HIPAA
The Regulatory Sprint Catches up to HIPAA: New Proposed HIPAA Rules
Today, the Department of Health and Human Services’ (“HHS”) Office for Civil Rights (“OCR”) issued a Notice of Proposed Rulemaking (“NPRM”) which proposes significant changes to the Health Insurance Portability and Accountability Act (“HIPAA”) and to the Health Information Technology for Economic and Clinical Health Act (“HITECH”) Privacy Rule (the “Privacy Rule”). The NPRM includes numerous changes to the Privacy Rule that are part of HHS’ Regulatory Sprint to Coordinated Care which is intended to eliminate administrative barriers to a health care delivery system that fosters care coordination and value-based care for patients. OCR also issued a fact sheet about this NPRM, which is available here. This NPRM comes nearly two years after OCR issued a Request for Information (“RFI”) in December 2018 calling for information from the public regarding ways that HIPAA regulations could be modernized to support coordinated, value-based care. These changes in federal regulations are anticipated to make a significant impact on healthcare providers and other stakeholders that may have been reticent to initiate certain care coordination arrangements because of perceived HIPAA violations or a lack of regulatory certainty. Clarifications to existing regulations will impact stakeholders beyond their involvement in care coordination arrangements. The changes will also impact data sharing arrangements and reduce unnecessary administrative burdens on health care providers and health plans, such as eliminating the requirement to obtain an individual’s signature for the Notice of Privacy Practices (“NPP”) or the requirement to retain copies of the NPP for six years. Further, the proposed changes to the Privacy Rule provide clarification to the laws governing patient rights of access to their health records, and help to better facilitate disclosures of health information in order to improve care for patients in emergencies or who are experiencing a health crisis, including mental health crises and opioid overdose situations. Comments to the NPRM are invited from stakeholders, and will be due some time in February 2021, at a date that is 60 days after the NPRM is published in the Federal Register. Please contact the author of this post or your regular Dorsey attorney if you have questions about how these changes to the Privacy Rule could impact you, and for assistance in submitting comments to the OCR. The team of attorneys in Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group will continue to closely monitor these changes, and post updates and analysis on Dorsey’s Health Law Blog and on Dorsey’s Regulatory Sprint Webpage as new information becomes available.
December 10, 2020
by Alissa Smith
HIPAA
2020’s a Bust, but HIPAA Enforcement Is on a Roll!
The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) has been actively enforcing HIPAA regulations this year, including a series of seven settlements under OCR’s Right of Access Initiative to enforce patients’ rights to timely access their medical records at a reasonable cost. This year, OCR has recorded more than $12.2 million in resolution agreements. This post summarizes OCR’s settlements in 2020 to date. The OCR settlements have impacted a wide range of sectors in the health industry from health insurers, to hospital systems, physician clinics, FQHCs, mental health and substance abuse providers, business associates, and nonprofits serving those with AIDS/HIV. Enforcement has been taken against all sizes of entities, including against solo practitioners and very small non-profits. As with nearly all settlements with OCR, it was the initial breach notification that triggered the investigation. However, the settlement ultimately resulted after OCR’s investigation discovered widespread non-compliance with HIPAA’s privacy and security requirements. The following post provides a summary of these enforcement actions, and begins with an update about Anthem’s recent $39.5M settlement with 43 states and D.C. stemming from its massive data breach in 2014-2015, which resulted in a record $16 million settlement with OCR in 2018. Health Insurer Enforcement Anthem and 43-State Coalition Reach $39.5 Million Settlement Over Data Breach On September 30, 2020, state attorneys general in 43 states and Washington D.C. announced that they had reached a $39.5 million settlement with Anthem Inc., an Indianapolis, IN-based health insurer. This settlement stemmed from an investigation by the state attorneys general into the largest health data breach in history, a series of state-sponsored cyberattacks in December 2014 and January 2015 that exposed the ePHI of nearly 79 million individuals. In 2018, Anthem agreed to pay $16 million to OCR and to take substantial corrective action to settle potential violations of the HIPAA privacy and security rules related to the 2014 data breach. See the HHS press release about the OCR settlement here. Anthem has also paid $115 million to settle a class action related to the breach, the largest-ever class action settlement related to a data breach. Premera Blue Cross Pays $6.85 Million to Settle Data Breach Affecting Over 10.4 Million People In March, in the second-largest HIPAA settlement ever, Premera Blue Cross (PBC), the largest health plan in the Pacific Northwest, agreed to pay $6.85 to OCR and to implement a corrective action plan to settle potential HIPAA privacy and security rules violations related to a data breach. Using malware installed through a phishing email, cyber-attackers gained access to PBC’s system in August 2014 and went undetected until January 2015, resulting in the exposure of over 10.4 million individuals’ electronic protected health information (ePHI). OCR’s investigation determined that PBC had “systemic noncompliance with the HIPAA Rules including failure to conduct an enterprise-wide risk analysis, and failures to implement risk management, and audit controls.” See the HHS press release here. Hospital and Health System Enforcement Lifespan Pays $1.04 Million to Settle Unencrypted Stolen Laptop Breach Affecting Over 20,000 People In June, Lifespan Health System Affiliated Covered Entity (“Lifespan ACE”), a Rhode Island-based non-profit health system, agreed to pay a $1.04 million settlement to OCR and to adopt a corrective action plan to settle potential violations of the HIPAA privacy and security rules related to the theft of a hospital employee’s unencrypted laptop. The laptop contained the ePHI of more than 20,000 individuals. OCR’s investigation determined that there had been systematic noncompliance with the HIPAA Rules, including a failure to encrypt ePHI on laptops, a lack of device and media controls, and a failure to have a business associate agreement in place with the Lifespan Corporation, the parent company and business associate of Lifespan ACE. See the HHS press release here. Physician and Clinic Enforcement Solo Practice Pays $100,000 for Failing to Implement HIPAA Security Rule Requirements In February, Steven A. Porter, M.D., a Utah gastroenterologist and solo practitioner, agreed to pay $100,000 to OCR and to adopt a corrective action plan to settle a potential violation of the HIPAA security rule. OCR determined that Dr. Porter’s practice had demonstrated significant noncompliance with the HIPAA rules, specifically, failing to conduct any risk analysis and failing “to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.” See the HHS press release here. Orthopedic Clinic Pays $1.5 Million to Settle Systemic Noncompliance with HIPAA Privacy and Security Rules In July, Georgia-based Athens Orthopedic Clinic PA (“Athens Orthopedic”) agreed to pay $1.5 million to OCR and to implement a corrective action plan to settle potential violations of the HIPAA privacy and security rules. A hacker used a vendor’s credentials to access Athens Orthopedic’s electronic medical record system and exfiltrated patient health data, then demanded money from Athens Orthopedic in return for the return of the stolen records. Nearly 210,000 individuals were affected by the breach. OCR’s investigation found noncompliance with the HIPAA privacy and security rules, including “failures to conduct a risk analysis, implement risk management and audit controls, maintain HIPAA policies and procedures, secure business associate agreements with multiple business associates, and provide HIPAA Privacy Rule training to workforce members.” See the HHS press release here. FQHC Pays $25,000 for Failing to Implement HIPAA Security Rule Requirements In March, Metropolitan Community Health Services (“Metro”), doing business as Agape Health Services, agreed to pay $25,000 to OCR and to implement a corrective plan to settle potential violations of the HIPAA security rule. In 2011, Metro reported impermissible disclosure of PHI to an unknown email account, which affected over 1,200 patients. OCR’s investigation found that Metro had failed to conduct any risk analysis, failed to implement any HIPAA security rule policies and procedures, and not provided workforce members with security awareness training until 2016. Metro is a Federally Qualified Health Center that provides medical services in underserved areas in rural North Carolina on a sliding fee scale, which was taken into account in reaching this agreement. See the HHS press release here. Business Associate Enforcement CHSPSC Agrees to Pay $2.3 Million to Settle Data Breach Affecting Over 6 Million People In March, CHSPSC LLC (“CHSPSC”) agreed to pay $2.3 million and to adopt a corrective action plan to settle potential violation of the HIPAA privacy and security rules related to a breach affecting more than 6 million people. CHSPSC is based in Tennessee and provides a variety of business associate services, including IT and health information management. In 2014, the Federal Bureau of Investigation (FBI) notified CHSPSC that it had traced a cyber-attack to CHSPSC’s information system. OCR’s subsequent investigation found “longstanding, systematic noncompliance” with the HIPAA security rule, including “failure to conduct a risk analysis, and failures to implement information system activity review, security incident procedures, or access controls.” See the HHS press release here. Right of Access Initiative Enforcement In 2019, OCR announced the Right of Access Initiative as an enforcement priority to support individuals’ right to timely access to their health records at a reasonable cost and in the readily producible format of their choice under the HIPAA privacy rule’s right of access provision, 45 CFR § 164.524. The HIPAA Rules generally require covered health care providers to provide medical records within 30 days of the request and providers can only charge a reasonable cost-based fee. This right to patient records extends to parents seeking access to their minor children’s medical records. To date this year, OCR has completed seven enforcement actions totaling $396,500 in settlement payments under the Right of Access Initiative, bringing the total number of enforcement settlements under this initiative to nine. In June, Housing Works Inc. (Housing Works), a New York City-based non-profit organization providing a range of services to individuals living with and affected by HIV/AIDS, including health care, agreed to pay $38,000 to OCR and to take corrective actions to settle a potential right of access violation. In complaints filed with OCR in July and August 2019, a patient alleged that he had not received his records in response to a June 2019 request. OCR opened an investigation, found a possible violation, and the patient received his medical records in November 2019. In July, All Inclusive Medical Services (AIMS), a California-based multi-specialty family medicine clinic, has agreed to pay $15,000 to OCR and to adopt a corrective action plan to settle a potential right of access violation. A patient alleged that in January 2018, AIMS had denied her requests to inspect and receive a copy of her records, in an April 2018 complaint filed with OCR. The patient ultimately received her medical records in August 2020. In August, Beth Israel Lahey Health Behavioral Services (BILHBS), the largest network of mental health and substance use disorder services in eastern Massachusetts, agreed to pay $70,000 to OCR and to take corrective actions following a potential right of access violation. A personal representative filed a complaint with OCR in April 2019 alleging that she had requested her father’s medical records in February 2019 and BILHBS had failed to provide them. BILHBS provided the requested medical records in October 2019. In August, Patricia King, M.D. (King MD), a small provider of psychiatric services in Virginia, agreed to pay $3,500 to OCR and to adopt a corrective action plan to settle a potential right of access violation. OCR received a complaint from a patient in October 2018, alleging that King MD failed to respond to her August 2018 request for her medical records. After OCR provided King MD with technical assistance on right of access requirements, a second complaint, and an OCR investigation that found that the failure to provide the requested medical records was a potential violation, the patient received her medical records in July 2020. In August, Wise Psychiatry, PC (Wise Psychiatry) a small provider of psychiatric services in Colorado, agreed to pay $10,000 to OCR and to take corrective actions to settle a potential right of access violation. A father requested his minor son’s medical records in November 2017, and following two complaints to OCR, OCR providing technical assistance to Wise Psychiatry on the HIPAA right of access requirements, and OCR opening an investigation, Wise Psychiatry sent the requested medical records in May 2019. See HHS’s press release about OCR’s first five right to access settlements of 2020 here. In September, Dignity Health, doing business as St. Joseph’s Hospital and Medical Center (SJHMC), agreed to pay $160,000 and to adopt a corrective action plan to settle a potential right of access violation. SJHMC is based in Arizona and is a large, acute-care hospital with several hospital-based clinics. A mother made several requests for her son’s medical records, as his personal representative, beginning in January 2018, but did not receive all of the requested records until December 2019. See the HHS press release here. In September, NY Spine Medicine (NY Spine), a private medical practice specializing in neurology and pain management with offices in New York and Florida, agreed to pay $100,000 and to take corrective actions to settle a potential right of access violation. A patient requested a copy of her medical records in June 2019, and NY Spine provided some records in response, but did not provide the diagnostic films that the patient had specifically requested until October 2020, after OCR had initiated an investigation. See the HHS press release here. OCR’s enforcement of the HIPAA security and privacy rules this year is increasingly aggressive. Per HHS, OCR’s enforcement actions are “designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.” If you have questions about HIPAA compliance, please contact the authors, your regular Dorsey attorney or any attorney in the Dorsey & Whitney health transactions and regulations practice group.
October 15, 2020
by Alissa Smith and Elizabeth Greiter
HIPAA
Privacy of Substance Use Disorder Records and The CARES Act: Steps Toward Harmonizing Part 2 Privacy Laws with HIPAA
The recently-enacted Coronavirus Aid, Relief, and Economic Security Act (the “CARES Act”) is generally known for providing relief funds and other resources to help individuals, small businesses, state and local governments, and hospitals and healthcare providers address the COVID-19 public health emergency. However, among the lesser-known of the CARES Act provisions are changes to federal law that will allow a significant harmonization of rules governing the confidentiality of substance use disorder patient records with the general federal rules governing the privacy of individually identifiable health information (i.e., the HIPAA privacy rules). Currently, a unique set of federal regulations found at 42 C.F.R. Part 2 restrict the disclosure and use of substance use disorder patient records that are maintained in connection with any federally-assisted substance use disorder program. These “Part 2” rules are far stricter than the federal HIPAA privacy rules that apply generally to health plans and health care providers. For example, whereas the HIPAA privacy rules allow health plans and health care providers to use and disclose protected health information (“PHI”) for purposes of treatment, payment, and health care operations without a patient’s written or oral consent, the Part 2 rules do not. Another important distinction between the Part 2 rules and HIPAA is that if a patient authorizes the disclosure of PHI under HIPAA to an entity that is not regulated by HIPAA, then the PHI disclosed to that recipient falls outside the protections of HIPAA. In contrast, when a patient consents to the disclosure of their substance use disorder records under Part 2, the Part 2 rules continue to apply to the records disclosed, even when the recipient is not a regulated Part 2 SUD program. Section 3221 of the CARES Act modifies the statute governing the confidentiality of SUD records in various and important ways. First, a Part 2 SUD program will be allowed to obtain the prior written consent of a patient to use and disclose SUD records for purposes of treatment, payment, and health care operations as permitted by the HIPAA privacy rules. An SUD program will need to obtain that patient consent only once, and the consent will apply to all future uses and disclosures of SUD records until a patient revokes the consent in writing. The statute goes on to state that any information disclosed pursuant to such a consent may then be redisclosed in accordance with the HIPAA regulations. Although not entirely clear, this appears to mean that an entity not regulated by HIPAA that receives SUD records pursuant to a consent may redisclose the records without limitation under either HIPAA or the Part 2 rules. The CARES Act also states explicitly that the HIPAA breach notification provisions apply to SUD records held by a Part 2 program in the same manner that those rules apply to HIPAA covered entities. Furthermore, the CARES Act extends HIPAA’s penalty and enforcement provisions to violations of the Part 2 rules. Although the Department of Health and Human Services (“HHS”) will need to issue regulations to confirm the operation of these enforcement provisions, this appears to mean that the HHS Office for Civil Rights may take on the civil enforcement of the Part 2 rules, in addition to enforcing the HIPAA rules. The primary reason for the historically strict privacy rules applicable to SUD records is to ensure that a patient receiving treatment for a substance use disorder in a Part 2 program is not more vulnerable because of the availability of their patient record than an individual with a substance use disorder who does not seek treatment. In an effort to maintain this public policy goal while at the same time making the Part 2 rules more consistent with the HIPAA rules, the CARES Act enacts a general antidiscrimination provision prohibiting any entity from discriminating against an individual on the basis of information in Part 2 SUD records in: (a) admission, access to, or treatment for health care; (b) hiring, firing, or terms of employment or receipt of worker’s compensation; (c) the sale, rental, or continued rental of housing; (d) access to federal, state, or local courts; or (e) access to, approval of, or maintenance of government social services and benefits. Furthermore, other than as authorized by a court order or consented to by the patient, no SUD records or testimony relaying the information contained in such records, may be disclosed or used in any civil, criminal, administrative, or legislative proceedings conducted by any governmental authority against a patient. The statute mandates that regulations to implement and enforce these CARES Act provisions be issued to facilitate their application to all uses and disclosure of SUD records occurring on or after one (1) year following the enactment of the CARES Act (which would be March 27th, 2021). Once implemented, the CARES Act provisions will be helpful to Part 2 programs, many of which struggle with the complexity of complying with both HIPAA and the Part 2 privacy rules. But the new Part 2 law will by no means alleviate all of that complexity. For example, a Part 2 program will be required to obtain a patient’s written consent in order to use and disclose SUD records for treatment, payment, and health care operations purposes; for those Part 2 program patients that refuse to sign such a consent, the Part 2 program will likely need to segregate those SUD records in order to manage the stricter limitations on their use and disclosure. Moreover, the CARES Act does not harmonize Part 2 and HIPAA entirely; there will remain many uses and disclosures that are permitted under HIPAA but not permitted with regard to SUD records under Part 2. Ultimately the CARES Act provisions modifying the Part 2 confidentiality rules will mitigate, but not eliminate, the complexities of managing patient records regulated by two separate sets of federal privacy rules. If you have questions about the CARES Act, HIPAA, or the Part 2 rules, please contact the author or any attorney in the Dorsey & Whitney health transactions and regulations practice group.
April 22, 2020
by Ross C. D'Emanuele
HIPAA
HIPAA and COVID-19 Updates: The Office for Civil Rights Provides Additional Guidance on Permitted Disclosures to First Responders
Since the COVID-19 outbreak, many health care providers have had a myriad of HIPAA questions, including questions about whether they can share some types of information and, if so, the type of information they can share with first responders who may have been exposed. Today, the Office for Civil Rights (OCR) published guidance outlining the already-existing HIPAA provisions that permit health care providers to share the name or other identifying information of an individual who has been infected with or exposed to the virus, with paramedics, other first responders, law enforcement and public health authorities, available here. The guidance addresses some of the most relevant disclosures that are allowed under HIPAA without the individual’s authorization: when needed for treatment, when required by law to notify a public health authority when necessary to prevent or lessen a serious and imminent threat to the health and safety of a person of the public, and when responding to a request by a correctional institution or law enforcement official that has custody of an inmate or other individual. As a reminder, except for disclosures that are required by law or disclosures for treatment purposes, health care providers are required to make reasonable efforts to limit the information to that which is “minimum necessary” to accomplish the purpose of the disclosure. The OCR also provided a couple of helpful examples that will be relevant to health care providers in the coming days. Here is one of them: “Example: A covered entity, such as a hospital, may provide a list of the names and addresses of all individuals it knows to have tested positive, or received treatment, for COVID-19 to an EMS dispatch for use on a per-call basis. The EMS dispatch (even if it is a covered entity) would be allowed to use information on the list to inform EMS personnel who are responding to any particular emergency call so that they can take extra precautions or use personal protective equipment (PPE). Discussion: Under this example, a covered entity should not post the contents of such a list publicly, such as on a website or through distribution to the media. A covered entity under this example also should not distribute compiled lists of individuals to EMS personnel, and instead should disclose only an individual’s information on a per-call basis. Sharing the lists or disclosing the contents publicly would not ordinarily constitute the minimum necessary to accomplish the purpose of the disclosure (i.e., protecting the health and safety of the first responders from infectious disease for each particular call).” Additional articles about the application of HIPAA during the COVID-19 outbreak, and other legal resources applicable to the COVID-19 outbreak are available here and here. Please contact the author or your regular Dorsey attorney with any questions about this guidance.
March 24, 2020
by Alissa Smith
HIPAA
COVID-19 and Cross-State Clinician Licensure: Federal and State Regulations, Revisited, and What To Do About Them
The COVID-19 pandemic has dramatically increased the number of patients and providers seeking to implement and use telehealth visits and other digital health solutions – and rapidly, at that. The challenge of implementing digital health solutions, particularly telehealth, has historically been the patchwork setup of both federal and various state regulations that made it difficult for providers and telehealth vendors to offer solutions at a large scale, particularly across state lines. In the current state of public emergency, both the federal government and various state governments are recognizing the need to ease prior restrictions and expand telehealth availability in order to help patients receive care at home; this helps limit the spread of COVID-19 by further enabling social distancing and freeing up providers’ brick-and-mortar hospitals and clinics to treat COVID-19 patients. The need is clear, as is the desire by all parties to jump in and offer telehealth visits. The new challenge has become understanding how state requirements fit in daily updates to federal law. In this blog post, we will look first to the current legal environment with respect to the federal waiver and state regulations, and then provide recommendations (in numbered list below) as to what this means for your plans to offer telehealth visits. Specifically, clinical licensure has traditionally been amongst the most challenging regulations to contend with in offering telehealth visits. Federal reimbursement and state clinician licensure rules generally restrict clinicians from offering telehealth services to a patient physically located in a state without the appropriate medical license in that state. Now, however, through CMS 1135 waivers and state-specific executive orders, which we have described more below, clinicians are able to leverage relaxed cross-state reimbursement and licensure rules to offer telehealth services more easily and immediately during this time of public health emergency. Historically, the general rule, with few exceptions, is that a clinician must be licensed to practice in the state in which the patient receiving telehealth services is located. These rules are derived from state professional licensing laws, as well as from payor requirements, including the conditions of payment under the Medicare and Medicaid programs. Therefore, a physician licensed to practice in Minnesota, for example, could not typically provide telehealth services to a patient located in Iowa during the time of the visit without first obtaining an Iowa license to practice medicine. Failure to do so could subject the physician’s medical license to discipline, and could also render the services not billable to various private and governmental payors. Currently, the in-state licensure requirements of payors and professional licensing bodies are beginning to change within the confines of the COVID-19 public health emergency. With respect to Medicare and Medicaid billing requirements, under the emergency proclamation by the President, CMS has the authority to issue “1135 waivers” that will temporarily waive or modify certain Medicare and Medicaid requirements to ensure that sufficient health care items and services are available to meet the needs of individuals enrolled in Federal health care programs. Shortly following the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak, both HHS and CMS issued statements announcing a number of COVID-19 1135 waivers now either applicable automatically nationwide or available through request by individual providers and the states, depending on the type of waiver. These waivers encompass an array of options and relaxing of rules that apply to services provided to Medicare and Medicaid patients. One of the waivers provides that CMS will “temporarily waive [reimbursement] requirements that out-of-state providers be licensed in the state where they are providing services when they are licensed in another state” (the “Clinician Licensing Waiver”). (Other waivers ease restrictions surrounding provider Medicare and Medicaid enrollment, skilled nursing and other long-term care facility requirements, and bed allocation requirements). This is an enormous and important shift, and one that digital health advocates have been championing for a long time, as it enables clinicians to “see” patients in other states without a protracted cross-state licensure process. The challenge, however, is understanding how the federal waivers and existing state requirements interact. These 1135 waivers apply only to federal requirements, and any providers looking to practice in accordance with these waivers must be careful to also comply with applicable state laws. Largely, the COVID-19 1135 waivers fall in two categories: (1) blanket waivers; and (2) case-by-case waivers. The blanket waivers include those waivers listed by CMS in their statement and are applicable automatically nationwide with respect to Medicare rules (not Medicaid or other CMS programs, except by request, as noted below). The Clinician Licensing Waiver is one such waiver. This waiver applies automatically to Medicare reimbursement, but clinicians must also ensure they are practicing in accordance with a particular state’s licensing rules before issuing professional services in that state. States that would like these Medicare blanket waivers, including the Clinician Licensing Waiver, to apply to their state’s Medicaid program must send a request to CMS for case-by-case approval. Currently, only Florida and Washington have received approval for their requested COVID-19 1135 waivers, including the Clinician Licensing Waiver along with other provider enrollment and prior authorization requirement waivers. However, CMS states that it will continue to expeditiously review and approve 1135 waivers during the COVID-19 public health emergency. This CMS website will provide up-to-date information on all states that receive any COVID-19 1135 waivers. While the Clinician Licensing Waiver is limited in applicability to Medicare and Medicaid reimbursement, states are beginning to follow suit by temporarily waiving their state level professional licensure requirements for telehealth providers. Still, providers should take caution to not provide services without a state license unless and until it is confirmed that the state will allow this practice. One state that we have identified as permitting telehealth practice without a state license during the COVID-19 public health emergency is Iowa. Iowa’s emergency proclamation contains a section that temporarily suspends various telehealth practice standards, including the requirement that Iowa telehealth providers be licensed in Iowa. Note, however, that commercial payor rules may be unaffected by both the federal waivers and the easing of state professional licensing rules. From an operational standpoint, the Clinician Licensing Waiver ostensibly eases offering telehealth visits across state lines, but the state-specific regulations still require ongoing vigilance. For those providers and other types of vendors seeking to offer telehealth, we would encourage the following: Identify exactly which populations you must be able to treat in order for the telehealth visits to be feasible and viable (financially and operationally) for your organization While organizations would like to be able to immediately offer telehealth visits for everyone, the reality at this time, while states sort out whether they will ease state licensure restrictions, is that you may only be able to conduct telehealth visits and receive reimbursement in states in which your clinician is allowed to practice without a license and for certain populations only. It will vary tremendously by state, and the answer may change on a near-daily basis, as states make their decisions. Speak with your attorney about the states in which you want to offer visits (or where your patient populations may currently be) to understand the current status for those states Per above, the situation is changing rapidly, and we strongly recommend asking your attorney to check the state’s status vis-à-vis the federal waivers. We would advise adding that into your tracking document (see next item). Draft your quick state-by-state plan and what your readiness checks will be to start with a new state (and do not worry – this can be rough-and-ready) We often help our clients with state rollout plans and readiness checklists, and they are still important now; however, given the dramatic need for speed, do not let the perfect be the enemy of the good. Based on your answers to the above two items, you should confirm with your team both the plan for which states you will be able to offer visits in and also the criteria for when and how you will assess and identify the next states in which you can offer telehealth services. You can perfect and polish these plans at a later point, but having a plan of action for all involved will prevent confusion or, worse, lack of compliance if you do not pay careful attention to states’ evolving rules. We would recommend that your state readiness checklist include an attorney approval step; this is particularly important now, since the states’ rules are changing so rapidly. The good news is that, for the most part, the changes are leaning toward the more permissive rather than restrictive, so you may find new states in which you are able to operate. Identify exactly which active state licenses your clinicians hold and document, ideally in a spreadsheet or other easy tracking mechanism We recommend (and create for our clients) tracking tools with respect to clinical licensure during regular times, and it is equally important now. While the goal is to be able to offer telehealth visits to patients in states in which your clinicians are not currently licensed, you will need to keep track of who is actually licensed where, so that if and when regulations should revert, or if and when there should be changes to the scope of licensure or reimbursement, you are able to quickly assess your own staff’s licensure status and pivot as needed. These tracking tools need not be fancy, though it is helpful to tie them to calendar reminders or other ticklers to enable consistent monitoring. Keep in mind – and regularly monitor – other relevant requirements as you contemplate the nature and process of the telehealth visits. For example, you will still want to abide by current HIPAA requirements (which are also changing during this public emergency – please see our article here), documentation requirements, and reimbursement-related considerations. Your standard operating procedure and telehealth visit process will likely need to be altered to include verbal caveats or discussion points between your providers and the patients. We would advise reviewing and then either drafting or updating your current visit script, as well as the documentation presented on your website portal for the telehealth visit. Your plan for downtime procedures is going to become all the more important – assess if you’re ready and that your providers are aware of what to do. With so many people using internet and particularly video chat services, our IT infrastructure and that of the telehealth platform vendors themselves is experiencing a surge in usage, which will test capacity levels. This would be the case in “regular” life, but becomes more important now, as you reach out to and conduct telehealth visits with new patients: does your script and posted information include information as to how the patient can reach you if the telehealth visit is interrupted? What should be their plan with respect to reaching out to local (in-state) providers versus your organization, both for downtime and post-visit? This issue is rapidly changing and being updated at both the Federal and state level on a day-to-day basis. For additional information on various COVID-19 responses, guidance and resources, please see our articles on Medicare payment for telehealth services; HIPAA provisions now allowing the use of personal devices and everyday communication technology to deliver telehealth; DEA prescribing laws now allowing controlled substances to be prescribed via telehealth without an in person exam; and numerous other helpful legal analyses and guidance on COVID-19 related matters. If you would like specific information on how your state is currently treating these issues, please reach out to the authors or your usual Dorsey attorney or Dorsey Health Strategies business consultant.
March 20, 2020
by Ross C. D'Emanuele, Randall Hanson, and Shira Hauschen
HIPAA
Medicare Telehealth Payment Expanded to Help Address the COVID-19 Public Health Emergency
On March 17, 2020, the Centers for Medicare and Medicaid Services (“CMS”) and the Department of Health and Human Services Office of the Inspector General (“OIG”) each issued policy statements which expand access to telehealth services for Medicare beneficiaries and permit physicians and other practitioners to reduce or waive beneficiary cost-sharing obligations for Medicare telehealth services during the COVID-19 public health emergency. Immediately following the enactment of the Coronavirus Preparedness and Response Supplemental Appropriations Act, available here, CMS issued a temporary expansion of the Medicare telehealth benefit beginning as of March 6, 2020 and effective until the public health emergency declared by the Secretary of the Department of Health and Human Services ends. The CMS policy statement can be found here. A key element of this telehealth expansion is that payment will be made for office visits and other covered Medicare telehealth services furnished to beneficiaries located in any part of the U.S. Moreover, the CMS waiver facilitates payment for telehealth services furnished while the beneficiary is located in their home or in any care setting. Without this emergency expansion, current Medicare rules at Social Security Act § 1834(m) generally limit coverage for telehealth services to beneficiaries located in rural areas, and only when the beneficiary is within a hospital, clinic, or other medical facility at the time of the telehealth visit. Clinicians who may offer telehealth services to Medicare beneficiaries include physicians, nurse practitioners, physician assistants, clinical social workers, clinical psychologists, and registered dieticians. CMS also states that to the extent Medicare reimbursement for a telehealth service requires a prior relationship between the clinician and beneficiary, CMS will use its enforcement discretion and not audit claims submitted during the public health emergency to determine if such a prior relationship existed. The CMS waiver explicitly permits clinicians to use telephones with audio and video capabilities to furnish Medicare telehealth services during the COVID-19 public health emergency. Together with the new waiver of certain HIPAA privacy rules (addressed in our prior blog post found here), this now will permit clinicians to conduct visits with Medicare beneficiaries using common communications tools such as personal phones, devices and computers, and common technologies such as FaceTime or Skype. CMS issued a FAQ document on this temporary and emergency telehealth benefit expansion, which can be found here. In tandem with CMS’ expansion of the Medicare telehealth benefit, the OIG issued a policy statement to address the potential anti-kickback and beneficiary inducement issues that providers may face during this emergency. OIG states that it will not sanction physicians or other practitioners for reducing or waiving cost-sharing obligations that a beneficiary may owe for telehealth services furnished during the COVID-19 public health emergency and furnished in accordance with the then-applicable Medicare rules (which would include the CMS telehealth benefit expansion during the emergency). Normally, the routine reduction or waiver of Medicare beneficiary cost-sharing obligations would implicate the federal anti-kickback statute and the civil monetary penalty law prohibiting beneficiary inducement. Clinicians are not obligated to reduce or waive Medicare beneficiary coinsurance and deductible obligations, but may do so in accordance with the OIG policy statement without risk of anti-kickback or beneficiary inducement enforcement. Moreover, the OIG states that it will not view providing future services that may occur as a result of any free telehealth services to, by itself, be evidence of beneficiary inducement. The OIG Policy Statement can be found here. These CMS and OIG issuances are intended to give providers added flexibility to combat the COVID-19 emergency. Hospitals and other providers should consider how the temporary Medicare telehealth expansion and the flexibility in dealing with beneficiary cost-sharing can help them keep clinicians and beneficiaries safer, alleviate some of the burden on provider staff and space, and help reduce the spread of COVID-19. If you have any questions, please contact the author or any member of Dorsey’s healthcare transactions and regulations practice group.
March 18, 2020
by Ross C. D'Emanuele
HIPAA
New HIPAA Waivers for Health Care Providers During the COVID-19 Emergency
This post provides an update on a number of HIPAA waivers that have just been made available to health care providers: (1) Waivers for hospitals in the initial 72 hours of enacting a disaster protocol; and (2) Waivers for all health care providers to allow them to use “everyday communications technologies, such as FaceTime or Skype, during the COVID-19 nationwide public health emergency” for the provision of patient care services. Each waiver is addressed more fully, below: Waivers for Hospitals in the Initial 72 Hours of Enacting a Disaster Protocol First, the Secretary of the Department of Health and Human Services (HHS) has issued limited HIPAA waivers to hospitals. The waivers are retroactive to March 15, 2020. See the HHS HIPAA waiver document here. We addressed the possibility of these waivers in our earlier post, available here, along with a summary of some of the main HIPAA laws already in place which may be helpful to covered entities and business associates during this time of national and public health emergency. The HIPAA waiver document starts by reminding covered entities and their business associates that, in general, the HIPAA rules are not suspended during this time of a national and public health emergency. In particular, addressing a topic of much discussion among providers, the guidance includes a reminder that the HIPAA security safeguards rules (mandating reasonable administrative, technical and physical safeguards) apply to uses and disclosures of electronic protected health information as always. This statement is a reminder to health care providers of their obligations to use appropriate safeguards when using or disclosing protected health information (but, see Part 2 of this blog post, below, which describes a new waiver allowing providers to use everyday communications technologies for patient care.) The HIPAA waiver will only apply to hospitals: (1) in the emergency area identified in the public health emergency declaration (the declaration applies nationwide, see the declaration here); (2) that have instituted a disaster protocol; and (3) for up to 72 hours from the time the hospital implements its disaster protocol. After the 72 hours elapses, the hospital is required to return to full HIPAA compliance, even for patients who are still under care at the time. Also, if the national emergency or the public health emergency is terminated, the hospital is required to return to full HIPAA compliance, even if the 72 hours has not elapsed. The waivers permit U.S. hospitals that have instituted their disaster protocol to have the following HIPAA requirements waived during the initial 72 hours of the disaster protocol: • the requirements to obtain a patient's agreement to speak with family members or friends involved in the patient's care. See 45 CFR 164.510(b). • the requirement to honor a request to opt out of the facility directory. See 45 CFR 164.510(a). • the requirement to distribute a notice of privacy practices. See 45 CFR 164.520. • the patient's right to request privacy restrictions. See 45 CFR 164.522(a). • the patient's right to request confidential communications. See 45 CFR 164.522(b). Waivers for All Health Care Providers to Allow the use of Everyday Communications Technologies for Patient Care Second, the HHS Office for Civil Rights (OCR) announced that it will “exercise enforcement discretion and waive penalties for HIPAA violations against health care providers that serve patients in good faith through everyday communications technologies, such as FaceTime or Skype, during the COVID-19 nationwide public health emergency”. See the announcement from OCR here. A few days later, OCR issued FAQs regarding telehealth and OCRs waiver of penalties for the use of everyday communications technologies, available here. This second announcement is particularly refreshing for health care providers who have been anxiously seeking easier methods, such as the use of personal devices and specific technologies, to interact via audio and/or video technologies with their patients and colleagues. Specifically, OCR states: “A covered health care provider that wants to use audio or video communication technology to provide telehealth to patients during the COVID-19 nationwide public health emergency can use any non-public facing remote communication product that is available to communicate with patients….This exercise of discretion applies to telehealth provided for any reason, regardless of whether the telehealth service is related to the diagnosis and treatment of health conditions related to COVID-19.” OCR provides the following examples of technology that will be allowed: “…a video chat application connecting the provider’s or patient’s phone or desktop computer in order to assess a greater number of patients while limiting the risk of infection of other persons who would be exposed from an in-person consultation.” “…popular applications that allow for video chats, including Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, or Skype…” The OCR makes clear that this technology is also allowed to assess or treat any other medical condition, even if not related to COVID-19. Further, the OCR also states in the notice that it will not impose penalties against health care providers that do not have a business associate agreement in place with such technology vendors. The OCR provides the following examples of technology that will not be allowed because they are public facing: Facebook Live Twitch TikTok similar video communication applications are public facing Finally, the OCR acknowledges that some health care providers may still wish to use technology vendors that are “HIPAA compliant” and with whom the health care provider has entered into a business associate agreement related to the vendor’s video communications products. The OCR provides a list of some technology vendors that represent that they provide HIPAA-compliant video communication products and will enter into a business associate agreement (although the OCR states that it does not endorse any particular technology and it has not reviewed the business associate agreements of these vendors): Skype for Business Updox VSee Zoom for Healthcare Doxy.me Google G Suite Hangouts Meet However, a few words of caution: The OCR encourages providers to notify their patients that these third-party applications potentially introduce privacy risks. Providers should also take as many security precautions as possible to protect patient information such as enabling “all available encryption and privacy modes when using such applications,” and having these conversations in private spaces to avoid others who are not involved in the patient’s care overhearing the communication. Further, even if a provider is using “everyday communications technologies”, providers should take care to record the interactions in the patient’s medical record to ensure that patients’ records are complete and accurate. We are continuing to monitor this ever evolving area of the law and will continue to post updates. Please call the authors of this post or your regular Dorsey attorney if you have any questions.
March 17, 2020
by Alissa Smith and Charis Zimmick
HIPAA
CMS "Actively Working" on Stark Law Reforms to be Issued Later this Year; “Regulatory Sprint to Coordinated Care” Continues
The Centers for Medicare & Medicaid Services (CMS) is “actively working” on updates to regulations under the federal physician self-referral law (or “Stark Law”), according to CMS Administrator Seema Verma during a March 4, 2019 speech. Verma stated that the updated regulations will be issued later this year, and “will represent the most significant changes to the Stark law since its inception.” Verma explained in her remarks that the Stark Law, when enacted in 1989, made sense in a fee-for-service context, but as health care transitions to a value-based system where providers take on risk and payment is for outcomes rather than individual services, “we don’t have nearly as much need to interfere with who’s getting paid for what service.” According to Verma, CMS hopes that Stark Law regulatory changes “will help spur better care coordination and help support our work to remove barriers to innovation while continuing to provide appropriate safeguards for our programs.” Verma stated that the updated regulations will include “clarifying the regulatory definitions of volume or value, commercial reasonableness and fair market value; addressing issues such as lack of signature, incorrect dates or other areas of technical noncompliance; and updating the regulation to address a world in which there are cybersecurity and electronic health records requirements.” These Stark Law regulatory reforms are part of the “Regulatory Sprint to Coordinated Care” launched by the Department of Health and Human Services (HHS). Under this initiative, various HHS agencies have issued requests for information (RFIs) to solicit feedback from stakeholders on removing regulatory obstacles to care coordination. CMS published an RFI on June 25, 2018 soliciting comments regarding Stark Law reforms (as we described in our post here), which received 392 comments before the close of the comment period. We anticipate that CMS will summarize and respond to many of the comments that it received in preamble to the proposed Stark Law regulations to be issued later this year, as well as incorporate suggestions from stakeholders in the proposed regulations themselves. Also as part of the Regulatory Sprint, the HHS Office of Inspector General (OIG) published an RFI on August 27, 2018 soliciting comments on reforms to the anti-kickback statute and beneficiary inducements civil monetary penalty (as we described in our post here), which received 359 comments before the close of the comment period. Additionally, the HHS Office for Civil Rights (OCR) published an RFI on December 14, 2018 soliciting comments on reforms to the Health Insurance Portability and Accountability Act (HIPAA) privacy and security regulations, on which the comment period closed last month. The fourth and final area of focus of the Regulatory Sprint (according to an HHS press release) is 42 CFR Part 2, which relates to the confidentiality of substance use disorder patient records. An RFI under the Regulatory Sprint for this regulation has not been published by the Substance Abuse and Mental Health Services Administration (SAMHSA, which is the agency that administers this regulation). We will provide information about regulatory reform developments under these other areas of the Regulatory Sprint as they become available.
March 18, 2019
by Alissa Smith and Laura B. Morgan
HIPAA
CMS Announces Strategy to Reduce Health IT and EHR Burden
On Wednesday, November 28, 2018, the U.S. Department of Health and Human Services (“HHS”) released a draft document titled, Strategy on Reducing Regulatory and Administrative Burden Relating to the Use of Health IT and EHRs. The report was developed by the Centers for Medicare and Medicaid Services (“CMS”) and the HHS Office of the National Coordinator for Health Information Technology (“ONC”). HHS was required under the 21st Century Cures Act—signed into law in December 2016—to develop goals, strategies, and recommendations to reduce electronic health record (“EHR”) burdens that impact the delivery of health care services. HHS solicited input for the strategy in listening sessions, written responses, and other stakeholder contact. Now that the draft strategy is released, HHS is soliciting additional feedback on their website for sixty days, until January 28, 2019. To provide written comments and review the strategy, visit the strategy webpage here. The report identifies three goals: Reduce the effort and time required to record health information in EHRs for clinicians; Reduce the effort and time required to meet regulatory reporting requirements for clinicians, hospitals, and healthcare organizations; and Improve the functionality and intuitiveness (ease of use) of EHRs. Potentially more enlightening are the strategies and recommendations, which offer a guide to what actions CMS may take in future rulemaking and guidance. The report recommends that the regulatory burden around patient encounter documentation should continue to be reduced. HHS notes that office and outpatient evaluation and management visit documentation has already been updated and streamlined in the 2019 Physician Fee Schedule final rule and that CMS removed some documentation requirements for admission orders to inpatient rehabilitation facilities. Other recommendations that may directly reduce or alter the regulatory burden on providers include the following: Waive documentation requirements for alternative payment models Automate ordering and prior authorization procedures by adopting standardized templates, data elements, and real-time standards-based electronic transactions Support pilots for standardized electronic ordering Simplify scoring for the Promoting Interoperability performance category (of the Quality Payment Program and Promoting Interoperability Programs, formerly EHR Incentive Programs for hospitals and clinicians) Incentivize innovative uses of health IT and interoperability Continue providing states with Medicaid funding for health IT systems and to promote interoperability among Medicaid providers Adopt additional data standards for better access, integration, and analysis across different systems Explore less burdensome electronic quality measurements Improve interoperability between EHRs and state prescription drug monitoring programs Increase the use of electronic prescribing of controlled substances, with better access to medication history Harmonize EHR data reporting requirements across federal programs to reduce reporting burden Provide additional guidance on HIPAA privacy and other federal confidentiality requirements regarding substance use disorder health information (to facilitate electronic health information exchange) When health IT and EHR incentive programs, such as the Medicare EHR Incentive Program (commonly known as “meaningful use,” and now part of the Merit-Based Incentive Payment System (“MIPS”)), were first rolled out, much of the focus was on switching providers to electronic systems to enable better care and patient access. For example, in ONC’s Federal Health IT Strategic Plan 2015 – 2020, goals include: improving health care quality and value, supporting individual access, privacy, and autonomy, honoring personal health preferences, and building a culture of EHR use. The 2015 – 2020 strategic plan makes minimal reference to improving clinical workflows or enabling efficiencies for providers. As health IT and EHRs have matured in the past few years, it is increasingly clear that individual clinicians and health care organizations have become more burdened through the implementation of electronic systems, not less. The new Strategy on Reducing Regulatory and Administrative Burden Relating to the Use of Health IT and EHRs discusses the issues faced and potential solutions to be implemented by CMS and other federal programs. The final version of the strategy will be published in late 2019 after ONC reviews and analyzes the comments made through January 28, 2019.
January 7, 2019
by Edwin N. McIntosh and Aaron Mohr
HIPAA
HIMMS, Chronic Care Management, and the Top 5 Overlooked Items
Harnessing existing digital health solutions to improve chronic care management was a prominent topic at HIMMS this year (amongst many others, including AI and cybersecurity, both of which we will cover in upcoming blog posts). While this is not a new topic, it was particularly “buzzy” this year due to the ever-increasing number of large technology and wearables vendors entering the healthcare space, and as medical device manufacturers look to pair services with their existing devices. Chronic care management, as its name denotes, involves higher-touch and ongoing communication between the patient and the provider. Since digital health solutions are a cost-effective means to connect patients and providers, and because providers can use them to reach patients at home to help correct behaviors that contribute to or ameliorate chronic conditions, digital health solutions hold great promise as an effective chronic care management tool – and, indeed, as HIMMS this year made apparent, digital health solutions are poised for exponential growth. As with any relatively new field, however, we have noticed that certain key issues tend to be overlooked, often at great cost. Here are the top 5 overlooked issues we have noted: Value proposition in a crowded market: Make no mistake about it: this is a crowded market with many different types of vendors hoping to launch the next big thing in digital chronic care management solutions. So many of the pitch decks and conversations we have been privileged to be a part of tend to focus on the market size in terms of clinical need: that there are X number of patients with Y chronic condition who would welcome Z solution. The mistake, however, is presuming that this suffices to capture attention. The barrier to market entry is relatively low (FDA considerations, if applicable, notwithstanding!), and the customers – providers and patients – are relatively wary of yet another device, application, or website to manage. Investors and customers alike will ask, what, specifically, is your digital health chronic care solution’s real value proposition; what truly differentiates you? Effectively managing a chronic condition is the baseline minimum expectation. You must offer something more. EHR integration – the how and where: Many sellers of digital health chronic care solutions tout the ability of the device or software program to integrate with a provider’s EHR and/or with a patient-facing application so that providers and patients can monitor the relevant condition. This is all to the good, as transparent, real-time results are a key facet of chronic care management. The item that is missed, however, is how that information will be displayed in the EHR; where, exactly, will it appear? Is that in readable and, importantly, reportable format for the providers? It does a provider little good if a blood viscosity result appears in the EHR as a pdf attachment that is not searchable as a discrete data element. It is important to ask vendors and potential partners this at the outset, and to obtain the answer in writing. Process flow: Providers and medical device manufacturers alike are doing a good job of convening clinical experts to discuss particular care needs and associated care management regimen. This is then translated into the digital health offering. What is missed, however, is thinking through the end-to-end process between provider, patient, and both their interactions with the software, to ensure that it’s as seamless and hassle-free as possible. Patients who would be, well, patient with a clinician who is taking a few extra moments to answer a question would not necessarily be as patient with extra clicks or wait time from a digital health program. Providers, in turn, are looking for the least amount of clicks to enable them to do what they do best: offer the patients helpful advice. Mapping out the exact flow of when and how the software – and any integrated devices – will behave, and who is required to do what, is critical. Data ownership and access: While vendors – medical device and software and analytics alike – race to develop in-house chronic-care solutions, many are looking to partner with providers to provide clinical input and data and to serve as a beta testing and initial customer site. Partnerships are proliferating, and while good attention is paid in the negotiating process to the typical business terms, we have noted that data flow, ownership, and access tends to be a secondary thought. To be clear, HIPAA, privacy, and cybersecurity are still at the front of everyone’s minds; however, the operational brass tacks of exactly what data will display where, which party will provide that data, and exactly who will access the data and its derivatives is still oft-overlooked. Just as we recommend process flows from the user-end perspective (see above point), we also have found that data maps are instrumental to a successful partnership. If you have created one for your organization for cybersecurity and breach incident response, you will find that to be a useful starting point; you will then want to discuss and create a new, macro-level flow that reflects the flow across the parties. Then, check with counsel, and ensure that the relevant contracts (e.g., partnership, services, and/or BAA agreement(s)) align with that data map. Licensure – you probably need it: “Chronic care management” encompasses so many conditions that it can, at times, be used as a marketing lure to sell wellness-related devices and services. Any company that considers itself in the “wellness” sphere and employing people to provide ongoing advice – whether by phone, video, e-mail, or other means – should make a point to check with counsel as to whether professional licensure is required. It does not matter what label you give to those employees (e.g., “coach” vs. “counselor,” or “care guide” vs. “RN”), rather, it matters what type of care is being offered through the digital health solution and what condition(s) it is addressing. A digital health solution that addresses a specific clinical condition is likely one that is regulated, which means that the employees interacting with the patient are also likely to need some form of relevant licensure. This one is a mission-critical ask, so be sure to check with counsel early on (and title your employees correctly on your website and sales materials). We welcome your suggestions for additional focus topics within this series on digital health-related issues. Please contact Shira Hauschen at Hauschen.Shira@Dorsey.com with any comments, suggestions, or questions.
March 20, 2018
by Shira Hauschen
HIPAA
HIPAA As a Basis for FCA Liability? One Court Says Yes
https://dorseyfca.com/hipaa-as-a-basis-for-fca-liability-one-court-says-yes/
January 22, 2018
by Nathan J. Ebnet