Legal Issues in Electronic Health Records Acquisition, Implementation and Monitoring



Similar documents
New Safe Harbors and Stark Exceptions for Electronic Prescribing and Electronic Health Records Arrangements

Rebecca Williams, RN, JD Partner Co-chair Health Information Technology/HIPAA Practice Davis Wright Tremaine LLP

FRAUD AND ABUSE CONCERNS FOR ELECTRONIC PRESCRIBING AND ELECTRONIC HEALTH RECORDS

Health Law Bulletin. New Stark Law Exception and Anti-Kickback Statute Safe Harbor for E-Prescribing and Electronic Health Record Technology

Safe Harbors and Exceptions for E-Prescribing and Electronic Health Records: What Now?

group practice journal

Providing Subsidized EHR to Physicians Under Stark and Anti-Kickback Statute. Charles B. Oppenheim, Esq.

EHR Donation: Compliance with Stark Law and the Anti-Kickback Statute

ReedSmith. CMS and the OIG Extend Protections for Electronic Health Record Donations. Client Alert. Life Sciences Health Industry Group

STARK AND ANTI-KICKBACK PROTECTION FOR E-PRESCRIBING AND ELECTRONIC HEALTH RECORDS

Health October Proposed Health Information Technology Protections Under New Antikickback Statute Safe Harbors and New Stark Exceptions

HEALTH CARE ADVISORY

Stark and Anti-kickback Regulations: Proposed Changes for E-prescribing and Electronic Health Records

Electronic Health Record License Agreements

Fraud and Abuse Primer. Stark Law The Anti-Kickback Statute False Claims Act

Pre-conference Symposium Security and Privacy Issues in Electronic Health Records Acquisition and Implementation

Department of Health and Human Services

Donating Health Information Technology:

The Interoperable Electronic Health Record Understanding and Addressing the Legal and Regulatory Risks

Health information technology donations: A guide for physicians. Readiness survey inside

Legal Issues for Accountable Care Organizations

REGULATORY UPDATE: TELEMEDICINE

Department of Health and Human Services

What is the Meaning of Meaningful Use? How to Decode the Opportunities and Risks in Health Information Technology

Business Associates: HITECH Changes You Need to Know

How To Defend An Ehr Subsidy

EMR SHARING AND CONTRACTING ISSUES, RISKS AND PITFALLS KEVIN M. MOONEY, ESQ. COUNSEL/CHAIR IT PRACTICE GROUP THE CLEVELAND CLINIC FOUNDATION

ELECTRONIC MEDICAL RECORDS

Society of Corporate Compliance and Ethics

How To Help Your Health Care Provider With A Health Care Information Technology Bill

Data Breach, Electronic Health Records and Healthcare Reform

Adopting Electronic Medical Records: What Do the New Federal Incentives Mean to Your Individual Physician Practice?

PHYSICIAN/HOSPITAL FINANCIAL ARRANGEMENTS POST-TEST. Name: Date: Practice Plan:

Covered Entities and Business Associates: An Evolving Relationship

Physician Champions David C. Kibbe, MD, & Daniel Mongiardo, MD FAQ Responses

Health Care Mergers and Acquisitions

2014 HCCA Compliance Institute San Diego California Monday, March 31, :30 2:30

2014 HCCA Compliance Institute San Diego California Monday, March 31, :30 2:30

Legal Issues in the EHR Acquisition RFP Process

Fraud, Waste and Abuse Prevention Training

Part II: Exploration of Common Exceptions to the Stark Law. Kristin Cilento Carter

General Policy Statement and Standards on Prohibition on Self-Referrals, Kickbacks and Inducements to Refer. Refer to document abstract on Pulse

TJ RAI, M.D. THERAPY MEDICATION WELLNESS PRIVACY POLICY STATEMENT

HCCA 2013 COMPLIANCE INSTITUTE ANTI-KICKBACK STATUTE 101 SEATTLE, WASHINGTON

Negotiating EHR Acquisition Contracts

Fraud, Waste and Abuse Page 1 of 9

LMHS COMPLIANCE ORIENTATION Physicians and Midlevel Providers. Avoiding Medicare and Medicaid Fraud & Abuse

Fraud, Waste and Abuse Network Pharmacy Training 2011

CLINICALLY INTEGRATED NETWORKS: BUSINESS AND LEGAL CONSIDERATIONS

Fraud, Waste & Abuse. Training Course for UHCG Employees

New Privacy Laws Impacting the Health Care Work Place

A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1

MEDICARE COMPLIANCE TRAINING EMPLOYEES & FDR S Revised

2010 Fraud, Waste, and Abuse Training Materials

Medicare Advantage and Part D Fraud, Waste, and Abuse Training. October 2010

The Evolution of Service Line Co-Management Relationships with Physicians - Key Observations on Relationships and Fair Market Value

11 Key Concepts from the Stark Law

Federal Fraud and Abuse Laws

HIPAA Compliance, Notification & Enforcement After The HITECH Act. Presenter: Radha Chanderraj, Esq.

Health Care Compliance Association

AHLA. Y. Advising Providers in Adopting or Substituting a Health IT System. Charles C. Dunham Bond Schoeneck & King PLLC Albany, NY

Negotiating EHR Agreements: Complying with HIPAA, Stark and AKS, Overcoming Privacy and Security Risks

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers

Fraud, Waste, and Abuse

Compliance: What Every Reference Lab Representative Should Know By Peter Francis

TIPS FOR SELECTING AN ELECTRONIC HEALTH RECORD FOR YOUR PRACTICE 2009

The Patient Portal Ecosystem: Engaging Patients while Protecting Privacy and Security

EHRs in 2013: A Holistic View of Issues Facing Providers Wednesday, May 15, 2013

New Stark Rules Effective October, 2008: Are You In Compliance?

FirstCarolinaCare Insurance Company Business Associate Agreement

E-Health and Medical Billing Requirements


Over the last few months, several regulatory developments

SELLING YOUR PRACTICE: to an integrated delivery system

2Q. Will the Department provide guidance on the fair market value (FMV) for software and donated systems?

Auditing Medical School Clinical Departments

APPENDIX 1: Frequently Asked Questions

Thursday, October 10, 2013 POTENTIAL BARRIERS TO HOSPITAL SUBSIDIES FOR HEALTH INSURANCE FOR THOSE IN NEED

Department of Health and Human Services

Seven Component Framework For Compliance Auditing & Monitoring Physician Contracting In Healthcare Organizations

Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates

Federal and State Laws Relating to Referrals

HIPAA Security. 1 Security 101 for Covered Entities. Security Topics

HIPAA Compliance Issues and Mobile App Design

BUSINESS ASSOCIATE AGREEMENT

Accountable Care Organizations The Future Integrated Health Care Delivery Model?

Meaningful Use Requires Meaningful Laboratory Results

Finally! HHS Issues Proposed Rule Implementing Changes to the HIPAA Privacy, Security and Enforcement Rules under HITECH

ACCESS TO ELECTRONIC HEALTH RECORDS AGREEMENT

Meaningful Use Audits. NextGen Physician Consulting Services

C.T. Hellmuth & Associates, Inc.

Legal & Policy Issues Related to ACO Formation by Independent Physician Groups

Keeping our Focus: Compliance Summary for Customers and Health Care Professionals. Understanding the Olympus Health Care Compliance Code of Conduct

Access to Electronic Health Records Policy Franciscan Health System

FORM OF HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT

CMA BUSINESS ASSOCIATE AGREEMENT WITH CMA MEMBERS

2013 EHR Donation Program ELIGIBILITY FORM Doing business with HealthTronics Lab Solutions is NOT a condition of receiving a donation

What is HIPAA? The Health Insurance Portability and Accountability Act of 1996

The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq.

Transcription:

Legal Issues in Electronic Health Records Acquisition, Implementation and Monitoring Thomas E. Jeffry, Jr., Esq. Partner Los Angeles, CA 90017-2566 213-633-4265 tomjeffry@dwt.com Rebecca L. Williams, RN, JD Partner Seattle, WA 98101-1688 206-628-7769 beckywilliams@dwt.com

Introduction What s Driving EHRs? National initiative toward interoperable health records (by 2014) Quality of care and the push to reduce medical errors Transparency Electronic billing E-prescribing Homeland Security dealing with disasters 2

Key Decisions with Legal Impacts Nature of network: Centralized or peer-to-peer; record locator or central record repository; types of services e.g. ASP, closed or internet based Stand alone or integration with hospital or community; involvement of participating providers in governance and operations Plan for expansion; integration with RHIOs and the NHIN; who will decide who participates in network labs, pharmacies, public health agencies Acquisition and payment for necessary equipment and software to run the network, purchased by or given to physician participants; scope of training and support; ongoing fees and charges 3

The Stark Law Prohibits paying remuneration for referrals of Designated Health Services by physicians to entities with whom the physician has a financial relationship, unless an exception applies Financial relationship includes direct and indirect compensation arrangements even if the compensation is unrelated to a Designated Health Service Free or discounted hardware, software and other access to EHRs could qualify as remuneration creating an indirect compensation arrangement Argument: No financial relationship Historic relationship of information sharing between a hospital and its medical staff Caveat: other valuable remuneration may be at issue (e.g., hardware or software used for other purposes; network fees paid by hospital) If remuneration, find an exception 4

The Stark Law: Electronic Health Records Items and Services Exception IT items or services provided to a physician necessary and used predominantly to create, maintain, or share EHRs are not remuneration if all requirements of the exception are met. Donor requirements Any entity that provides designated health services Donor does not take any action to limit or restrict use, compatibility, or interoperability of EHR items or services Donor does not know that recipient has obtained equivalent items/services No reckless disregard Recipient requirements Recipient may be any physician Recipient physician does not make items/services a condition of doing business Selection of recipients/determination of nature of donation Not provided in a manner that takes into account the volume or value of referrals Donation Hardware, software, information technology and training Technology requirements Interoperable software Able to communicate and exchange data accurately, effectively, securely, and consistently with different information technology systems, software applications, and networks, in various settings and so purpose and meaning of data are reserved At the time it is provided Certification by certifying body recognized by the Secretary within 12 months of date provided No current standards Usable for all patients and payors Contains e-prescribing capabilities 5

The Stark Law: EHR Exception Payment for Technology Donors may not pay more than 85% of the cost of the donated technology Recipient must pay at least 15% of the donor s cost Cost sharing also applies to related services, e.g. training, help desk Recipient pays its share before receipt of items/services No donor financing Arrangement is Written and signed by the parties Specifies the items and services, donor s cost and recipient s contribution Covers all EHR items/services by donor Does not include physicians office staffing Items and services are not used primarily for personal business The arrangement does not violate the Anti-kickback or other laws related to claims submission Sunset: December 31, 2013 6

The Stark Law: EHR Exception Not Considered Volume or Value: The determination is based on: Total number of prescriptions written (but not volume or value of Rx dispensed or paid by donor or billed to the Medicare program) Size of medical practice (e.g., total patients, total patient encounters, total RVUs) Number of hours the physician practices medicine Overall use of automated technology in medical practice Whether physician is a medical staff member Other reasonable and verifiable manner that does not directly take into account the volume or value of referrals or business generated between parties 7

The Stark Law: Other Exceptions Medical staff incidental benefit Offered only on the hospital campus Related to facilitating hospital services Low value (less than $25/occurrence) Equipment lease Payments by a physician at FMV Non-monetary compensation up to $300 E-Prescribing Necessary and used solely for e-prescribing Compliant with Part D standards, including interoperability Donor-recipients: hospitals-medical staffs; physician practices-physician members; prescription drug plan sponsors and Medicare Advantage organizations-prescribing physicians No recipient cost sharing 8

Anti-Kickback Law Prohibits payment, solicitation, offer or acceptance of remuneration in exchange for a referral 2004 GAO Report: Physicians may be reluctant to accept... resources from a hospital... knowing that the resources may be viewed as remuneration and a violation of the Anti-kickback laws 9

Anti-Kickback Law: Safe Harbors Electronic health records items and services (More or less equivalent to Stark exception) Very different approach for OIG E-prescribing (also similar to Stark exception) Rental Personal services Otherwise rely on other considerations to negate intent that one purpose was to encourage referrals FMV No requirements to refer 10

Tax-Exempt Status [501(c)(3)] Charitable purposes Operated exclusively for charitable, scientific, educational and religious purposes Includes community benefits consistent with purposes Avoids more than incidental benefits Private inurement Private inurement No part of net earnings inures to the benefit of an insider Could include key members of the medical staff Private benefit Prohibition on conferring more than incidental benefits on private parties (quantitative v. qualitative) RHIOs as tax-exempt organizations IRS plans to release its hold this fall on PLRs Fact-specific analysis including no competition with for-profits and examination of funding sources 11

Privacy: Use and Disclosure Compliance with HIPAA and State laws related to privacy of health information Uses and disclosures generally permitted for: Treatment, payment and (at least limited) health care operations With authorization from patient or personal representative Business associate Organized Health Care Arrangements 12

Privacy: Individual Rights General issues Determine responsibilities Centralized v. de-centralized Allocation of risk Access Amendment Accounting of Disclosures Requests for additional privacy protections Alternate communications Notice of privacy practices 13

Security HIPAA security standards apply to protected health information (PHI) that is either stored or transmitted electronically Security is only as good as the weakest link in the network Need to consider administrative, physical and technical safeguards related to storage and transmission of electronic data Authentification of users who access records Protection from alteration or destruction Monitoring where it goes who protects the audit trail 14

Antitrust Antitrust laws prohibit anti-competitive behavior Price-Fixing Exclusionary, anti-competitive practices Tying arrangements Permissible forms of clinical integration as compared with unlawful horizontal integration IPAs Financially and operationally integrated medical groups 15

Coordination of Agreements Acquisition of hardware Software licenses User agreements Sanctions Service agreements Connectivity Business associate contracts Network policies and procedures 16

Liability Breaches of privacy/security Breach of user agreement and licenses Malpractices issues Exit strategy Ownership of records Determine if/how to separate Porting data to new platform Records retention 17

Questions 18