HIPAA & your practice management software By Bruce D. Armon, Esq. & Shardul Mehta

Size: px
Start display at page:

Download "HIPAA & your practice management software By Bruce D. Armon, Esq. & Shardul Mehta"

Transcription

1 HIPAA & your practice management software By Bruce D. Armon, Esq. & Shardul Mehta Published March 2002 React to this article in the Discussion Forum. Most physician practices are computerized in some fashion. The level of computerization may range from simple billing functions and patient scheduling to electronic medical records and entire practice management activities. By now, most of the health care industry has heard of the Health Insurance Portability and Accountability Act (HIPAA). HIPAA does not require practices to purchase computer systems. However, the installation of a HIPAA-compliant software system may actually help a practice reduce its administrative costs. Two of the principal areas of a physician s practice affected by HIPAA are the practice s billing software and practice management software. HIPAA includes six sets of rules related to the format of electronic transactions; protection of patient s privacy; ensuring the security of patients health information; and defining universal identifiers for individuals, health care providers and employers. The timeline for compliance for two components of HIPAA is rapidly approaching. These are the Transactions and Code Set Standard (Transaction Standards) and the Privacy Standards, which have already been finalized and are set to take effect in October 2002 and April 2003, respectively. President Bush recently extended the deadline for compliance with the Transaction Standards to October However, this is not a blanket extension of the deadline. Congress recognized that this extension had the potential to result in an indefinite delay in the implementation of the Transaction Standards. Therefore, HIPAA-covered entities (this includes physicians and their practices) must get approval for an extension from the Secretary of HHS. The covered entity must explain how it plans to use the extra year to achieve compliance. HHS is required to provide a model compliance form for covered entities seeking an extension by March 31, 2002, though a covered entity is not required to use this model form when making its request for an extension. If no extension is sought, all

2 covered entities that can reasonably meet the original October 2002 deadline are expected to continue their efforts to do so. Regardless of whether a physician practice seeks an extension, it must begin internally evaluating its own practice and its relationships with its various vendors now to ensure a smooth HIPAA-compliant transition. According to the 2000 edition of Guide to Medical Practice Software published by Harcourt, there are more than 1,500 active practice management software vendors. The medical practice software industry has revenues exceeding $4 billion per year. Hence, how does a physician practice evaluate its current software system for HIPAA compliance? If the practice is in the market for a new software system, how should it evaluate various vendors in terms of HIPAA compliance? Make sure the vendor understands the requirements of the Transaction Standards. The Transaction Standards has specified ANSI ASC X12 as the standard for electronic transactions, including billing, payment, eligibility verification and preauthorization. This means, for example, that a physician must make sure the electronic claims sent to payers are in ANSI ASC X12 format. According to HHS, there are approximately 400 different formats currently in place for electronic health transactions. Therefore, whether a practice is evaluating its current computer vendor or shopping for a new one, it should make sure that the vendor is not only aware of the Transaction Standards, but is able to speak intelligently about how their systems are, or will be, compliant with the Transaction Standards. Here are two examples of the potential impact of the Transaction Standards on a physician s computer system. Dr. A uses a computer system that prepares claim information in an electronic file to be submitted to a clearinghouse. Once the system prepares the electronic file, Dr. A dials into the bulletin board service (BBS) provided by the clearinghouse and uploads the electronic file. Some time later, Dr. A dials back into the BBS and downloads an electronic remittance file. Dr. A s software reads this file and automatically posts payment information. In this example, Dr. A will get maximum value for his or her computer software if both the electronic claim file prepared by the computer system and the electronic remittance file provided by the clearinghouse are in standard ANSI format. This is possible only if both Dr.

3 A s system and the clearinghouse accept and submit standard transactions. Dr. B uses a computer system that prepares claim information in an electronic file to be submitted directly to a payer (e.g., Medicare). Dr. B dials into the payer s BBS and uploads the electronic file. Some time later, Dr. B dials back into the payer s BBS and downloads an electronic remittance file. Dr. B s software reads this file and automatically posts payment information. In this example, both Dr. B s system and the payer must support standard transactions, since Dr. B and the payer are transacting directly with each other. A physician will get maximum value if his or her billing or practice management system is able to prepare, send, receive and process ANSI standard electronic transactions. Note that HIPAA does not apply to the format in which data is stored. Computer systems are free to use any data format of their choosing in order to store data. HIPAA only applies to the format in which data is transmitted. Check if the vendor is able to assist the practice in complying with the Privacy Rule. The Privacy Rule imposes numerous requirements upon physicians and their practices. For instance, prior to disclosing a patient s protected health information (PHI) for the purposes of treatment, payment or health care operations (TPO), a physician practice must obtain the patient s consent. In addition, a physician practice must obtain a patient s authorization to use or disclose PHI for purposes other than TPO. An authorization is more detailed and specific, and has a definite expiration date. A practice management system can ease the administrative headaches a physician practice may encounter in complying with the Privacy Rule with a few simple mouse clicks. For example, the practice management system could provide the following functions: Tracking the date that the patient s consent was obtained. Maintaining electronic copies of the signed consent and authorization forms. Tracking patient requests for restrictions on use and disclosure of PHI, whether the physician agreed to the request, and if so, retaining a copy of the modified consent.

4 Tracking whether and when the consent was revoked by the patient. Tracking when patient authorizations were obtained, what they were obtained for, and their expiration dates. The Privacy Standards provide that a patient may request an accounting of all disclosures made by a covered entity (which includes a physician) within the preceding six years. The accounting of the disclosure must include, among other items, the date, name and address (if available) of the person or entity that received the information, and a description of the PHI disclosed. Practice management software designed in compliance with the Privacy Standards could make all of this information available to the physician s office by viewing the main "window" or connected "windows" related to that particular patient, rather than having to undertake a manual review of the hard copy of the file. Note that a software vendor is not required to provide all of these services. However, it is in the best interest of a physician practice to partner with a vendor who is willing to work with the practice in achieving HIPAA compliance. Be aware that, if a practice contracts with an entity considered a "business associate" as described by the Privacy Standards, the practice should make sure that the agreement between them includes certain protections as defined in the Privacy Standards. This includes a requirement that the business associate use appropriate safeguards to prevent use of disclosure of PHI other than as provided in the agreement. During the course of the upcoming months physicians will be bombarded with requests and reminders to ensure their practices are HIPAA-compliant. Because so many physician practices now rely on sophisticated computer systems to assist them with their day-to-day office activities, physicians need to start reviewing their current practice management and billing systems. Doing so can save them time, money and administrative headaches in the long run. If a physician finds that his or her current vendor is unable or unwilling to help it meet the HIPAA standards, then now is time to begin shopping for a new vendor whose products and services can help the physician s practice achieve HIPAA compliance before the HIPAA compliance date. Bruce D. Armon, Esq., is a member of the Health Law Practice of Saul Ewing LLP in its Philadelphia office.

5 Shardul Mehta is Product Manager at InfoQuest Systems, Inc., a full service provider of health care information management systems. Free Offer! Get Daily News Briefs by , Physician's News Digest, Inc. All rights reserved. Delaware Valley Edition Texas Edition Western PA Edition Recruitment Cover Story Cover Story Cover Story CME Spotlight Interview Spotlight Interview Spotlight Interview Discussion News Briefs Medicine & Computers News Briefs Editor's Notebook Medicine & the Law Editor's Notebook Search Commentary Medicine & Business Commentary Archives Medicine & Computers Personal Finance Medicine & Computers About PND Medicine & the Law Medicine & the Law Advertising Medicine & Business Medicine & Business List Rentals Personal Finance Personal Finance Subscriptions

HIPAA (The Health Insurance Portability and Accountability Act)

HIPAA (The Health Insurance Portability and Accountability Act) Section 16. HIPAA Requirements and Information HIPAA (The Health Insurance Portability and Accountability Act) Molina Healthcare s Commitment to Patient Privacy Protecting the privacy of members personal

More information

Understanding the HIPAA standard transactions: The HIPAA Transactions and Code Set rule

Understanding the HIPAA standard transactions: The HIPAA Transactions and Code Set rule Understanding the HIPAA standard transactions: The HIPAA Transactions and Code Set rule Many physician practices recognize the Health Information Portability and Accountability Act (HIPAA) as both a patient

More information

HIPAA Administrative Simplification and Privacy (AS&P) Frequently Asked Questions

HIPAA Administrative Simplification and Privacy (AS&P) Frequently Asked Questions HIPAA Administrative Simplification and Privacy (AS&P) Frequently Asked Questions ELECTRONIC TRANSACTIONS AND CODE SETS The following frequently asked questions and answers were developed to communicate

More information

HIPAA COMPLIANCE AND THE EMPLOYMENT INDICATOR SYSTEM

HIPAA COMPLIANCE AND THE EMPLOYMENT INDICATOR SYSTEM HIPAA COMPLIANCE AND THE EMPLOYMENT INDICATOR SYSTEM January 26, 2010 Presented by: Sandra K. Mann, Esquire Devine, Millimet & Branch, P.A. 111 Amherst Street Manchester, NH 03101 603.695.8656 smann@devinemillimet.com

More information

PERSONAL HEALTH RECORDS AND

PERSONAL HEALTH RECORDS AND PERSONAL HEALTH RECORDS AND THE HIPAA PRIVACY RULE INTRODUCTION A personal health record (PHR) is an emerging health information technology that individuals can use to engage in their own health care to

More information

APPENDIX 1: Frequently Asked Questions

APPENDIX 1: Frequently Asked Questions APPENDIX 1: Frequently Asked Questions Practice Name Q: What is the HIPAA Privacy Rule? A: The HIPAA Privacy Rule controls the use and disclosure of what is known as Protected Health Information (PHI).

More information

General HIPAA Implementation FAQ

General HIPAA Implementation FAQ General HIPAA Implementation FAQ What is HIPAA? Signed into law in August 1996, the Health Insurance Portability and Accountability Act ( HIPAA ) was created to provide better access to health insurance,

More information

GENERAL OVERVIEW OF STANDARDS FOR PRIVACY OF INDIVIDUALLY IDENTIFIABLE HEALTH INFORMATION [45 CFR Part 160 and Subparts A and E of Part 164]

GENERAL OVERVIEW OF STANDARDS FOR PRIVACY OF INDIVIDUALLY IDENTIFIABLE HEALTH INFORMATION [45 CFR Part 160 and Subparts A and E of Part 164] GENERAL OVERVIEW OF STANDARDS FOR PRIVACY OF INDIVIDUALLY IDENTIFIABLE HEALTH INFORMATION [45 CFR Part 160 and Subparts A and E of Part 164] OCR HIPAA Privacy The following overview provides answers to

More information

HIPAA Considerations for Small Non-Profits. Jill M. Girardeau July 20, 2011

HIPAA Considerations for Small Non-Profits. Jill M. Girardeau July 20, 2011 HIPAA Considerations for Small Non-Profits Jill M. Girardeau July 20, 2011 Mission of Pro Bono Partnership of Atlanta: To provide free legal assistance to community-based nonprofits that serve low-income

More information

Health Insurance Portability and Accountability Act HIPAA. Glossary of Common Terms

Health Insurance Portability and Accountability Act HIPAA. Glossary of Common Terms Health Insurance Portability and Accountability Act HIPAA Glossary of Common Terms Terms: HIPAA Definition*: PHCS Definition/Interpretation: Administrative Simplification HIPAA Subtitle F It is the purpose

More information

HIPAA CHECKLISTS DEVELOPING YOUR HIPAA DOCUMENTS PRACTICAL TOOLS AND RESOURCES. MASSACHUSETTS MEDICAL SOCIETY Getting Ready for

HIPAA CHECKLISTS DEVELOPING YOUR HIPAA DOCUMENTS PRACTICAL TOOLS AND RESOURCES. MASSACHUSETTS MEDICAL SOCIETY Getting Ready for MASSACHUSETTS MEDICAL SOCIETY Getting Ready for HIPAA BASIC ELEMENTS FOR COMPLIANCE WITH THE PRIVACY REGULATIONS CHECKLISTS Assess and Begin Your HIPAA Compliance Efforts DEVELOPING YOUR HIPAA DOCUMENTS

More information

-1- PERSONNEL CERTIFIED / NON-CERTIFIED 4112.61/4212.61

-1- PERSONNEL CERTIFIED / NON-CERTIFIED 4112.61/4212.61 -1- HIPAA Privacy Policies The Wallingford Board of Education ("the Board" or the "Plan Sponsor") sponsors a group health plan that provides medical and dental benefits (the "Plan"). These Privacy Policies

More information

MEDICARE TEXAS (TRAILBLAZERS) PRE ENROLLMENT INSTRUCTIONS MR085

MEDICARE TEXAS (TRAILBLAZERS) PRE ENROLLMENT INSTRUCTIONS MR085 MEDICARE TEXAS (TRAILBLAZERS) PRE ENROLLMENT INSTRUCTIONS MR085 HOW LONG DOES PRE ENROLLMENT TAKE? Standard processing time is 5 business days after receipt. WHAT FORM(S) SHOULD I COMPLETE? IF you have

More information

Shipman & Goodwin LLP. HIPAA Alert STIMULUS PACKAGE SIGNIFICANTLY EXPANDS HIPAA REQUIREMENTS

Shipman & Goodwin LLP. HIPAA Alert STIMULUS PACKAGE SIGNIFICANTLY EXPANDS HIPAA REQUIREMENTS Shipman & Goodwin LLP HIPAA Alert March 2009 STIMULUS PACKAGE SIGNIFICANTLY EXPANDS HIPAA REQUIREMENTS The economic stimulus package, officially named the American Recovery and Reinvestment Act of 2009

More information

BUSINESS ASSOCIATES [45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)]

BUSINESS ASSOCIATES [45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)] OR HIPAA Privacy BUSINESS ASSOIATES [45 FR 164.502(e), 164.504(e), 164.532(d) and (e)] Background By law, the HIPAA Privacy Rule applies only to covered entities health plans, health care clearinghouses,

More information

The Privacy Rule is designed to minimize conflicts between Federal requirements and those of State law. It establishes a floor of Federal privacy

The Privacy Rule is designed to minimize conflicts between Federal requirements and those of State law. It establishes a floor of Federal privacy The Privacy Rule is designed to minimize conflicts between Federal requirements and those of State law. It establishes a floor of Federal privacy protections and individual rights with respect to individually

More information

Double-Take in a HIPAA Regulated Health Care Industry

Double-Take in a HIPAA Regulated Health Care Industry Double-Take in a HIPAA Regulated Health Care Industry Abstract: This document addresses the contingency plan and physical access control requirements of the Administrative Simplification security provision

More information

Introducing the NASW Updated Sample HIPAA Privacy Forms and Policies

Introducing the NASW Updated Sample HIPAA Privacy Forms and Policies Introducing the NASW Updated Sample HIPAA Privacy Forms and Policies Presenter: Sherri Morgan, JD, MSW Associate Counsel, NASW Legal Defense Fund and Office of Ethics & Professional Review 2013 National

More information

HIPAA Compliance Calendar

HIPAA Compliance Calendar TITLE DESCRIPTION National Provider Identifier National Provider Identifier This final rule establishes the standard for a unique health identifier for health care providers for use in the health care

More information

Chapter 4: Electronic Data Interchange

Chapter 4: Electronic Data Interchange Electronic Billing NOTE: ELECTRONIC CLAIM SUBMISSION IS REQUIRED UNDER SECTION 3 OF THE ADMINISTATIVE SIMPLIFICATION COMPLIANCE ACT (ASCA), PUB.L. 107-105, AND THE IMPLEMENTING REGULATION AT 42 CFR 424.32.

More information

Dear Provider, Vendor, Clearinghouse or Billing Service:

Dear Provider, Vendor, Clearinghouse or Billing Service: Dear Provider, Vendor, Clearinghouse or Billing Service: Thank you for your interest in Electronic Media Claims (EMC). Enclosed is a summary of the available electronic claims services for Medicare Part

More information

ELECTRONIC HEALTH RECORDS

ELECTRONIC HEALTH RECORDS ELECTRONIC HEALTH RECORDS Understanding and Using Computerized Medical Records CHAPTER TEN LESSON ONE Privacy and Security of Health Records Understanding HIPAA HIPAA: acronym for Health Insurance Portability

More information

MYTHS AND FACTS ABOUT THE HIPAA PRIVACY RULE PART 1

MYTHS AND FACTS ABOUT THE HIPAA PRIVACY RULE PART 1 CIRCA 2004 MYTHS AND FACTS ABOUT THE HIPAA PRIVACY RULE PART 1 Since April 14, 2003, health care providers, health plans, and health care clearinghouses have been required to be in compliance with the

More information

Entities Covered by the HIPAA Privacy Rule

Entities Covered by the HIPAA Privacy Rule Entities Covered by the HIPAA Privacy Rule Who Is A Covered Entity? HIPAA standards apply only to: Health care providers who transmit any health information electronically in connection with certain transactions

More information

Chapter. 21TMHP Electronic Data Interchange (EDI)

Chapter. 21TMHP Electronic Data Interchange (EDI) Chapter 21TMHP Electronic Data Interchange (EDI) 21 21.1 TMHP EDI Overview............................................... 21-2 21.2 Advantages of Electronic Services.....................................

More information

EDI TRADING PARTNER AGREEMENT BETWEEN DIRECT SUBMITTER AND WELLPOINT, INC.

EDI TRADING PARTNER AGREEMENT BETWEEN DIRECT SUBMITTER AND WELLPOINT, INC. EDI TRADING PARTNER AGREEMENT BETWEEN DIRECT SUBMITTER AND WELLPOINT, INC. This EDI Trading Partner Agreement, ( Agreement ) is entered into by and between Hoschton Medical, PC ( Direct Submitter or Trading

More information

INTERMEDIATE ADMINISTRATIVE SIMPLIFICATION CENTERS FOR MEDICARE & MEDICAID SERVICES. Online Guide to: ADMINISTRATIVE SIMPLIFICATION

INTERMEDIATE ADMINISTRATIVE SIMPLIFICATION CENTERS FOR MEDICARE & MEDICAID SERVICES. Online Guide to: ADMINISTRATIVE SIMPLIFICATION 02 INTERMEDIATE» Online Guide to: CENTERS FOR MEDICARE & MEDICAID SERVICES Last Updated: February 2014 TABLE OF CONTENTS INTRODUCTION: ABOUT THIS GUIDE... i About Administrative Simplification... 2 Why

More information

HIPAA Frequently Asked Questions Free & Charitable Clinic HIPAA Toolbox May 2014

HIPAA Frequently Asked Questions Free & Charitable Clinic HIPAA Toolbox May 2014 HIPAA Frequently Asked Questions Free & Charitable Clinic HIPAA Toolbox May 2014 Following is a list of FAQs answered by Ropes & Gray, a law firm focusing on health care practices, on behalf of AmeriCares

More information

SARASOTA COUNTY GOVERNMENT EMPLOYEE MEDICAL BENEFIT PLAN HIPAA PRIVACY POLICY

SARASOTA COUNTY GOVERNMENT EMPLOYEE MEDICAL BENEFIT PLAN HIPAA PRIVACY POLICY SARASOTA COUNTY GOVERNMENT EMPLOYEE MEDICAL BENEFIT PLAN HIPAA PRIVACY POLICY Purpose: The following privacy policy is adopted to ensure that the Sarasota County Government Employee Medical Benefit Plan

More information

The HIPAA Privacy Rule: Overview and Impact

The HIPAA Privacy Rule: Overview and Impact The HIPAA Privacy Rule: Overview and Impact DISCLAIMER: This information is provided as is without any express or implied warranty. It is provided for educational purposes only and does not constitute

More information

Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices

Graphic Communications National Health and Welfare Fund. Notice of Privacy Practices Notice of Privacy Practices Section 1: Purpose of This Notice and Effective Date THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION.

More information

PATIENT RECORDS PRIVACY POLICIES AND PROCEDURES FOR HIPAA COMPLIANCE (4/03)

PATIENT RECORDS PRIVACY POLICIES AND PROCEDURES FOR HIPAA COMPLIANCE (4/03) PATIENT RECORDS PRIVACY POLICIES AND PROCEDURES FOR HIPAA COMPLIANCE (4/03) Use and Disclosure of PHI: Protected Health Information ( PHI ) may not be used or disclosed in violation of the Health Insurance

More information

The HIPAA Security Rule Primer A Guide For Mental Health Practitioners

The HIPAA Security Rule Primer A Guide For Mental Health Practitioners The HIPAA Security Rule Primer A Guide For Mental Health Practitioners Distributed by NASW Printer-friendly PDF 2006 APAPO 1 Contents Click on any title below to jump to that page. 1 What is HIPAA? 3 2

More information

What it Means for You and Your Organization

What it Means for You and Your Organization HIPAA What it Means for You and Your Organization Wednesday, October 17, 2001 Mark J. Rich Jennifer Hillery, JD, CPC Colin J. Zick, Esq. Feeley & Driscoll, P.C. Feeley & Driscoll, P.C. Foley, Hoag & Eliot

More information

HIPAA Enforcement Training for State Attorneys General

HIPAA Enforcement Training for State Attorneys General : State Attorneys General Enforcement of Federal Health Privacy Law HIPAA Enforcement Training for State Attorneys General Module Introduction : Introduction This module of the HIPAA Enforcement Training

More information

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association DISCLAIMER This general information fact sheet is made available

More information

HIPAA Security. 1 Security 101 for Covered Entities. Security Topics

HIPAA Security. 1 Security 101 for Covered Entities. Security Topics HIPAA SERIES Topics 1. 101 for Covered Entities 2. Standards - Administrative Safeguards 3. Standards - Physical Safeguards 4. Standards - Technical Safeguards 5. Standards - Organizational, Policies &

More information

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices

The Health and Benefit Trust Fund of the International Union of Operating Engineers Local Union No. 94-94A-94B, AFL-CIO. Notice of Privacy Practices The Health and Benefit Trust Fund of the International Union of Operating Section 1: Purpose of This Notice Notice of Privacy Practices Effective as of September 23, 2013 THIS NOTICE DESCRIBES HOW MEDICAL

More information

RONALD V. MCGUCKIN AND ASSOCIATES Post Office Box 2126 Bristol, Pennsylvania 19007 (215) 785-3400 (215) 785-3401 (Fax) childproviderlaw.

RONALD V. MCGUCKIN AND ASSOCIATES Post Office Box 2126 Bristol, Pennsylvania 19007 (215) 785-3400 (215) 785-3401 (Fax) childproviderlaw. RONALD V. MCGUCKIN AND ASSOCIATES Post Office Box 2126 Bristol, Pennsylvania 19007 (215) 785-3400 (215) 785-3401 (Fax) childproviderlaw.com HIPAA The Health Insurance Portability and Accountability Act

More information

Payer Agreement Instructions for Trailblazer Medicare Payers

Payer Agreement Instructions for Trailblazer Medicare Payers Capario EDI 1901 E. Alton Ave. #100 Santa Ana, CA. 92705 Phone: (800) 792-5256 Option 1 Fax: (404) 877-3324 provider.enrollment@capario.com Payer Agreement Instructions for Trailblazer Medicare Payers

More information

Data Breach, Electronic Health Records and Healthcare Reform

Data Breach, Electronic Health Records and Healthcare Reform Data Breach, Electronic Health Records and Healthcare Reform (This presentation is for informational purposes only and it is not intended, and should not be relied upon, as legal advice.) Overview of HIPAA

More information

SDC-League Health Fund

SDC-League Health Fund SDC-League Health Fund 1501 Broadway, 17 th Floor New York, NY 10036 Tel: 212-869-8129 Fax: 212-302-6195 E-mail: health@sdcweb.org NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION

More information

ProviderNews2013. Recent and upcoming changes to our precertification, utilization management, and clinical practice guidelines TEXAS

ProviderNews2013. Recent and upcoming changes to our precertification, utilization management, and clinical practice guidelines TEXAS TEXAS ProviderNews2013 Recent and upcoming changes to our precertification, utilization management, and clinical practice guidelines We already faxed or mailed and posted notices on our website about important

More information

REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI

REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI REGULATORY CHANGES DEMAND AN ENTERPRISE-WIDE APPROACH TO DISCLOSURE MANAGEMENT OF PHI Healthcare Organizations Can Adopt Enterprise-Wide Disclosure Management Systems To Standardize Disclosure Processes,

More information

FIVE EASY STEPS FOR HANDLING NEW HIPAA REQUIREMENTS & MANAGING YOUR ELECTRONIC COMMUNICATIONS

FIVE EASY STEPS FOR HANDLING NEW HIPAA REQUIREMENTS & MANAGING YOUR ELECTRONIC COMMUNICATIONS FIVE EASY STEPS FOR HANDLING NEW HIPAA REQUIREMENTS & MANAGING YOUR ELECTRONIC COMMUNICATIONS James J. Eischen, Jr., Esq. October 2013 Chicago, Illinois JAMES J. EISCHEN, JR., ESQ. Partner at Higgs, Fletcher

More information

Healthcare Applications and HIPAA. BA590-IT Governance Final Term Project Prof. Mike Shaw

Healthcare Applications and HIPAA. BA590-IT Governance Final Term Project Prof. Mike Shaw Healthcare Applications and HIPAA BA590-IT Governance Final Term Project Prof. Mike Shaw Michael McIntosh 5/4/2007 Table of Contents 1. Abstract 3 2. Introduction 3 3. Section 1: HIPAA definition and history

More information

Combined Insurance Company of America

Combined Insurance Company of America Combined Insurance Company of America Companion Guide Combined Insurance Company of America HIPAA Transaction Standard Companion Guide Refers to the Implementation Guides Based on X12 version 004010 Companion

More information

HIPAA: AN OVERVIEW September 2013

HIPAA: AN OVERVIEW September 2013 HIPAA: AN OVERVIEW September 2013 Introduction The Health Insurance Portability and Accountability Act of 1996, known as HIPAA, was enacted on August 21, 1996. The overall goal was to simplify and streamline

More information

The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq.

The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq. The HITECH Act: Implications to HIPAA Covered Entities and Business Associates Linn F. Freedman, Esq. Introduction and Overview On February 17, 2009, President Obama signed P.L. 111-05, the American Recovery

More information

Section 10. Compliance

Section 10. Compliance Section 10. Compliance Fraud, Waste, and Abuse Introduction Molina Healthcare of [state] maintains a comprehensive Fraud, Waste, and Abuse program. The program is held accountable for the special investigative

More information

HIPAA Privacy Rule Primer for the College or University Administrator

HIPAA Privacy Rule Primer for the College or University Administrator HIPAA Privacy Rule Primer for the College or University Administrator On August 14, 2002, the Department of Health and Human Services ( HHS ) issued final medical privacy regulations (the Privacy Rule

More information

HIPAA and Its Implications for Dental Hygiene

HIPAA and Its Implications for Dental Hygiene HIPAA and Its Implications for Dental Hygiene By Trudy Ring Privacy it s something we all value, even if there s nothing particularly sensitive in our personal information that could possibly be used against

More information

3 Learning Objectives (cont d.)

3 Learning Objectives (cont d.) 1 2 Learning Objectives Summarize advantages of electronic claim submission. Identify the transactions and code sets to use for insurance claims transmission. State which insurance claim data elements

More information

Frequently Asked Questions About the Privacy Rule Under HIPAA

Frequently Asked Questions About the Privacy Rule Under HIPAA Q-1: What is HIPAA? Frequently Asked Questions About the Privacy Rule Under HIPAA A: HIPAA is the Health Insurance Portability and Accountability Act (passed by Congress in 1996). The Privacy Rule was

More information

The HIPAA Security Rule Primer Compliance Date: April 20, 2005

The HIPAA Security Rule Primer Compliance Date: April 20, 2005 AMERICAN PSYCHOLOGICAL ASSOCIATION PRACTICE ORGANIZATION Practice Working for You The HIPAA Security Rule Primer Compliance Date: April 20, 2005 Printer-friendly PDF 1 Contents Click on any title below

More information

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES I. Overview / Definitions The Health Insurance Portability and Accountability Act is a federal law

More information

Right to Request Access to Designated Record Set

Right to Request Access to Designated Record Set HIPAA Procedure 5002B Right to Request Access and Amendment to Designated Record Effective Date: April 14, 2003 Revised Date: September 16, 2013 Right to Request Access to Designated Record... 1 Denial

More information

Agenda. OCR Audits of HIPAA Privacy, Security and Breach Notification, Phase 2. Linda Sanches, MPH Senior Advisor, Health Information Privacy 4/1/2014

Agenda. OCR Audits of HIPAA Privacy, Security and Breach Notification, Phase 2. Linda Sanches, MPH Senior Advisor, Health Information Privacy 4/1/2014 OCR Audits of HIPAA Privacy, Security and Breach Notification, Phase 2 Linda Sanches, MPH Senior Advisor, Health Information Privacy HCCA Compliance Institute March 31, 2014 Agenda Background Audit Phase

More information

HIPAA Employee Compliance Program TRAINING MANUAL

HIPAA Employee Compliance Program TRAINING MANUAL HIPAA Employee Compliance Program TRAINING MANUAL Training Manual to Assist Employees in HIPAA Compliance January 2013 Program For HIPAA Compliance Plan Goal The purpose of this manual is to instruct our

More information

Patient Financial Policies

Patient Financial Policies Patient Financial Policies Diabetes & Internal Medicine Associates, PLLC 2302 E. Terry St., Pocatello, ID 82301 208-235-5910 Fax 208-235-5920 Thank you for choosing Diabetes & Internal Medicine Associates,

More information

Emdeon Claims Provider Information Form *This form is to ensure accuracy in updating the appropriate account

Emdeon Claims Provider Information Form *This form is to ensure accuracy in updating the appropriate account PAYER ID: SUBMITTER ID: Emdeon Claims Provider Information Form *This form is to ensure accuracy in updating the appropriate account 1 Provider Organization Practice/ Facility Name Provider Name Tax ID

More information

HIPAA & Colorado Workers Compensation

HIPAA & Colorado Workers Compensation HIPAA & Colorado Workers Compensation May 2003 The privacy rules implementing the federal Health Insurance Portability and Accountability Act ( HIPAA ) took effect April 14, 2003. Although the federal

More information

Alert. Client PROSKAUER ROSE LLP. HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements

Alert. Client PROSKAUER ROSE LLP. HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements PROSKAUER ROSE LLP Client Alert HIPAA Compliance Update: Employers, As Group Health Plan Sponsors, Will Be Affected By HIPAA Privacy Requirements The U.S. Department of Health and Human Services published

More information

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES CONTENTS Introduction 3 Brief Overview of HIPPA Final Omnibus Rule 3 Changes to the Definition of Business Associate

More information

HIPAA Privacy, Security and Breach Notification Audits

HIPAA Privacy, Security and Breach Notification Audits HIPAA Privacy, Security and Breach Notification Audits Program Overview & Initial Analysis Verne Rinker JD, MPH 2013 NIST / OCR Security Rule Conference May 21-22, 2013 Program Mandate HITECH Act, Section

More information

National Provider Identifier (NPI) Frequently Asked Questions

National Provider Identifier (NPI) Frequently Asked Questions National Provider Identifier (NPI) Frequently Asked Questions I. GETTING, SHARING, AND USING NPI GENERAL QUESTIONS II. TYPE 1 (INDIVIDUAL) VS TYPE 2 (ORGANIZATIONAL) III. ELECTRONIC CLAIM SUBMISSION IV.

More information

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES THE PHYSICIAN PRACTICE, P.A. NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW

More information

HIPAA 5010 It is important to prepare now Deanna Stohl ETP Contracting and Relations e-business Interchange Group Blue Cross Blue Shield Michigan

HIPAA 5010 It is important to prepare now Deanna Stohl ETP Contracting and Relations e-business Interchange Group Blue Cross Blue Shield Michigan HIPAA 5010 It is important to prepare now Deanna Stohl ETP Contracting and Relations e-business Interchange Group Blue Cross Blue Shield Michigan August 31, 2011 1 Housekeeping Please place your phones

More information

HIPAA OMNIBUS RULE: EXPANDED COMPLIANCE REQUIREMENTS

HIPAA OMNIBUS RULE: EXPANDED COMPLIANCE REQUIREMENTS HIPAA OMNIBUS RULE: EXPANDED COMPLIANCE REQUIREMENTS James J. Eischen, Jr., Esq. November 2013 San Diego, California JAMES J. EISCHEN, JR., ESQ. Partner at Higgs, Fletcher & Mack, LLP 26+ years of experience

More information

White Paper. Applying HIPAA s Framework to the Sale and Purchase of Healthcare Receivables

White Paper. Applying HIPAA s Framework to the Sale and Purchase of Healthcare Receivables White Paper Applying HIPAA s Framework to the Sale and Purchase of Healthcare Receivables ACA International www.acainternational.org Final October 2007 I. About ACA Applying HIPAA s Framework to the Sale

More information

How To Write A Community Based Care Coordination Program Agreement

How To Write A Community Based Care Coordination Program Agreement Section 4.3 Implement Business Associate and Other Agreements This tool identifies the types of agreements that may be necessary for a community-based care coordination (CCC) program to have in place in

More information

BUSINESS ASSOCIATES [45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)]

BUSINESS ASSOCIATES [45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)] BUSINESS ASSOCIATES [45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)] Background By law, the HIPAA Privacy Rule applies only to covered entities health plans, health care clearinghouses, and certain

More information

HIPAA PRIVACY AND SECURITY STANDARDS CITY COMPLIANCE

HIPAA PRIVACY AND SECURITY STANDARDS CITY COMPLIANCE Important: Conducting an assessment of your health plan(s) is the first step to determining HIPAA compliance. You will need to conduct a separate assessment for each of your health plans. (Please be aware

More information

HIPAA PRIVACY AND EDI RULES

HIPAA PRIVACY AND EDI RULES The Health and Human Services (HHS) issued final HIPAA privacy regulations on August 14, 2002. These rules govern how individually identifiable medical information must be protected. HIIPAA also requires

More information

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview Updated HIPAA Regulations What Optometrists Need to Know Now The U.S. Department of Health & Human Services Office for Civil Rights recently released updated regulations regarding the Health Insurance

More information

HIPAA COMPLIANCE. What is HIPAA?

HIPAA COMPLIANCE. What is HIPAA? HIPAA COMPLIANCE What is HIPAA? The Health Insurance Portability and Accountability Act (HIPAA) also known as the Privacy Rule specifies the conditions under which protected health information may be used

More information

The HIPAA Standard Transaction Requirements: How do Health Plans Comply?

The HIPAA Standard Transaction Requirements: How do Health Plans Comply? The HIPAA Standard Transaction Requirements: How do Health Plans Comply? April 17, 2014 As most employers are aware, the federal government has released a good deal of guidance related to various provisions

More information

Bradley D. Powell, PhD NOTICE OF PRIVACY PRACTICES: Effective June 1, 2004

Bradley D. Powell, PhD NOTICE OF PRIVACY PRACTICES: Effective June 1, 2004 Bradley D. Powell, PhD NOTICE OF PRIVACY PRACTICES: Effective June 1, 2004 A Summary of the Provisions of the Health Insurance Portability and Accountability Act ( HIPAA ) Privacy Rule (45 C.F.R. parts

More information

Legislative & Regulatory Information

Legislative & Regulatory Information Americas - U.S. Legislative, Privacy & Projects Jurisdiction Effective Date Author Release Date File No. UFS Topic Citation: Reference: Federal 3/26/13 Michael F. Tietz Louis Enahoro HIPAA, Privacy, Privacy

More information

Presentation to the Senate Committee on State Affairs: Health Care Information Security

Presentation to the Senate Committee on State Affairs: Health Care Information Security Presentation to the Senate Committee on State Affairs: Health Care Information Security Patricia Vojack Deputy Executive Commissioner, Health Policy and Clinical Services Texas Health and Human Services

More information

MLN EDUCATIONAL PRODUCTS UPDATE

MLN EDUCATIONAL PRODUCTS UPDATE This issue of the e News will be available in PDF format within 24 hours of its release in the archive with other past issues. CMS asks that you share the following important information with all of your

More information

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 HIPAA and the HITECH Act Privacy and Security of Health Information in 2009 What is HIPAA? Health Insurance Portability & Accountability Act of 1996 Effective April 13, 2003 Federal Law HIPAA Purpose:

More information

New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010

New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010 New HIPAA Breach Notification Rule: Know Your Responsibilities Loudoun Medical Group Spring 2010 Health Information Technology for Economic and Clinical Health Act (HITECH) As part of the Recovery Act,

More information

HIPAA Regulations and the Higher Education Institution

HIPAA Regulations and the Higher Education Institution EDUCAUSE Center for Applied Research Research Bulletin Volume 2003, Issue 7 April 1, 2003 Life with HIPAA A Primer for Higher Education Toby D. Sitko, EDUCAUSE Center for Applied Research Norma K. S. Kenigsberg,

More information

BlueCross BlueShield of Tennessee Electronic Provider Profile

BlueCross BlueShield of Tennessee Electronic Provider Profile Date: Business Name: SECTION 1 PURPOSE FOR PROFILE Please PLACE A CHECK MARK using blue or black ink by the purpose for completing the. The chart below indicates with an X the sections that need to be

More information

SOP Number: OCR-HIP-001 Effective Date: August 2013 Page 1 of 5

SOP Number: OCR-HIP-001 Effective Date: August 2013 Page 1 of 5 Title: HIPAA Research Policy: General Nova Southeastern University Standard Operating Procedure for GCP Version # 1 SOP Number: OCR-HIP-001 Effective Date: August 2013 Page 1 of 5 PURPOSE: Federal privacy

More information

HIPAA Compliance for Small Healthcare Providers

HIPAA Compliance for Small Healthcare Providers White Paper 2.2.1 HIPAA Compliance for Small Healthcare Providers Prepared by: Agent 77 Originally created: February 2002 Revised: September 2002 Legislative Background The intent of the Healthcare Portability

More information

LTC Online Portal Security Training Manual

LTC Online Portal Security Training Manual LTC Online Portal Security Training Manual Texas Medicaid & Healthcare Partnership Page 1 of 16 Print Date: 8/22/2006 Table of Contents 1.0 Texas Medicaid & Healthcare Partnership (TMHP) Website Security

More information

Introduction to ICD-10: A Guide for Providers. Centers for Medicare & Medicaid Services

Introduction to ICD-10: A Guide for Providers. Centers for Medicare & Medicaid Services Introduction to ICD-10: A Guide for Providers Centers for Medicare & Medicaid Services 1 Table of Contents Compliance Date: October 1, 2014» What is ICD-10?» Why ICD-10 matters» Why transition to ICD-10»

More information

WISHIN Pulse Statement on Privacy, Security and HIPAA Compliance

WISHIN Pulse Statement on Privacy, Security and HIPAA Compliance WISHIN Pulse Statement on Privacy, Security and HIPAA Compliance SEC-STM-072014 07/2014 Contents Patient Choice... 2 Security Protections... 2 Participation Agreement... 2 Controls... 3 Break the Glass...

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( BA Agreement ) is entered into by Medtep Inc., a Delaware corporation ( Business Associate ) and the covered entity ( Covered Entity

More information

Executive Memorandum No. 27

Executive Memorandum No. 27 OFFICE OF THE PRESIDENT HIPAA Compliance Policy (effective April 14, 2003) Purpose It is the purpose of this Executive Memorandum to set forth the Board of Regents and the University Administration s Policy

More information

PATIENT REGISTRATION FORM

PATIENT REGISTRATION FORM 201 N. Park Ave Suite 201 Apopka, FL 32703 Office (407)228-3180 Fax: (407)-228-3725 PATIENT REGISTRATION FORM Last Name: First Name: Middle Initial Male Female Date of Birth: Marital Status: Single Married

More information

BUSINESS ASSOCIATES AND BUSINESS ASSOCIATE AGREEMENTS

BUSINESS ASSOCIATES AND BUSINESS ASSOCIATE AGREEMENTS PRIVACY 27.0 BUSINESS ASSOCIATES AND BUSINESS ASSOCIATE AGREEMENTS Scope: Purpose: All subsidiaries of Universal Health Services, Inc., including facilities and UHS of Delaware Inc. (collectively, UHS

More information

HIPAA Privacy Overview

HIPAA Privacy Overview HIPAA Privacy Overview General HIPAA stands for a federal law called the Health Insurance Portability and Accountability Act. This law, among other purposes, was created to protect the privacy and security

More information

HIPAA Compliance Policies and Procedures. Privacy Standards:

HIPAA Compliance Policies and Procedures. Privacy Standards: Privacy Standards: Policy Name: Protected Health Information Policy #: 1-01 Reference: 45 CFR 164 Performance Physical Therapy will not use or disclose protected health information without the consent

More information

Program Memorandum Intermediaries

Program Memorandum Intermediaries Program Memorandum Intermediaries Department of Health & Human Services (DHHS) Centers for Medicare & Medicaid Services (CMS) Transmittal A-02-051 Date: JUNE 18, 2002 CHANGE REQUEST 2128 SUBJECT: Health

More information

HIPAA Refresher. HIPAA Health Insurance Portability & Accountability Act

HIPAA Refresher. HIPAA Health Insurance Portability & Accountability Act HIPAA Health Insurance Portability & Accountability Act This presentation and materials provided are for informational purposes only. Please seek legal advisor assistance when dealing with privacy and

More information

HIPAA Transactions and Code Set Standards As of January 2012. Frequently Asked Questions

HIPAA Transactions and Code Set Standards As of January 2012. Frequently Asked Questions HIPAA Transactions and Code Set Standards As of January 2012 Frequently Asked Questions Version 20 Rev 11222011 Frequently Asked Questions: HIPAA Transactions and Code Set Standards One of the most prominent

More information

FMH Benefit Services, Inc.

FMH Benefit Services, Inc. FMH Benefit Services, Inc. HIPAA Transaction Electronic Data Interchange (EDI) Implementation Guide For Health Care Providers Version Number: 2.0 Issued: October 28, 2003 FMH Benefit Services, Inc. a division

More information