Leveraging Big Data in Healthcare: Navigating HIPAA, Antitrust, Stark and AKS Compliance and Security Issues

Size: px
Start display at page:

Download "Leveraging Big Data in Healthcare: Navigating HIPAA, Antitrust, Stark and AKS Compliance and Security Issues"

Transcription

1 Presenting a live 90-minute webinar with interactive Q&A Leveraging Big Data in Healthcare: Navigating HIPAA, Antitrust, Stark and AKS Compliance and Security Issues THURSDAY, MAY 21, pm Eastern 12pm Central 11am Mountain 10am Pacific Today s faculty features: Adria Warren, Partner, Foley & Lardner, Boston Chanley T. Howell, Partner, Foley & Lardner, Jacksonville, Fla. Sara J.B. English, CIPP/US, Partner, Kutak Rock LLP, Omaha, Ne The audio portion of the conference may be accessed via the telephone or by using your computer's speakers. Please refer to the instructions ed to registrants for additional information. If you have any questions, please contact Customer Service at ext. 10.

2 Tips for Optimal Quality FOR LIVE EVENT ONLY Sound Quality If you are listening via your computer speakers, please note that the quality of your sound will vary depending on the speed and quality of your internet connection. If the sound quality is not satisfactory, you may listen via the phone: dial and enter your PIN when prompted. Otherwise, please send us a chat or sound@straffordpub.com immediately so we can address the problem. If you dialed in and have any difficulties during the call, press *0 for assistance. Viewing Quality To maximize your screen, press the F11 key on your keyboard. To exit full screen, press the F11 key again.

3 Continuing Education Credits FOR LIVE EVENT ONLY For CLE purposes, please let us know how many people are listening at your location by completing each of the following steps: In the chat box, type (1) your company name and (2) the number of attendees at your location Click the SEND button beside the box In order for us to process your CLE, you must confirm your participation by completing and submitting an Official Record of Attendance (CLE Form) to Strafford within 10 days following the program. The CLE form is included in your dial in instructions and in a thank you that you will receive at the end of this program. Strafford will send your CLE credit confirmation within approximately 30 days of receiving the completed CLE form. For additional information about CLE credit processing call us at ext. 35.

4 Program Materials FOR LIVE EVENT ONLY If you have not printed the conference materials for this program, please complete the following steps: Click on the ^ symbol next to Conference Materials in the middle of the lefthand column on your screen. Click on the tab labeled Handouts that appears, and there you will see a PDF of the slides for today's program. Double click on the PDF and a separate page will open. Print the slides by clicking on the printer icon.

5 Leveraging Big Data in Health care: Navigating HIPAA, Antitrust, Stark and AKS Compliance May 21, 2015 Chanley T. Howell Partner Foley & Lardner Adria Warren Partner Foley & Lardner Sara English Partner Kutak Rock LLP 5

6 Introduction to Big Data in Health care Improved Technologies (data storage, data mining, data sharing) U.S. Government Initiatives and Public/Private Opportunities (NIH s BD2K ) Enhanced Infrastructure and Capacity (EMRs) Expanding Health Care Operation Functions (data analytics) Proliferation of Web-based Technologies and Mobile Devices Big Data Technical, Institutional, Operational Challenges??????? Legal Considerations Privacy and Security Laws and Regulations $$$$$$$$ 6

7 Introduction to Big Data in Health Care Older people were less inclined to share anonymized health data, an NPR-Truven Health Analytics poll found. Poll: Most Americans Would Share Health Data for Research - Scott Hensley (Shots-Health News:NPR) January 9, 2015 Available at: 7

8 Risk/Reward Quality and nature of the risks and rewards are different than other industries: Patient outcomes are at stake. PHI is always in-scope at some stage. There are ethical and policy considerations. It is important to get it right. Collection and use of Big Data is ubiquitous and everyone is paying attention. Failures are costly violation of multiple legal regimes. 8

9 Risk/Reward Strategic and technical challenges Inherent to the V s of Big Data: Volume Velocity Variety Veracity Specifically, collecting quality data that is from reliable methods. Complying with all requirements that attach to the data. Maintaining a consistent institutional program. 9

10 Capstone: HIPAA Health Insurance Portability and Accountability Act ( HIPAA ): Touches all aspects of most health care data. Covered Entities and their Business Associates. Governs the use of PHI and establishes frameworks for nearly each step in the process. 10

11 Capstone: HIPAA Protected Health Information is broad. The definition is based on IIHI: Individually identifiable health information is information that is a subset of health information, including demographic information collected from an individual, and: (1) Is created or received by a health care provider, health plan, employer, or health care clearinghouse; and (2) Relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual; and (i) That identifies the individual; or (ii) With respect to which there is a reasonable basis to believe the information can be used to identify the individual. 11

12 Capstone: HIPAA Generally, PHI may be used by the covered entity for Payment Treatment Health Care Operations Consent is not required for these three areas, but frequently sought. Uses of PHI outside of these categories require a written authorization (permission) from the patient. Consent Authorization. 12

13 State v. Federal Laws HIPAA provides a federal floor of privacy protections and states are free to impose more stringent protections should they deem appropriate. (See 45 C.F.R ). 13

14 State Privacy & Security Laws: A Patchwork Quilt 50-State Survey Disclaimer Survey was designed to provide an overview of applicable state law, limited to select state statutes. State administrative regulations, attorney general opinions, licensure board opinions, and court decisions may impact a state s privacy regime. In that regard, the survey should be used for reference purposes only and not relied on as legal advice. 14

15 State Privacy & Security Laws: A Patchwork Quilt States that have worked to harmonize their regimes with HIPAA compliance with HIPAA may constitute deemed compliance under equivalent state law include: Hawaii Iowa Kansas Missouri Ohio West Virginia 15

16 State Privacy & Security Laws: A Patchwork Quilt States with relatively comprehensive, broad or stringent privacy regimes: California (Cal. Civ. Code 56.10) Florida (Fla. Stat ) Illinois (410 Ill. Comp. Stat. 50/3) Maine (Me. Rev. Stat. Ann. Tit. 22, 1711-C) Massachusetts (111 Mass. Gen. Laws ch. 70E) New Hampshire (N.H. Rev. Stat. Ann. 151:21) Tennessee (Tenn. Code Ann ) Vermont (Vt. Stat. Ann. tit. 18, ) 16

17 State Privacy & Security Laws: A Patchwork Quilt Patient Bill of Rights Florida: Every patient who is provided health care services retains certain rights to privacy, which must be respected without regard to the patient s economic status or source of payment for his or her care. ) (Fla. Stat ) Massachusetts: Every patient or resident of a facility shall have the right... to confidentiality of all records and communications to the extent provided by law. (111 Mass. Gen. Laws ch. 70E) 17

18 State Privacy & Security Laws: A Patchwork Quilt Expansive Privacy Protections HIPAA (45 C.F.R ) Protected Health Information includes individually identifiable health information that (1) is created or received by covered entities, (2) relates to past, present or future physical or mental health or condition... provision of healthcare... or payment for care and (3) identifies the individual, or with which there is reasonable basis to believe the information can be used to identify the individual. California Medical Information Act (Cal. Civ. Code 56.10, (2013)) Medical information means any individually identifiable information... in possession of or derived from a provider of health care, health care service plan, pharmaceutical company, or contractor regarding a patient s medical history, mental or physical condition, or treatment. Any business organized for the purpose of maintaining medical information in order to make the information available... shall be deemed a provider of health care. 18

19 State Privacy & Security Laws: A Patchwork Quilt Restrictions may apply to specific persons/entities, e.g., providers/other licensed professionals, hospitals, insurers, managed care organizations or health maintenance organizations. Example: Oregon (Or. Rev. Stat ) restricts an insurer s ability to disclose medical information about an individual collected or received in connection with an insurance transaction without that person s written authorization. 19

20 State Privacy & Security Laws: A Patchwork Quilt Most states also protect designated categories of sensitive data e.g., mental health, genetic information, substance abuse, communicable diseases (HIV/AIDs). Example (mental health): Unless waived by express and informed consent... the confidential status of the clinical record shall not be lost by either authorized or unauthorized disclosure. Fla. Stat

21 Examples of Non-HIPAA Google Flu Target Pregnancy Predictor 21

22 Examples of Non-HIPAA PHI Exceptions Education Records Employment Records Deceased > 50 Years Personal Health Records Mobile Devices / Web 22

23 Legal Considerations (other than HIPAA) Family Educational Rights and Privacy Act ( FERPA ) FTCdone Privacy Policies Contractual 23

24 Legal Considerations (other than HIPAA) Privacy Act of 1974 (Federal Agencies) Clinical Laboratory Improvements Act (Labs) Children s Online Privacy Protection Act of 1998 (COPPA) Gramm-Leach-Bliley Act and ERISA (Health Plans) Federal Substance Abuse Records Statutes 24

25 Legal Considerations (other than HIPAA) FTC v. PaymentsMD Patient Portal Deceived Consumers Consent Health Information = Sensitive 25

26 Additional Considerations AKS & Stark Anti-Kickback Statute Generally, prohibits offering, paying, soliciting or receiving anything of value to induce or reward referrals or generate federal health care program business. Stark Law Prohibits a physician from referring Medicare patients for designated health services to an entity with which the physician (or immediate family member) has a financial relationship, unless an exception applies. Prohibits the designated health services entity from submitting claims to Medicare for those services resulting from a prohibited referral. 26

27 Additional Considerations - Antitrust Coopertition Manage Risk: Competitively sensitive data? Economic information Cost Volume Competitive Effect? Criteria for accessing data Inclusive/exclusive Test = Rule of Reason 27

28 Security Increases in Health Care Data Breaches Criminal attacks increased by 125% Past 2 years 91% of health care organizations at least 1 breach 39% reported 2 to 5 breaches 40% more than 5 breaches Source: Ponemon Institute Fifth Annual Benchmark Study on Privacy and Security of Healthcare Data 28

29 Security Sources of Health Care Data Breaches Criminal attacks 45% Lost or stolen laptops / devices 43% Employee mistakes 40% Malicious insiders 12% Source: Ponemon Institute Fifth Annual Benchmark Study on Privacy and Security of Healthcare Data 29

30 Security 30

31 Security 31

32 Security 32

33 Security 33

34 Contractual Limitations Business Associates Business Associates: Third parties that have access to, create or receive Protected Health Information To perform or assist in the performance of a function on behalf of the Covered Entity: Utilization review, quality assurance, billing, practice management To provide legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation or financial services Covered Entity can be Business Associate of another Covered Entity. Subcontractor would be defined as Business Associate. 34

35 Contractual Limitations Business Associates Business Associates are directly subject to applicable HIPAA regulations and to civil penalties for violations (regardless of whether BAA executed). Business Associates are subject to Security Rule. Business Associates are directly subject to certain Privacy Rule provisions: Use and disclose PHI in accordance with Business Associate Agreement or Privacy Rule. Disclose PHI for compliance purposes. Provide individual access to PHI. Comply with minimum necessary standard. Enter into Business Associate Agreements with Subcontractors. 35

36 Contractual Limitations Business Associates The Omnibus Final Rule effectively made a Covered Entity or Business Associate strictly/vicariously liable for violations by its agent. The most important criterion is the right to exercise control over the Business Associate. In drafting a BAA, consider the trade-off between the need to control the Business Associate and the liability associated with such control. 36

37 Case Study - 1 ABC Health System and its owned hospitals and clinics are an OHCA. ABC wants to hire Aggregate4U, an analytics company, to mine its databases and electronic health records for various purposes. 37

38 Case Study - 1 Treatment, Payment, Health Care Operations Ethics: Predictive Analytics Other uses? 38

39 Case Study - 2 ABC uses XYZ Medical Management, a world-class EHR system. ABC s deployment of XYZ s solution (Giant EHR) is managed as a shared electronic health system environment. All OHCA participants use it, and ABC resells/sublicenses Giant EHR to community clinics and small hospitals who are not members of the OHCA. ABC wants to assure that the shared Giant EHR participants are also participating in the regional HIE, AnyStateHealth. ABC wants all the shared Giant EHR participants to send records to, and participate in, an oncology database. 39

40 Case Study - 2 Stark and AKS (Shared EHR) What limitations? Legal Authorizations Can this be segmented? Database participation Antitrust considerations 40

41 Case Study - 3 RST Oncology Specialists is a physician-owned clinic that participates in ABC s shared Giant EMR. The owners of RST, including Dr. Bill, are all non-employed staff physicians at several ABC hospitals. In order to achieve meaningful use, and to report on a number of other quality initiatives, Dr. Bill needs ABC to help him extract a significant amount of information from his patient files. 41

42 Case Study - 3 Meaningful Use Requires greater interoperability and data sharing. More opportunities and incentives to move beyond using the EHR for day-to-day. Extraction Assistance, Consulting, Reporting Tools, Etc.? Fair market value. If applicable, are these permissible donations? 42

43 Case Study - 3 Stark Electronic health records items and services exclusion (the 85 rule). Nonmonetary remuneration (consisting of items and services in the form of software or information technology and training services) necessary and used predominantly to create, maintain, transmit or receive electronic health records.... Stark identifies certain types of remuneration which, if provided, would not create a compensation arrangement subject to the physician selfreferral prohibition. Such remuneration includes the provision of items, devices or supplies that are used solely to order or communicate the results of tests or procedures for such entity. 43

44 Case Study - 4 ABC and its OHCA participants are exploring more effective ways to support research, both through organizing ongoing internal research programs and potentially supporting external research conducted by third parties. 44

45 Case Study - 4 Authorization/Consent De-Identified Data -- No subject authorization or consent required -- Unlimited uses and disclosures permitted Limited Data Set (with Data Use Agreement) -- No subject authorization or consent required -- Only includes a few more elements than de-identified data. Limited? Institutional Review Board (IRB) or Privacy Board Waiver of Authorization -- No subject authorization or consent required -- Approval may not be available in cases where it is feasible to request authorization 45

46 Case Study - 4 Sample State Provisions Governing Disclosure/Use of PHI in Research Statutory Construct State/Citation Similar States Research De-identified data Permissive disclosure in connection with use in actuarial or research studies, provided: (A) no individual is identified; (B) materials in which the individual may be identified are returned or destroyed; and (C) the organization agrees not to further disclose the information. Conn. Gen. Stat. 38a-988 (2012) (applicable to insurance institutions, agents and insurancesupport organizations) Connecticut, Florida, Illinois, Massachusetts, Minnesota, New Jersey, North Carolina, Tennessee, Wisconsin Research Waiver of authorization (privacy board) PHI may be disclosed for research, with approval or waiver of the applicable privacy board in accordance with HIPAA, subject to a finding of (1) no more than a minimal risk to privacy of individuals, based on, at least, an adequate plan to protect the identifiers from improper use and disclosure, to destroy the identifiers at the earliest opportunity, and adequate written assurances that the protected health information will not be reused or further disclosed except as permitted; (2) the research could not practicably be conducted without the waiver or alteration; and (3) the research could not practicably be conducted without access to and use of the protected health information. Del. Code tit. 16, 1212 California, Delaware, Maine, Maryland, Washington, Wyoming 46

47 Case Study - 5 ABC Hospital would like to use its patient information for marketing purposes. It would like to know what information it can use, how it can use it, and when specific patient authorization is required and not required. 47

48 Case Study - 5 Use of PHI for marketing requires authorization Communications about health-related products or services that encourage purchase (third party) Financial remuneration Payments in exchange for making marketing communications Authorization not required products and services of the Covered Entity 48

49 Case Study - 5 HIPAA Omnibus Rule 2013 Previous exception for treatment-related marketing communications Previously opt-out rather than opt-in Now opt-in express written authorization Authorization must disclose remuneration 49

50 Case Study - 5 Exceptions Refill reminders Other communications about prescriptions Remuneration must be reasonably related to the cost of the communication 50

51 Case Study - 5 Exceptions Face-to-face communications (Even if remuneration or promotional gift of nominal value) Telephone is NOT face-to-face Communications promoting health that do not promote a particular provider Communications about government-sponsored programs 51

52 Case Study - 5 Sale of PHI CE or BA receives remuneration Not limited to financial remuneration Not just sale access, licenses and leases 52

53 Case Study - 5 Exceptions Remuneration reasonable cost Research reasonable cost Treatment and payment M&A activity 53

54 Case Study - 5 Exceptions Business Associates Disclosures to patients Payments from grants research Exchange of PHI through HIEs 54

55 Case Study - 6 XYZ Medical Management has access to a significant amount of health information as a world-class EHR. Although it has been in business for several years, it is just starting to explore opportunities to leverage all this data for other business uses. 55

56 Case Study - 6 Industry Solutions Business Associate Agreements Business Associate Agreements should provide: Express authorization to aggregate PHI for health care operations purposes Permit the Business Associate to de-identify PHI Exclude de-identified data from any provisions related to the Covered Entity s ownership of the data 56

57 Case Study - 6 De- Identification Safe Harbor Expert Determination 57

58 Case Study - 6 Sample Business Associate Agreement Provision De-Identified Information ( BA friendly ) Business Associate may de-identify any and all Protected Health Information created or received by Business Associate under this Agreement; provided, however, that the de-identification conforms to the requirements of the [HIPAA Rules]. Such resulting de-identified information would not be subject to the terms of this Agreement. 58

59 Case Study - 7 Dr. Jones, a primary care physician, is in negotiations to sell her practice to the local community hospital. Dr. Jones believes that the practice s patient records have significant value and she would like to negotiate a higher price on that basis. The parties are also starting due diligence, and Dr. Jones would like to have a compliant process from a privacy perspective. 59

60 Case Study - 7 Industry Solutions Mergers and Acquisitions Anti-Kickback Considerations: Payments for intangibles are particularly suspect and may be subject to scrutiny This includes patient records Valuation methodologies to take into consideration 60

61 Case Study - 7 Due Diligence Healthcare Operations is defined to include any of the following activities of the covered entity to the extent that the activities are related to covered functions: Business management and general administrative activities of the entity, including, but not limited to... (iv) The sale, transfer, merger, or consolidation of all or part of the covered entity with another covered entity, or an entity that following such activity will become a covered entity and due diligence related to such activity. 45 C.F.R

62 Additional Case Studies ABC terminates its relationship with Aggregate4U in favor of launching a homegrown internal data warehouse system for ABC and its OHCA. Its CISO, Privacy Officer, and HIM director are arguing over logging requirements. AnyState Health, the HIE, would like to facilitate the sharing of PHI among health care providers but is concerned about verifying the identity of users (providers and patients) on the front end and, after the users have been initially verified, authenticating the users when they log in to the HIE. 62

63 Summary Step through the process. From where does data originate? Who owns it? Who processes it? Who are the data subjects? What legal regime(s) apply? Develop a program. 63

64 Summary Be aware of applicable federal and state requirements; tailor privacy policies as applicable. Designate people responsible for security in the organization. Conduct security training for employees. Take reasonable steps to ensure vendors/service providers protect data. Consider minimizing data collection. De-identify where possible. Conduct a privacy or security risk assessment initially, and periodically thereafter. Consider encryption.

Negotiating EHR Agreements: Complying with HIPAA, Stark and AKS, Overcoming Privacy and Security Risks

Negotiating EHR Agreements: Complying with HIPAA, Stark and AKS, Overcoming Privacy and Security Risks Presenting a live 90-minute webinar with interactive Q&A Negotiating EHR Agreements: Complying with HIPAA, Stark and AKS, Overcoming Privacy and Security Risks Acquiring an EHR and Meeting Incentive Program

More information

Overcoming Ethical Challenges for Multi-Firm Lawyers and Their Firms: Fiduciary Duty, Conflict, Fee-Splitting and More

Overcoming Ethical Challenges for Multi-Firm Lawyers and Their Firms: Fiduciary Duty, Conflict, Fee-Splitting and More Presenting a live 90-minute webinar with interactive Q&A Overcoming Ethical Challenges for Multi-Firm Lawyers and Their Firms: Fiduciary Duty, Conflict, Fee-Splitting and More TUESDAY, SEPTEMBER 16, 2014

More information

Ensuring HIPAA Compliance When Transmitting PHI via Patient Portals, Email and Texting

Ensuring HIPAA Compliance When Transmitting PHI via Patient Portals, Email and Texting Presenting a live 90-minute webinar with interactive Q&A Ensuring HIPAA Compliance When Transmitting PHI via Patient Portals, Email and Texting Protecting Patient Privacy, Complying with State and Federal

More information

ERISA Retirement Plans: Fiduciary Compliance and Risk Management for Investment Fund Selection and Fee Disclosures

ERISA Retirement Plans: Fiduciary Compliance and Risk Management for Investment Fund Selection and Fee Disclosures Presenting a live 90-minute webinar with interactive Q&A ERISA Retirement Plans: Fiduciary Compliance and Risk Management for Investment Fund Selection and Fee Disclosures Discharging Fiduciary Duties

More information

Payment and Performance Surety Bonds in Construction Projects: Perspectives of Owners, Contractors and Sureties

Payment and Performance Surety Bonds in Construction Projects: Perspectives of Owners, Contractors and Sureties Presenting a live 90-minute webinar with interactive Q&A Payment and Performance Surety Bonds in Construction Projects: Perspectives of Owners, Contractors and Sureties Asserting and Defending Surety Bond

More information

How To Listen To A Conference On A Computer Or Cell Phone

How To Listen To A Conference On A Computer Or Cell Phone Presenting a live 90-minute webinar with interactive Q&A M&A Auctions: Successful Bidding Strategies Planning and Executing Winning Bids, Minimizing Costs of Losing Bids THURSDAY, JANUARY 8, 2015 1pm Eastern

More information

Mobile Medical Devices and BYOD: Latest Legal Threat for Providers

Mobile Medical Devices and BYOD: Latest Legal Threat for Providers Presenting a live 90-minute webinar with interactive Q&A Mobile Medical Devices and BYOD: Latest Legal Threat for Providers Developing a Comprehensive Usage Strategy to Safeguard Health Information and

More information

Table A-7. State Medical Record Laws: Minimum Medical Record Retention Periods for Records Held by Medical Doctors and Hospitals*

Table A-7. State Medical Record Laws: Minimum Medical Record Retention Periods for Records Held by Medical Doctors and Hospitals* Summary of statutory or regulatory provision by entity. Alabama As long as may be necessary to treat the patient and for medical legal purposes. Ala. Admin. Code r. 545-X-4-.08 (2007). (1) 5 years. Ala.

More information

Massachusetts Adopts Strict Security Regulations Governing Personal Information LISA M. ROPPLE, KEVIN V. JONES, AND CHRISTINE M.

Massachusetts Adopts Strict Security Regulations Governing Personal Information LISA M. ROPPLE, KEVIN V. JONES, AND CHRISTINE M. Massachusetts Adopts Strict Security Regulations Governing Personal Information LISA M. ROPPLE, KEVIN V. JONES, AND CHRISTINE M. SANTARIGA Establishing itself as a leader in the data security area, Massachusetts

More information

for Landlords and Tenants Negotiating Insurance, Indemnity and Mutual Waiver of Subrogation Provisions

for Landlords and Tenants Negotiating Insurance, Indemnity and Mutual Waiver of Subrogation Provisions Presenting a live 90 minute webinar with interactive Q&A Commercial Leases: Risk Mitigation Strategies for Landlords and Tenants Negotiating Insurance, Indemnity and Mutual Waiver of Subrogation Provisions

More information

Video Voyeurism Laws

Video Voyeurism Laws Video Voyeurism Laws Federal Law Video Voyeurism Prevention Act of 2004, 18 U.S.C.A. 1801. Jurisdiction limited to maritime and territorial jurisdiction, or federal property including but not limited to

More information

Solar Leases: Legal Considerations for Property Owners

Solar Leases: Legal Considerations for Property Owners Presenting a live 90-minute webinar with interactive Q&A Solar Leases: Legal Considerations for Property Owners Analyzing Lease Sites and Deal Structures and Addressing Key Document Provisions WEDNESDAY,

More information

DATA BREACH CHARTS (Current as of December 31, 2015)

DATA BREACH CHARTS (Current as of December 31, 2015) DATA BREACH CHARTS (Current as of December 31, 2015) The charts below provide summary information about data breach notification statutes across the country. California adopted the first data breach notification

More information

HEALTH CARE INTERPRETERS: ARE THEY MANDATORY REPORTERS OF CHILD ABUSE? 1

HEALTH CARE INTERPRETERS: ARE THEY MANDATORY REPORTERS OF CHILD ABUSE? 1 1444 I St NW, Suite 1105 Washington, DC 20005 (202) 289-7661 Fax (202) 289-7724 I. Introduction HEALTH CARE INTERPRETERS: ARE THEY MANDATORY REPORTERS OF CHILD ABUSE? 1 As the nation continues to diversify

More information

HIPAA Compliance During Litigation and Discovery

HIPAA Compliance During Litigation and Discovery Presenting a live 90-minute webinar with interactive Q&A HIPAA Compliance During Litigation and Discovery Safeguarding PHI and Avoiding Violations When Responding to Subpoenas and Discovery Requests WEDNESDAY,

More information

SURVEY OF THE CURRENT INSURANCE REGULATORY ENVIRONMENT FOR AFFINITY MARKETIG 1 A

SURVEY OF THE CURRENT INSURANCE REGULATORY ENVIRONMENT FOR AFFINITY MARKETIG 1 A SURVEY OF THE CURRENT INSURANCE REGULATORY ENVIRONMENT FOR AFFINITY MARKETIG ARRANGEMENTS (FORC Journal: Vol. 23 Edition 4 - Winter 2012) Kevin G. Fitzgerald, Esq. (414) 297-5841 N. Wesley Strickland (850)

More information

STATE BY STATE ANTI-INDEMNITY STATUTES. Sole or Partial Negligence. Alaska X Alaska Stat. 45.45.900. Except for hazardous substances.

STATE BY STATE ANTI-INDEMNITY STATUTES. Sole or Partial Negligence. Alaska X Alaska Stat. 45.45.900. Except for hazardous substances. State STATE BY STATE ANTI-INDEMNITY STATUTES Sole Negligence Sole or Partial Negligence Closes A.I. Loophole Comments Alabama Alaska Alaska Stat. 45.45.900. Except for hazardous substances. Arizona (Private

More information

PRIVACY REGULATIONS FOR BEHAVIORAL HEALTH PROVIDERS WHAT YOU NEED TO KNOW

PRIVACY REGULATIONS FOR BEHAVIORAL HEALTH PROVIDERS WHAT YOU NEED TO KNOW PRIVACY REGULATIONS FOR BEHAVIORAL HEALTH PROVIDERS WHAT YOU NEED TO KNOW September 10, 2013 AGENDA The Changing Privacy Climate Overlapping Laws & Regulations Health Insurance Portability & Accountability

More information

University Healthcare Physicians Compliance and Privacy Policy

University Healthcare Physicians Compliance and Privacy Policy Page 1 of 11 POLICY University Healthcare Physicians (UHP) will enter into business associate agreements in compliance with the provisions of the Health Insurance Portability and Accountability Act of

More information

Fraud, Waste & Abuse. Training Course for UHCG Employees

Fraud, Waste & Abuse. Training Course for UHCG Employees Fraud, Waste & Abuse Training Course for UHCG Employees Overview The Centers for Medicare & Medicaid Services (CMS) require Medicare Advantage Organizations and Part D Plan Sponsors to provide annual fraud,

More information

Estate Planning Using LLCs and Limited Partnerships Achieving Estate Tax Savings Through Valuation Discounts, Protecting Against Creditor Claims

Estate Planning Using LLCs and Limited Partnerships Achieving Estate Tax Savings Through Valuation Discounts, Protecting Against Creditor Claims Presenting a live 90-minute webinar with interactive Q&A Estate Planning Using LLCs and Limited Partnerships Achieving Estate Tax Savings Through Valuation Discounts, Protecting Against Creditor Claims

More information

Data Breach, Electronic Health Records and Healthcare Reform

Data Breach, Electronic Health Records and Healthcare Reform Data Breach, Electronic Health Records and Healthcare Reform (This presentation is for informational purposes only and it is not intended, and should not be relied upon, as legal advice.) Overview of HIPAA

More information

Business Associates, HITECH & the Omnibus HIPAA Final Rule

Business Associates, HITECH & the Omnibus HIPAA Final Rule Business Associates, HITECH & the Omnibus HIPAA Final Rule HIPAA Omnibus Final Rule Changes Business Associates Marissa Gordon-Nguyen, JD, MPH Health Information Privacy Specialist Office for Civil Rights/HHS

More information

Exhibit B. State-By-State Data Security Overview

Exhibit B. State-By-State Data Security Overview Exhibit B State-By-State Data Security Overview Michele A. Whitham Partner, Founding Co-Chair Security & Privacy Practice Group Foley Hoag LLP 155 Seaport Boulevard Boston, MA 02210 State Statute Citation

More information

Protecting Social Security Numbers

Protecting Social Security Numbers Protecting Social Security Numbers: Federal Legislation in Sight STEVEN C. BENNETT, MAURICIO F. PAEZ, and Gwendolynne Chen Due to an alarming increase in identity theft crimes, a bipartisan bill, Protecting

More information

Settling Wage/Hour Claims: Weighing Settlement Options, Negotiating Damages, and Ensuring Court Approval

Settling Wage/Hour Claims: Weighing Settlement Options, Negotiating Damages, and Ensuring Court Approval Presenting a live 90-minute webinar with interactive Q&A Settling Wage/Hour Claims: Weighing Settlement Options, Negotiating Damages, and Ensuring Court Approval WEDNESDAY, JANUARY 15, 2014 1pm Eastern

More information

Mandatory Reporting of Child Abuse 6/2009 State Mandatory Reporters Language on Privilege Notes Alabama

Mandatory Reporting of Child Abuse 6/2009 State Mandatory Reporters Language on Privilege Notes Alabama Alabama any other person called upon to render aid to any child ALA. CODE 26-14-10 Alaska ALA. CODE 26-14-3(a) paid employees of domestic violence and sexual assault programs, and crisis intervention and

More information

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA): FACT SHEET FOR NEUROPSYCHOLOGISTS Division 40, American Psychological Association DISCLAIMER This general information fact sheet is made available

More information

A-79. Appendix A Overview and Detailed Tables

A-79. Appendix A Overview and Detailed Tables Table A-8a. Overview: Laws Expressly Granting Minors the Right to Consent Disclosure of Related Information to Parents* Sexually Transmitted Disease and HIV/AIDS** Treatment Given or Needed Alabama 14

More information

Builder's Risk Insurance for Construction Projects: Legal Issues

Builder's Risk Insurance for Construction Projects: Legal Issues Presenting a live 90-minute webinar with interactive Q&A Builder's Risk Insurance for Construction Projects: Legal Issues Evaluating Scope of Coverage, Policy Exclusions and Coverage Extensions and Sub-Limits

More information

Business Entity Conversions: Income Tax Consequences You May Not Anticipate

Business Entity Conversions: Income Tax Consequences You May Not Anticipate Presenting a live 110-minute teleconference with interactive Q&A Business Entity Conversions: Income Tax Consequences You May Not Anticipate Understanding and Navigating Complex Federal Income Tax Implications

More information

Structuring Rooftop Lease Agreements: Legal and Business Considerations

Structuring Rooftop Lease Agreements: Legal and Business Considerations Presenting a live 90 minute webinar with interactive Q&A Structuring Rooftop Lease Agreements: Legal and Business Considerations Negotiating Leases for Telecom Equipment, Solar Energy, Commercial Farming,

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (the "Agreement") is made and entered into this day of,, by and between Quicktate and idictate ("Business Associate") and ("Covered Entity").

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (the Agreement ) is by and between ( Covered Entity )and CONEX Med Pro Systems ( Business Associate ). This Agreement has been attached to,

More information

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES I. Overview / Definitions The Health Insurance Portability and Accountability Act is a federal law

More information

OFFICE OF CONTRACT ADMINISTRATION 60400 PURCHASING DIVISION. Appendix A HEALTHCARE INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPPA)

OFFICE OF CONTRACT ADMINISTRATION 60400 PURCHASING DIVISION. Appendix A HEALTHCARE INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPPA) Appendix A HEALTHCARE INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPPA) BUSINESS ASSOCIATE ADDENDUM This Business Associate Addendum ( Addendum ) supplements and is made a part of the contract ( Contract

More information

2012-2013 MEDICARE COMPLIANCE TRAINING EMPLOYEES & FDR S. 2012 Revised

2012-2013 MEDICARE COMPLIANCE TRAINING EMPLOYEES & FDR S. 2012 Revised 2012-2013 MEDICARE COMPLIANCE TRAINING EMPLOYEES & FDR S 2012 Revised 1 Introduction CMS Requirements As of January 1, 2011, Federal Regulations require that Medicare Advantage Organizations (MAOs) and

More information

Medical Expert Depositions in Workers' Comp Cases

Medical Expert Depositions in Workers' Comp Cases Presenting a live 90-minute webinar with interactive Q&A Medical Expert Depositions in Workers' Comp Cases Effective Techniques for Deposing Experts and Raising Strategic Objections TUESDAY, MARCH 11,

More information

LABORATORY CORPORATION OF AMERICA HOLDINGS BUSINESS PRACTICES MANUAL

LABORATORY CORPORATION OF AMERICA HOLDINGS BUSINESS PRACTICES MANUAL LABORATORY CORPORATION OF AMERICA HOLDINGS BUSINESS PRACTICES MANUAL Subject: Compliance With False Claims Acts Section: 27.0 Under Federal and State Laws Update: January 2015 Replaces: January 2013 Initiated

More information

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features:

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features: Presenting a live 90-minute webinar with interactive Q&A Drafting and Negotiating Convertible Preferred Stock Provisions: Protecting Interests of Businesses and Investors Structuring Liquidation and Distribution

More information

Model Regulation Service - January 1993 GUIDELINES ON GIFTS OF LIFE INSURANCE TO CHARITABLE INSTITUTIONS

Model Regulation Service - January 1993 GUIDELINES ON GIFTS OF LIFE INSURANCE TO CHARITABLE INSTITUTIONS Model Regulation Service - January 1993 These Guidelines have been prepared for use by state insurance department personnel who may be presented with questions or concerns regarding charitable gifts of

More information

This chart accompanies Protection From Creditors for Retirement Plan Assets, in the January 2014 issue of The Tax Adviser.

This chart accompanies Protection From Creditors for Retirement Plan Assets, in the January 2014 issue of The Tax Adviser. This chart accompanies Protection From Creditors for Retirement Plan Assets, in the January 2014 issue of The Tax Adviser. State-by-state analysis of IRAs as exempt property State State Statute IRA Alabama

More information

Welcome. This presentation focuses on Business Associates under the Omnibus Rule of 2013.

Welcome. This presentation focuses on Business Associates under the Omnibus Rule of 2013. Welcome. This presentation focuses on Business Associates under the Omnibus Rule of 2013. Business Associates have been part of the focus of the HIPAA regulations since 2003 when the privacy rule went

More information

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES NOTICE OF PRIVACY PRACTICES Effective Date: September, 2013 THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW

More information

Deficit Reduction Act Employee Information Requirements

Deficit Reduction Act Employee Information Requirements November 9, 2006 Deficit Reduction Act Employee Information Requirements The Deficit Reduction Act ( DRA ) requires states participating in the Medicaid program to amend their State Plans to mandate that

More information

Maintaining the Privacy of Health Information in Michigan s Electronic Health Information Exchange Network. Draft Privacy Whitepaper

Maintaining the Privacy of Health Information in Michigan s Electronic Health Information Exchange Network. Draft Privacy Whitepaper CHARTERED BY THE MICHIGAN HEALTH INFORMATION NETWORK SHARED SERVICES MIHIN OPERATIONS ADVISORY COMMITTEE (MOAC) PRIVACY WORKING GROUP (PWG) Maintaining the Privacy of Health Information in Michigan s Electronic

More information

Presented by: Leslie Bender, CIPP General Counsel/CPO The ROI Companies www.theroi.com

Presented by: Leslie Bender, CIPP General Counsel/CPO The ROI Companies www.theroi.com Healthcare Compliance: How HiTECH May Affect Relationships with Business Associates Presented by: Leslie Bender, CIPP General Counsel/CPO The ROI Companies www.theroi.com Legal Disclaimer This information

More information

Captive Insurance Companies in Estate Planning: A Profit Maximization and Risk Reduction Tool

Captive Insurance Companies in Estate Planning: A Profit Maximization and Risk Reduction Tool Presenting a live 90-minute webinar with interactive Q&A Captive Insurance Companies in Estate Planning: A Profit Maximization and Risk Reduction Tool Leveraging the Benefits for Asset Protection, Wealth

More information

HIPAA/HITECH Privacy and Security for Long Term Care. Association of Jewish Aging Services 1

HIPAA/HITECH Privacy and Security for Long Term Care. Association of Jewish Aging Services 1 HIPAA/HITECH Privacy and Security for Long Term Care 1 John DiMaggio Chief Executive Officer, Blue Orange Compliance Cliff Mull Partner, Benesch, Healthcare Practice Group About the Presenters John DiMaggio,

More information

2010 Fraud, Waste, and Abuse Training Materials

2010 Fraud, Waste, and Abuse Training Materials 2010 Fraud, Waste, and Abuse Training Materials UnitedHealthcare Medicare Plans Medicare Advantage AARP MedicareComplete Erickson Advantage Evercare Sierra Spectrum Sierra Village Health SM SecureHorizons

More information

HIPAA Privacy FAQ s. 3. Generally, what does the HIPAA Privacy Rule require the average provider or health plan to do?

HIPAA Privacy FAQ s. 3. Generally, what does the HIPAA Privacy Rule require the average provider or health plan to do? HIPAA Privacy FAQ s 1. What is the HIPAA privacy regulation? Until Congress passed HIPAA in 1996, personal health information (PHI) was protected by a patchwork of federal and state laws. Patients health

More information

AMWELL SERVICE PROVIDER SUBSCRIPTION AGREEMENT

AMWELL SERVICE PROVIDER SUBSCRIPTION AGREEMENT Revised: July 27, 2015 AMWELL SERVICE PROVIDER SUBSCRIPTION AGREEMENT Welcome to the AmWell Exchange Service (the Service ), which is owned and operated by American Well Corporation, a Delaware corporation

More information

MODEL REGULATION TO REQUIRE REPORTING OF STATISTICAL DATA BY PROPERTY AND CASUALTY INSURANCE COMPANIES

MODEL REGULATION TO REQUIRE REPORTING OF STATISTICAL DATA BY PROPERTY AND CASUALTY INSURANCE COMPANIES Model Regulation Service June 2004 MODEL REGULATION TO REQUIRE REPORTING OF STATISTICAL DATA Table of Contents Section 1. Section 2. Section 3. Section 4. Section 5. Section 6. Section 7. Section 8. Section

More information

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features: Dean C. Berry, Partner, Cadwalader Wickersham & Taft, New York

Presenting a live 90-minute webinar with interactive Q&A. Today s faculty features: Dean C. Berry, Partner, Cadwalader Wickersham & Taft, New York Presenting a live 90-minute webinar with interactive Q&A Estate Planning Involving Resident and Non-Resident Aliens Navigating Estate, Gift and GST Tax Rules, and Leveraging Estate and Lifetime Gifting

More information

FRANCHISE SALES COMPLIANCE

FRANCHISE SALES COMPLIANCE FRANCHISE SALES COMPLIANCE FRANCHISE SALES COMPLIANCE Federal Law Presale Disclosures Advance Delivery of Franchise Contracts Financial Performance Representations State Franchise Sales Laws Business Opportunity

More information

New Safe Harbors and Stark Exceptions for Electronic Prescribing and Electronic Health Records Arrangements

New Safe Harbors and Stark Exceptions for Electronic Prescribing and Electronic Health Records Arrangements New Safe Harbors and Stark Exceptions for Electronic Prescribing and Electronic Health Records Arrangements November 15, 2006 Steve Nash and Sara Hill, Holme Roberts & Owen LLP Agenda Introduction Background

More information

A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1

A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1 A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1 Policy and Procedure Templates Reflects modifications published in the Federal Register

More information

MEDICAL MALPRACTICE STATE STATUTORY

MEDICAL MALPRACTICE STATE STATUTORY MEDICAL MALPRACTICE STATE STATUTORY REFERENCE GUIDE 41 MEDICAL MALPRACTICE STATE STATUTORY REFERENCE GUIDE The following references to statutes relevant to medical malpractice cases are intended exclusively

More information

Updates on HITECH and State Breach Notification and Security Requirements Robin Campbell

Updates on HITECH and State Breach Notification and Security Requirements Robin Campbell Who s Afraid Of A Big Bad Breach?: Updates on HITECH and State Breach Notification and Security Requirements Robin Campbell Overview Identifying the laws that protect personal information and protected

More information

HIPAA Compliance: Are you prepared for the new regulatory changes?

HIPAA Compliance: Are you prepared for the new regulatory changes? HIPAA Compliance: Are you prepared for the new regulatory changes? Baker Tilly CARIS Innovation, Inc. April 30, 2013 Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed

More information

The Interoperable Electronic Health Record Understanding and Addressing the Legal and Regulatory Risks

The Interoperable Electronic Health Record Understanding and Addressing the Legal and Regulatory Risks The Interoperable Electronic Health Record Understanding and Addressing the Legal and Regulatory Risks HCCA Physician Immersion Session April 2006 Judy S. Ireland, Esq. Vice-President, Ethics and Compliance

More information

BUSINESS ASSOCIATE AND DATA USE AGREEMENT NAME OF COVERED ENTITY: COVERED ENTITY FEIN/TAX ID: COVERED ENTITY ADDRESS:

BUSINESS ASSOCIATE AND DATA USE AGREEMENT NAME OF COVERED ENTITY: COVERED ENTITY FEIN/TAX ID: COVERED ENTITY ADDRESS: BUSINESS ASSOCIATE AND DATA USE AGREEMENT NAME OF COVERED ENTITY: COVERED ENTITY FEIN/TAX ID: COVERED ENTITY ADDRESS:, City State Zip This Business Associate and Data Use Agreement ( Agreement ) is effective

More information

ADULT PROTECTIVE SERVICES, INSTITUTIONAL ABUSE AND LONG TERM CARE OMBUDSMAN PROGRAM LAWS: CITATIONS, BY STATE

ADULT PROTECTIVE SERVICES, INSTITUTIONAL ABUSE AND LONG TERM CARE OMBUDSMAN PROGRAM LAWS: CITATIONS, BY STATE ADULT PROTECTIVE SERVICES, INSTITUTIONAL ABUSE AND LONG TERM CARE OMBUDSMAN PROGRAM LAWS: CITATIONS, BY STATE (Laws current as of 12/31/06) Prepared by Lori Stiegel and Ellen Klem of the American Bar Association

More information

Listing of Mortgage Broker Definitions

Listing of Mortgage Broker Definitions State Definition Citation Text ALABAMA MORTGAGE BROKERS LICENSING ACT Mortgage broker means any person who directly or indirectly solicits, Ala. Code 5 25 2(9) processes, places, or negotiates mortgage

More information

HIPAA Policy Use and Disclosure of Protected Health Information November 3, 2015

HIPAA Policy Use and Disclosure of Protected Health Information November 3, 2015 HIPAA Policy Use and Disclosure of Protected Health Information November 3, 2015 SCOPE This policy applies to Florida Atlantic University s Covered Components and those working on behalf of the Covered

More information

Business Associate Agreement

Business Associate Agreement This Business Associate Agreement Is Related To and a Part of the Following Underlying Agreement: Effective Date of Underlying Agreement: Vendor: Business Associate Agreement This Business Associate Agreement

More information

Insurance Due Diligence in M&A Deals: Evaluating Coverage and Gaps, Mitigating Risks and Potential Liabilities

Insurance Due Diligence in M&A Deals: Evaluating Coverage and Gaps, Mitigating Risks and Potential Liabilities Presenting a live 90-minute webinar with interactive Q&A Insurance Due Diligence in M&A Deals: Evaluating Coverage and Gaps, Mitigating Risks and Potential Liabilities THURSDAY, OCTOBER 29, 2015 1pm Eastern

More information

HIPAA Compliance Guide

HIPAA Compliance Guide HIPAA Compliance Guide Important Terms Covered Entities (CAs) The HIPAA Privacy Rule refers to three specific groups as covered entities, including health plans, healthcare clearinghouses, and health care

More information

M&A Purchase Price Adjustment Clauses

M&A Purchase Price Adjustment Clauses Presenting a live 90-minute webinar with interactive Q&A M&A Purchase Price Adjustment Clauses Crafting Provisions to Mitigate Buyers' Financial Risks and Achieve Fair Compensation for Sellers THURSDAY,

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT ( Agreement ) by and between OUR LADY OF LOURDES HEALTH CARE SERVICES, INC., hereinafter referred to as Covered Entity, and hereinafter referred

More information

PUBLIC INSURANCE ADJUSTER FEE PROVISIONS 50 STATE SURVEY AS OF 6/29/07. LIKELY YES [Cal. Ins. Code 15027]

PUBLIC INSURANCE ADJUSTER FEE PROVISIONS 50 STATE SURVEY AS OF 6/29/07. LIKELY YES [Cal. Ins. Code 15027] Alabama Alaska Arizona Arkansas California [Cal. Ins. Code 15027] ] Colorado [Cal. Ins. Code 15027] Connecticut Delaware of the actual or final settlement of a loss [Conn. Ins. Code 38a-788-8] 2.5% of

More information

Business Associate Agreement (BAA) Guidance

Business Associate Agreement (BAA) Guidance Business Associate Agreement (BAA) Guidance Introduction The purpose of this document is to provide guidance for creating or updating business associate agreements between your Practice ( Covered Entity

More information

Commercial Leases: Risk Mitigation Strategies for Landlords and Tenants

Commercial Leases: Risk Mitigation Strategies for Landlords and Tenants Presenting a live 90-minute webinar with interactive Q&A Commercial Leases: Risk Mitigation Strategies for Landlords and Tenants WEDNESDAY, OCTOBER 10, 2012 1pm Eastern 12pm Central 11am Mountain 10am

More information

HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule

HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule JANUARY 23, 2013 HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule By Linn Foster Freedman, Kathryn M. Sylvia, Lindsay Maleson, and Brooke A. Lane On

More information

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers Compliance Tip Sheet National Hospice and Palliative Care Organization www.nhpco.org/regulatory HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers Hospice Provider Compliance To Do List

More information

Business Associate Agreement Involving the Access to Protected Health Information

Business Associate Agreement Involving the Access to Protected Health Information School/Unit: Rowan University School of Osteopathic Medicine Vendor: Business Associate Agreement Involving the Access to Protected Health Information This Business Associate Agreement ( BAA ) is entered

More information

Why Lawyers? Why Now?

Why Lawyers? Why Now? TODAY S PRESENTERS Why Lawyers? Why Now? New HIPAA regulations go into effect September 23, 2013 Expands HIPAA safeguarding and breach liabilities for business associates (BAs) Lawyer is considered a business

More information

MASS MARKETING OF PROPERTY AND LIABILITY INSURANCE MODEL REGULATION

MASS MARKETING OF PROPERTY AND LIABILITY INSURANCE MODEL REGULATION Table of Contents Model Regulation Service January 1996 MASS MARKETING OF PROPERTY AND LIABILITY INSURANCE MODEL REGULATION Section 1. Section 2. Section 3. Section 4. Section 5. Section 6. Section 7.

More information

HIPAA, HIPAA Hi-TECH and HIPAA Omnibus Rule

HIPAA, HIPAA Hi-TECH and HIPAA Omnibus Rule HIPAA, HIPAA Hi-TECH and HIPAA Omnibus Rule NYCR-245157 HIPPA, HIPAA HiTECH& the Omnibus Rule A. HIPAA IIHI and PHI Privacy & Security Rule Covered Entities and Business Associates B. HIPAA Hi-TECH Why

More information

PRIVACY PRACTICES OUR PRIVACY OBLIGATIONS

PRIVACY PRACTICES OUR PRIVACY OBLIGATIONS PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. General Information To comply

More information

Table of Mortgage Broker (and Originator) Bond Laws by State Current as of July 1, 2010

Table of Mortgage Broker (and Originator) Bond Laws by State Current as of July 1, 2010 Alabama Ala. Code 5-25-5 Bond only required where licensee does not submit evidence of net worth. Loan originators may be covered by Alaska 25,000 Alaska Stat. 06.60.045 Arizona $10,000-$15,000 Ariz. Rev.

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (the Agreement ) is entered into by and between Professional Office Services, Inc., with principal place of business at PO Box 450, Waterloo,

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( BAA ) is effective ( Effective Date ) by and between ( Covered Entity ) and Egnyte, Inc. ( Egnyte or Business Associate ). RECITALS

More information

Health Law Section Spring Conference May 7, 2013 Scott S. Bell. parsonsbehle.com

Health Law Section Spring Conference May 7, 2013 Scott S. Bell. parsonsbehle.com ANTI-KICKBACK STATUTE AND STARK LAW UPDATE Health Law Section Spring Conference May 7, 2013 Scott S. Bell parsonsbehle.com Anti-Kickback Statute Don t pay for referrals! 2 Anti-Kickback Statute Prohibits

More information

Cloud Computing in Healthcare: HIPAA and State Law Challenges Navigating Privacy and Security Risks

Cloud Computing in Healthcare: HIPAA and State Law Challenges Navigating Privacy and Security Risks Presenting a live 90-minute webinar with interactive Q&A Cloud Computing in Healthcare: HIPAA and State Law Challenges Navigating Privacy and Security Risks WEDNESDAY, JUNE 12, 2013 1pm Eastern 12pm Central

More information

Electronic Health Record License Agreements

Electronic Health Record License Agreements Presenting a live 90-minute webinar with interactive Q&A Electronic Health Record License Agreements Negotiating Scope of License, Warranties and Liability Disclaimers and Other Key Provisions THURSDAY,

More information

Standards of. Conduct. Important Phone Number for Reporting Violations

Standards of. Conduct. Important Phone Number for Reporting Violations Standards of Conduct It is the policy of Security Health Plan that all its business be conducted honestly, ethically, and with integrity. Security Health Plan s relationships with members, hospitals, clinics,

More information

False Claims Act Regulations by State

False Claims Act Regulations by State False Claims Act Regulations by State Under the False Claims Act, 31 U.S.C. 3729-3733, those who knowingly submit, or cause another person or entity to submit, false claims for payment of The purpose of

More information

New HIPAA regulations require action. Are you in compliance?

New HIPAA regulations require action. Are you in compliance? New HIPAA regulations require action. Are you in compliance? Mary Harrison, JD Tami Simon, JD May 22, 2013 Discussion topics Introduction Remembering the HIPAA Basics HIPAA Privacy Rules HIPAA Security

More information

Health Insurance Portability and Accountability Policy 1.8.4

Health Insurance Portability and Accountability Policy 1.8.4 Health Insurance Portability and Accountability Policy 1.8.4 Appendix C Uses and Disclosures of PHI Procedures This Appendix covers procedures related to Uses and Disclosures of PHI. Disclosures to Law

More information

3/13/2015 HIPAA/HITECH WHAT S YOUR COMPLIANCE STATUS? Daniel B. Mills Pretzel & Stouffer, Chartered WHAT IS HIPAA?

3/13/2015 HIPAA/HITECH WHAT S YOUR COMPLIANCE STATUS? Daniel B. Mills Pretzel & Stouffer, Chartered WHAT IS HIPAA? HIPAA/HITECH WHAT S YOUR COMPLIANCE STATUS? Daniel B. Mills Pretzel & Stouffer, Chartered WHAT IS HIPAA? 1 DEFINITIONS HIPAA Health Insurance Portability and Accountability Act of 1996 Primarily designed

More information

State Income and Franchise Tax Laws that Conform to the REIT Modernization Act of 1999 (May 1, 2001). 1

State Income and Franchise Tax Laws that Conform to the REIT Modernization Act of 1999 (May 1, 2001). 1 State Income and Franchise Tax Laws that Conform to the REIT Modernization Act of 1999 (May 1, 2001). 1 1. Alabama does not adopt the Code on a regular basis but instead specifically incorporates only

More information

Covered Entities and Business Associates: An Evolving Relationship

Covered Entities and Business Associates: An Evolving Relationship Covered Entities and Business Associates: An Evolving Relationship Rebecca L. Williams, RN, JD Partner, Chair of HEALTH/HIPAA Practice Davis Wright Tremaine LLP beckywilliams@dwt.com 1 No health care provider

More information

HIPAA Business Associate Addendum

HIPAA Business Associate Addendum HIPAA Business Associate Addendum THIS HIPAA BUSINESS ASSOCIATE ADDENDUM (this Addendum ) is by and between ( Covered Entity ) and TALKSOFT CORPORATION ( Business Associate ) (hereinafter, Covered Entity

More information

HIPAA PRIVACY FOR EMPLOYERS A Comprehensive Introduction. HIPAA Privacy Regulations-General

HIPAA PRIVACY FOR EMPLOYERS A Comprehensive Introduction. HIPAA Privacy Regulations-General HIPAA PRIVACY FOR EMPLOYERS A Comprehensive Introduction HIPAA Privacy Regulations-General The final HIPAA Privacy regulation was released on December 20, 2000 and was effective for compliance on April

More information

Population Health Management Program Notice of Privacy Practices from Evolent Health

Population Health Management Program Notice of Privacy Practices from Evolent Health Population Health Management Program Notice of Privacy Practices from Evolent Health MedStar Health, Inc., a Maryland not-for-profit corporation, has contracted with Evolent Health, Inc., a Delaware corporation

More information

Am I a Business Associate?

Am I a Business Associate? Am I a Business Associate? Now What? JENNIFER L. RATHBURN Quarles & Brady LLP KATEA M. RAVEGA Quarles & Brady LLP agenda» Overview of HIPAA / HITECH» Business Associate ( BA ) Basics» What Do BAs Have

More information

NAIC ANNUITY TRAINING Regulations By State

NAIC ANNUITY TRAINING Regulations By State Select a state below to display the current regulation and requirements, or continue to scroll down. Light grey text signifies states that have not adopted an annuity training program. Alabama Illinois

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This HIPAA Business Associate Agreement and is made between BEST Life and Health Insurance Company ( BEST Life ) and ( Business Associate ). RECITALS WHEREAS, the U.S.

More information

Fraud, Waste and Abuse Page 1 of 9

Fraud, Waste and Abuse Page 1 of 9 Page 1 of 9 Overview It is the policy of MVP Health Care, Inc. and its affiliates (collectively referred to as MVP ) to comply with all applicable federal and state laws regarding fraud, waste and abuse.

More information