Title II of the ADA and Section 504 and examples about how to apply them in the child welfare system, including child welfare investigations, assessments, guardianship, removal of children from their homes, case planning, adoption, foster care, and family court hearings, such as termination of parental rights proceedings.  It also underscores that Title II and Section 504 prohibit child welfare agencies from acting based on unfounded assumptions, generalizations, or stereotypes regarding persons with disabilities.

HHS and DOJ hope “[p]roviding this technical assistance to state and local agencies and courts will help ensure that families who have a member with a disability get equal access to vital child welfare services,” said Mark Greenberg, HHS’ Administration for Children and Families’ Acting Assistant Secretary.

The new child welfare technical assistance is part of a broader ongoing emphasis on investigation and enforcement of disability and other discrimination laws by HHS, DOJ and other agencies under the Obama Administration. Under the Obama Administration, HHS, DOJ and other agencies already have heavily sanctioned many child welfare, health care and other agencies and providers for alleged violation of these and other federal disability discrimination laws.  See, e.g., Health Care Employer’s Discrimination Triggers Medicare, EEOC Prosecutions; Hospital Will Pay $75K For Refusing To Hire Disabled Worker;  OCR Settlements Show Health Care & Disabled Housing Providers Face Growing Disability Discrimination RisksGenesis Healthcare Disability HHS OCR Discrimination Settlement Reminder To Use Interpreters, Other Needed Accommodations For Disabled.   In the face of this emphasis, child welfare, health care and other agencies and their legal counsel and other service providers should expect greater deference and enforcement to the needs of children and parents with disabilities in child custody, adoption, divorce and other proceedings, as well as continued investigation and enforcement of disability and other discrimination laws against child welfare, health care, and other social service agencies, their legal counsel and other advocates and others providing services.  These and other organizations and service providers should  evaluate the defensibility of the existing policies, practices and recordkeeping practices of their own organization, as well as those of their contractors and subcontractors in light of these and other disability discrimination laws, regulations and enforcement practices.

For More Advice, Assistance Or More Information

If you need assistance reviewing or responding to these or other health care related risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer, may be able to help. Ms. Stamer is a highly regarded practicing attorney with extensive health industry legal and policy experience, also recognized as a knowledgeable and highly popular health industry thought and policy leader, who writes and publishes extensively  on health industry concerns. Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, recognized as a “Top” lawyer in Health Care, Labor and Employment and Employee Benefits Law, Board Certified in Labor & Employment Law, and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 27 years experience advising health industry clients about these and other matters. Her experience includes advising and defending hospitals, nursing home, home health, physicians and other health care professionals, rehabilitation and other health care providers and health industry clients to establish and administer compliance and risk management policies and programs in response under CMS, OCR, HHS, FDA, IRS, DOJ, DEA, NIH, licensing, and other regulations; prevent, conduct and investigate, and respond to Board of Medicine, OIG, DOJ, DEA, DOD, DOL, Department of Health, Department of Aging & Disability, IRS, Department of Insurance, and other federal and state regulators; ERISA and private insurance, prompt pay and other reimbursement and contracting; peer review and other quality concerns; and other health care industry investigation, and enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. This experience includes extensive work advising and defending physicians, practices, hospitals and other health care organizations and others about Medicare and other health care billing and reimbursement practices,  as well as advising and defending providers against Medicare, Medicaid, Tricare and other audits, prepayment suspensions, provider exclusions and provider number revocation, and counseling and defending providers, medical staff and peer review committees, hospitals, medical practices and other health care organizations and others in relation to the conduct of audits and investigations, peer review investigations and discipline, employment, licensing board and other associated events.

The scribe for the American Bar Association (ABA) Joint Committee on Employee Benefits annual agency meeting with the Department of Health & Human Services Office of Civil Rights,  past Board President of the Richardson Development for Children and former Board Audit Committee Chair of the National Kidney Foundation of North Texas, Ms. Stamer has lead, advised, represented and conducted training and investigations of disability and other legal and operations risk management and compliance for early childhood intervention (ECI) and other childcare, health care, public and private schools, social service and other public and private organizations.  Ms. Stamer also  has worked extensively with health care providers, health plans, health care clearinghouses, their business associates, employers, banks and other financial institutions, and others on risk management and compliance with HIPAA and other information privacy and data security rules, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns.  Her clients include public and private health care providers, health insurers, health plans, technology and other vendors, and others.  In addition to representing and advising these organizations, she also has conducted training on Privacy & The Pandemic for the Association of State & Territorial Health Plans,  as well as  HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for  Los Angeles County Health Department, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others. Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her insights on these and other related matters appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications.  You can get more information about her health industry experience here. If you need assistance responding to concerns about the matters discussed in this publication or other health care concerns, wish to obtain information about arranging for training or presentations by Ms. Stamer, wish to suggest a topic for a future program or update, or wish to request other information or materials, please contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.

About Solutions Law Press

Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you or someone else you know would like to receive future updates about developments on these and other concerns from Ms. Stamer such as the following, see here:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here. For important information about this communication click here.THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN. ©2015 Cynthia Marcotte Stamer.  Non-exclusive right to republish granted to Solutions Law Press, Inc.  All other rights reserved.


7 Arrested, Charged In Detroit-Area Home Health Care Fraud Takedown

January 18, 2013

January 17, 2013; U.S. Department of Justice

Seven Arrested, Charged with $22 Million Detroit-area Home Health Care Fraud Scheme

Six Detroit-area residents and one Chicago-area resident were arrested on January 17, 2012 by federal agents on charges arising from the ongoing investigation into an alleged $22 million home health care fraud scheme that the indictment charges operated out of four Oakland County, Michigan home health agencies claiming to provide in-home health service, Royal Home Health Care Inc., Prestige Home Health Services Inc., Platinum Home Health Services Inc. and Empirical Home Health Care Inc. (the “Agencies”).  The defendants arrested are Detroit-area residents Muhammad Aamir, Usman Butt, Hemal Bhagat, Syed Shah, Tariq Tahir, and Raquel Ellington, and Chicago-area resident Tayyab Aziz (the “Defendants”).

According to the Justice Department, the arrests and Medicare payment suspensions stem from charges brought in an 18-count indictment returned January 15, 2013, which alleges that the Defendants participated in a Medicare fraud scheme operating out of the Agencies. The indictment alleges Medicare paid the agencies approximately $22 million for fraudulently reported services since August 2008. See Aamir, Muhammed et al. (Prestige) Indictment.  In addition to the arrests, law enforcement agents suspended Medicare payments to the Agencies associated with the alleged scheme.

According to the indictment, Aamir and Butt owned and operated Prestige; Butt, Bhagat and Shah owned and operated Royal; and Aamir owned and operated Platinum and Empirical.  The indictment alleges that of the Agencies allegedly claimed to provide home health therapy services to Medicare beneficiaries that were unnecessary and/or were never performed.  The indictment also alleges that Tahir and Ellington recruited Medicare beneficiaries, paying them kickbacks for their Medicare information and signatures on documents that detailed physical therapy and/or skilled nursing services that were either never rendered or not medically necessary.  The indictment also charges Aamir, Butt, Bhagat, Shah, Tahir and Ellington with conspiring to pay kickbacks to Tahir and Ellington for their recruiting work and Butt, Bhagat, Shah and Aziz with allegedly conspiring to launder the proceeds of the scheme.

Based on the alleged conduct, the indictment charges each of the Defendants with conspiracy to commit health care fraud.  All but Aziz are also charged with health care fraud and with conspiracy to violate the Anti-Kickback Statute.  Butt, Bhagat, Shah and Aziz are additionally charged with conspiracy to commit money laundering.

A conviction on the charges is likely to carry heavy penalities.  The charges of health care fraud conspiracy and health care fraud each carry a maximum potential penalty of 10 years in prison and a $250,000 fine.  The charge of conspiracy to violate the Anti-Kickback Statute carries a maximum potential penalty of five years in prison and a $25,000 fine.  The charge of conspiracy to commit money laundering carries a maximum potential penalty of 20 years in prison and a $500,000 fine.
 
The arrests and indictments reflect the continuing and growing government commitment to, coordination and sophistication in the investigation and prosecution of health care crimes by health care providers in the federal war on what officials view as health care fraud.  The Obama Administration has made investigation and prosecution of health care fraud laws a key element of its strategy to manage U.S. health care program costs. Recently enacted changes in the False Claims Act and other laws are making it easier for federal prosecutors to successfully prosecute these and other health care fraud cases.

Since their inception in March 2007, the the HEAT health care fraud task force operations in nine locations have lead to charges against more than 1,480 defendants who Federal officals claim collectively have falsely billed the Medicare program for more than $4.8 billion.  In addition, the HHS Centers for Medicare and Medicaid Services, working in conjunction with the HHS-OIG, are taking steps to exclude and impose other remedies against health care providers that it perceives engage in fraud or other aggressive billing or other practices.These and other stepped up oversight and enforcement activities make it critical that all health industry organizations strengthen their internal controls, compliance and audit activities as well as be prepared to defend their actions against the rising tide of federal and state oversight and enforcement.

For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs

If you need help with HIPAA or other health industry, regulatory policy or enforcement developments, or to review or respond to these or other health care or health IT related risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.

Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 24 years experience advising health industry clients about these and other matters. Ms. Stamer has extensive experience advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical privacy and other compliance and risk management policies, to health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.

Scheduled to serve as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR, Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.  Her publications and insights appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications.   For instance, Ms. Stamer for the second year will serve as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR.  Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.  You can get more information about her HIPAA and other experience here.

If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.

You can review other recent publications and resources and additional information about the other experience of Ms. Stamer hereExamples of some recent publications that may be of interest include:

If you need help investigating or responding to a known or suspected compliance, litigation or enforcement or other risk management concern, assistance with reviewing, updating, administering or defending a current or proposed employment, employee benefit, compensation or other management practice, wish to inquire about federal or state regulatory compliance audits, risk management or training, or need legal representation on other matters please contact Ms Stamer here or at (469) 767-8872.

About Solutions Law Press, Inc.™

Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives.  Solutions Law Press, Inc.™ also conducts and assist businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs.  For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com   These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com.  CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN. If you are an individual with a disability who requires accommodation to participate, please let us know at the time of your registration so that we may consider your request.

 ©2013 Cynthia Marcotte Stamer, P.C. All rights reserved.


TSHHRAE Provides Health Industry Managers Employment Law Update & Other Timely Management Training At April Barnstorm 2010: Creating Effective Leaders Programs

March 23, 2010

Get Details & Registration Information here!

A Legal Update on Employment Law presentation by Attorney Cynthia Marcotte Stamer is among 5 hours of “Barnstorm 2010: Creating an Effective Leaders-Tools of the Trade” management training that the Texas Society for Healthcare Human Resources Administration and Education (TSHHRAE) will be hosting for health industry human resources and other managers in five Texas cities between April 26 and April 30, 2010. 

Interested health industry human resources and other managers can elect to participate in TSHHRAE’s Barnstorm 2010 management training at the following dates and locations:  

  • April 26 – Weslaco, Knapp Medical Center
  • April 28 – Sweetwater, Rolling Plains Memorial Hospital
  • April 28 – Brenham, Trinity Medical Center
  • April 29 – Lubbock, University Medical Center
  • April 30 – Odessa, Medical Center Hospital

Update on Employment Law Program Highlights

Ms. Stamer’s Legal Update on Employment Law Program will address:

  • Recent changes in FMLA, Military Leave, wage and hour, ADA & other disability, COBRA, GINA, HIPAA and other selected federal & Texas employment laws and regulations;
  • Rising government enforcement of EEOC, HIPAA, wage & hour, worker classification, and other laws and regulations;
  • Recent developments and increases in retaliation claims;
  • Recent cases related to supervision; and
  • Other selected developments impacting health industry human resources management.

Other Barnstorm 2010 Program Highlights and Details

In addition to the Legal Update on Employment Law that Ms. Stamer is scheduled to present, the Barnstorm Program also will feature presentations on:

  • Leadership in 2010
  • Dealing with Poor Performers; and
  • Cultivating a Superstar

For registration and other information about the Barnstorm Program, see here.

About Ms. Stamer

Nationally and internationally recognized for more than 22 years of work with health industry and other organizations, publications, workshops and presentations and leadership on health industry and other labor and employment, staffing and credentialing, employee benefits, performance management and discipline, regulatory compliance and internal controls, risk management, and public policy matters, Ms. Stamer is Chair of the Curran Tomko Tarski Labor & Employment & Health Care Practice Groups, Vice President of the North Texas Health Care Compliance Professionals Association, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is.  The publisher of Solutions Law Press HR & Benefits Update, the Solutions Law Press Health Care Update, and Solutions Law Press Health Care Privacy & Technology Update and a former legal columnist for MD News, Ms. Stamer also is a popular speaker and author of these topics.  She regularly speaks and conducts training for the ABA, American Health Lawyers Association (AHLA), Health Care Compliance Association, Institute of Internal Auditors, Harris County Medical Society, the Medical Group Management Association, SHRM, Southwest Benefits Association and many other organizations.  Publishers of her many highly regarded writings on health industry and human resources matters include the Bureau of National Affairs, Aspen Publishers, ABA, AHLA, Spencer Publications, World At Work, SHRM, Business Insurance, James Publishing and many others.  You can review other highlights of Ms. Stamer’s health care experience here, and employment experience hereHer insights on these and other matters appear in Managed Care Executive, Modern Health Care, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, MDNews, Kentucky Physician, and many other national and local publications.

If you need assistance with health industry human resources or other management, concerns, wish to inquire about compliance, risk management or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer at cstamer@cttlegal.com or 214.270.2402. 

Other Resources

If you found this information of interest, you also may be interested in reviewing other updates and publications by Ms. Stamer including:

For More Information

We hope that this information is useful to you.  If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here. To unsubscribe, e-mail here.

©2010 Cynthia Marcotte Stamer.  All rights reserved.


HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website

February 25, 2010

By Cynthia Marcotte Stamer

The Department of Health and Human Services Office of Civil Rights (OCR) has begun posting on its website the names and certain information about health care providers, health insurers,  employer and other health plans, health care clearinghouses and their business associates (Covered Entities) reporting to OCR “breaches” of “unsecured protected health information” (UPHI) under new breach notice rules added by the Health Information Technology for Economic and Clinical Health Act (HITECH Act).

Covered Entities should anticipate the posting of the breach information and other HITECH Act breach notices coupled with amendments to the medical privacy and security requirements of the Health Insurance Portability & Accountability Act (HIPAA) effective since February 17, 2010, will heighten enforcement risks and public sensitivities about medical information privacy safeguards.  As failing to comply with the amended rules effective February 17, 2010 can trigger obligations under the Breach Regulations and other significant liability exposures, Covered Entities should act quickly to manage these emerging risks.

Covered Entity Breach Notification Requirements

The initial list of Covered Entities reporting  breaches of UPHI affecting 500 or more individuals posted by OCR on February 22, 2010 discloses the Covered Entity’s name and State, the approximate number of individuals affected, the date and type of breach and the location of the breached information. OCR’s posting of this information is required under the HITECH Act breach notification requirements as part of its implementation and enforcement of new breach notification requirements added to HIPAA by Section 13402(e)(3) of the HITECH Act.

The HITECH Act amended HIPAA to require Covered Entities to require Covered Entities provide notification to individuals, OCR and others when certain breaches of UPHI happen.  The implementing interim “Breach Notification For Unsecured Protected Health Information” regulations (Breach Regulation) published by OCR here require Covered Entities subject to HIPAA to notify affected individuals, OCR and in some cases the media within specified periods following a “breach” of UPHI occurring on or after September 23, 2009 unless the Covered Entity can demonstrate that the breach qualified as exempt from the breach notification obligation under the Breach Regulations.

Covered Entities generally should consider the need to provide breach notification under the Breach Regulation whenever electronic or non-electronic protected health  information which is not adequately encrypted or destroyed to qualify as “secured” under the breach rules is used, accessed or disclosed in violation of HIPAA.  

Since the potential need to provide breach notification is triggered by an impermissible use, access or disclosure of UPHI, up-to-date maintenance, monitoring and enforcement is at the heart of compliance with the Breach Regulation as well as HIPAA generally.

You can review the currently posted list of Covered Entities that have reported breaches on the OCR website here.  Learn more about the Breach Regulation requirements here

Broader & Stricter Medical Privacy Mandates Effective 2/17/210

The new breach notification requirements are part of a series of changes made to HIPAA under the HITECH Act that are increasing the responsibilities and liability exposures of Covered Entities. On February 17, 2010, Covered Entities and their business associates also became subject to tighter federal requirements for the use, access, protection and disclosure of protected health information under amendments to HIPAA’s Privacy & Security Standards enacted in the HITECH Act. When the HITECH Act was signed into law on February 17, 2009, Covered Entities also became subject to expanded sanctions and remedies for HIPAA violations.

To comply with the HITECH Act changes to HIPAA effective on February 17, 2010, most Covered Entities and their business associates generally will need to update their written policies, operational procedures, technical safeguards, privacy notices, vendor and other agreements, training, and other management procedures in several respects. For more details, see here.

While the HITECH Act gave Covered Entities and business associates a year to complete the necessary arrangements to comply with these HITECH Act changes, many Covered Entities and business associates have not adequately implemented the necessary arrangements. To mitigate these exposures, Covered Entities and their business associates should act quickly to review and update their policies, procedures, training, business associate and other services agreements, and other practices and procedures, as well as to implement the training, oversight, and other management necessary to comply with the HITECH Act changes and to mitigate other HIPAA risks.

Exposures Significant & Growing

HIPAA-associated exposures for Covered Entities are significant and growing. Timely action to comply with the amended HIPAA requirements and Breach Regulations is important to avoid triggering the breach notification requirements; to prevent loss of public trust and reputation;  and to minimize exposures to legal actions, administrative complaints and sanctions and the  investigation, defense and correction costs likely to result when a Covered Entity violates or is accused of violating HIPAA or otherwise mishandling medical or other personal information. 

Even before the HITECH Act changes became effective, federal regulators were stepping up HIPAA enforcement. The HITECH Act amendments further increase the risk that Covered Entities violating HIPAA face investigation and sanction. The HITECH Act amendments increase the likelihood that Covered Entities violating HIPAA will get caught and will face some form of damage or penalty assessment.  Heightened awareness of UPHI breaches resulting from HITECH Act mandated breach notifications are likely to fuel new HIPAA-related complaints, charges and demands.  Covered Entities, workforce members who wrongfully access protected health information now face potential civil penalties,  criminal prosecution, civil lawsuits and other actions. Allowing state attorneys general to bring suit adds more manpower to the enforcement team.   Furthermore, the wrongful use, access or disclosure of protected health information or other confidential information also increasingly is the basis of civil or criminal actions brought under a variety of other federal and state laws.

New Risks Created By HITECH Act Amendments

Heightened HIPAA exposures stem in part from the HITECH Act’s amendments to HIPAA’s remedy provisions.  Among other things, the HITECH Act amended HIPAA to:

  • Allow a State Attorney General to sue Covered Entities that commit HIPAA violations after February 16, 2009 for damages caused to state citizens;
  • Expand the mandate by OCR to investigate violations and audit compliance with HIPAA;
  • Require OCR to impose civil sanctions against Covered Entities and business associates involved in violations of HIPAA in accordance with tightened standards added to HIPAA by the HITECH Act;
  • Revise the criminal sanctions that the Department of Justice can seek against Covered Entities and others for violations of HIPAA; and
  • Amend HIPAA to make clear that workforce members and others improperly using, accessing or disclosing protected health information in violation of HIPAA can face criminal prosecution.

State Attorney General Lawsuit Exposures

Covered Entities must be concerned about the potential that a state Attorney General may bring civil suit to remedy damages caused to state citizens by a breach of HIPAA.  In certain situations, the HITECH Act empowers a state attorney general to sue Covered Entities for damages if their HIPAA violations harm state citizens. Statutory damages equal to the sum of the number of violations multiplied by 100 up to a maximum of $25,000 per calendar year plus attorneys fees and costs are authorized.

A HIPAA civil lawsuit demonstrates the willingness of at least some states to exercise the new authority to sue Covered Entities. On January 13, 2010 Connecticut Attorney General Richard Blumenthal sued Health Net of Connecticut, Inc. (Health Net) for failing to secure private patient medical records and financial information involving 446,000 Connecticut enrollees and promptly notify consumers endangered by the security breach.   The first attorney general enforcement action brought based on amendments made to HIPAA under the HITECH Act, Connecticut charges that Health Net violated HIPAA by failing to safeguard protected medical records and financial information on almost a half million Health Net enrollees in Connecticut then allowing this information to remain exposed for at least six months before notifying authorities and consumers. The suit also names UnitedHealth Group Inc. and Oxford Health Plans LLC, who have acquired Health Net. 

Stepped Up Federal Enforcement

Even before the HITECH Act amendments, OCR and Department of Justice increased HIPAA investigation and enforcement.  The Department of Justice has obtained a variety of criminal convictions against violators of HIPAA.  See, e.g., 2 New HIPAA Criminal Actions Highlight Risks From Wrongful Use/Access of Health InformationMeanwhile, OCR also is emphasizing HIPAA enforcement.  In February, 2009, OCR announced that CVS Pharmacies, Inc. would pay $2.25 million to resolve HIPAA charges.  This announcement followed OCR’s announcement in July, 2008 that Providence Health Care would pay $100,000 to resolve HIPAA violation charges.  OCR also has taken HIPAA enforcement actions against a broad range of other Covered Entities. See more details hereWhile not resulting in the significant payments involved in CVS or Providence, all Covered Entities involved in these and other enforcement actions or investigations have incurred significant legal and other defense costs, loss of community trust, or both.

In addition to these HIPAA-specific exposures, wrongful use, access or disclosure of medical information also can expose Covered Entities, members of their workforce and others improperly using, accessing or disclosing protected health information to liability under other federal or state laws.  Federal and state prosecutors may and increasingly do bring criminal or civil actions against organizations or individuals for improperly accessing or using medical or other personal information under a variety of other federal or state laws .  See e.g., Cybercrime & Identity Theft: Health Information Security Beyond HIPAA; NY AG Cuomo Announcement of 1st Settlement For Violation of NY Security Breach Notification Law; Woman Who Revealed AIDs Info Gets A Year

State Civil Lawsuits

Covered Entities also need to prepare to defend HIPAA-related conduct in state civil actions.  Individual plaintiffs increasingly used alleged HIPAA violations in state privacy, negligence, retaliation, wrongful discharge or other lawsuits.  State courts have allowed private plaintiffs to use the obligations imposed by HIPAA as the basis of a Covered Entity’s duty for purposes of certain state law lawsuits.  In  Sorensen v. Barbuto, 143 P.3d 295 (Utah Ct. App. 2006), for example, a Utah appeals court ruled a private plaintiff could use HIPAA standards to establish that a physician owed a duty of confidentiality to his patients for purposes of maintaining a state law damages claim.  Similarly, the Court in Acosta v. Byrum, 638 S.E. 2d 246 (N.C. Ct. App. 2006) ruled that a plaintiff could use HIPAA to establish the “standard of care” in a negligence lawsuit. Meanwhile, disgruntled employees or other business partners performing services for  Covered Entities also increasingly are pointing to HIPAA as the basis for their retaliation or wrongful discharge claims. See, e.g.,  Retaliation For Filing HIPAA Complaint Recognized As Basis For State Retaliatory Discharge Claim. Read more here

Coupled with the HITECH Act changes, these and other enforcement actions signal growing potential hazards for Covered Entities that  fail to properly manage their HIPAA compliance obligations and risks. To help guard against these exposures, Covered Entities should act quickly to strengthen their HIPAA defenses by updating policies, contracts, practices, security, training, oversight, documentation and management.

Covered Entities & Business Associates Urged To Act Promptly To Manage Mitigating Expanded HIPAA Risks & Obligations

Faced with these expanding obligations and exposures, Covered Entities should prepare for the need to defend the adequacy of their HIPAA compliance efforts on paper and in operation. As part of these efforts, Covered Entities should consider:

  • Reviewing the adequacy of the practices, policies and procedures of the Covered Entities, business associates, and others that may come into contact with protected health information within the scope of attorney-client privilege taking into consideration the Corrective Action Plan, published OCR noncompliance and enforcement statistics, their own and reports of other security and privacy breaches and near misses, and other developments to determine if additional steps are necessary or advisable;
  • Updating policies, privacy and other notices, practices, procedures, training and other practices as needed to promote compliance and defensibility;
  • Renegotiating and enhancing service provider agreements to detail the specific compliance obligations of each party; to clarify the respective rights, procedures and responsibilities of each party in regards to compliance audits, investigation, breach reporting, and mitigation; to clarify rights of indemnification; and other related relevant matters;
  • Improving technological and other tracking, documentation and safeguards and controls to the use, access and disclosure of protected health information;
  • Conducting well-documented training as necessary to ensure that members of the Covered Entity’s workforce understand and are prepared to comply with the expanded requirements of HIPAA, can detect potential breaches or other compliance concerns, and understand and are prepared to follow appropriate procedures for reporting and responding to suspected violations;
  • Tracking actual and near miss violations and making adjustments to policies, practices, training, safeguards and other compliance components as necessary to deter future concern
  • Establishing and providing well-documented monitoring of compliance;
  • Establishing and providing well-documented timely investigation and redress of reported violations or other compliance concerns;
  • Establishing contingency plans for responding in the event of a breach;
  • Establishing a well-documented process for monitoring and updating policies, practices and other efforts in response to changes in risks, practices and  requirements;
  • Preparing and maintaining a well-documented record of compliance activities; and
  • Pursuing other appropriate strategies to enhance the Covered Entity’s ability to demonstrate its compliance commitment both on paper and in operation.

For Assistance With Compliance Or Other Concerns

The author of this article,  Ms. Stamer has extensive experience advising and assisting health care practitioners and other businesses and business leaders to establish, administer, investigate and defend health care fraud and other compliance and internal control policies and practices to reduce risk under federal and state health care and other laws. If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact the author of this article, Cynthia Marcotte Stamer, CTT Health Care Practice Group Chair, at cstamer@cttlegal.com, 214.270.2402 or another Curran Tomko Tarski LLP attorney of your choice.  You can get more information about the CTT Health Care Practice  and more specifics about Ms. Stamer’s health industry experience here.

Ms. Stamer is nationally known for her work, training and presentations, and publications on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts. 

Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 22 years experience advising clients, conducting workshops and other training, and providing policy advice about health care, privacy, data security, and other matters. She advises health care providers, health insurers and administrators, employer and other health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, ERISA, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters. A widely published author on privacy, data security, health care and other related matters, Ms. Stamer is the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.  

Other Helpful Resources & Other Information

If you found these updates of interest, you also be interested in one or more of the following other recent articles:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to here.

©2010 Cynthia Marcotte Stamer.  All rights reserved. 


Federal HEAT & Other Federal Health Care Fraud Efforts Score More Than 15 Successes As OIG Claims $20.97 Billion Saved From Enforcement Activities In December

December 30, 2009

As the interagency Medicare Fraud Strike Force targeting Medicare Fraud scored another series of more than 15 successful criminal enforcement actions across the national during December, 2009, the Department of Health & Human Services (HHS) Office of Inspector General (OIG) credited the Medicare Fraud Strike Force and other stepped up oversight and enforcement activities as helping it achieve $20.97 Billion in Medicare and other federal health care program savings during Fiscal Year 2009 in its Semiannual Report to Congress

The Detroit convictions were among three of more than 15 other criminal enforcement successes reported by the Department of Justice during December.  These and other reports document the rising prosecution and enforcement risks that health care providers face for failing to tailor their billing and other practices to comply with federal health care fraud laws.  In light of the growing enforcement and emphasis of federal prosecutors and regulations on the detection and prosecution of organizations and individuals participating in billing or other activities that violate federal health care fraud laws, health care organizations, their officers, directors, employees, consultants and other business partners should tighten practices and step up oversight to minimize the likelihood that they or their organizations will engage in activities that federal regulators view as federal health care fraud.

December 13 Detroit Criminal Convictions

The U.S. Department of Justice Criminal Division (Justice Department), Federal Bureau of Investigation (FBI) and Inspector General for the U.S. Department of Health and Human Services (HHS) jointly announced Friday (December 11, 2009) that Baskaran Thangarasan, Sandeep Aggarwal and Wayne Smith had plead guilty for their roles in connection with several Detroit-area health care fraud scheme.

On December 9, 2009, Thangarasan plead guilty to one count of conspiracy to commit health care fraud and Aggarwal plead guilty to one count of conspiracy to launder money. On December 11, 2009, Smith plead guilty to one count of conspiracy to commit health care fraud.

  • Thangarasan Guilty Plea To Conspiracy To Commit Health Care Fraud

On December 9, 2009, Thangarasan plead guilty to one count of conspiracy to commit health care fraud. And Aggarwal plead guilty to one count of conspiracy to launder money. He faces a maximum sentence of 10 years in prison and a $250,000 fine at sentencing.

According to information contained in plea documents, Thangarasan, a licensed physical therapist, admitted that he began working in approximately September 2003 as a contract therapist for a co-conspirator. This co-conspirator owned and controlled several companies operating in the Detroit area that purported to provide physical and occupational therapy services to Medicare beneficiaries. Thangarasan admitted that he, the co-conspirator and others created fictitious therapy files appearing to document physical therapy services provided to Medicare beneficiaries, when in fact no such services had been provided. According to court documents, the fictitious services reflected in the files were billed to Medicare through sham Medicare providers controlled by Thangarasan’s co-conspirators.

Thangarasan admitted that his role in creating the fictitious therapy files was to sign documents and progress notes indicating he had provided physical therapy services to particular Medicare beneficiaries, when in fact he had not. Thangarasan was paid approximately $50 by co-conspirators per file that he falsified in this manner. Thangarasan also admitted that in the course of the scheme charged in the indictment, he signed approximately 1,011 fictitious physical therapy files, falsely indicating he had provided physical therapy services to Medicare beneficiaries. Thangarasan admitted he knew that the files he helped falsify were used to justify fraudulent billings to Medicare.

In addition, Thangarasan admitted that between approximately September 2003 and May 2006, his co-conspirators submitted claims to the Medicare program totaling approximately $5,055,000 for files that were falsified by Thangarasan. Medicare actually paid approximately $2,325,000 on those claims. Thangarasan admitted that throughout the conspiracy, he was fully aware that Medicare was being billed for occupational therapy services he had falsely indicated he had performed.

  • Aggarwal Guilty Plea to Money Laundering

Aggarwal faces a maximum sentence of 20 years in prison and a $500,000 fine after admitting in the same case to assisting co-conspirator Suresh Chand in laundering the proceeds of Chand’s Medicare fraud scheme. Chand, who pleaded guilty in September 2009 to conspiracy to commit health care fraud and conspiracy to launder money, admitted to conspiring to submit approximately $18 million in fraudulent physical and occupational therapy claims to the Medicare program. Aggarwal, who admitted working at Chand’s office, acknowledged that his role in the scheme was to set up sham entities at Chand’s direction, with the purpose of using those entities to distribute the proceeds of the fraud to the various co-conspirators. According to plea documents, one such entity was called Global Health Care Management Services. Aggarwal admitted that Global Health Care Management Services, which he helped create, provided no health or management services of any type, but existed solely as a mechanism to conceal the location of fraudulently obtained Medicare proceeds. Aggarwal admitted in his plea that he and Chand laundered approximately $393,000 through this sham entity.

  • Smith Guilty Plea To Conspiracy To Commit Health Care Fraud

At sentencing, Smith face a maximum sentence of 10 years in prison and a $250,000 fine for his participation in a scheme to falsely bill Medicare.  His indictment charged that he transported and paid Medicare beneficiaries to attend Sacred Hope Center, a Southfield, Mich.-infusion clinic. According to the indictment, the Medicare beneficiaries he paid and transported were paid to sign paperwork indicating that they had received infusions and injections of specialty medications that they did not in fact receive.

According to the indictment, Sacred Hope Center routinely billed the Medicare program for services that were medically unnecessary and/or never provided. The primary owners and operators of Sacred Hope Center have pleaded guilty and admitted purchasing only a small fraction of the medications that the clinic billed the Medicare program for providing. These co-conspirators have also stated that patients were prescribed medications at the clinic based not on medical need, but instead based on which medications were likely to generate Medicare reimbursements.

Other Criminal Enforcement Actions During December

The Detroit convictions are three of nearly 20 successful criminal enforcement activities that DOJ announced during December, 2009.  During the same month, DOJ also announced:

  • On December 20, 2009, sentencing of an Audiologist to six months in prison for Medicare Fraud in California  here
  • On December 17, 2009 , the guilty plea and sentencing of a Houston physician for operating an illegal pill mill here
  • On December 16, 2009, the sentencing in Michigan of the owner of health care agency to 18 months prison in Medicare kickback scheme here
  • On December 15, 2009, the sentencing of a Lexington. South Carolina doctor to perform community service in a health care fraud case  here
  • On December 15, 2009, the guilty plea of a Plymouth, Minnesota man to defrauding Medicaid out of $74,000  here
  • On December 14, 2009, the sentencing of a Miami, Georgia man to more than a decade in Federal prison for million dollar Medicaid fraud here
  • On December 11, 2009, the charging of a durable medical equipment company and six other defendants in Pennsylvania in a Medicare Fraud And Kickback Scheme here
  • On December 11, 2009, the guilty plea of an Aulander, North Carolina woman to $650,000 Health Care Fraud  here
  • On December 7, 2009, the guilty plea of a corporation various health care fraud schemes here
  • On December 6, 2009, the guilty plea of a Dallas, Texas durable medical equipment business owner to aggravated id theft in a Medicare Fraud scheme  here
  • On December 3, 2009, the arrest of the owner of a Florida home health care provider and his alleged accomplice for a scheme to bribe a government contractor  here
  • On December 3, 2009, the conviction of two defendants for Health Care Fraud in Idaho here
  • On December 2, 2009, the entry of an order requiring a Sioux City, Iowa hospital to pay $400,000 to resolve false claims allegations  here
  • On December 1, 2009, the admission by a Maryland man to health care fraud on a hospital in the District of Columbia  here
  • On December 1, 2009, the arrest of a Miami, Florida man for obstructing a Health Care Fraud Investigation here
  • On December 1, 2009, the $125,000  fine of a Michigan chiropractor for Falsifying Records here

HEAT Operations Continued & Expanded

The Detroit and many of these other criminal successes resulted from joint investigations by the FBI and the OIG as part of the Medicare Fraud Strike Force as part of various interagency Medicare Fraud “Strike Forces” operating in several regions of the U.S. as part of the continuing Health Care Fraud Prevention and Enforcement Action Team (HEAT) operations of the FBI, HHS and the Justice Department which DOJ credits with producing more than 250 criminal convictions since their inception,  Based on initial successes of Strike Force operations in Miami (Phase One) and  Los Angeles (Phase Two), the Justice Department and HHS on May 20, 2009 expanded the scope of these operations to include Detroit and Houston Strike Force teams. Recently, DOJ and HHS announced the expansion of its HEAT operations to include Strike Force teams also targeting health care fraud in Brooklyn, New York; Tampa, Florida and Baton Rouge, Louisiana.

The heightened emphasis on enforcement of federal health care fraud laws reflected in the HEAT program the enactment of recent amendments to the False Claims Act, 31 U.S.C. § 3729 (FCA)  under the “Fraud Enforcement and Recovery Act of 2009”(FERA).  The FERA amendments increase the likelihood both that whistleblowers will turn in health care providers and other individuals and organizations that file false claims in violation of the FCA and the liability that violators may incur for that misconduct.

The FERA amendments and the HEAT Team and Strike Force activities are part of a broader emphasis in the enforcement of federal health care fraud laws by both the Administration and Congress.  President Obama’s proposed Fiscal Year 2010 budget seeks to further increase funding for fraud prevention and enforcement by investing $311 million — a 50 percent increase from 2009 funding — to strengthen program integrity activities within the Medicare and Medicaid programs.  The Obama Administration anticipates that all combined, the anti-fraud efforts in the President’s budget could save $2.7 billion over five years by improving oversight and stopping fraud in the Medicare and Medicaid programs, including the Medicare Advantage and Medicare prescription drug programs.  Many state agencies also are stepping up their health care fraud investigations and enforcement.

Health Care Providers Must Step Up Compliance & Risk Management

In light of this new emphasis upon health care fraud detection and enforcement, health care providers now more than ever need to prepare to demonstrate the appropriateness and defensibility of their health care billing and other compliance efforts.

Solutions Law Press author and Curran Tomko and Tarski LLP Health Care Practice Chair Cynthia Marcotte Stamer has extensive experience advising and assisting health care practitioners and other businesses and business leaders to establish, administer, investigate and defend health care fraud and other compliance and internal control policies and practices to reduce risk under federal and state health care and other laws. You can get more information about the CTT Health Care Practice  and more specifics about Ms. Stamer’s health industry experience here on the CTT Website.

If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer, CTT Health Care Practice Group Chair, at cstamer@cttlegal.com, 214.270.2402, CTT White Collar Defense Litigation Practice Chair Edwin J. Tomko at etomko@cttlegal.com, or  214.270.1405 or another Curran Tomko Tarski LLP attorney of your choice.. 

Other Helpful Resources & Other Information

We hope that this information is useful to you.   If you found these updates of interest, you also be interested in other updates on HEAT activities such as the following:

Other recent updates that also may be of interested published on our electronic Solutions Law Press Health Care Update publication include:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please register to receive this Solutions Law Press Health Care Update here and be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.

©2009 Cynthia Marcotte Stamer.  All rights reserved. 


HIT Policy Committee’s Nationwide Health Information Network Workgroup Meets December 16, 2009

December 1, 2009

The Office of the National Coordinator for Health Information Technology (ONC) HIT Policy Committee’s Nationwide Health Information Network Workgroup will hold a public meeting on December 16, 2009.  The meeting is scheduled from 10 a.m. to 5 p.m./Eastern Time at the OMNI Shoreham Hotel, 2500 Calvert Street, NW., Washington, DC. Members of the public care invited to participate live, via telephone, or Webcast.  For details about options for participation, instructions to present input, and other details, see here.

For More Information

We hope that this information is useful to you.  If you need assistance with these or other health care public policy, regulatory, compliance, risk management, workforce and other staffing, transactional or operational concerns, please contact the author of this update, Curran Tomko Tarski LLP Health Practice Group Chair, Cynthia Marcotte Stamer, at (214) 270‑2402, cstamer@cttlegal.com. Ms. Stamer has extensive experience advising clients and writes and speaks extensively on these and other health industry and other reimbursement, operations, internal controls and risk management matters.  You can review other recent health care and related resources and additional information about the health industry and other experience of Ms. Stamer here

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here and/or by participating in the SLP Health Care Risk Management & Operations Group on LinkedIn.  To unsubscribe, e-mail here.

©2009 Cynthia Marcotte Stamer.  All rights reserved.


Pfizer To Pay $2.3 Billion For Fraudulent Marketing In Largest DOJ Health Care Fraud Settlement

September 2, 2009

Announcement Highlights Growing Fraud Prosecution Risks of Health Industry Businesses

Today’s announcement that Pfizer Inc. and its subsidiary Pharmacia & Upjohn Company Inc. (collectively “Pfizer”) will pay $2.3 billion, the largest health care fraud settlement in the history of the Department of Justice, to resolve criminal and civil liability for alleged illegal promotion of certain pharmaceutical products and other stepped up oversight and enforcement activities make it critical that all health industry organizations strengthen their internal controls, compliance and audit activities as well as be prepared to defend their actions against the rising tide of federal and state oversight and enforcement.

The pharmaceutical giant Pfizer Inc. and its subsidiary Pharmacia & Upjohn Company Inc. have agreed to pay $2.3 billion, the largest health care fraud settlement in the history of the Department of Justice, to resolve criminal and civil liability arising from the alleged illegal promotion of certain pharmaceutical products, the Justice Department (DOJ) announced today (September 2, 2009).

According to DOJ, Pharmacia & Upjohn Company agreed to plead guilty to a felony violation of the Food, Drug and Cosmetic Act for misbranding Bextra with the intent to defraud or mislead.  Bextra is an anti-inflammatory drug that Pfizer pulled from the market in 2005. 

The Food, Drug and Cosmetic Act requires that a company specify the intended uses of a product in its new drug application to FDA.  Once approved, the drug may not be marketed or promoted for so-called “off-label” uses – i.e., any use not specified in an application and approved by FDA.  DOJ charged Pfizer promoted the sale of Bextra for several uses and dosages that the FDA specifically declined to approve due to safety concerns.  Under the announced settlement, Pfizer will pay a criminal fine of $1.195 billion, the largest criminal fine ever imposed in the United States for any matter.  Pharmacia & Upjohn will also forfeit $105 million, for a total criminal resolution of $1.3 billion.

In addition, Pfizer agreed to pay $1 billion to resolve allegations under the civil False Claims Act that the company illegally promoted four drugs – Bextra; Geodon, an anti-psychotic drug; Zyvox, an antibiotic; and Lyrica, an anti-epileptic drug – and caused false claims to be submitted to government health care programs for uses that were not medically accepted indications and therefore not covered by those programs.  The civil settlement also resolves allegations that Pfizer paid kickbacks to health care providers to induce them to prescribe these, as well as other, drugs.  The federal share of the civil settlement is $668,514,830 and the state Medicaid share of the civil settlement is $331,485,170.  This is the largest civil fraud settlement in history against a pharmaceutical company.

As part of the settlement, Pfizer also has agreed to enter into an expansive corporate integrity agreement with the Office of Inspector General of the Department of Health and Human Services.  That agreement provides for procedures and reviews to be put in place to avoid and promptly detect conduct similar to that which gave rise to this matter.

Whistleblower lawsuits filed under the qui tam provisions of the False Claims Act that are pending in the District of Massachusetts, the Eastern District of Pennsylvania and the Eastern District of Kentucky triggered this investigation.  As a part of today’s resolution, six whistleblowers will receive payments totaling more than $102 million from the federal share of the civil recovery.

Today’s announcement of this historic settlement emphasizes the continuing and growing government commitment to, coordination and sophistication in the investigation and prosecution of health care crimes by pharmaceutical industry and other health care providers.  The Obama Administration has made investigation and prosecution of health care fraud laws a key element of its strategy to manage U.S. health care program costs. Recently enacted changes in the False Claims Act and other laws are making it easier for federal prosecutors to successfully prosecute these and other health care fraud cases.

The enhanced coordination among agencies central to this strategy is reflected in the collaboration among the many agencies involved in the investigation leading to these charges. The U.S. Attorney’s offices for the District of Massachusetts, the Eastern District of Pennsylvania, and the Eastern District of Kentucky, and the Civil Division of the Department of Justice handled these cases.  The U.S. Attorney’s Office for the District of Massachusetts led the criminal investigation of Bextra.  The investigation was conducted by the Office of Inspector General for the Department of Health and Human Services (HHS), the FBI, the Defense Criminal Investigative Service (DCIS), the Office of Criminal Investigations for the Food and Drug Administration (FDA), the Veterans’ Administration’s (VA) Office of Criminal Investigations, the Office of the Inspector General for the Office of Personnel Management (OPM), the Office of the Inspector General for the United States Postal Service (USPS), the National Association of Medicaid Fraud Control Units and the offices of various state Attorneys General.

These and other stepped up oversight and enforcement activities make it critical that all health industry organizations strengthen their internal controls, compliance and audit activities as well as be prepared to defend their actions against the rising tide of federal and state oversight and enforcement.

Register Now For Upcoming September Health Industry Update Programs

If you found this information of interest, you also may be interested in one of the following upcoming health industry programs to be presented by Ms. Stamer during September:

  • HITECH ACT Health Data Security & Breach Update on September 9, 2009 hosted live or via teleconference by Curran Tomko Tarski LLP 
  • How to Ensure That Your Organization Is In Compliance With Regulations Governing Discrimination — What You Should Be Doing To Be Prepared for the New, Stepped Up Enforcement Actions on September 10, 2009 hosted via teleconference by Health Resources Publishing
  • Health Information Security & Data Breach Under HITECH Act on September 17, 2009 hosted via teleconference by the Health Care Compliance Association

To register or for other details about these and other upcoming programs and presentations by Ms. Stamer and other Curran Tomko Tarski members, see here.

Other Recent Developments

If you found this information of interest, you also may be interested in reviewing some of the following recent Curran Tomko Tarski LLP Latest in Health Care Updates available online by clicking on the article title:

For More Information

We hope that this information is useful to you.  If you need assistance with auditing or defending health care fraud concerns or other health care compliance, risk management, transaction or operation concerns, please contact the author of this update, Curran Tomko Tarski LLP Health Practice Group Chair, Cynthia Marcotte Stamer, at (214) 270‑2402, cstamer@cttlegal.com, Edwin J. Tomko at (214) 270-1405 or another Curran Tomko Tarski LLP Partner of your choice. Ms. Stamer has extensive experience advising clients and writes and speaks extensively on these and other health industry and other internal controls and risk management matters. 

You can review other recent health care and internal controls resources and additional information about the health industry and other experience of Ms. Stamer here.  If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information to cstamer@cttlegal.com.

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.  To unsubscribe, e-mail here.

©2009 Cynthia Marcotte Stamer.  All rights reserved.


Health Care Providers & Other HIPAA-Covered Entities & Their Business Associates Must Comply With New HHS Health Information Data Breach Rules By September 24

August 24, 2009

Register Now To Participate in September 9  “HITECH Act Health Data Security & Breach Update”

Health care providers, health clearinghouses, health plans and their business associates generally must start complying with new federal data breach notification rules on September 24, 2009. 

The new “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) published here in today’s Federal Register requires health care providers, health plans, health care clearinghouses and their business associates (Covered Entities) covered under the personal health information privacy and security rules of the Health Insurance Portability & Accountability Act (HIPAA) to notify affected individuals following a “breach” of “unsecured” protected health information. The Breach Regulation is part of a series of guidance that HHS is issuing to implement new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).

You are invited to catch up on what these new rules mean for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Wednesday, September 9, 2009 from Noon to 1:30 P.M. Central Time.

HITECH Act Data Breach and Unsecured PHI Rules

Scheduled for publication in the Federal Register on August 24, 2009, the new Breach Regulation implements the HITECH Act requirement that Covered Entities and their business associates notify affected individuals, the Secretary of HHS, and in some cases, the media, when a breach of “unsecured protected health information” happens and the form, manner, and timing of that notification. Covered Entities must begin complying with the new Breach Regulation on September 24, 2009. 

Part of a series of new HHS rules implementing recent changes to HIPAA enacted under the HITECH Act to strengthen existing federally mandates requiring Covered Entities to safeguard protected health information, the Breach Regulation will obligate Covered Entities and business associates to provide certain notifications following a breach of “protected health information” that not secured at the time of the breach through the use of a technology or methodology meeting minimum standards issued by HHS pursuant to other provisions of the HITECH Act.

Under the HITECH Act, the breach notification obligations contained in the Breach Notification only apply to a breach of “unsecured protected health information.” The Breach Regulation exempts breaches of protected health information that qualify as “secured” under separately issued HHS and Federal Trade Commission (FTC) standards for encryption and destruction of protected health information from its breach notification requirements.  

For purposes of the HITECH Act, electronic protected health information is considered “unsecured” unless the Covered Entity has satisfied certain minimum standards for the protection of that data established pursuant to the HITECH Act.  Earlier this year, HHS and the FTC issued interim rules defining the minimum encryption and destruction technologies and methodologies that Covered Entities must use to render protected health information unusable, unreadable, or indecipherable to unauthorized individuals for purposes of determining when protected health information is “unsecured” for purposes of the HITECH Act.  Concurrent with its publication of the Breach Regulation, HHS also released guidance updating and clarifying this previously issued guidance. 

Read the Breach Regulation here.  To review the HITECH Act Breach Notification Guidance and Request for Information, see here.

September 9 “HITECH Act Health Data Security & Breach Update” Briefing

Interested persons are invited to register here now  to learn what these new rules mean for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Wednesday, September 9, 2009 from Noon to 1:30 P.M. Central Time. For a registration fee of $45.00, registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201.  For information about registering for this program or other questions here 

Conducted by Curran Tomko and Tarski LLP Partner Cynthia Marcotte Stamer, the briefing will cover:

  • Who must comply
  • What your organization must do
  • How to qualify protected health information as exempt from the breach regulations as “secure” protected health information
  • What is considered a breach of unsecured protected health information
  • What steps must a covered entity take if a breach of unsecured protected information happens
  • What liabilities do covered entities face for non-compliance
  • What new contractual requirements, policies and procedures Covered Entities and Business Associates will need
  • How the Breach Regulation, the Privacy Regulation, impending FTC red flag rules and state data breach and privacy rules interrelate
  •  Other recent developments
  • Practical tips for assessing, planning, moving to and defending compliance
  • Participant questions
  • More 

About The Presenter

 The program will be presented by Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.  Ms. Stamer is nationally known for her work, publications and presentations on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts. 

Vice President of the North Texas Health Care Compliance Professionals Association  and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, and Former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 20 years experience advising clients about health and other privacy and security matters.  A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters.  Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.  

We hope that this information is useful to you.  If you need assistance monitoring, evaluating or responding to these or other compliance, risk management, transaction or operation concerns, please contact the author of this update, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or another Curran Tomko Tarski LLP Partner of your choice.

Other Helpful Resources & Other Information

If you found these updates of interest, you also be interested in one or more of the following other recent articles published on our electronic Curran Tomko Tarski LLP publications available for review here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@cttlegal.net.

©2009 Cynthia Marcotte Stamer.   All rights reserved. 

 


HHS Issues Interim Final Requiring Health Care Provider, Health Plans & Other Covered Entities To Give Breach Notifications When Certain Personal Health Information Breached Beginning In September; Register to Participate In September 10th Briefing on New Rules In Person or Via Telephone

August 20, 2009

The U.S. Department of Health and Human Services (HHS) yesterday (August 19, 2009) issued “breach notification” regulations requiring health care providers, health plans and other covered entities (Covered Entities) under the personal health information privacy and security rules of the Health Insurance Portability & Accountability  (HIPAA) to notify affected individuals following a “breach” of “unsecured” protected health information. Scheduled for publication in the Federal Register on August 24, 2009, the new breach notification regulations are part of a series of new rules that implement new electronic personal health information data security and data breach notification requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).  Covered entities must begin complying with the new rules no later than September 24, 2009.

Curran Tomko Tarski, LLP Health Practice leader Cynthia Marcotte Stamer will conduct a briefing on these new protected health information data security and data breach rules on Thursday, September 10, 2009 from Noon to 1:30 P.M. Central Time. For a registration fee of $45.00, registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201.  For more information, e-mail here.

 HITECH Act Data Breach and Unsecured PHI Rules

The new data breach notification rules are part of a series of recent HIPAA enacted under the HITECH Act to strengthen the federal rules requiring HIPAA covered entities to safeguard electronic and certain other protected health information. Enhanced data security and data breach rules added as part of these HITECH Act amendments obligate  covered entities and business associates to provide certain notifications following a breach of “unsecured”  “protected health information” within the meaning of HIPAA, as amended.  “Unsecured protected health information” is defined as protected health information that is not secured through the use of a technology or methodology specified by the HHS Secretary.

The new data breach regulations implement the HITECH Act requirement that Covered Entities and their business associates notify affected individuals, the Secretary of HHS, and in some cases, the media, of a breach and the form, manner, and timing of that notification.  For purposes of the HITECH Act, electronic protected health information is considered “unsecured” unless the covered entity has satisfied certain minimum standards for the protection of that data established pursuant to the HITECH Act.  HHS and the Federal Trade Commission previously issued certain initial guidance concerning the HITECH Act standards for determining when electronic personal health information qualifies as secure.  To help further define when electronic health information is treated as “unsecured” and therefore subject to the breach notification requirements, the data breach rules also update and clarify the previously issued existing HHS guidance specifying encryption and destruction as the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals published earlier this year by HHS to for purposes of determining when protected health information will be considered “unsecured” for purposes of the HITECH Act data breach rules.  Entities subject to the HHS and FTC regulations that secure health information as specified by the guidance through encryption or destruction are relieved from having to notify in the event of a breach of such information.  

The HHS interim final regulations are effective September 24, 2009, which is the date 30 days after the date they will be published on the Federal Register and include a 60-day public comment period. To review the interim final data breach regulations, see here.  To review the HITECH Act Breach Notification Guidance and Request for Information, see here.

For More Information

The author of this article, Curran Tomko and Tarski LLP Health Care Practice Chair Cynthia Marcotte Stamer has extensive experience advising and assisting health care providers, payors and their business associates about HIPAA and other privacy and data security matters, as well as a diverse range of health care policy, regulatory, compliance, risk management and operational concerns. 

Past chair of the American Bar Association Health Law Section Managed Care & Insurance Section, Martindale Hubble AV-rated and recognized in International Who’s Who of Professionals, Ms. Stamer continuously advises health care providers, health care payers and administrators, employers, governments and others about health care, insurance, human resources, privacy and data security, technology, and other legal and operational concerns.  A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer also writes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters.  She currently serves as the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010.  Examples of her other works include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of others.  Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service Privacy Report, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a various other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.  

We hope that this information is useful to you.  If you need assistance monitoring, evaluating or responding to these or other proposed health care or other regulatory reforms or with other health care compliance, risk management, transaction or operation concerns, please contact the author of this update, Curran Tomko Tarski LLP Health Practice Group Chair, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or your other favorite Curran Tomko Tarski LLP Partner.

We also encourage you and others to join the discussion about these and other health care reform proposals and concerns by joining the Coalition for Responsible Health Care Reform Group on Linkedin, registering to receive these updates here.

Other Helpful Resources & Other Information

We hope that this information is useful to you.   If you found these updates of interest, you also be interested in one or more of the following other recent articles published on our electronic Solutions Law Press Health Care Update publication available here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please register to receive this Solutions Law Press Health Care Update here and be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.

©2009 Cynthia Marcotte Stamer.  All rights reserved. 


House Democrats Introduce the “American’s Affordable Health Care Choices Act of 2009”

July 15, 2009

House Democrats introduced their proposal for health care reform this afternoon (July 14, 2009), the “America’s Affordable Health Choices Act of 2009 (the “House Bill”).  Introduced under the sponsorship of three key House committees — Energy and Commerce, Ways and Means, and Education and Labor — the 1018 page House Bill details the sweeping and comprehensive health care reforms touted by House Democrat Leaders..  A copy of the House Bill as introduced may be reviewed here

The House Bill proposes sweeping reforms built around the establishment of a public plan option while technically continuing to permit private plans to operate but in a federally regulated form allowing for little meaningful plan design control to private payers, health care providers or the individuals choosing among the plan options.   The Congressional Budget Office estimates that the coverage side of the bill will cost $1 trillion and cover 97 percent of the legal population within 10 years.

The following is a brief overview of certain key provisions of the House Bill drawn mostly from a series of high level summaries released by House Democrats along with the House Bill.  Long on politically comforting phrasing and short on details, you can read these summaries here.

Public Plan Option.  The House Bill proposes the establishment of a public health insurance option that would compete with allowable private plans, both of which would be subject to sweeping federal controls.  Democrat House co-sponsors represent the House Bill:

  • Provides a public health insurance option that would compete with private insurers within the Health Insurance Exchange.
  • The public health insurance option would be made available in the new Health Insurance Exchange (Exchange) along with private health insurance plans that comply with the design dictates established in the House Bill.
  • The public health insurance option and private plan options meet the same benefit requirements and comply with the same insurance market reforms
  • The public option’s premiums would be established for the local market areas designated by the Exchange.
  • Individuals with affordability credits could choose among the private carriers and the public option.
  • Require that the public health plan and private health plan options and private options each must be financially self-sustaining
  • Promote primary care, encourage coordinated care and shared accountability, and improve quality.
  • Institute new payment structures and incentives to promote these critical reforms.
  • Specify health care provider participation in the plans will be voluntary; Medicare providers are presumed to be participating unless they opt out.
  • Provides for provider reimbursements for services from the plans initially will be established using “rates similar to those used in Medicare with greater flexibility to vary payments.
  • Speaker of the House Nancy Pelosi has announced plans to proceed immediately on mark up on the House Bill with the intention to of scheduling a vote on the House Bill by the end of July. Assuming that House leaders adhere to this schedule, the planned timetable leaves little opportunity for critical evaluation and input by members of Congress or the public who may have questions or concerns about the proposed legislation. Prompt and coordinated action is required for individuals with concerns about any of the proposed reforms.

Federal Mandates Health Plan Benefits.  In order to achieve affordable, quality health care for all, the House Bill would impose federal standards regulating the benefits that the public health plan and private health plans would be required and permitted to offer.  Under these provisions, the House Bill would:

  • Establish a standardized benefit package that covers essential health services.
  • Vest the power in the Secretary of Health & Human Services to decide the coverage that would be included in this mandated standardize benefit package.
  • Eliminate cost-sharing for preventive care (including well baby and well child care)
  • Impose caps annual out-of-pocket spending for individuals and families.
  • Create a new independent Benefits Advisory to recommend to the Secretary and update the core package of benefits.
  • Provide for the public health plan option to offer four tiers of benefit packages from which consumers can choose to best meet their health care needs. Each allowable plan would be required to provide the dictated core benefits.
    • The Basic Plan would include the federally mandated core set of covered benefits and cost sharing protections;
    • The Enhanced Plan would include the federally mandated core set of covered benefits with more generous cost sharing protections than the Basic plan;
    • The Premium Plan would include the federally mandated core set of covered benefits with more generous cost sharing protections than the Enhanced plan; and
    • The Premium Plus Plan would include the federally mandated core set of covered benefits, the more generous cost sharing protections of the Premium plan, and additional covered benefits (e.g., oral health coverage for adults, gym membership, etc.) that will vary per plan. In this category, insurers must disclose the separate cost of the additional benefits so consumers know what they’re paying for and can choose among plans accordingly.

The House Bill empowers the Secretary of Health & Human Services to decide the federally dictated, required core set of benefits provides coverage with input from a newly created Benefits Advisory Commission.  These core benefits are intended to include inpatient hospital services, outpatient hospital services, physician services, equipment and supplies incident to physician services, preventive services, maternity services, prescription drugs, rehabilitative and habilitative services, well baby and well child visits and oral health, vision, and hearing services for children and mental health and substance abuse services.  However, the particular, terms and scope of these benefits is left to HHS to define.

Health Insurance Exchange.  The House Bill also calls for the establishment of a “Health Insurance Exchange” meeting federal mandates through which low income individuals initially, and certain small businesses would be offered the option to purchase health care coverage through federally mandated purchasing groups.  In the first year, the House Bill provides for the Health Insurance Exchange to accept those without health insurance, those who are buying health insurance on their own, and small businesses with fewer than 10 people. In the second year, the Health Insurance Exchange could accept small businesses with fewer than 20 people. After that, “larger employers as permitted by the Commissioner.” In other words, expansion is discretionary, not mandated.

Affordability & Subsidies.  The House Bill provides sliding-scale affordability credits for individuals and families with incomes above the Medicaid thresholds but below 400% of poverty and imposes a cap on total out-of-pocket spending for individuals and families covered under the plans regardless of income.  In addition, the House Bill would broaden Medicaid coverage to include individuals and families with incomes below 133% of poverty.

Effective 2013, sliding scale affordability credits would be provided provided to individuals and families between 133% to 400% of poverty. That means the credits phase out completely for an individual with $43,320 in income and a family of four with $88,200 in income (2009).

The sliding scale credits limit individual family spending on premiums for the essential benefit package to no more than 1.5% of income for those with the lowest income and phasing up to no more than 11% of income for those at 400% of poverty.

The affordability credits also subsidize cost sharing on a sliding scale basis, phasing out at 400% of poverty, ensuring that covered benefits are accessible.

The Health Insurance Exchange would administer the affordability credits in relationship with other federal and state entities, such as local Social Security offices and Medicaid agencies.

The essential benefit package, and all other benefit options, limit exposure to catastrophic costs with a cap on total out of pocket spending for covered benefits. Special provisions would apply to Medicaid. 

Effective 2013, individuals with family income at or below 133% of poverty ($14,400 for an individual in 2009) are eligible for Medicaid. State Medicaid programs would continue to cover those individuals with incomes above 133% of poverty, using the eligibility rules states now have in place.

Paying The Tab.  House Democrats propose to finance approximately half of the estimated $1 trillion bill for their proposed reforms through projected $500 billion or so in savings from Medicare and Medicaid achieved by a variety of reimbursement and benefit cutbacks and other reforms. The rest of the financing would come from a combination of revenue expections from employer and individual mandates (an estimated $200 billion over 10 years) and a surtax on the richest 1.5 percent of Americans. The surtax is 1 percent on income between $350,000 and $500,000; 1.5 percent on income between $500,000 and $1,000,000; and 5.4 percent in income above $1,000,000. The House Bill permits the amount of this surtax to vary if the bill is less or more expensive than initially anticipated.

The author of this article, Curran Tomko and Tarski LLP Health Care Practice Chair Cynthia Marcotte Stamer has extensive experience advising and assisting health industry clients and others about a diverse range of health care policy, regulatory, compliance, risk management and operational concerns.  You can get more information about her health industry experience here.  

If you need assistance evaluating or formulating comments on the proposed reforms contained in the House Bill or on other health industry matters please contact Cynthia Marcotte Stamer, CTT Health Care Practice Group Chair, at cstamer@cttlegal.com, 214.270.2402 or your other favorite Curran Tomko Tarski LLP attorney. 

Other Helpful Resources & Other Information

We hope that this information is useful to you.  If you or someone else you know would like to receive future updates about developments on these and other concerns, please register to receive this Solutions Law Press Health Care Update in real time here, joining the LinkedIn SLP Health Care Risk Management & Operations Group, and/or subscribing to receive e-mail distributions of some of these updates by sharing your current contact information – including your preferred e-mail- by creating or updating your profile here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject  here.

©2009 Cynthia Marcotte Stamer.  All rights reserved.


OCR Requires Health Care Providers To Improve Services for Limited English Speakers, Hearing Impaired As HHS Steps Up Enforcement of Federal Discrimination Laws

July 14, 2009

Health care providers should review the adequacy of translation and other mechanisms required to allow limited English speakers, hearing impaired, and other language limited populations effective access to services in light of recent enforcement actions taken by Department of Health and Human Services (HHS) Office of Civil Rights (OCR) against health care providers for discrimination under Title VI of the Civil Rights Act of 1964 (Title VII), the Americans With Disabilities Act (ADA) and other federal discrimination laws. 

As part of a broader Obama Administration initiative to make prevention and redress prohibited national origin, disabilities and other discrimination in employment, public services, public accommodations and telecommunications a priority, HHS has announced that OCR will hold health care providers accountable for ensuring effective and adequate access by individuals seeking services having limited English language proficiency, hearing loss or other language or communication restrictions impacting on their ability to access care and services.

Medco Health Solutions, Inc. National Origination Settlement

On June 22, 2009, OCR announced that national pharmacy benefit management company Medco Health Solutions, Inc. had agreed to implement a multi-faceted plan to improve services to limited and non-English speaking members in 2009. 

The commitment to take corrective action by the nation’s largest mail-order pharmacy operation arose from OCR’s investigation of a complaint filed with OCR on behalf of a Spanish-speaking member. The complaint alleged that Medco violated Title VI of the Civil Rights Act of 1964 (Title VII) by failing to provide limited English proficiency members (LEP members) with meaningful access to mail-order pharmacy services and other pharmacy benefit management services. 

Under Title VI, health care providers and other recipients of federal financial assistance are required to take reasonable steps to provide meaningful access to their programs by limited English proficient individuals who are eligible to receive their services.

Under the commitment letter, Medco agreed to implement a number of measures to strengthen its provision of language assistance services to LEP members starting with those for Spanish-speaking members in 2009.  The corrective actions agreed to by Medco include:

  • Expanding its pool of bilingual customer service representatives who speak Spanish
  • Revising its systems to enhance its ability to route Spanish-speaking members who need help with prescription drug questions or problems directly to bilingual staff, including pharmacists where possible and appropriate
  • Continuing to use a telephonic interpreter service available for more than 150 other languages to communicate with other non-English speakers. 
  • Implementing a critical improvement in Medco’s internal computer systems that will flag language preference on an ongoing basis to aid effective communication with limited English proficient persons during member-Medco contact. 
  • Continuing to improve its ability to identify and track individuals’ language preferences so that important written communications and outbound telephone calls are placed to members in their primary language. 
  • Reviewing how best to notify limited English proficient members that language assistance services are available.
  • Developing an evaluation process with respect to interpreter competency.  Staff at call centers and pharmacies expected to communicate directly with members in languages other than English will be assessed as to language proficiency, and those serving as interpreters will be assessed for interpreting competency. 
  • Training all relevant staff on system changes intended to improve access to limited English proficient members, and will monitor the results of these efforts through periodic assessments.

Read the Medco Commitment Letter here.

Scottsdale Healthcare – Osborn (SHO) Voluntary Resolution Agreement

 The Medico Commitment Letter follows OCR’s April, 2008 announcement that d a signed Resolution Agreement that requiring Scottsdale Healthcare – Osborn (“SHO”) a 337–bed full–service Arizona hospital to improve access to sign language interpreters and other services required for hearing impaired patients to effectively access services.  The SHO VRA resolves a disability discrimination complaint against SHO brought by a patient with severe hearing loss, who reported that she was denied a sign language interpreter when treated in the SHO emergency room and intensive care unit.

Following OCR’s investigation of the complaint, SHO among other things agreed to: (1) affirm its compliance with Section 504 of the Rehabilitation Act of 1973, 29 U.S.C. § 794; (2) issue and post revised policies to ensure that appropriate auxiliary aids, including sign language interpreters or video interpretation services, are provided to deaf or hard-of-hearing patients or companions within a two hour time period; (3) develop procedures to assess the sign language interpreter needs of patients or companions; (4) train hospital personnel and physicians on its revised policies and procedures to ensure effective communication; (5) place TTY lines throughout its facility; (6) maintain a centralized telecommunication number 24-hours per day, 7-days per week for sign language interpreter requests; and (7) provide regular compliance reports to OCR. Read SHO VRA here

Health Care Providers Should Act To Manage Risks As Obama Administration Makes Enhanced Investigation and Enforcement of Federal Discrimination Laws A Priority

Health care providers and other businesses covered by Title VII, the Americans with Disabilities Act and other federal discrimination laws should heed the Medco and SHO actions of the advisability of taking prompt action to review and if necessary, strengthen the adequacy of reasonable accommodations necessary to enable individuals with limited English proficiency, hearing or other language impairments to access services.

Beyond the adequacy of services to address language impairments, health care providers and others also generally should anticipate that the willingness by the OCR under the Obama Administration to act on the Medco and SHO complaints reflects a heightened willingness by federal agencies to investigate and enforce disabilities, national origin and charges of federal discrimination violations by health care providers and others by OCR and other federal agencies under the Obama Administration.  Review Obama Administration Civil Rights Enforcement Agenda here. While OCR took a series of enforcement actions under the predecessor Bush Administration, this announced renewed emphasis on federal discrimination law enforcement coupled by the series of actions taken by OCR and other federal agencies since January, 2009 reflects that OCR and other agencies are acting on the direction of President Obama to make prevention and redress of disabilities and other discrimination in employment, public services, public accommodations and telecommunications a priority. Read about other recent OCR federal discrimination enforcement activates here. See also, e.g., recent discrimination policies and enforcement activities by Department of Justice, the Equal Employment Opportunity Commission, the Department of Housing and Urban Development.

The Medco and SHO actions, as well as a series of other recently announced enforcement actions reflect that OCR and other federal agencies are likely to continue to expand investigation and enforcement of disability and other violations by health care providers of federal disability and other discrimination laws in recent months.  Health care providers and others regulated by these federal discrimination laws should consider auditing the adequacy of existing practices, reaffirming their commitment to compliance to workforce members and constituents, retraining workforce and taking other appropriate steps to help prevent illegal discrimination within their organization and to position their organization to respond and defend against potential discrimination investigations or charges.

The author of this article, Curran Tomko and Tarski LLP Health Care Practice Chair Cynthia Marcotte Stamer has extensive experience advising and assisting health care practitioners and other businesses and business leaders to establish, administer, investigate and federal and state discrimination and other compliance and internal control policies and practices to reduce risk under federal and state health care, discrimination and other laws. Board Certified in Labor and Employment Law by the Texas Board of Legal Specialization, Ms. Stamer’s practice emphasizes assisting health industry clients to monitor compliance and other legal and operational risks and to design, administer and defend internal controls and other risk management practices to mitigate these exposures.  You can get more information about her health industry experience here.  

If you need assistance investigating the adequacy of your current compliance efforts, with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer, CTT Health Care Practice Group Chair, at cstamer@cttlegal.com, 214.270.2402 or your other favorite Curran Tomko Tarski LLP attorney. 

Other Helpful Resources & Other Information

We hope that this information is useful to you.   If you found these updates of interest, you also be interested in one or more of the following other recent articles published on our electronic Solutions Law Press Health Care Update publication available here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please register to receive this Solutions Law Press Health Care Update here and be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.

©2009 Cynthia Marcotte Stamer.  All rights reserved. 


8 Miami-Area Residents Charged, Assets Frozen in $22 Million Home Health Medicare Fraud Scheme

June 29, 2009

Eight Miami-Dade County, Florida residents have been indicted in connection with an alleged $22 million Medicare fraud scheme operated out of Miami businesses purporting to specialize in home health care services and the assets of those charged and their companies frozen as part of a joint Department of Justice (DOJ) and Department of Health & Human Services (HHS) Medicare Fraud Strike Force operation.

DOJ and HHS officials jointly announced the Florida indictments and injunction action on June 26, 2009, just two days after their June 24, 2009 joint announcement of that a Detroit Medicare Fraud Strike Force had secured indictments against 53 people for schemes to submit more than $50 million in false Medicare claims.

Both the Florida and Detroit actions arose from health care fraud conducted by Medicare Fraud Strike Force teams acting as part of a recently formalized and expanded Health Care Fraud Prevention & Enforcement Action Team (HEAT) jointly announced by the DOJ and HHS on May 20, 2009.  The Florida and Detroit actions announced last week reflect the growing commitment of federal officials to investigate and prosecute Medicare and other alleged heath care fraud.

8 Florida Indictments

The Florida indictments announced June 26, 2009 charge Gladys Zambrana, Javier Zambrana, Enrique Perez, Alejandro Hernandez Quiros aka Alex Hernandez, Vanessa Estrada, Vicenta Tellechea, Modesto Hidalgo and Carlos Castaneda conspiracy to commit health care fraud.  Gladys Zambrana was also charged with four counts of health care fraud.  Gladys Zambrana and Hernandez Quiros were charged with three counts each of paying health care kickbacks, while Perez, Hidalgo and Tellechea were charged with one count each of paying health care kickbacks.  Gladys Zambrana, Perez, Alejandro Quiros, Tellechea and Castaneda were also charged with conspiracy to launder health care fraud proceeds.

According to the indictment, Gladys Zambrana, Perez and Hernandez Quiros operated ABC Home Health Care Inc. (ABC), listing Javier Zambrana as the owner; and Gladys Zambrana and Castaneda operated Florida Home Health Care Providers Inc. (Florida Home Health), listing Tellechea as the owner.  Both ABC and Florida Home Health purported to be home health agencies that catered to Medicare beneficiaries.  The indictment alleges that at both agencies, beneficiaries were recruited and paid kickbacks and bribes to arrange for their Medicare beneficiary numbers to be used by their co-conspirators to file claims with Medicare for purported home health care services.  The indictment alleges that the services were not provided and were not medically necessary.

The indictment alleges that in addition to exerting ownership and control of the home health agencies, Hernandez Quiros and Castaneda acted as Medicare beneficiary recruiters for ABC and Florida Home Health, respectively; and Hidalgo, a medical assistant, falsified medical tests and records to make it appear that the services were needed.  The indictment alleges that ABC billed more than $17 million to the Medicare program for services provided from January 2006 through December 2008 that were medically unnecessary and were not actually provided.  During that time frame, Medicare paid more than $11 million on those fraudulent claims submitted by ABC.  The indictment also alleges that from October 2007 through March 2009, Florida Home Health billed more than $5 million to the Medicare program for services that were medically unnecessary and not actually provided.  During that time frame, Medicare paid more than $4 million on those fraudulent claims submitted by Florida Home Health.

The charge of conspiracy to commit health care fraud carries a maximum prison sentence of 10 years.  Each charged count of health care fraud carries a maximum prison sentence of 10 years and each count of paying health care kickbacks carries a maximum prison sentence of five years.  Conspiracy to launder health care fraud proceeds carries a maximum prison sentence of 10 years per count.

In conjunction with the criminal case, on June 24, 2009, the U.S. Attorney’s Office filed a civil complaint for injunctive relief under the fraud injunction statute and obtained a temporary restraining order freezing the assets of ABC, Florida Home Health, Gladys Zambrana, Javier Zambrana, Perez, Hernandez Quiros, Castaneda and Tellechea.  In addition, that temporary restraining order also freezes certain financial assets of four other companies the defendants owned or controlled and allegedly used to launder money fraudulently obtained from Medicare.  The temporary restraining order is intended to preserve the remaining proceeds of the fraud for recovery by the United States as part of the criminal case and any related civil proceedings.

53 Indicted In Detroit June 24

The announcement of the Florida indictment comes just 2 days after DOJ, HHS and FBI officials announced that a Detroit Medicare Fraud Strike Force had secured indictments against 53 people for their involvement in alleged schemes to submit false Medicare claims.  The indictments unsealed June 24, 2009 returned by a grand jury in Detroit resulted in arrests in Miami, New York City and Detroit resulted from a concentrated effort by the Detroit Medicare Fraud Strike Force targeting infusion therapy and physical/occupational therapy providers involved in schemes orchestrated to defraud the Medicare program.

Collectively, the Detroit indictment accuses the physicians, medical assistants, patients, company owners and executives charged in the indictments of conspiring to submit more than $50 million in false claims to the Medicare program.  According to the indictments, the defendants participated in schemes to submit claims to Medicare for treatments that were in fact medically unnecessary and oftentimes, never provided.  In many cases, indictments also allege that beneficiaries accepted cash kickbacks in return for allowing providers to submit forms saying they had received the unnecessary and not provided treatments. 

Federal Officials Turning On The HEAT on Health Care Fraud

 

The Florida and Detroit indictments reflect the growing commitment and cooperation among federal and state officials to investigation and prosecution of health care fraud using Medicare Fraud Task Forces operating as part of HEAT.  Drawing upon successful experiences gained from Medicare Fraud Task Forces operating in Miami and Los Angeles since 2007, HEAT is an expanded multi-agency effort jointly announced by HHS and DOJ in May, 2009 that uses a multi-agency team of federal, state and local investigators to investigate and combat Medicare fraud through the use of Medicare data analysis techniques and an increased focus on community policing. Since strike force operations began in March 2007, DOJ officials report that the Medicare Fraud Task Forces already have resulted in the indictment of 257 defendants in 115 cases for their allegedly fraudulently billing Medicare for more than $600 million.

Before the May 20, 2009 HEAT announcement, Medicare Fraud Strike Forces operating demonstration projects in South Florida and Los Angeles already had produced a number of indictments. The Medicare Fraud Strike Force team operating in South Florida has already convicted 146 defendants and secured $186 million in criminal fines and civil recoveries.  After the success of operations in South Florida, the Medicare Fraud Strike Force expanded in May 2008 to phase two in Los Angeles, where 37 defendants have been charged with criminal health care fraud offenses.  To date in the Los Angeles cases, more than $55 million has been ordered in restitution to the Medicare program.  DOJ and HHS officials have indicated that the success of these demonstration projects lies behind the founding of the HEAT initiative.

The heightened emphasis on enforcement of federal health care fraud laws reflected in the HEAT program the enactment of recent amendments to the False Claims Act, 31 U.S.C. § 3729 (FCA)  under the “Fraud Enforcement and Recovery Act of 2009”(FERA).  The FERA amendments increase the likelihood both that whistleblowers will turn in health care providers and other individuals and organizations that file false claims in violation of the FCA and the liability that violators may incur for that misconduct.

The FERA amendments and the HEAT Team and Strike Force activities are part of a broader emphasis in the enforcement of federal health care fraud laws by both the Administration and Congress.  President Obama’s proposed Fiscal Year 2010 budget seeks to further increase funding for fraud prevention and enforcement by investing $311 million — a 50 percent increase from 2009 funding — to strengthen program integrity activities within the Medicare and Medicaid programs.  The Obama Administration anticipates that all combined, the anti-fraud efforts in the President’s budget could save $2.7 billion over five years by improving oversight and stopping fraud in the Medicare and Medicaid programs, including the Medicare Advantage and Medicare prescription drug programs.  Many state agencies also are stepping up their health care fraud investigations and enforcement.

In light of this new emphasis upon health care fraud detection and enforcement, health care providers now more than ever need to prepare to demonstrate the appropriateness and defensibility of their health care billing and other compliance efforts.

Curran Tomko and Tarski LLP Health Care Practice Chair Cynthia Marcotte Stamer has extensive experience advising and assisting health care practitioners and other businesses and business leaders to establish, administer, investigate and defend health care fraud and other compliance and internal control policies and practices to reduce risk under federal and state health care and other laws. You can get more information about her health industry experience here.  

If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer, CTT Health Care Practice Group Chair, at cstamer@cttlegal.com, 214.270.2402 or your other favorite Curran Tomko Tarski LLP attorney. 

Other Helpful Resources & Other Information

We hope that this information is useful to you.  If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.

©2009 Cynthia Marcotte Stamer.  All rights reserved. 


53 Doctors, Health Care Executives & Beneficiaries Indicted For Involvement In A $50 Million Alleged False Billing Ring

June 24, 2009

Fifty-three people have been indicted for schemes to submit more than $50 million in false Medicare claims in the continuing operation of the Medicare Fraud Strike Force in Detroit, Attorney General Eric Holder, Department of Health and Human Services (HHS) Secretary Kathleen Sebelius, and FBI Director Robert Mueller announced today (June 24, 2009).

The charges were unsealed today against the 53 individuals who are accused of various Medicare fraud offenses, including conspiracy to defraud the Medicare program, criminal false claims and violations of the anti-kickback statutes.  The indictments returned by a grand jury in Detroit resulted in arrests in Miami, New York City and Detroit. 

According to the DOJ, federal agents from the FBI and the HHS Office of Inspector General (HHS-OIG) began executing arrest warrants and made arrests in Detroit, Miami and New York City earlier today as part of a concentrated effort targeting infusion therapy and physical/occupational therapy providers involved in schemes orchestrated to defraud the Medicare program.

Collectively, the indictment accuses the physicians, medical assistants, patients, company owners and executives charged in the indictments of conspiring to submit more than $50 million in false claims to the Medicare program.  According to the indictments, the defendants participated in schemes to submit claims to Medicare for treatments that were in fact medically unnecessary and oftentimes, never provided.  In many cases, indictments also allege that beneficiaries accepted cash kickbacks in return for allowing providers to submit forms saying they had received the unnecessary and not provided treatments.  An indictment is merely an allegation, and defendants are presumed innocent until and unless proven guilty.

The investigation and enforcement action that lead to today’s indictment was conducted as part of the continuing activities of the new interagency Health Care Fraud Prevention and Enforcement Action Team (HEAT) that DOJ and HHS jointly announced last month.  On May 20, 2009, DOJ and HHS jointly announced they were combining forces to find and prosecute health care fraud through the HEAT and identified Detroit and Houston as cities targeted for Medicare Fraud Strike Force attention.

Before the May 20, 2009 HEAT announcement, Medicare Fraud Strike Forces operating demonstration projects in South Florida and Los Angeles already had produced a number of indictments. The Medicare Fraud Strike Force team operating in South Florida has already convicted 146 defendants and secured $186 million in criminal fines and civil recoveries.  After the success of operations in South Florida, the Medicare Fraud Strike Force expanded in May 2008 to phase two in Los Angeles, where 37 defendants have been charged with criminal health care fraud offenses.  To date in the Los Angeles cases, more than $55 million has been ordered in restitution to the Medicare program.  The success of these demonstration projects lies behind the founding of the HEAT initiative.

The heightened emphasis on enforcement of federal health care fraud laws reflected in the HEAT program the enactment of recent amendments to the False Claims Act, 31 U.S.C. § 3729 (FCA)  under the “Fraud Enforcement and Recovery Act of 2009”(FERA).  The FERA amendments increase the likelihood both that whistleblowers will turn in health care providers and other individuals and organizations that file false claims in violation of the FCA and the liability that violators may incur for that misconduct.

The FERA amendments and the HEAT Team and Strike Force activities are part of a broader emphasis in the enforcement of federal health care fraud laws by both the Administration and Congress.  President Obama’s proposed Fiscal Year 2010 budget seeks to further increase funding for fraud prevention and enforcement by investing $311 million — a 50 percent increase from 2009 funding — to strengthen program integrity activities within the Medicare and Medicaid programs.  The Obama Administration anticipates that all combined, the anti-fraud efforts in the President’s budget could save $2.7 billion over five years by improving oversight and stopping fraud in the Medicare and Medicaid programs, including the Medicare Advantage and Medicare prescription drug programs.  Many state agencies also are stepping up their health care fraud investigations and enforcement.

In light of this new emphasis upon health care fraud detection and enforcement, health care providers now more than ever need to prepare to demonstrate the appropriateness and defensibility of their health care billing and other compliance efforts.

Curran Tomko and Tarski LLP Health Care Practice Chair Cynthia Marcotte Stamer has extensive experience advising and assisting health care practitioners and other businesses and business leaders to establish, administer, investigate and defend health care fraud and other compliance and internal control policies and practices to reduce risk under federal and state health care and other laws. You can get more information about her health industry experience here.  

If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer, CTT Health Care Practice Group Chair, at cstamer@cttlegal.com, 214.270.2402 or your other favorite Curran Tomko Tarski LLP attorney. 

Other Helpful Resources & Other Information

We hope that this information is useful to you.  If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.

©2009 Cynthia Marcotte Stamer.  All rights reserved. 


FTC Issues FAQ Guidance On Red Flag Rules Applicable To Health Care Providers & Others

June 12, 2009

The Federal Trade Commission (FTC) and five other federal agencies yesterday (June 11, 2009) jointly issued a set of frequently asked questions (FAQs) about  federal regulations on the “Red Flags and Address Discrepancy Rules” (Red Flag Rules) implementing sections of the Fair and Accurate Credit Transactions Act of 2003 (FACT Act) now scheduled to take effect on August 1, 2009.  

Health care providers and a broad range of other entities are among the organizations generally required to comply with the broadly reaching Red Flag Rules, which require “financial institutions” and “creditors” to develop and implement written Identity Theft Prevention Programs and require issuers of credit cards and debit cards to assess the validity of notifications of changes of address.  The rules also provide guidance for users of consumer reports regarding reasonable policies and procedures to employ when consumer reporting agencies send them notices of address discrepancy.  

The sweeping reach of the definition of “creditor: and “financial institutions” in the Red Flag Rules and other confusion about the Red Flag Rules have prompted the agencies to delay the deadline for compliance several times.  The most recent delay, which extended the compliance deadline from May 1 to August 1, 2009, was announced by the FTC on April 30, 2009.  The FTC promised to issue additional guidance to help promote better understanding of the rules when it announced this latest delay in the compliance deadline on April 30, 2009.

Fulfilling this promise, the FAQs discuss numerous aspects of the Red Flag Rules, including:

  • Types of entities and accounts covered;
    Establishment and administration of an Identity Theft Prevention Program;
  • Address validation requirements applicable to card issuers; and
  • Obligations of users of consumer reports upon receiving a notice of address discrepancy.

FACTA directed financial regulatory agencies, including the FTC, to promulgate rules requiring “creditors” and “financial institutions” with covered accounts to implement programs to identify, detect, and respond to patterns, practices, or specific activities that could indicate identity theft. FACTA’s definition of “creditor” applies to any entity that regularly extends or renews credit – or arranges for others to do so – and includes all entities that regularly permit deferred payments for goods or services. Accepting credit cards as a form of payment does not, by itself, make an entity a creditor. Some examples of creditors are finance companies; automobile dealers that provide or arrange financing; mortgage brokers; utility companies; telecommunications companies; non-profit and government entities that defer payment for goods or services; and businesses that provide services and bill later, including many  doctors and other health care providers and other professionals. “Financial institutions” include entities that offer accounts that enable consumers to write checks or make payments to third parties through other means, such as other negotiable instruments or telephone transfers.  The FTC has made clear it perceives most health care providers as falling within the scope of these rules.

FACTA is only one of a growing list of the evolving privacy and data security mandates applicable to businesses under federal and state laws that organizations must address under applicable federal laws.   In addition to FACTA, most businesses also face other specific data security and data breach requirements under a tapestry of other federal and state laws which are constantly evolving.  In addition to these FACTA and other generally applicable data security and breach rules, many organizations face evolving industry specific mandates. For example, health care providers, health plans, health care and their business associates also are required to update their privacy and data security practices to comply with recent amendments to the Health Insurance Portability & Accountability Act Privacy & Security Standards signed into law February 17, 2009.

Many of these federal laws provide for both civil penalties as well as criminal penalties that bring violations of these regulations under the Federal Sentencing Guidelines.  As a consequence, most organizations need to implement and administer compliance programs to manage these Federal Sentencing Guideline risks.  Even where criminal sanctions are not triggered, noncompliance with these and other data security mandates can trigger substantial judgment awards, administrative penalties or both.

If you need assistance with auditing, updating, administering or defending your privacy, data security or other privacy and data security practices or addressing other health care compliance, risk management, transactions or operations concerns, please contact Cynthia Marcotte Stamer at (214) 270-2402, CStamer@CTTLegal.com.

For More Information

We hope that this information is useful to you. You can find more information about the Red Flag Rules and other privacy and identity theft matters at here. You also can review other recent health care and internal controls resources and additional information about the health industry and other experience of Ms. Stamer here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information to CStamer@CTTLegal.com.


Newly Enacted FERA Amendments To False Claims Act Signal New Risks For Health Industry Organizations & Others

May 26, 2009

Health care providers and other parties covered by the False Claims Act, 31 U.S.C. § 3729 (FCA), now face expanded whistleblower and other liability under amendments to the FCA enacted under the “Fraud Enforcement and Recovery Act of 2009”(FERA).  The amendments increase the likelihood both that whistleblowers will turn in health care providers and other individuals and organizations that file false claims in violation of the FCA and the liability that violators may incur for that misconduct.

Signed into law by President Obama last Wednesday (May 20, 2009), FERA immediately upon enactment:

  • Amends the whistleblower protections afforded to employees, contractors and agents who suffer retaliation for taking lawful efforts to stop violations of the FCA and to make it easier for those individuals to pursue retaliation claims;
  • Expands liability under for making false or fraudulent claims to the federal government under the FCA;
  • Applies liability under the FCA for presenting a false or fraudulent claim for payment or approval (currently limited to such a claim presented to an officer or employee of the federal government); and
  • Requires persons who violate such Act to reimburse the federal government for the costs of a civil action to recover penalties or damages 

Concurrent with President Obama’s signature of FERA into law, the U.S. Departments of Justice (DOJ) and Health & Human Services (HHS) jointly announced the expansion of federal health care fraud enforcement efforts.  On May 20, 2009, HHS and DOJ announced their activation of a new interagency team to combat health care fraud highlights the increasing need for health care providers and health plans to review and tighten their practices for dealing with Medicare and other federal programs to survive scrutiny under federal health care fraud initiatives.  Coupled with FERA and the already significant increase in federal health care fraud detection and enforcement activities in recent years and a proposed 50 percent increase in funding for these activities included in President Obama’s Fiscal Year 2010 budget, health care providers and payers must be prepared to defend their dealing with Medicare, Medicaid and other federal health care programs.

The expanded protections afforded under FERA to whistleblowers and others suffering retaliation for opposing or reporting illegal actions can be expected to serve as a key tool in these efforts. These new retaliation safeguards are designed further increase the likelihood that employees and other insiders will help government officials ferret out false claims and other fraud. Specifically with regard to retaliatory action claims Section 4(d) of FERA amends 31 U.S.C.§ 3730(h) to provide for the recovery of “all relief necessary to make that employee, contractor, or agent whole” where that individual is discharged, demoted, suspended, threatened, harassed, or in any other manner discriminated against in the terms and conditions of employment because of lawful acts he does or takes on behalf of an individual in furtherance of other efforts to stop a violation of the FCA. 

FERA expressly provides that relief to victims of retaliation will include “reinstatement with the same seniority status that employee, contractor, or agent would have had but for the discrimination, 2 times the amount of back pay, interest on the back pay, and compensation for any special damages sustained as a result of the discrimination, including litigation costs and reasonable attorneys’ fees.” 

The FERA amendments to the FCA, the new TEAMS enforcement effort announced simultaneously with its signature into law mean that health care industry organizations and others covered by the FCA must implement appropriate fraud prevention, detection, redress and other procedures to help defend against possible FCA or other health care fraud claims and investigations.

The attorneys at Curran Tomko Tarski, LLC have extensive experience representing and advising health industry and other clients against FCA and other federal health care and fraud laws. 

For More Information

We hope that this information is useful to you. If you need assistance with auditing or defending health care fraud concerns or other health care compliance, risk management, transactions or operations concerns, please contact Curran Tomko Tarski LLP Partners Cynthia Marcotte Stamer at (214) 270-2402, CStamer@CTTLegal.com; Michael T. Tarski at (214) 270-1420 or MTarski@CTTLegal.com; Edwin J. Tomko at (214) 270-1405 or ETomko@CTTLegal.com.

You can review other recent health care and internal controls resources and additional information about the health industry and white collar experience of the Curran Tomko Tarski LLP attorneys at http://www.CTTLegal.com. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at CTTLegal.com or e-mailing this information to CStamer@CTTLegal.com.


Stamer To Discuss “Making Gainsharing Work: Managing Physician Performance” At June 17, 2009 Dallas Bar Association Health Law Section Meeting

May 26, 2009

Health care organizations, health plans and regulars increasingly point to gainsharing and pay-for-performance strategies as key to securing needed key physician buy-in and performances to achieve desired health care quality and cost objectives.  Using physician gainsharing to promote desired performances within the bounds of the law without undesirable side effects involves more than staying within the STARK exceptions and anti-kickback safe harbors. 

Curran, Tomko Tarski, LLP attorney Cynthia Marcotte Stamer will discuss key strategies and processes for designing and administering legally defensible pay-for-performance and other gainsharing arrangements that promote desired outcomes in operation at the Dallas Bar Association Health Law Section meeting on June 17, 2009. 

Former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, attorney and author Cynthia Marcotte Stamer is nationally and internationally recognized for her legal work, publications and programs, and advocacy on health industry performance management and other health industry matters.  Ms. Stamer works extensively with health care organizations, managed care and health insurance organizations, governments and others to manage performance and legal risks.  Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, Ms. Stamer combines her more than 22 years of health industry regulatory and risk management experience with an in-depth knowledge of workforce management and regulation to help clients manage performance and legal and operational risks.  Her experience includes advising public and private health industry clients domestically and internationally on a wide range of matters.  A widely published author and popular speaker, Ms. Stamer’s insights on health industry matters also are quoted in HealthLeaders, Managed Care Executive, the Wall Street Journal and many other national popular, business and industry publications.

 Ms. Stamer is scheduled to begin her remarks at Noon on June 17, 2009 at the offices of the Dallas Bar Association located at 2101 Ross Avenue, Dallas, Texas 75201.  For additional information, call the Dallas Bar Association at 214-220-7400 or see http://www.dallasbar.org.


DOJ/HHS Step Up Health Care Fraud Enforcement By Announcing New Interagency Health Care Fraud Prevention and Enforcement Action Team

May 20, 2009

Lead DOJ Health Care Fraud Enforcer Speaks In Dallas Tomorrow

The joint announcement today (May 20, 2009) by the U.S. Departments of Justice (DOJ) and Health & Human Services (HHS) of a new interagency team to combat health care fraud highlights the increasing need for health care providers and health plans to review and tighten their practices for dealing with Medicare and other federal programs to survive scrutiny under federal health care fraud initiatives.   Houston and Detroit are targeted for the attention of a new Strike Force.

Participants attending tomorrow’s Dallas Health Industry Council Southwest Healthcare Transaction Conference will get to hear the latest about these and other federal health care fraud prevention and enforcement activities from one of its key players. The Justice Department’s lead federal health care fraud prosecutor, John “Jay” S. Darden, the U.S. Department of Justice Assistant Chief for Healthcare Fraud is scheduled to provide an update on these and other federal regulatory and enforcement activities affecting health care transactions when he speaks at the Conference tomorrow afternoon at the Omni Mandalay Hotel Dallas at Las Colinas at 1:30 p.m.

Attorney General Eric Holder and Health and Human Services (HHS) Secretary Kathleen Sebelius announced the creation of the Health Care Fraud Prevention and Enforcement Action Team (HEAT), to combat Medicare fraud and the expansion of Strike Force team operations to Detroit and Houston.  Medicare Fraud Strike Forces, currently in operation in South Florida and Los Angeles, fight Medicare fraud on a targeted local level.  Statements made by Secretary Sebelius and Attorney General Holder in connection with the announcement of HEAT and the Strike Force Expansion make clear that the Obama Administration views health care fraud enforcement and prevention as a key element of its efforts to control health care costs.

The HEAT team will include senior officials from DOJ and HHS who will build upon and strengthen existing programs to combat fraud while also investing new resources and technology to prevent fraud, waste and abuse before it happens.  Efforts will include the expansion of joint DOJ-HHS Medicare Fraud Strike Force teams that have been successfully fighting fraud in South Florida and Los Angeles. 

Established in 2007, these Strike Force teams have a proven record of success using a “data-driven” approach to identify unexplainable billing patterns and investigating these providers for possible fraudulent activity.  The Medicare Fraud Strike Force team operating in South Florida has already convicted 146 defendants and secured $186 million in criminal fines and civil recoveries.  After the success of operations in South Florida, the Medicare Fraud Strike Force expanded in May 2008 to phase two in Los Angeles, where 37 defendants have been charged with criminal health care fraud offenses.  To date in the Los Angeles cases, more than $55 million has been ordered in restitution to the Medicare program. 

In addition to health care fraud enforcement and prosecution, HHS and DOJ also view prevention as critical to reforming the system.  Therefore, in addition to investigating and prosecuting fraud, the HEAT team will also focus critical resources on preventing fraud from occurring in the first place.  These efforts are expected to include:

  • Drawing from demonstration projects by the HHS Inspector General and the Centers for Medicare & Medicaid Services (CMS) that have focused on suppliers of durable medical equipment (DME) including increasing site visits to potential suppliers to prevent imposters from posing as legitimate DME providers. 
  • Increasing training for providers on Medicare compliance, offering providers the resources and the knowledge they need to help identify and prevent fraud.
  • Improving data sharing between CMS and law enforcement to help identify patterns that lead to fraud.
  • Strengthening program integrity activities to monitor and ensure Medicare Parts C (Medicare Advantage plans) and D (prescription drug programs) compliance and enforcement.

The Attorney General and the HHS Secretary also called on the American people to visit a new Web site http://www.hhs.gov/stopmedicarefraud or call 1-800-HHS-TIPS (1-800-447-8477) to report suspected Medicare fraud.

The HEAT Team and Strike Force activities are part of a broader emphasis in the enforcement of federal health care fraud laws.  President Obama’s proposed Fiscal Year 2010 budget seeks to further increase funding for fraud prevention and enforcement by investing $311 million — a 50 percent increase from 2009 funding — to strengthen program integrity activities within the Medicare and Medicaid programs.  The Obama Administration anticipates that all combined, the anti-fraud efforts in the President’s budget could save $2.7 billion over five years by improving oversight and stopping fraud in the Medicare and Medicaid programs, including the Medicare Advantage and Medicare prescription drug programs.

For More Information

We hope that this information is useful to you. If you need assistance responding to concerns about the matters discussed in this publication or other health care concerns, wish to obtain information about arranging for training or presentations by Ms. Stamer, wish to suggest a topic for a future program or update, or wish to request other information or materials, please contact Ms. Stamer via telephone at (214) 270-2402 or via e-mail to cstamer@CTTLegal.com.

You can review other recent updates and other publications by Ms. Stamer and other helpful health care resources and additional information about Ms. Stamer and her experience, see Stamer Health Industry Experience. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here or by registering to participate in the Solutions Law Press Health Care Update blog at Health Care Update Blog. For important information concerning this communication click here.    If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.


HIPAA Complaint Basis For Texas Whistleblower Claim

April 4, 2009

In a March 19, 2009 ruling, the U.S. District Court for the Northern District of Texas recently recognized that the Texas Whistleblower Act prohibits health care organizations run by the State of Texas from retaliating against employees for making good faith complaints of violations of the Privacy Rules of the Health Insurance Portability Act (“HIPAA”).Nevertheless, the court dismissed the wrongful discharge lawsuit brought by a former Terrell State Hospital security guard who alleged he was wrongfully fired for complaining to the U.S. Department of Health and Human Services Office of Civil Rights (”OCR”) that the Hospital violated the HIPAA Privacy Rules because the plaintiff had failed to present sufficient proof that he was terminated in retaliation for filing a HIPAA complaint.

 

Illustrative of a growing number of state law retaliatory discharge claims brought be employees claiming to have been retaliated against for complaining about alleged violations of HIPAA’s Privacy Rules, Faulkner v. Department of State Health Servs., 2009 U.S. Dist. LEXIS 22419 (N.D. Tex. Mar. 19, 2009), involved claims made by plaintiff Anthony Faulkner (”Faulkner”) that the Texas Department of State Health Services (”DSHS”); Terrell State Hospital; Texas DSHS Commissioner David L. Lakey, M.D.; Terrell State Hospital Superintendent Fred Hale; and Terrell State Hospital Risk Management Coordinator Clent Holmes, R.N. violated the Whistleblower Act and the First and Fourteenth Amendments by firing him seven days after he complained to OCR that Terrell State Hospital violated the HIPAA Privacy Rule by leaving admissions logs containing patient names and admission dates in a public area.

The Texas Whistleblower Act generally prohibits a state or local governmental entity from terminating or taking any other adverse personnel action against a public employee who in good faith reports a violation of law by the employing governmental entity or another public employee to an appropriate law enforcement authority.See Tex. Gov’t Code § 554.002(a).While the Court affirmed that the Texas Whistleblower Act permits a public employee of the State of Texas discharged or otherwise retaliated against for complaining in good faith to OCR that his public employer or its employee violated the HIPAA Privacy Rules, the Court nevertheless granted summary judgment to the defendants.

According to the court, Faulkner’s failure to introduce evidence rebutting defendant’s affidavit that he was terminated for repeatedly violating rules requiring him to report suspected abuse of patients precluded him from proving his termination was in retaliation for his filing of the HIPAA complaint.Meanwhile, the court also ruled that Faulkner’s claims against the individual defendants should be dismissed as the Whistleblower Act only creates a cause of action against governmental entities and not their employees. Having found Faulkner’s constitutional claims also without merit, the District Court granted the defendant’s motion for summary judgment.

While the defendants were able to overcome Faulkner’s retaliatory discharge claim, the decision highlights the need for health care providers and other HIPAA covered entities to take appropriate precautions to defend against potential wrongful discharge, retaliation or other claims by employees or other service providers for complaining of possible HIPAA violations or for attempting to exercise other HIPAA-protected rights.HIPAA covered entities now should avoid engaging in actions that might unnecessarily fuel claims of retaliation.  They also should carefully document and preserve evidence necessary to demonstrate the legitimacy of their disciplinary actions on an ongoing basis.

We hope you found this information helpful. If your organization needs assistance with understanding or managing its responsibilities or liabilities under HIPAA or other health care or employment laws or wishes to inquire about HIPAA training or other services and experience of Cynthia Marcotte Stamer, please contact Ms. Stamer via e-mail at Cstamer@Solutionslawyer.net or by telephoning Ms. Stamer at 469.767.8872.You also can review other helpful resources and register to receive other updates at CynthiaStamer.com.


Connecticut Man Pleads Guilty To Multi-Million Dollar Tax Fraud Conspiracy Involving False Charges For Hospital Maintenance & Insulation Services

April 4, 2009

A Connecticut resident faces  five years in prison, three years of supervised release and a $250,000 fine after pleading guilty this week to conspiracy to aid another in filing false tax returns between approximately 2000 and February 2005 through a fraudulent check cashing scheme for the owner of a corporation that was engaged in the business of providing maintenance and insulation services to New York Presbyterian Hospital (NYPH).  The action reflects the risks to individuals and businesses that illegally claim tax deductions, bill for services or violate other federal criminal laws.

Krzysztof Koczon plead guilty in U.S. District Court in Manhattan to charges he provided false documentation to co-conspirators indicating that he had performed construction services and received more than $2.3 million in checks from the co-conspirators as payment for the construction services, the Department of Justice announced Thursday, April 2, 2009.   Koczon cashed the checks but returned the bulk of the money to the co-conspirators in exchange for a fee. The co-conspirators then took false deductions for those payments made to Koczon’s businesses.

The tax fraud conspiracy that Koczon is charged with carries a maximum penalty of five years in prison, three years of supervised release and a $250,000 fine. The maximum fine may be increased to twice the gain derived from the crime or twice the loss suffered by the victims of the crime, if either of those amounts is greater than the statutory maximum fine.

In April 2007, as part of the same investigation, Michael Theodorobeakos and two maintenance and insulation companies he co-owned–Monosis Inc. and STU Associates Inc. pleaded guilty to conspiring to rig bids on the supply of maintenance and insulation services to NYPH and Mount Sinai Medical Center (Mount Sinai). In addition, Michael Vignola and Mister AC Ltd. pleaded guilty in November 2007 to conspiring to rig bids on heating, ventilation and air conditioning (HVAC) services provided to NYPH and paying kickbacks to former NYPH purchasing officials. In April 2008, Aaron S. Weiner pleaded guilty to participating in a conspiracy wherein Weiner acted as a conduit in another million-dollar kickback scheme also involving one of the same former NYPH purchasing officials involved with the Vignola kickback schemes. On March 25, 2009, Mariusz Debowski pleaded guilty to participating in the same tax fraud conspiracy at NYPH.

These charges arose from an ongoing federal antitrust investigation of fraud, bribery, tax-related offenses and bidding irregularities relating to contracts administered by the Facilities Operations Department and the Engineering Department at NYPH and the Engineering Department at Mount Sinai conducted by the Antitrust Division’s New York Field Office, the FBI and the Internal Revenue Service Criminal Investigation’s New York Field Office.

Cynthia Marcotte Stamer, Ed Tomko and other members of Curren Tomko and Tarski LLP are experienced with assisting health industry and other clients establish and administer internal and external fraud and other controls, investigate potential fraud or other misconduct, defend Federal or state criminal or civil investigations, audits and prosecutions.  If your organization needs assistance with assessing or managing its compliance responsibilities or liabilities under health care, employment, environmental, antitrust, securities or other federal or state laws, wishes to inquire about compliance audit or training or other services; or would like to review or engage and experience of Ms. Stamer, Mr. Tomko or other Curren Tomko Tarski LLP attorneys, please contact Ms. Stamer at cstamer@cttlegal.com, (214) 270-2402;  or Mr. Tomko at etomko@cttlegal.com, (214) 270-1405, or see CTTLegal.com or CynthiaStamer.com.