Tune in to 1st Talk Compliance with your host, Catherine Short, Partnership Marketing Specialist at First Healthcare Compliance. On this 30-minute, informative program, Catherine, and her guests will discuss the hottest topics, pain points and learning opportunities related to healthcare compliance management in America. Whether you’re wondering about federal fraud and abuse laws, OSHA, or human resources compliance, tune in to gain insight. Here you can also enjoy our archived library of audio webinars and partner interviews! We help healthcare compliance officers achieve peace of mind and we’re excited to bring some of the brightest minds together to 1st Talk Compliance!
In a landmark episode of 1st Talk Compliance, Kevin Chmura, CEO of Panacea Healthcare Solutions and host of the show, is joined by George Kelley, president of Panacea’s KA Consulting Services division.
For over 40 years, KA Consulting Services has delivered unmatched revenue cycle solutions, helping hospitals and health systems nationwide enhance reimbursement, improve compliance, and streamline Medicaid eligibility. Known for its eligibility services, clinical coding and auditing services, and revenue integrity solutions, KA Consulting has earned a reputation for providing solutions that go the extra mile to obtain appropriate reimbursement and to improve compliance. We are thrilled to welcome them as a division of Panacea Healthcare Solutions, further enhancing our commitment to delivering industry-leading healthcare financial, revenue integrity, and clinical solutions nationwide.
Tune in to get the inside scoop on this latest development as Kevin and George delve into KA’s background and our shared history and discuss how our newly combined expertise complements each other’s teams.
The False Claims Act—alongside the Anti-Kickback Statute and Stark Law—represents one of the five core fraud, waste, and abuse laws identified by the HHS Office of the Inspector General. Out of the billions of dollars reclaimed through False Claims Act recoveries in 2023, the majority was attributed to the healthcare industry. This concerning trend highlights the importance of maintaining robust compliance programs and prioritizing education surrounding these regulations.
In this episode of 1st Talk Compliance, Rachel Rose, JD, MBA discusses recent key developments in the False Claims Act landscape and shares tips on how healthcare providers can enhance their compliance strategies and mitigate regulatory risks. Tune in to gain a comprehensive understanding of the False Claims Act and its role in the healthcare sector, hear updates on several recent significant fraud, waste, and abuse cases, and receive actionable insights into bolstering your organization’s compliance initiatives.
Previously on First Talk Compliance, we spoke with Kevin Chmura, CEO of Panacea Healthcare Solutions, about how the advent of price transparency has caused the business of healthcare to evolve and opened up fresh possibilities for healthcare providers to gain a competitive advantage.
In this episode, we continue that conversation by inviting on two additional experts from Panacea—Govind Goyal, President of Financial Services, and Henry Gutierrez, Senior Vice President, Financial Consulting Services—to dive deeper into the recent changes to price transparency requirements and expand upon the many ways healthcare providers can adapt to succeed in this new consumer-driven arena. From navigating compliance regulations to leveraging data for a competitive advantage, tune into Part 2 of “The Sky’s the Limit – How Price Transparency Can Empower Healthcare Providers” to gain insight into the evolving landscape of price transparency and what lies ahead.
Private equity has become increasingly entrenched in the healthcare sector, offering various financing options for providers to consider. However, like all types of financing, private equity introduces its own unique set of benefits and drawbacks and carries important legal implications. It’s essential to understand all the factors at play in order to maximize financial impact and preserve operational efficiencies while avoiding sacrificing compliance and quality of care.
Tune in to hear Grace Walsh in conversation with Rachel Rose, JD, MBA, to explore this timely topic. In addition to providing a detailed overview of private equity in healthcare and its various pros and cons, Rachel shares valuable updates on enforcement actions by the U.S. Department of Justice and Congressional inquiries.
Grace Walsh speaks with Kevin Chmura, CEO at Panacea Healthcare Solutions, to explore an extremely timely topic: price transparency and its far-reaching impact on how healthcare providers interact with consumers, with each other, and with the market at large. Tune in as Kevin shares some important insights about how price transparency has opened the door to a whole new world of data analysis and strategic business strategies for healthcare providers, and covers what we might expect to see for the future of price transparency. We’ll also include some key resources for listeners hoping to boost their knowledge of CMS price transparency regulations and learn how they can leverage price transparency data to empower their own strategic initiatives.
Grace Walsh is joined by Govi Goyal, President of Panacea’s Financial Services Division, and Brian Prokop, Senior Vice President of Financial Consulting Services at Panacea, to discuss the importance of undertaking a strategic pricing initiative for your organization. In our current healthcare climate, it’s more crucial than ever to maintain defensible and rational healthcare pricing while remaining competitive and optimizing net revenue. As Govi and Brian can tell you, it’s a tricky balance to strike. Tune in as they share their tried-and-true approaches to developing defensible pricing strategies and learn how these measures can position hospitals for success in the era of price transparency.
Grace Walsh is joined by Becky Jacobsen, Vice President of CDM, Coding & Audit Services at Panacea Healthcare Solutions, to explore the key updates to evaluation and management (E/M) guidelines for 2024. On the surface, this year’s changes may appear fairly straightforward, but dig a little deeper and you’ll find that the updates have important implications for correct coding procedures. From payers, providers, and coders to those who work in auditing or IT template development, it is essential to keep up a comprehensive grasp on E/M coding guidelines. Tune in as Becky breaks down a few of the most significant guideline updates, clarifies some common areas of confusion, and shares her insider tips as an expert in the field of coding compliance auditing and education.
Grace Walsh is joined by Becky Jacobsen, Vice President of CDM, Coding & Audit Services at Panacea Healthcare Solutions, to explore the key updates to evaluation and management (E/M) guidelines for 2024. On the surface, this year’s changes may appear fairly straightforward, but dig a little deeper and you’ll find that the updates have important implications for correct coding procedures. From payers, providers, and coders to those who work in auditing or IT template development, it is essential to keep up a comprehensive grasp on E/M coding guidelines. Tune in as Becky breaks down a few of the most significant guideline updates, clarifies some common areas of confusion, and shares her insider tips as an expert in the field of coding compliance auditing and education.
In this episode of 1st Talk Compliance, we dive into an increasingly crucial topic in healthcare: price transparency and its ever-growing impact on the industry. Kevin Chmura, CEO at Panacea Healthcare Solutions, joins us to share expert insights on strategic pricing and compliance, emphasizing the transformative benefits for healthcare providers. Learn how to proactively engage with CMS regulations and set your organization apart as an ethical leader in the realm of price transparency.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX will be presenting this informative webinar. Cybersecurity risk management and the potential for enforcement actions is not diminishing. An area of increasing interest by the Federal Trade Commission, the United States Department of Justice, and Congress is third parties taking sensitive data (especially by social media and search engine giants), including protected health information, without obtaining affirmative patient/consumer consent and benefiting financially. The U. S. Department of Health and Human Services, the agency tasked with enforcing HIPAA, also plays a critical role. The purpose of this presentation is to address different federal government initiatives, recent enforcement actions and incidents, and risk mitigation.
1st Talk Compliance features guest Govi Goyal, President, Financial Services, at Panacea Healthcare Solutions, on the topic of Evolution of Price Transparency and How to Stay Ahead of CMS Requirements. Govi joins our host Catherine Short to discuss how the new CMS Price Transparency Rule and No Surprises Act are closely related. By providing Good Faith Estimates for healthcare services, hospitals can comply with both regulations. This helps patients understand their expected costs upfront and avoid surprise medical bills. Panacea's CMS Price Transparency and Hospital Zero-Base Pricing software solutions can assist hospitals in providing accurate Good Faith Estimates to their patients and stay compliant with the latest regulations.
1st Talk Compliance features attorneys Sean McKenna, Lauren Nelson, and Vincent Aiello of Spencer Fane LLP, on the topic of Healthcare Assets: How to Preserve and Protect. Sean, Lauren, and Vince join our host Catherine Short to discuss the interplay between enforcement and liability proceedings with asset protection, explore how government and private litigation matters can impact healthcare companies, clinicians, and executives, and provide tips and preventative strategies to preserve income and assets prior to such action to ensure business continuity and succession planning.
1st Talk Compliance features guest Lauren Moak Russell, Counsel at Young Conaway Stargatt & Taylor, LLP in Wilmington, Delaware, on the topic of “A Harassment-Free Workplace vs the Right to Engage in Concerted Activity.” Lauren joins our host Catherine Short to discuss how the National Labor Relations Board under the Biden Administration has expressed a renewed interest in expanding its influence into non-unionized work forces. This includes reviewing and–in the right circumstances challenging–employers’ use of workplace civility, confidentiality, and anti-harassment policies. Listen as we discuss what you need to know to safely navigate the National Labor Relations Act while ensuring that your employees enjoy a safe and respectful work environment.
Catherine Short: 0:01
Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.
On today’s episode, we are speaking with Lauren Moak Russell, Counsel at Young Conaway Stargatt & Taylor, LLP in Wilmington, Delaware, on the topic of a harassment free workplace versus the right to engage in concerted activity. The National Labor Relations Board under the Biden administration has expressed a renewed interest in expanding its influence into non-unionized workforces. This includes reviewing and in the right circumstances, challenging employers use of workplace civility, confidentiality, and anti-harassment policies. Listen as we discuss what you need to know to safely navigate the National Labor Relations Act while ensuring that your employees enjoy a safe and respectful work environment.
Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals, and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Sharon Miller, administrator at Gulf Coast Dermatopathology Laboratory. Sharon says “patient care is paramount and by creating a culture of caring, compassion and respect, we have succeeded in all we do. We try to promote a family atmosphere which in turn translates to ultimate patient care”. Congratulations, Sharon. Our team is honored to have the privilege of working with you.
Well, thank you so much, Lauren, for being on First Talk Compliance. Thank you for being here.
Lauren Russell 2:16
My pleasure. Thank you for having me.
Catherine Short 2:18
Today, we’re talking about workplace civility, and also about the National Labor Relations Board. Can you get us started in talking about how things have changed as opposed to the previous administration?
Lauren Russell 2:34
Absolutely. So I think that the first thing that listeners really need to understand is that the National Labor Relations Board is not just for unionized workforces, that it has a role in regulating nonunion workforces, particularly where employer policies impact what we call section seven rights, and that’s really employee’s rights to talk about the terms and conditions of their employment. This is an area where we see a lot of ebb and flow between Republican and Democratic administrations at the federal level. I know it’s not a popular thing to talk politics these days, it’s oftentimes very inflammatory, but the reality is that the board changes its conduct very significantly between administrations. And so we had under the Trump administration, a board that really saw its role as very limited in terms of just regulating the relationship between organized labor, which is what we call a unionized workforce and management. To a Biden administration and a board that really sees its role as very expansive and is very focused on ensuring that even in a non-organized workforce, so a non-unionized workforce, that employers are conducting themselves in a way that does not adversely impact employees, what we call Protected Concerted Activity. So their ability to talk about the terms and conditions of employment. This includes a lot of things that make employers uncomfortable, including wages, compensation, comparing how much I make to how much you make, masking, vaccination requirements, anything that keeps a manager up at night, is something that almost certainly touches on Protected Concerted Activity and that can be protected by the National Labor Relations Board.
Catherine Short 4:33
So, employees have the right then to discuss their pay with each other. Is that correct?
Lauren Russell 4:41
Yes, it is. This is something that makes employers really uncomfortable. I understand. I come from a family where we don’t talk about money because I think a lot of us do, right? It’s very crass.
Catherine Short 4:59
Yeah. I never asked my parents or if I did, I was shut down right away. You know, like what you don’t talk about, you don’t ask people how much they make, what’s wrong with you?
Lauren Russell 5:09
Even at 40, I don’t know how much my parents made at any point in their lives. So no, it’s not just about being a child. It doesn’t change. That was very much the way of things. In my parent’s generation, it was simply something that wasn’t done, and certainly my grandparents never, never, never, never, in a million years, never. But wages are really the heart of the terms and conditions of employment, that is the most essential thing. So, the National Labor Relations Board for a very long time predating my practice, starting back in 2009, well before that, the National Labor Relations Board has said policies that prohibit employees from discussing and comparing wages are a violation of the National Labor Relations Act. It does not matter if you have a unionized or a non-unionized workforce, you still may not have policies like this. It’s hard, it does create resentment and frustration and questions and gossip among employees. We have to look at it from the flip side, from the public policy perspective. On that side, employees can’t know if they’re being treated unfairly unless they’re able to talk about wages. That’s really the impetus for these policies and I think that it’s helpful, it keeps employers from getting really angry when we look at it from the public policy perspective. Then you can say, well, it makes my life more difficult. I guess I can understand that women or minorities or individuals with disabilities, they couldn’t discover that they were being treated differently if they were never, ever under any circumstance allowed to talk about their wages with other employees. That’s the way we figure this stuff out.
The Obama administration was very focused on the expansion of the role of the National Labor Relations Board, the Trump administration, I had a much more conservative view of the role of the federal government, and really pared back the enforcement activities that the board was engaged in. Now that we are back under a Democratic administration, that role is expanding, again. I happen to be somebody who thinks that predictability is a very important thing for business. So, whether you are going to have an expansive view or a retracted view of the board’s role, and there are grounds to argue for both, it’s not that one side is patently wrong and the other is patently right. It’s really a matter of philosophy, on whatever the case may be, it is good for businesses to know what the expectations of them are. The National Labor Relations Board swings much more broadly than any other federal enforcement agency. That’s a tough thing for employers to cope with so this is really a problem for both sides of the aisle. I don’t think that anybody is conducting themselves, necessarily in the way that provides the most predictability for business. The best we can do here on the outside is to make sure that employers are educated and know that these risks are out there. I’m certainly talking about it a lot more because I am seeing and I was in practice, under the Obama administration, the Trump administration, and now under the Biden administration, I have never seen as much effort to enforce against the private sector, as I am seeing now. So, Biden has held true to his promise to be the most labor friendly president that many of us will see in our lifetimes. So, even though the Obama administration expressed an interest in pursuing these matters, we’re seeing the enforcement drive from the Biden administration that perhaps was not quite so present before.
Catherine Short 9:19
Okay, so it sounds like there’s a lot of reason to be concerned. And I know this from talking to a lot of our administrators, like hospital administrators, practice administrators, all kinds of CEOs and CFOs, etc., that they have a lot on their plates right now and so much to be concerned about. It feels probably for some, that this is just another thing that they need to be worried about, right? If you could give one piece of advice to businesses and if they can only do one thing, what should it be?
Lauren Russell 9:52
I would take a really careful look at handbooks. That is an area that almost every business I represent neglects because, it’s there and this other thing is an emergency and I’ve got to put out that fire. And to your point, everybody has a tremendous amount of work on their plates right now. This is the most difficult environment to operate and that I’ve ever seen. It is truly amazing that people are able to get up and soldier on every morning. That’s from the management side and from the labor side, everybody’s got a lot on their plate. If we could move the handbook to the top of your non-emergency stack, that’s what I would do. Handbooks should really get a thorough going over every couple of years anyway. If you haven’t taken a careful look at your handbook in the last two years, to update it and make sure that it’s compliant with your current labor and employment laws, that’s a great thing to do. And take a look at those things: workplace civility, social media, and make sure that you’re really focused on illegal behavior and not just that employee shouldn’t say things that make us unhappy. Any policy that’s designed to keep employees from saying embarrassing things in public is going to likely be a problem. We should really be focused on: do not engage in illegal behavior, if you are on Facebook with a picture of you and your favorite marijuana paraphernalia that’s something we can prohibit. We can prohibit harassment and discrimination and defamation. Defamation is illegal behavior. That is it’s a tort, it is unlawful. You can prohibit defamatory conduct. But when we’re talking about general civility and being nice and be courteous, that’s a tough thing to enforce.
Catherine Short 11:44
If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Lauren Russell, Council at Young Conaway Stargatt & Taylor, LLP, on the topic of a harassment free workplace versus the right to engage in concerted activity.
Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.
Okay, could you talk to us about the National Labor Relations Board or the NLRB’s current enforcement policies?
Lauren Russell 12:35
Yeah, I mean, as I said a few minutes ago, there’s really been a focus on expanding their role in the private sector non-unionized workforce. When we’re looking at that, the driving force behind this is the current general counsel for the board, Jennifer Abruzzo. She is a brilliant woman. There has been a sense at times that she may be a little bit more aggressive than even sometimes the unions are comfortable with. But she is the driving force behind these priorities, and they include a couple of things.
She certainly is very focused on lowering barriers to unionization in the workforce. And so she’s looking to bring back certain on administrative policies from the Obama era that either got stalled out or were challenged in court, including lowering thresholds to union organizing, and in a non-unionized workforce. And then also making it harder to oust a union, once it’s in. She is looking to reverse past decisions by the National Labor Relations Board under the Trump administration. It’s helpful to understand a little something about the composition of the board. The board consists of five individuals, five members who are appointed. Under a Democratic administration, it’s usually three Democrats, two Republicans, under a Republican administration, it’s usually three Republicans and two Democrats, and then the general counsel is a presidential appointee. So, she was appointed by Biden, after he terminated her predecessor, who was a Trump appointee who refused to step down. So, there’s a bit of a kerfuffle there. The board changes its orientation very promptly upon a change in administration. You usually have to wait for some for one of the members to come to the end of their tenure, but then you have a very rapid switch, and so the board can completely flip from a Democratic and Republican administration. With that in mind, with that background, she’s looking to reverse precedent on a couple of things including when an employee is engaged in Protected Concerted Activity. She wants to reverse some case law that held that an employee is not engaged in protected activity when other employees don’t join in complaint or offended by the complaint. This is really designed to protect individuals who are expressing unpopular opinions. She wants to reverse past case law that gave employers discretion, she wants to limit employers’ ability to impose confidentiality in the course of internal investigations and in settlement agreement and challenge that, because it impacts an employee’s freedom to speak about the terms and conditions of employment.
Then she really wants to focus on limiting what an employer can do in a handbook. So, limiting a handbook policies that in any way, on their face, would make a cautious employee less likely to engage in their section seven rights. By that I mean to talk to other coworkers about terms and conditions of employment. When we’re looking at those kinds of policies, we’re looking at confidentiality, non-disparagement, social media, media communications, civility, and respectful workplace policies, offensive language prohibitions, and no cameras at work rules. All of those things, when they are applied in just the right way can make a cautious employee and that’s the standard she wants. Not an average employee. Usually in the law, we look at a reasonable person, right? That is an imaginary reasonable person is who we look at when we decide what the legal standard is. She says, no, I don’t want you to think about a reasonable person. I want you to think about a cautious employee. That is our standard. If they feel like an employer policy, inhibits their ability to speak freely to coworkers about terms and conditions of employment her position is that handbook policy gotta go
Catherine Short 17:20
Can you expand a little bit more on what her definition of what a cautious employee might be?
Lauren Russell 17:25
Well, it’s certainly not a defined concept. But I’ll tell you a cautious employee is one that complains to the board.
Catherine Short 17:31
In my mind, a cautious employee would be somebody who’s super careful, but who would not complain, who would be really careful about what they say. Cautious to me is caution.
Lauren Russell 17:42
Keep in mind that the National Labor Relations Board, like every other federal agency has very limited resources. So as a general rule, they do not have a practice of auditing, non-unionized workplaces. The board would not knock on the door at First Healthcare Compliance and say “we’d like to see your employee handbook, please show it to us”. Similarly, they would not do that at my firm. So what has to happen is an employee has to go to the board and say, I think this, this handbook is discouraging. It’s somebody who’s not necessarily complaining internally and that is very frustrating to employers as well. How was I supposed to know you felt discouraged? I didn’t intend to discourage you. You never told me you felt discouraged. Instead, you went off and filed a charge. That’s the cautious employee.
Catherine Short 18:38
Okay. All right. Interesting. Okay, let’s talk about social media for a second. Can you explain a little bit about what is expected concerning social media at this time?
Lauren Russell 18:52
Social media is my nightmare.
Catherine Short 18:56
And for a lot of employers. You have some employees who don’t engage in social media whatsoever, and then some employees who are extremely engaged. So what’s the role right now?
Lauren Russell 19:07
Yeah. Certainly, you can expect employees to be lawful online. That is a perfectly reasonable expectation to say. Believe it or not, I’ve got clients who have to have a policy that says, Please do not post photos of unlawful activity. You should not have open containers of alcohol in a vehicle. You should not post photos of your marijuana paraphernalia. You should not post racist diatribes on Facebook. Depending on your workforce that may or may not be something you need to say. All of that behavior is something that you can expressly prohibit. What you can’t prohibit and what a lot of social media policy say is that you may not post anything online that criticizes the company or its customers client, patients etc. Now, in the healthcare context, we have some additional overlays. Most employees have HIPAA obligations, and you can absolutely say you may not post anything online that violates your duty of confidentiality under HIPAA. You cannot say Mrs. Smith was in today and she was a raging you-know-what, and I hate her and I hope she never comes back to this practice.
Catherine Short 20:26
I know perhaps some people like to go on diatribes on social media, personally, as themselves not as representative of their company and say, all kinds of things.
Lauren Russell 20:38
When we’re talking about where the board wants to flex its authority, it comes in two places. One is the policy itself. If you have no social media policy, then then there’s nothing for them to look at. The other is, when we apply the policy, are we adversely impacting Protected Concerted Activity. Going on Facebook and saying every member of the Green Party is an unmitigated idiot is not protected concerted activity, it’s not about the workplace, it’s about the world out there. So you can absolutely and if a patient or a coworker comes in and says, your receptionist on Facebook called me an idiot, and I don’t want to deal with them anymore, if you don’t fire them, I’m going to leave the practice. That’s okay. You can fire the employee, because their social media conduct has adversely impacted the business and they have tied themselves to the business in some way. Very frequently this happens because somebody tagged themselves to your company’s Facebook page, or they have a picture of themselves wearing a First Healthcare Compliance T shirt, and so they associate themselves online, and then somebody figures it out. They say, so and so was saying offensive things on the internet, I see they’re wearing their shirt, I went to your website and see that they work for you and I think you should know about that. I have had those cases and that person’s gone. They were the ones who tied themselves to your company on the internet and that’s their fault.
When we’re talking about actual concerted activity or the impact on the workplace, and this does happen, somebody posts on the internet, for example, something inflammatory about undocumented immigrants that borders on racist right on or says every member of the Republican Party is a racist, you can’t be Republican and not be racist, and you have a Republican employee who says, this is outrageous. This person is calling me racist on the internet, I’m deeply offended, I don’t feel comfortable working with them anymore. Again, that behavior is not protected, concerted activity. They’re talking about Republicans out in the world, they’re not saying the Republicans I work with are racists, they’re saying all of them in their totality. That is again, behavior that creates a hostile environment, it makes people deeply uncomfortable, and you can discipline that behavior, or you can terminate the employee. In the same way if somebody was posting racist or sexist messages, so instead of calling somebody else racist, I am posting deeply inappropriate things on the internet, jokes and memes about women should be barefoot and, in the kitchen, right? Because a female coworker comes in and says, I am deeply offended. I am a working woman and a mother, and this person thinks my only worth is to be at home. Like that’s, that’s offensive to me. Okay, we can discipline that behavior.
Where the board gets interested, is when an employee goes on social media and criticizes the employer. If I go in on social media and say, my manager at XYZ company is racist, he will not denounce police violence in the country. Or he is paying female employees less well than male employees. That is Protected Concerted Activity. I have gone into a public environment and on behalf of myself and other workers have criticized management and said, this is an illegal environment, or there were unlawful behaviors happening here. I don’t know a single manager that I’ve ever met, who wouldn’t be deeply offended and upset that somebody took that to Facebook instead of talking to them first. And so the gut reaction is always fire them, discipline them. They took internal business to Facebook, they never talked to me. I had no chance to deal with this and now they’re defaming us on social media that’s Protected Concerted Activity and that is a real risk to the business if you discipline.
Catherine Short 24:47
So I have a question about employee expectations and labor rights perhaps do they extend to part time contract employees and also interns?
Lauren Russell 24:57
They apply to part time employees. Yes. Contractors? No. When you have independent contractors who are regularly working on your site like temporary staffers, the answer is often Yes because there’s a joint employment relationship. Interns, it depends. But generally if they’re paid interns like a summer intern, yes, they’re going to be covered. If it’s a volunteer, like at a hospital, you often have individuals who come in to read to sick children, or they will sit with the elderly patients. Those are not employees of any stripe, they’re volunteers. And even if it’s sort of a summer internship candy striper situation, it’s really more on the nature of volunteerism, and not within the scope of the board’s authority.
Catherine Short 25:47
Okay, well, I think we’re just about out of time. Did you have any other words of advice or things that you wanted to discuss that we didn’t talk about? Perhaps,
Lauren Russell 25:59
No solid guidance, but I will tell you anecdotally that I have watched businesses unionized, and I have watched them vote out unions. The key distinction is a level of basic respect between management and labor. You know, there’s a lot of research out there on healthy marriages. The marriages that succeed are ones where there’s mutual respect between spouses. If there’s a lack of respect, if spouses roll their eyes at each other, that’s a sure sign that one day they’re going to be divorced. That same guidance applies to labor management relations. You don’t have to agree on everything, and they oftentimes don’t. But when you can have dignity and respectful communications, that is a workforce where you are much less likely to see unionizing efforts generally, and specifically where you’re going to see even in non-unionized workforces, where you’re going to see charges brought before the board. When employees feel respected, and like their partners, you are always going to be in better stead. It’s a hard thing to do, but cultivating respect, making sure that even your low-level employees feel like they are a critical part of your success, and that they help you to have a voice in how decisions are made. It’s hard to do, but that makes a huge difference. Okay,
Catherine Short 27:33
Well, I want to just thank you so much. Lauren, did you have any other words of advice that you wanted to leave us with today?
Lauren Russell 27:39
Tolerance, kindness. I will tell you that you run into union problems when both sides of the equation management and employees are not able to take a deep breath and say, hey, I really need you to hear me but I could have said that nicer. I keep seeing these news headlines about how mean people are right now, that people are just hit their limits and they are mean. I hear that anecdotally from clients too. I think we’ve got to take a deep breath and be a little less mean. When there was a sense of respect and dignity between labor and management you really avoid the vast majority of these issues. So kindness.
Catherine Short 28:22
Great. That’s always wonderful advice. I wanted to thank you so much for being here today.
Lauren Russell 28:27
Very happy to be here. Thank you for the opportunity.
Catherine Short 28:31
And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.
Expert presenter, Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX guides us through current trends and tips.
With its roots stemming back to 1863, the False Claims Act continues to be the U.S. Department of Justice’s primary enforcement tool for returning money to the Federal Treasury. It is also considered one of five fundamental fraud, waste, and abuse laws, which potentially impact a provider every time a claim is submitted to Medicare, Medicaid, and other government programs because of the attestation language. The purpose of this webinar is to provide a synopsis of the False Claims Act and the current landscape in relation to coverage determinations and the federal Anti-Kickback Statute.
This webinar will cover the following objectives:
1st Talk Compliance features guest Raymond Ribble, CEO and Founder at SPHER, Inc., on the topic of A Practical Approach to The Safe Harbor Law. Ray joins our host Catherine Short to discuss how HIPAA data breach penalties typically get measured in millions of dollars, even following an organization implementing NIST cybersecurity framework measures. However, with the new HIPAA Safe Harbor Law, signed in January 2021, HHS and OCR may consider some penalty mitigation. It is important to understand that the Safe Harbor Law, while offering substantial protection, does not provide a true safe harbor and only offers some protection. This episode will examine what the established security practices for healthcare are, and how to pivot your organization’s security profile to mitigate breach penalties if an event occurs.
Catherine Short 0:01
Welcome, and let’s, 1st Talk Compliance. I’m Catherine Short, Marketing Manager for First Healthcare Compliance, a division of Panacea Healthcare Solutions. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. Please show your support by taking a moment to provide a review on Google, Facebook, or iTunes, and be sure to follow us on social media and subscribe to our YouTube channel.
On today’s episode, we are speaking with Raymond Ribble, CEO and Founder at SPHER Inc, on the topic of A Practical Approach to The Safe Harbor Law. HIPAA data breach penalties typically get measured in millions of dollars even following an organization implementing NIST cybersecurity framework measures. However, with the new HIPAA Safe Harbor Law signed in January 2021, HHS and OCR may consider some penalty mitigation, it is important to understand that the Safe Harbor Law while offering substantial protection does not provide a true Safe Harbor and only offers some protection. This episode will examine what the established security practices for healthcare are, and how to pivot your organization’s security profile to mitigate breach penalties if an event occurs.
Catherine Short 1:39
So Ray, thank you so much for joining me on 1st Talk Compliance. It’s a pleasure to have you on.
Raymond Ribble 1:42
Thank you for having me, I appreciate it.
Catherine Short 1:43
Again, I’m so happy you’re here today. Today we’re discussing about the Safe Harbor Law and we’re going to be talking about a practical approach. For people who are new to this, can you give us a good background or a brief description about what we are going to be discussing as far as some compliance background? Or how we got here as far as I know that HIPAA has a Safe Harbor Law? And I know that that affects how people need to protect their health data and their data in general. Can you give us a little bit of background of what we should be protecting and what we should be careful of and what we should be discussing?
Raymond Ribble 2:27
Sure. For our listeners, I’ll try to give you the cliff note version of what it is. What I wanted to do for everybody who’s listening today is just give you a brief introduction to what is the Safe Harbor Law. I don’t want you to become experts on the Safe Harbor Law, I don’t want you to be able to click off the five things that it does. That’s not the background. It’s just that some well thought politicians in both the Senate and the House got together and said, Hey, look, we’ve provided all this money to help these medical institutions move from paper to digital. In doing so, we’ve exposed them to a brand new set of risks in terms of data breaches that can occur that didn’t exist before. And now we’re asking them to spend more money to implement policies and procedures and potentially technology solutions in order to protect that digital data. So that’s the first part of it. And they said look, for the organizations that embrace these ideas that go the extra mile that implement these policies and procedures, that are not experts on the Privacy Rule in the Security Rule and HIPAA, but they do understand that protecting patient data is a new requirement that they have to adhere to, and they want to do their best. They don’t want to do the best. They want to do their best to protect that data. They wanted to incentivize those organizations for implementing cybersecurity best practices.
And in doing so, they put out what was called the House Resolution 78 98, which became the Safe Harbor Law. It was signed into law on January 5, 2021, by the President, and basically, that became public law 116-321, which is affectionately called the Safe Harbor Law. There are Safe Harbor Laws in other industries. This particular Safe Harbor Law is specific to the healthcare industry. So that’s why it’s important to you and I and to our listeners today.
This Safe Harbor Law again, 116-321 is the high-tech Safe Harbor Law if you want to think of it that way. And what it says is that if you implement policies and procedures, technologies, training, documentation around protecting your patients PHI (Protected Health Information), and you still experience a breach, that when the investigation from the OCR auditors occurs, and it will occur, that you will not be penalized as heavily as an organization who did nothing. That you should be incentivized ie through that lack of penalties and monetary penalties, you should be incentivized to do that, so that there is a risk-reward type scenario that’s set up in this. If you’re going to spend the money to protect that data, and then ultimately, it really happens and you have a breach, you should be getting a pat on the back and a reward for having spent that money and the time and the investment and the education with your staff to do the best that you can do. Nobody can fully prevent a breach, but you went the extra mile, and they wanted those organizations to be rewarded.
The word they use, is it mitigates the probability of a major penalty, but in my opinion, really what they’re saying is attaboy, it’s not going to cost you 8.1 3 million and might cost you 50,000. You had a breach, that’s a bad thing. There’s some risk slapping that has to take place, but you’re not going to pay millions of dollars, because you paid up front, you made the investment to do the best that you could do, those cybersecurity best practices that I spoke about, you implemented parts of NIST, you went out and purchase some third party products, you educated your staff, you documented all of that, you did your security risk assessment every year, you did what was reasonable and appropriate for an organization of your size, and you still had a breach. Should you be blamed for that? The bad guys can basically spend 365 days a year trying to break into your system. You’re not going to spend 365 days trying to prevent them from breaking into your system. So there’s got to be some risk reward there. That’s where the Safe Harbor Law is coming from.
Catherine Short 7:17
That was a really great explanation. Thank you so much. That actually was a very practical approach. Concerning standards of security. What should we be using as a guide? For example, does HHS provide a guidebook?
Raymond Ribble 7:32
I think a great starting point is NIST. For those of you who don’t know what NIST is or what it stands for, so National Institute of Science and Technology. Basically what they do is they provide a security framework for many industries, not just the healthcare industry. What I’ve recommended to organizations is if you take a look at NIST in the five key areas that they identify, and then you put that together with the recommendations coming from the 405(d) taskforce, then I think that that is a blueprint that you can start going down towards protecting your organization without making mistakes or spending money where you don’t need to spend money.
Catherine Short 8:16
What is NIST cybersecurity framework?
Raymond Ribble 7:20
The NIST cybersecurity framework comes from the National Institute of Standards and Technology. It was developed many years ago, as a guideline to help organizations to understand what they need to do in order to identify, protect, detect, respond, and recover important data. So outside of healthcare, it might be PII, in healthcare world what we call PHI (Protected Health Information).
It’s a set of guidelines that we can look at and apply to our organization. Some of them are procedural. Some of them are technical in terms of third party products, or downloadable products from manufacturers that cost us nothing, that we can put in place that allows us to see who’s looking at our data, when are they looking at the data? Is that appropriate for them to look at the data? If it’s not appropriate, and we’ve determined that it’s a problem, then how do we recover that and how do we respond to that? So NIST security framework would be complimentary to us following the HIPAA rules, whether it’s the Security Rule, the Privacy Rule, the Breach Notification Rule. By following NIST and the NIST cybersecurity framework. This is very much in line with what we’re doing for our HIPAA compliance
Catherine Short 9:53
If a facility can afford to do this does that in itself, grant them the protection and penalty mitigation that you’ve talked about previously?
Raymond Ribble 10:04
I like that question. Let me do my best to answer it. Let’s just take make the assumption that we don’t have a lot of money and historically, my organization has never spent a lot of money on technology to protect patient data. Let’s just that’s our example for this question. But I took the time to look at this NIST cybersecurity framework and I can see what the five key areas are. They’re making some recommendations, I went over to 405(d) task group, and I saw what they had and I said, Okay, I’m going to pick two or three things from each of those five things. I’ll repeat them just for the sake of the audience: identity, protect, detect, respond, and recover. And I’m going to apply a few of these rules to each of these that I think best aligns with the type of organization we have, whether we’re a pediatrics, an oncology, dermatology, plastic surgery, whatever type of practice we are, we all fall under that HIPAA umbrella. And what I’m trying to do is apply certain rules or guidelines that NIST provides in order to protect the data. Even if none of the things that I do involve me purchasing a third party product to do it. If I can accurately, regularly and appropriately document that I’m doing that, then the answer to your question is yes, that would allow us to mitigate, in the event of a breach mitigate the
exposure to penalties that might come from an OCR investigation.
Catherine Short 11:40
If you had to name perhaps three security practices, what do you see as being the most important first to use today?
Raymond Ribble 11:50
Three that I think would be the most important, I think protecting your email is extremely important. It is probably the one thing that everybody listening today uses and probably uses almost from the minute they get up until just before they go to bed. They’re accessing email, they’re looking at messages, they’re opening emails from third party, some of them are unknown third parties. So having email protection on your devices, especially devices that handle PHI, to me, is extremely important.
Two, access management. Knowing who’s coming into my system, and who is accessing the PHI and are they accessing that information for the purpose of providing care to our patients, would be equally important to me.
The last thing, if I look at this, I would say is going to be having good cybersecurity policies. So that’s more of not a technical thing. So email, access management, and cybersecurity policies. Educating my staff on what to do, and what to look for, if they see something that seems suspicious, just teaching them not to click on it, not to open it, to ask questions first, can save us millions of dollars. So if I broke down those 10 to three that I feel are important, and a different person might give you three different answers. Those would be the three I would pick off the top of my head.
Catherine Short 13:22
If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Raymond Ribble, CEO and Founder at SPHER Inc, on the topic of A Practical Approach to The Safe Harbor Law. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.
Catherine Short 13:57
If we’re discussing phishing emails, does it help if we monitor them, if we implement encrypted email?
Raymond Ribble 14:04
If we’re trying to prevent phishing emails from getting into our system, we would typically install something like Malwarebytes or Bitdefender, or Sophos, or many of these third-party products. Some of them are even sold with your laptop and your PCs, your Mac books when you buy them. You want to make sure that you activate those licenses and that you use them and they help to prevent certain types of phishing emails to come in.
Having said that, your question was also with regard to just email encryption as well. Email encryption is very different from phishing emails. Email encryption is encrypting, so it’s codifying the email that you’re using to do business and ensuring that if some third-party intercepts that email which is not phishing, that they cannot encode that and look at it unencoded, and see what was in there. Two different things completely. Just to be clear, I hope I’m answering this question correctly.
So I do recommend that you don’t use products like Gmail, or AOL, or any at home third party email system to be sending information to your patients. I think something that was discussed before is, you should be using the portal that’s provided to you by your EHR company, in the best of my knowledge 90% more provide those types of portals that you can use that as a way of communicating and that data is encrypted. So that email is encrypted, they’re providing that encryption for you as a byproduct of using their solution. So that solves a lot of problems for you.
If you have your own email server, that you communicate with your patients with for whatever reason, then you should be installing some type of third-party email encryption on that system. The responsibility under the law is you must encrypt that email going out. There is not the equivalent of the patients sending you email and having ePHI in that email, that is not a violation because HIPAA doesn’t apply to them the way it applies to you. So let me pause there and make sure. Am I answering the question correctly?
Catherine Short 16:32
Yes, sure.
Raymond Ribble 16:34
Okay. Because there are two different things there that you asked me actually.
Catherine Short 16:38
So yeah, that was great.
Raymond Ribble 16:42
Okay, good. So again, phishing, I want to use third party products, to catch the majority of the phishing emails. And then let me add to that, Catherine, is, let’s be careful. If we see something we recognize, just because we recognize it, please don’t click, look first, put that cursor over wherever it says click here. Look down in the lower left hand corner and see where it’s actually going. Ask yourself, was I expecting this email? Is this email something that I normally get from this organization? And if those answers are no, hey, just leave it alone. Go to your interface that you might interact with that company, whether it’s your bank, or your cable company, or you’re a third party hosting site, and call them and say, Hey, by the way, I got an email from you guys, it says, and I guarantee you 99% of the time, they will say to you, we would never send you an email for something like that, right? You hear it all the time. They don’t send those things because they know that’s what the bad guys are doing. So they don’t send them. So when in doubt, don’t click in check first. That’s I want to add that as a caveat to the answer for phishing. Okay,
Catherine Short 17:57
Perfect. When you’re talking about phishing emails, you probably look at this a lot more as far as where they’re coming from. With phishing emails, do you think that they coming more from organizations, either organizations as far as foreign entities or from criminal organizations and working as employers, there’s a head person, and then they have people working for them? And then they’re sending out tons? Or are there lots of individual people, 15-year-olds out there who are trying to make some dough? What does the stats say about what they think people are doing?
Raymond Ribble 18:34
Clearly, you understand the issue, because your examples are really good examples. So, I can share with you a couple of my own personal observations. I think I told you before Catherine, I lived in China for two and a half years and while I was there, and this was in the midst of the explosion of the internet, between 2005 and 2010 I had an opportunity to visit a couple of sites, where there were 1000s of employees who were working in these warehouses and what they were doing was hacking. They were paid to sit down and to hack into various systems using bots, using phishing mechanisms, using third party software, in order to break into the systems. Why I was allowed to go there and why I was there would be a different story, but I saw that, and then it was explained to me that these types of sites exist not only in China, but in a number of other countries, including Africa, Europe, and even unfortunately, here in the United States or in South America. So it’s not one nation, nation state sponsored attempt, but it could be a private industry, it could be for somebody, it’s a business. That’s what scary.
How do they target you? They can get third party data. You know, I always tell people, if you’re on Facebook or some social media, don’t answer your friends quizzes about who is your favorite teacher in fifth grade or what was the name of the street you lived on when you were growing up, because unfortunately, nine times out of 10, those are hints to the types of security passwords that you use. These companies are the ones sponsoring those social media trivia contests. They gather that data, they now have your email, they have some answers from you, they know that your proclivity is to answer those questions. And they start to put a behavioral reveal map together. Then what they do is they target you with an Amazon or Barnes and Noble, or they know somehow they figured out you’re an Anthem customer, or you’re using Signa, or whatever the case may be. Verizon, T Mobile AT&T. The probability that you’re using one of those three mobile companies is pretty high. I keep getting this one on my phone for a PayPal, I don’t use PayPal. But I’m getting emails and text messages saying that my PayPal account has been compromised, please login to correct right away. Well, it’s pretty obvious, somebody’s got bad information. But they got my phone number. That’s pretty easy for them to get my phone number. But they keep sending me these messages. And I just laugh at it. And I delete it. And I’ve tried to teach myself to be very diligent to anything that I’m not expecting. And I have a pretty good idea of what I have set up in terms of my automatic payments. I don’t trust anybody. I’m terrible. But what I’m doing is I’m looking at all of this data, and I’m just naturally suspicious. Sounds terrible to be that way.
To answer your question, I think it’s more external than it is internal. I think it is organized by a very large group. If it wasn’t working, if they weren’t able to get what they were looking for, they wouldn’t be doing it. So the bad news is that it’s an effective way for them to reach out to people and to steal data, and sometimes money.
Catherine Short 21:54
Great. Well, right. I had a question about employee snooping. I know, there’s probably a number of people who work on their own. And I know that you’ve said that there’s a lot of people who of course, are very curious so that’s always an issue. When we have an issue with employee snooping, is it usually just individuals working or do we sometimes find there are people working in concert with others, and it is sometimes some kind of a criminal type of element?
Raymond Ribble 22:30
It could be more of the former and very, very less of the latter. I’ll expand on that answer. What we find at SPHER, because one of the things that SPHER does is it actually monitors for snooping. So I can give you some firsthand examples here. We’re looking at employees that might be looking at their own files, might be looking at files that belong to their neighbors, or to their co workers, or to some VIP. We’re able to determine with our technology, whether or not that glance, or that long look at the record is consistent with their profile and the way that they use the system. Now that’s our perspective. That’s what SPHER is looking for. It’s one of the things we do. Your question isn’t how to SPHER do, your question is how does snooping occur? Who does it and the damage that occurs? So I do believe that snooping is somewhat nefarious for almost all instances.
A lot of people snoop just for the sake of gossip, unfortunately. I will tell you for example, that our highest rate of snooping is with our rural customers moreso than our big city customers, if that makes any sense whatsoever. We find that during the pandemic, snooping spiked quite a bit. People working from home, they were finding themselves not as busy or having as many tasks as they might have had in the office, or they weren’t in an environment where people could see over their shoulders to see what they were looking at, so they thought, hey, it’s okay to take a peek, right? All of that fit into that model where they went and took a look at something and forgot that there was some system that was in place that was looking at what they were doing and all of a sudden, they had a knock on their door or phone call from their manager saying, Hey, can you explain to me why you were in so and so’s file because that has nothing to do with anything that you had assigned to you or within your workflow.
And so people love what we do in that stage because that’s something they can lock down on. I’ll give you one example if you don’t mind me doing that.
Catherine Short 24:47
I would love it.
Raymond Ribble 24:48
We had a large organization in the south. I’m going to be very vague here.
Very large organization. When they went live with our technology. In the first month of use, they had 1800 snooping incidents in one month. Yes, it’s pretty bad. Now, the CIO called us and said, you know, I hate you guys, for two reasons. One is, now that I know that, I have to go fix it, and you’ve made my life a living hell, because clearly I don’t have a problem. I have systemic, across the organization problem. Everybody’s looking at everybody’s data. It has nothing to do with their day jobs. Right? So she put together a strategy, she went to market, nobody got fired because she figured it was the entire company doing it.
A side note, the two people who were assigned to review the data coming from SPHER were two of her biggest transgressors. So the guys who are responsible for watching were the ones watching the wrong stuff. Within two months, she was down to eight instances of snooping. Once a new culture was established, once the employees knew they were being watched, that somebody was looking at what they were doing, and what they were looking at, it changed the culture, it changed the habit that fast. Which I think is a testament to okay, we had a bad problem, we got forward, we taught everybody what we’re gonna do. We explained to them what we implemented, and we did it, and they changed. That’s great. That’s a great story. So that was us working together where a client and a really good outcome that happened from that but snooping is really a big issue. And I think a lot of it is gossip.
So I hope that helps to provide some insight.
Catherine Short 26:47
Yeah. The eight people who didn’t get the memo?
Raymond Ribble 26:52
Well, there’s always the ones who think, hey, I can beat the system. Right? Maybe. Right.
Catherine Short 26:58
So I wanted to thank you so much for being on 1st Talk Compliance today. Right? I appreciate it so much. Your explanations were excellent and concise, and very practical. So thank you so much.
Raymond Ribble 27:12
Well, as always, thank you for having me, Catherine. Thank you to everybody at First Healthcare Compliance. And to everybody listening today, I appreciate your time and your efforts as well.
Catherine Short 27:21
Thank you. I can’t wait to talk to you again. So appreciate it. Did you have any actual final thoughts before we totally wrap up?
Raymond Ribble 27:28
Please don’t be afraid of the answers that I just gave Catherine or the information that I presented. It’s not hard. Take it one step at a time. You’ve probably done better than you think you’ve done. But sitting down and just having a conversation with somebody within your organization and reaffirming that you have done the right things and that you have a plan that you’re working towards is the first step towards protecting your data. And I just recommend everybody do that.
Catherine Short 27:48
Great advice. So Ray, I wanted to thank you again so much for being here.
And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.
Raymond Ribble is the CEO and Founder at SPHER, Inc. a market-leading compliance analytics, cyber-security solution addressing: HIPAA compliance, State Privacy Laws, and ePHI security threats and our expert presenter for this webinar. HIPAA data breach penalties typically get measured in millions of dollars even following an organization implementing NIST cybersecurity framework measures. With the new HIPAA Safe Harbor Law, signed last January of 2021, HHS and OCR may consider increased penalty mitigation when an organization can demonstrate it has been following established good security practices for a period greater than 12 months.
It is important to understand that the Safe Harbor Law, while offering substantial protection, does not provide a true safe harbor. Safe harbor laws normally shield an entity from liability when the criteria are met, however the new HIPAA Safe Harbor Law only offers some protection. The Office for Civil Rights (OCR) may consider whether a covered entity had implemented certain technical safeguards for 12 months. where appropriate, it allows OCR leniency in assessing the breach.
Our presentation will examine what are the established security practices for healthcare, and how to pivot your organization’s security profile in order to mitigate breach penalties in the event of an event.
This webinar will cover the following objectives:
1st Talk Compliance features guest Iliana L. Peters, Shareholder at Polsinelli PC, on the topic of The Risk of Data Sharing. Iliana joins our host Catherine Short to discuss how these days, health data is an incredibly valuable commodity. Companies of all types should consider the legal risk with data valuation, data ownership, and data sharing agreements. In this episode, we will be discussing the scope and breadth of data sharing projects in development in the health care sector, examine contractual, state, federal, and international legal obligations for data privacy and security for such projects, and discuss issues related to data ownership that may also be part of such projects.
Catherine Short 0:03
Welcome, and let’s, 1st Talk Compliance. I’m Catherine Short, Marketing Manager for First Healthcare Compliance, a division of Panacea Healthcare Solutions. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. Please show your support by taking a moment to provide a review on Google, Facebook, or iTunes, and be sure to follow us on social media and subscribe to our YouTube channel.
On today’s episode, we are speaking with Iliana L. Peters, Shareholder at Polsinelli PC on the topic of The Risk of Data Sharing. These days health data is an incredibly valuable commodity. Companies of all types should consider the legal risk with data valuation, data ownership, and data sharing agreements. In this episode, we’ll be discussing the scope and breadth of data sharing projects in development in the healthcare sector, examine contractual, state, federal, international legal obligations for data privacy and security for such projects, and discuss issues related to data ownership that may also be part of such projects.
Before we begin, I would like to mention at First Healthcare Compliance we strive to serve as a trusted to resource for compliance professionals and we celebrate their hard work and dedication with our Compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Mika Lantz, Front Office Manager at Mountain Ridge Pediatrics. Mika says what she enjoys most about working at with Mountain Ridge Pediatrics is “interacting and forming relationships with our patients and their families.” Congratulations Mika! Our team is honored to have the privilege of working with you.
So thank you, Iliana, for joining me on 1st Talk Compliance. It’s such a pleasure to have you on!
Iliana Peters 2:24
Thanks for having me.
Catherine Short 2:26
Why don’t we start with an overview of health data value proposition, and what some of the legal risks are with data sharing projects?
Iliana Peters 2:37
Absolutely. This is a new and evolving area of practice, particularly because we have many different entities that are very interested in engaging in innovative data sharing projects that result from the need to do research of all different types. That is research with a small r in terms of research and developments within entities, development of new products and services and research with a big R, that is human subjects research as defined under the law that may be used to determine new therapies, new drugs, new devices for patients as well. So there are all kinds of research projects going on, related to the use of data, and for many different and important reasons. As a result, we’re seeing a lot of questions about the legal requirements and risks associated with those types of projects, and particularly the agreements that are necessary and that are put in place between business partners related to those projects.
Catherine Short 3:48
Can you give us an example of what some of these new and innovative projects or research?
Iliana Peters 3:55
Sure. For example, we have many different entities that are interested in developing new software applications that may help with treatment or billing or, services in the healthcare sector to some extent, and they need data to really do evaluation and development of those prototypes and tools. We know that there are a lot of entities that are working on developing new drugs or new treatments just based on data that is what kinds of treatments are they seeing working for certain populations of patients over time? And can we implement that same kind of treatment in a larger population? There are entities that are looking at all different types of health disparities issues. So how do we get better treatment to better locations or better population? What does that look like? And how can we help develop tools and technologies to help with those issues? There’s a variety of different projects in this space that have a lot of really important and practical implications for how we provide care in the healthcare sector.
Catherine Short 5:18
That’s really interesting. Some of the ones I would have thought of, and then some of the ones that you mentioned, I never would have thought of such as billing, and a few other things. How about a quick summary of the legal issues involved in these projects? I’m sure it’s Myriad. But if you could tell us some of the legal issues and do you think that there’s serious legal risks associated with some of these issues and projects? What are your thoughts on all of that?
Iliana Peters 5:47
The short answer is, yes, there is serious legal risks. There are requirements at the state, federal and international level in the law itself, related to how we can use and disclose data. And that includes a general prohibition on the sale of data. So many of these innovative projects include some kind of benefit to the entity originating the data, because they are contributing data to an important project that’s going to arguably result in a new service or a new application or some kind of new invention, for lack of a better term. I don’t mean that in the legal sense, I just mean that in a general sense. As a result, these agreements contemplate what we call direct or indirect remuneration, that is some kind of benefit to the entity that’s originating the data. That’s considered a sale of data. And so that would necessitate consent from the individuals whose data we’re using for these projects. It’s really important, I think, that entities understand what this looks like from a legal perspective, because of those risks. As a result, a lot of entities are anonymizing data so that we can use data for projects involving remuneration, without implications for patient privacy, because the patients are arguably not identifiable or we don’t know who those patients are, who those consumers are as part of those projects, because we’ve anonymized the data. But obviously, if we’re going to do that, we have to make sure that we do that properly and in a way that in fact, doesn’t allow for those individuals to be identified, doesn’t allow business partners or downstream users of that data, to re identify or recombine data with other data sets to figure out who those people are, that are the subjects of the data. That’s not easy. It’s a hard issue.
Additionally, we have contractual requirements with our own clients and business partners that may significantly restrict how we can use data, how we can put data together and datasets and how we can anonymize the data. For example, Centers for Medicare and Medicaid Services have significant prohibitions in agreements related to Medicare and Medicaid beneficiary data that we have to be aware of when we’re aggregating data or de-identifying it because we generally can’t use CMS data in that way. That’s just one example from a contractual perspective. And then, of course, we have data breach issues. Anytime we’re putting together lots of data into a big data set, that becomes a target for a criminal, a cyber criminal or threat actor and we have to be very cognizant of the risks there, particularly if we’re providing that data outside our entity, to another business partner, who’s then going to have our data and be subject to those risks.
Finally, there’s always a reputational issue here. Even if we do everything in a legal way, even if we protect the data from a data security perspective, individuals could still find out about how we’re using their data because maybe it’s not identifiable, maybe it’s anonymized data, but it still came from them originally. And they could feel very strongly about how we’re proposing to use data for a particular project. Maybe they don’t agree with that particular project for whatever reason, and that could also create reputational risks for us. So this is all they’re all risks that we have to consider from an underlying legal perspective, a contractual perspective, data ownership, data licensure, all of those important controls that we put in place for data security purposes. Then just considering what the consumer would feel about any particular data project to make sure that we consider their viewpoint on these projects as well.
Catherine Short 10:01
That’s an interesting point, though. But let’s see if data points came from, for example, a patient. I know that occasionally I’ve been in situations where prior to speaking with a doctor, perhaps a resident has come in and said, Do you mind signing this? We’re doing some research, if you’re okay with this, and I read the paper, etc. and, I’ve asked some questions, and I assume that I’m not the only one who’s done this. I ask, and I say what is this for? Is this anonymous, etc. and it seems like other people would have done the same thing and if they sign that, it seems like they are being informed, they gave informed consent about whatever information that they gave about themselves that it would go into this study. I guess that leads a little bit into this next question that I had, how should we consider addressing these issues and risks? I guess maybe one of them would be making human subjects or otherwise people aware of issues and risks.
Iliana Peters 11:06
Absolutely. At the end of the day, we could always get informed consent from the patient for any project that we want to move forward with. And that is the gold standard. So it’s a great point that you made that if what we really want to do is have a well informed consumer or research subject patient, whoever that person is, it’s always good to have a conversation with that patient, and get them to provide an informed consent or a HIPAA authorization for any particular project, because exactly as we say, then it’s clear that we had that conversation with the consumer, and that they’ve made the affirmative decision to share their data for whatever project that we’re contemplating. That said, there are a lot of these projects that we can’t maybe we have the data, and it’s very old, and we can’t go back to the person and get their consent to use it for some of these projects, in those circumstances, or in other circumstances where arguably, we don’t legally need informed consent, because again, it’s anonymized data or de identified data. That’s where those risks that we’ve been talking about come up and that is where we need to make sure that we have very robust contractual protections in place that allow for these projects to proceed in a way that will protect the privacy of those consumers and the ownership of the data for the originating entity. At the end of the day, if we can’t get informed consent, or HIPAA authorization for these projects from the individual, then we need to proceed in a way that is legal, that ensures that we’re not selling this data either directly or indirectly and that provides for good contractual protections for the data, such that we don’t have these really important issues associated with patient privacy, with consumer privacy and what data security
Catherine Short 13:12
Should entities go it alone, do you think or get help on these types of data sharing projects?
Iliana Peters 13:19
It’s a great question. In my experience, it is always good to have outside counsel to consult on these. That doesn’t mean your outside counsel has to look at every single agreement. They certainly can and it helps, but having a specialist in this area is often really helpful to understand the nuances because these are quite complicated issues and very rarely do entities have folks internally that have seen all of these issues, dealt with all of these issues in a way that allows for a really efficient and productive review, revision, negotiation of these types of agreements with business partners.
Catherine Short 14:04
If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Iliana L. Peters, Shareholder at Polsinelli PC on the topic of The Risk of Data Sharing. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.
Catherine Short 14:43
What are the most important risks to consider in innovative data sharing projects?
Iliana Peters 14:48
Great question. As we’ve been discussing, I think the most important risks are the risks associated with how the business partners that you’re working with are going to use your data. At the end of the day, making sure that we understand the data ownership and licensure issues, particularly with regard to the type of data that we’re using for any particular project, so that we can ensure the right controls for that data. Again, we want to make sure that we appropriately take care of that data. But that’s really less of a risk in this context because arguably, we can control how we use our own data.
It’s really about when we share that data with business partners, how we do our best to make clear to those business partners how we expect them to use and share our data and how we expect them to protect it. It’s about making sure they understand our ownership of the data, what the license to the data looks like, for purposes of a particular project, and how they’re going to protect the data as they hold it. I would say that’s the largest risk. It’s really when we share that data outside of our own institutions.
Catherine Short 16:13
Can you explain what some of those risks are? What are some of those various risks once they might start to go outside of your own entity?
Iliana Peters 16:22
I think one of the biggest data breach, obviously, if we don’t have a good data partner, that is as invested in protecting that data as we are and doesn’t have robust security controls for that data, we could very easily have a data breach, because it’s likely that they are a target for threat actors, because they probably do have a lot of data for a lot of different entities.
The other issue is they could also sell our data and we could ultimately be liable for that, because we handed over our data to an entity that then sold it without consent of the individual
We could also have an issue with re identification. So they could, if it’s anonymized data, they could sell it to an entity, which would arguably be permitted because it’s anonymized. And then that entity could re identify it, because we can’t control how they do that. So these are all serious risks associated with working with these business partners. If we don’t have good controls built into our contracts that says specifically, you know, how they can use the data, how they can disclose the data, and the data security controls that we expect them to put in place in their institution to protect the data.
Catherine Short 17:41
What do you mean when you’re saying that they re-identify it? What are they doing?
Iliana Peters 17:45
We could remove all of those 18 identifiers from the data or we could create, for example, what’s called synthetic data, that is data that is similar to an original data set, but not the original data set, or we could remove certain identifiers and not others in a way that we believe based on an expert opinion does not allow for an individual to be identified. We could give it to a vendor and the vendor could negotiate for example, with a very large internet based data company or an Internet service provider, or some someone who has very large amounts of data and based on the remaining items in that data set, whatever that is, that could be, let’s say a type of prescription drugs that someone is taking certain provider certain type of service that they’re getting for purposes of treatment, a certain state that they’re located in, in combination, it’s possible that someone else could have a dataset that includes enough identifiers that overlap with our de identified data, such that they can re identify it. That is, they can identify the individuals to whom it belong.
When we disclose it, it may not be clear that it’s early on as data. But when it goes to another entity, they may know enough about Iliana to re identify it and make it make it clear to them that that’s actually Iliana.
A good example of this was when HHS was working on The Genetic Information Non Discrimination Act. There was discussion about the identifiability of genetic data, and whether or not it could be de identified. The National Institutes for Health (NIH) had genetic databases on its website, and it was not a HIPAA covered entity to be clear, but they provided these genetic databases for purposes of research for different entities that were doing genetic research, and they believe the information that they had online was not identifiable because they had all identifiers for any particular individuals removed from it. That was very purely genetic information. Unfortunately, it was discovered that our researcher cross referenced at least one of these databases. This was obviously some time ago, cross referenced one of these NIH databases with a publicly available criminal database, and was able to identify convicted felon as a result of the data provided between the two databases. That is the kind of re identification problem that we would really want to avoid.
Catherine Short 20:38
Okay, I understand exactly. One other question. Should entities train their staff on these risks and issues?
Iliana Peters 20:49
I think the short answer is yes, but I don’t think this is the kind of training that everyone needs to this level. I think there are certain folks in every institution, legal and compliance that need this level of training. Otherwise, we need our business folks, our marketing folks, really anyone who has contact with business partners and vendors, who may propose these types of projects, to understand what these projects look like, and where the risks are, from a general sense. So they can appropriately identify this type of project and bring it to the folks that really need to take a closer look at it. We wouldn’t expect someone who is out in the community, working with business partners, to really know the nuances here, but we would want them to be the kind of employee that says “oh, you know what? I think this is one of those complicated data sharing projects, I probably need to work with legal or compliance on this one” so that they’re escalated appropriately. Not so that everybody has to keep this information handy, but so that they have enough knowledge and understanding of how risky this is for organizations, such that they can say, “oh yeah, this is one of those data sharing projects. I need to be sure to escalate this as soon as possible, so that we can have legal and compliance look at this so we can take advantage of this fantastic opportunity in the right way”.
Catherine Short 22:26
All right. I want to thank you so much, Iliana. Did you have any other words of advice or things that you thought of during the presentation that you didn’t bring up at the time?
Iliana Peters 22:36
I don’t think so. I just wanted to say thank you for having me, and that I absolutely understand this is a really complicated area of current legal issues and so I hope that individuals will take a little bit of time to walk this through with their teams, but of course, are free to get in touch if they have any additional questions.
Catherine Short 22:59
Okay, well, thank you so much. Iliana. I really loved having you today on 1st Talk Compliance. Can’t wait to have you back!
Iliana Peters 23:05
Thanks for having me!
Catherine Short 23:17
And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.
1st Talk Compliance features guest Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., on the topic of DMEPOS – In Compliance with CMS. Rachel joins our host Catherine Short to discuss special payment rules associated with durable medical equipment, prosthetics, orthotics and supplies. DMEPOS products must meet quality standards, suppliers need to be accepted by Medicare to participate, similar to providers, and are subject to fraud, waste, and abuse laws. This episode will provide an overview of participation and quality requirements, relay the latest compliance and requirements updates, and discuss the consequences of non-compliance, as well as submitting false and fraudulent claims.
Catherine Short:
Welcome, and let’s, 1st Talk Compliance. I’m Catherine Short, Marketing Manager for First Healthcare Compliance, a division of Panacea Healthcare Solutions. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. Please show your support by taking a moment to provide a review on Google, Facebook, or iTunes, and be sure to follow us on social media and subscribe to our YouTube channel.
On today’s episode, we are speaking with Rachel V Rose, JD, MBA, principal with Rachel V. Rose Attorney at Law P.L.L.C., Houston, Texas on the topic of DMEPOS – In Compliance with CMS. There are special payment rules associated with durable medical equipment, prosthetics, orthotics, and supplies. DMEPOS products must meet quality standards suppliers need to be accepted by Medicare to participate similar to providers and are subject to fraud, waste, and abuse laws. This episode will provide an overview of participation and quality requirements, relay the latest compliance and requirements updates and discuss the consequences of non compliance as well as submitting false and fraudulent claims.
Before we begin, I would like to mention at First Healthcare Compliance we strive to serve as a trusted resource for compliance professionals and we celebrate their dedication with our compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja, April Collins, Compliance Officer for Anesthesiology and Pain Management Consultants. April says “What I enjoy the most about working at Anesthesiology and Pain Management are definitely the patients. I very much enjoy helping people and find it very rewarding.” Congratulations, April, our team is honored to have the privilege of working with you.
So thank you, Rachel, for joining me on 1st Talk Compliance. It’s such a pleasure to have you on!
Rachel V Rose
Catherine thank you. It’s always my pleasure to be here with you and to engage in a meaningful and interesting dialogue on a variety of different topics.
Catherine Short
Well, thank you. Okay, so as we get started, can you first for our listeners here on 1st Talk Compliance, give us a definition of DMEPOS? what that is exactly?
Rachel V Rose
Sure. I think fundamentally, it is a type of equipment that is utilized by a person and the setting can vary. Typically when you think of Medicare Part B that would be utilized by a Medicare beneficiary in their home and Medicare Part A would be when a Medicare beneficiary utilizes a piece of DME and again, DME can range from anything from a wheelchair to a hospital bed, to a knee brace after a total knee replacement, or an ACL reconstruction, to more disposable items that a person who was diabetic or hypoglycemic or is on a certain medication might use that are disposable. And if we think about the diabetic testing strips, the glucometer, the lancets that are used to pick prick a person’s finger. Obviously, the glucometer is something that should last for at least three years unless it’s defective for some reason. So that’s not something that’s going to be replaced regularly. However, the lancets and the testing strips are single use. That’s something that is disposable and can be discarded. Those are the range and types of items that would be considered a durable medical equipment and the types of settings in which they could be utilized whether it is a skilled nursing facility, or an acute care hospital, which would be billed in a different manner than if someone is, as an example diabetic and utilizing the glucometer, lancets, and testing strips on a regular basis. It’s important that a person appreciate the difference between a long-term care facility which in fact could be a person’s home and Medicare Part B would apply or a skilled nursing facility and while a person is in a sniff, as they’re called, for that 100 day period or shorter depending on what they happen to be there for. It could in fact be a Medicare Part A submission instead.
Catherine Short
Could it include oxygen tanks, or medical foods or nutrition or things like that? Or in this case, are we only talking about just equipment type of things? I didn’t know if you would be able to clarify that, or is there some kind of difference?
Rachel V Rose
Sure. So going back to just DMEPOS that actually stands for Medicare, durable medical equipment, prosthetics, orthotics, and supplies, and you really brought up different rungs of items, if you’re looking at certain prescribed nutrition items that actually might fall under a pharmaceutical which is separate from DMEPOS. And it is separate for a lot of different reasons. One would have to make sure as to what category a particular item fell into, whether it falls under pharmaceutical drugs type item, or if it falls under a DMEPOS. Specific to oxygen and oxygen equipment. there’s actually a fee schedule related with that, and the Consolidated Appropriations Act of 2021, which is found at Public Law 116 -260 and was signed into law on December 27, of 2020 and effective April 1, of 2021, actually eliminated the budget neutrality requirements set forth in a provision of the Social Security Act for separate classes and national limited monthly payment rates established for any item of oxygen and oxygen equipment. Now, no doubt the pandemic had an impact on that because as anyone is mostly aware, a lot of the issues associated with COVID were respiratory in nature.
Catherine Short
Right! Actually, can we discuss that? How is COVID-19 impacting the supply or procurement of DMEPOS?
Rachel V Rose
In terms of the claim submission process, a standard written order from the provider is still required, and I’m using the outpatient setting and not in-patient. With a standard written order, you have to establish medical necessity. If a person has COVID, and they have the residual tests that substantiate the respiratory issues associated with it, meeting medical necessity should not be an issue. Making sure that the requirements for the claims on both the provider side and the supplier side are being met, those really have maintained consistency throughout the pandemic, so to speak. When you start talking about the supply chain side of the equation, as we saw from the outset, even with things such as gloves, and masks and gowns, there has been an impact on the supply chain side across and it just depends on where a person is and what the issues are at any given time. The last part of that which is important, and which may be again, given consideration in light of the requirements of a particular code, or what’s usual and I mentioned the lancets for diabetics, testing strips, different people with diabetes may be required or have a need to test themselves more than before each meal. The reason could be if they’re engaging in an athletic type of activity, or they feel a little wonky because they could have come down with a certain medical condition or a virus or something like that. You could see an increase in their use of lancets and testing strips. It doesn’t mean they’re acting outside of an abnormal use for their particular individual situation, but it is imperative that a medical provider document that and then that is translated to the supplier.
With oxygen and oxygen equipment, as you can imagine, there are CPAP machines or BiPAP machines in addition to, I believe what you articulated earlier with the rolly oxygen tank, right? Where a person has a tube that typically goes into their nose, right and has two nostril plugs. There might be a reason that Medicare typically approves, and I don’t know the number, so I’m just giving a number five of those tubes a month, I don’t know. Because of COVID and other factors that an individual may have to deal with, the provider will say, well, I want this changed more often because bacteria could right form in there and I don’t want that to be reinfecting the patient. He or she may request 10, 20, 30 and as long as that meets medical necessity, and then it’s brought to the attention of the MAC so a potential waiver could be gotten and approved, then there should not be an issue. It’s when it’s just a carte blanche, I’m just going to ship items without either an SWO (standard written order) or other requirements in documentation in place.
Catherine Short
If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Rachel V Rose, JD, MBA, principal with Rachel V. Rose Attorney at Law P.L.L.C. on the topic of DMEPOS – In Compliance with CMS. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.
I want to just shift ideas for a second. Anytime there’s stuff that can be bought or sold, there’s an opportunity for fraud. Could you speak to how DMEPOS, what the effects are of fraud or where and how fraud has occurred? And then since fraud is, I’m sure occurring in some places, what are the hottest areas in the US for DME fraud?
Rachel V Rose
So, I’ll take that in bite size type of process here. First, I’m going to go with the inverse and answer your last question first. What areas are hot for DME fraud? Well, if you look at the Z pick zones and the heat zones that HHS has identified, historically, that has included Texas and Florida, for whatever reason, and so a lot of DME fraud, which really isn’t surprising in Florida because it is a hotspot for retirees and therefore, a lot of Medicare beneficiaries live there. Those are two hotspots.
Other items. If you look at some recent actions that the Center for Program Integrity and the Center for Medicare services have taken in conjunction with the FBI and HHS OIG, which were prosecuted by the US Department of Justice that included 17 federal districts, the execution of over 80 search warrants, which resulted in 24 defendants being charged. These included CEOs, COOs, others associated with five telemedicine companies and owners of dozens of DME companies, as well as three licensed medical professionals who participated in a healthcare fraud scheme, involving more than 1.2 billion in losses overall, in relation to $1.7 billion in claims that were submitted. There were 130 DME companies that were investigated. This was a very significant reach.
But if you think about the historical areas where a lot of fraud has been perpetrated in relation to DME, and other types of health care fraud, Florida’s in specific and specifically the Southern District of Florida, as well as Texas, and if you look in particular at the Northern District of Texas and the Southern District of Texas, there is a lot of healthcare fraud. That’s a criminal side and that’s the reach.
If you look at the civil side, that is something that DOJ civil Law Enforcement Division has made a priority because oftentimes illegal inducements which take the form of free items and the routine waiver of co pays, which can result in over utilization and waste for taxpayer funds. Those can be brought in any jurisdiction in the country. A very significant case just came out of the Middle District of Tennessee. Now the Middle District of Tennessee is very interesting because it includes Nashville. And for those of you who know my bio, I am a Vanderbilt grad, so Nashville is near and dear to me. But also, one of the reasons I attended Vanderbilt is that Nashville is known as the Silicon Valley of healthcare. And so it’s not surprising that not only do we have some of the largest health systems located in Nashville, we also have a lot of ancillary businesses, including DMEs, which are located there as well. At one point, Arriva Medical Center was the nation’s largest Medicare mail order diabetic testing supplier, and its parent Alere ended up over shipping and providing free and no cost glucometers and routinely waiving or not collecting copayments for meters and the diabetic testing supplies which include those lancets and the testing strips that I mentioned. Basically, that type of fraud and submission occurred from April 2010 until the end of 2016. It cost that company over $160 million to resolve those allegations. For those who are interested in the citation, this case was brought under the False Claims Act, and it is captioned at United States ex rel Goodman versus Arriva Medical LLC et al., Case number 3:13-cv- 00760 and it is out of the Middle District of Tennessee.
Catherine Short
Are there a certain percentage of people who are accidentally caught up in fraud, doing something incorrectly? And just over and over doing something incorrectly? I mean, how often does that happen?
Rachel V Rose
So I think you raise an excellent point because as the sister webinar to this illustrated, it’s imperative in terms of compliance that you really train your staff, you make sure that they’re up to date on the correct codes, and you have an outside third party auditor come in at least once a year to make sure that a statistical sampling is done to ensure that the claims that are being submitted are being coded correctly, and that they’re meeting the regulatory requirements as well as the national coverage determination and local coverage determinations which are set forth by the max to ensure that people aren’t doing it to your point on a regular basis. And that’s really part of adopting a valid compliance program and cultivating a culture of compliance. There is a thin line at a certain point between what constitutes negligence and what constitutes reckless disregard for truth or falsity of the information and that’s where having the ongoing training and everything else can be absolutely critical to the success and viability of an organization avoiding and mitigating the risk of an enforcement action, whether it is through an administrative agency such as HHS and OIG, or through a whistleblower case under the False Claims Act.
Catherine Short
Can DMEPOS suppliers be excluded from Medicare? Is that a possibility?
Rachel V Rose
Absolutely. And because they are a participating provider, they are just as susceptible as any other individual or entity from being excluded by Medicare or alternatively having to enter into a Corporate Integrity Agreement.
Catherine Short
Okay, and what type of items should auditors consider?
Rachel V Rose
A type of item that an auditor should consider, one item is making sure that that SWO (standard written order) is in place.
Secondly, making sure that it’s updated annually.
Third, making sure that the medical record documents the medical necessity from the provider side, and then from the supplier side, making sure that that SWO is on file, that they have all of the appropriate signatures, that they’re not stamped, and that they’re meeting both the national coverage determinations and local coverage determinations, in addition to the regulatory and Medicare manual requirements.
Finally, on the DME side, the number of items and the waiver of co pays should also be looked into.
Catherine Short
Okay, I think I just had one last question. If you could just expand on how a either hospital administrative team or even a practice administrator in an office could cultivate a culture of compliance.
Rachel V Rose
Okay, so cultivating a culture of compliance is a phrase that is set forth by the government. Cultivating a culture of compliance is really realistic, and just like HIPAA, and the Final Omnibus Rule which is at 78 Federal Register 5566, and it was published on January 25, of 2013 states, you can’t get a certificate right for being HIPAA compliant. The government says they don’t accept that. You can get training certificates, you can indicate that you strive to cultivate a culture of compliance, but the minute someone posts something or sends a bill out to the wrong person, you’re no longer compliant with HIPAA.
Cultivating a culture of compliance means having the requisite items that are required to meet compliance measures to ensure that you’re acting in accordance with the relevant laws and regulations. A key component to doing that, whether it’s HIPAA, or you’re looking at claim submissions, is to make sure that a) you have adequate policies and procedures, b) to make sure that your staff and providers are trained on what is accurate and truthful and what needs to be substantiated in the medical record and also what needs to be sent to the supplier. And then on the supplier side, what they need to keep and what they need to provide in the event of an audit by either a recovery audit contractors Z pick contractor or a MAC contractor with the government. All of that is absolutely critical to document.
And then ensuring that you have the third party person come in and articulate to people where mistakes have been made, if there’s a requirement to pay the government for back overpayments that you weren’t aware of, and the risk that comes along with that.
Cultivating a culture of compliance again, it needs to be done in substance over the form and I always like to use the Tommy Boy movie example, I can crap in a box and stamp it guaranteed, then I’d have a guaranteed piece of crap. You don’t want the guaranteed piece of crap, you want something that guarantees a product or in this case, a compliance program that is absolutely substantive and in good faith when the government comes in or a lawsuit, God forbid, ensues, that you as an organization, or a hospital executive team or an individual providers team or a DME company can say, you know what, we didn’t just give this lip service, this is what we do in order to make sure that we’re adhering to all the regulations. And even if some items got through, it can be a very significant mitigating factor in terms of the amount of the penalty or the Corporate Integrity Agreement being assessed or not being assessed. It is a very dynamic area and a very dynamic time and I think the more proactive organizations could be as we’re transitioning out of COVID and getting out of this treading water period to really moving forward, personally and professionally, I think that’s going to become more and more of a focus for the government.
Catherine Short
Okay, thank you, Rachel, for this comprehensive presentation. And we haven’t had a presentation like this from this perspective. I very much appreciate you sharing your expert advice with us. Thank you for being on. Do you have any other words of advice that you’d like to leave with us concerning our presentation today about durable medical equipment?
Rachel V Rose
The only items that I would reemphasize are, when an entity implements a compliance program and tries to cultivate a culture of compliance, make sure that it is robust, that it’s reviewed at least annually, and that training is included with that. Because when the government comes in, and if you’re on the receiving end as a defendant in a False Claims Act case or a love letter from HHS OIG, you can potentially have a mitigating factor by having valid and robust compliance program. But again, it has to be genuine and they do look at the substance over the form of those types of programs.
Catherine Short
Okay, well, thank you so much for being on 1st Talk Compliance today.
Rachel V Rose
And thank you, Catherine.
Catherine Short
And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.
An audio version from the live event:
It’s important to understand how the application of the 2023 E&M codes impacts reimbursement. Inaccurate coding and inefficient documentation practices can result in a decline in revenue and increase the likelihood of downstream inaccuracies of patient data.
Join Panacea Healthcare Solutions’ Director of Coding & Documentation Services, Becky Jacobsen, CCS-P, CPC, CPEDC, CBCS, MBS, CEMC, BSN, and Executive Vice President of Coding & Documentation, Kathy Pride, RHIT, CPC, CCS-P, for a complimentary 90-minute training where they will review the 2023 E&M documentation guidelines and requirements and provide examples on how to improve your internal documentation processes to ensure appropriate reimbursement and avoid compliance issues.
A live Q&A at the end of the training will provide the opportunity to ask questions. Those who register will receive the recording along with a post-training FAQ sheet to reference as you put these new guidelines into practice.
The learning objectives for this training include:
– Explain the revised 2023 E&M guidelines for selecting the correct level of service
– Cover prolonged service codes, and updates to critical care and split/shared visits.
– Demonstrate efficiencies for documenting E&M levels of service based on the revised guidelines.
Expert presenter, Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX guides us during this important and informative webinar. Breaches and the lack of the requisite technical, administrative, and physical safeguards can have criminal consequences. While most people are familiar with civil cases, there is the potential for HIPAA violations and ransomware attacks to be prosecuted criminally. The purpose of this webinar is to highlight potential areas of criminal liability, give specific examples, and address mitigation techniques – both before and after a government discovery request or grand jury subpoena emerges.
This webinar will cover the following objectives:
Scenarios where criminal liability may arise under HIPAA and related laws.
The importance of understanding HIPAA’s law enforcement and whistleblower exception.
Mitigation considerations in terms of compliance, risk management, and government factors.
1st Talk Compliance features guest Raymond Ribble, CEO and Founder at SPHER, Inc., on the topic of “Employee Snooping & Insider Threats.” Ray joins our host Catherine Short to discuss snooping and insider threats and why user monitoring and ePHI access strategies are vital to the security of sensitive patient information and data protection. With so much attention and money surrounding cybersecurity in the healthcare industry, malicious employees may decide to purposefully disclose patient information. Since employees and contractors may have knowledge of your network setup, vulnerabilities, and access codes, snooping employees with malicious intent hold the key to exposing your organization to a series of unwanted risks and threats. Listen as we identify signs of unauthorized access, provide guidelines to prevent snooping, and offer procedures to detect insider threats.
Catherine Short:
Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.
On today’s episode, we are speaking with Raymond Ribble, CEO and founder at SPHER Inc, a market leading compliance analytics cybersecurity solution addressing HIPAA compliance, state privacy laws and ePHI security threats on the topic of “Employee Snooping and Insider Threats.” Snooping and insider threats are exactly why user monitoring and ePHI access strategies are vital to the security of sensitive patient information and data protection. With so much attention and money surrounding cybersecurity in the healthcare industry, malicious employees may decide to purposefully disclose patient information. Since employees and contractors may have knowledge of your network setup vulnerabilities and access codes, snooping employees with malicious intent hold the key to exposing your organization to a series of unwanted risks and threats. Listen, as we identify the signs of employee and contractor unauthorized access, provide guidelines to prevent employee snooping, and offer procedures to detect insider threats.
So thank you, Ray, for joining me on First Talk Compliance. It’s a pleasure to have you on.
Raymond Ribble
Thank you for having me today. It’s great.
Catherine Short
Yes, always wonderful to talk to you. So Ray, I have a question for you to start off. I know when people think about threats to their organization, they worry often about external risks such as hackers. Would you say that this is the right focus?
Raymond Ribble 2:15
For an organization, it’s not the wrong focus. It’s what we read about in the press the most. We’re online looking at some healthcare rag, what they’re talking about is some type of external threat that impacts the organizations. And I think from a cost perspective, it is the most impactful. Somebody coming in from the outside, a hacker to use the term, can cause hundreds of thousands if not millions of dollars in damage to an organization. Ransomware would be a perfect example of that. You or I don’t want to have to pay some X number of bitcoins in order to get access back to our data knowing that now that they’ve done that, that they’re probably going to come back and do it again. Having said that, I think the equal component of that is what we talked about in terms of snooping and the insider threat, because an individual snooping and then taking that information that they get through snooping and sharing it through social media, or in gossip to somebody on the outside, potentially could have a financial impact to an organization more so today in 2022, than say 20 years ago, or 30 years ago. So are hackers real? Yes, they are. Is the hacker the thing that you should stay awake at night worrying about? Not as much as you think. 26% of the breach events that are captured by most organizations that are responding to our surveys out there, IBM Parliament being the best, indicate that snooping and insider threats are much more detrimental to the business than the hackers on the outside. I think they’re more prevalent. I think that 67%, if I remember the number correctly, is what we have in terms of the percentage of healthcare breach types come from inside the organization, not outside. I think we tend to focus on what that cost is to the organization if we get caught, when we get caught and so therefore, hackers are more prominent because we use that word as a catch all for everything from phishing, to ransomware to XYZ. Does that make sense?
Catherine Short
It does. So all the time in the news and media and everything we hear about ransomware, ransomware there’s a cyber attack. So if you were talking about ransomware and cyber attacks, versus insider snooping, which is one of the topics here and employees snooping, what would you say then? Could you expand on that just a little bit more?
Raymond Ribble
I’m more worried about the insider threat personally, I think that there are things that we can do from a technology perspective to significantly limit our exposure to ransomware type events. So if we can educate our end users to not click on anything that comes up on their screen, to not look at third party applications or ads, and click on them to go see if that shirt from China is really interesting, and I really can get something for $25 that I’d have to pay $200 for, is worth it. Because when I click on that, what I’m actually doing is opening up a hole into my data system. So if we can educate people not to do those types of actions, through technology and encryption and such, then we can reduce the exposure to a ransomware event through that.
On the other hand, if I have people in my office, who are snooping or worse, in a malicious sense, stealing the credentials, and giving those credentials to somebody else in order to create havoc, that cost is exponential to our organization. That goes back to a major breach, it goes back to being measured in hundreds of thousands, if not millions of dollars. The impact to your organization from a cybersecurity insurance perspective, is significant. The reason we have that feeling, Catherine is because what articles we typically see out there in the press, whether it’s online or in print are stories about ransomware, a hospital being shut down, not being able to access their files. It’s rare that we see a story about a snooping incident, such as say, the Justice Mueller in Chicago, where it makes it to the point of news that’s worthy of being talked about. So it’s kind of a hidden crime in an organization that a lot of people think well is really causing the damage?
Catherine Short
So right. Can you give me some examples of what you’re talking about? When you mentioned insider threats or employee snooping?
Raymond Ribble
Yeah, the worst one that we’ve had with our organization where we work with a client, was an incident where they were brand new to our technology, we implemented the system for them. And maybe a little bit of background. It is a rural hospital. You and I both know that we love to talk about others. I mean, TV is loaded with shows about other people’s lives and reality TV, but what’s more reality than snooping that what’s happening in my community, viz a viz their healthcare and what they’re coming in, what type of ailments they have. This organization went live with SPHER and in the first month of using the system, they had 1800 snooping alerts. 1800.
Catherine Short 7:50
Wow, that was from one organization
Raymond Ribble
That was for one place, it was the hospital and when we sat down with that team, and investigated the 1800s, they were all legitimate. There was no false positives, everything was legitimate. They were they had a very, very bad problem in this hospital.
Catherine Short
That was in a month?
Raymond Ribble
That was in one month.
Catherine Short
Oh, my gosh, there must be a lot of gossiping going on there.
Raymond Ribble 8:22
Yeah. I’m not gonna say where it was, other than it was a rural hospital. It would be bad. But let’s just say yeah, there was a lot of gossiping in an area that’s famous for gossip like that. Everybody listening can say, now that’s my area. But now though, this is one that we probably would all agree upon. We sat down with them and this is where once they understood this was real, then they said, Okay, how are we going to solve this problem? And it really came down to the CIO. In this case, the CISO, saying, Okay, we’re clearly not educating our users on security and we don’t have a culture of compliance in this organization. So she decided to make it very public what they had found, to share some of the analytics without calling anybody out since it was everybody and saying, Okay, this is going to change immediately. We’ve implemented the system to monitor so I’m looking at you, just know that from today. Within two months, the snooping dropped from 1800 to five, five incidents, and those five incidents she told us, could all be explained. So you know, in essence, she said, Yeah, they did look, but here’s the reason they looked and she could accept that so basically, zero. Once people knew that somebody was looking at them looking at other people’s data, they stopped. Maybe they found a new way to do it, but they weren’t using the EHR system or the EMR system as their main source of Office gossip. How’s that?
Catherine Short
Wow. So when you have an incident where someone is looking at someone’s medical records, say like an ex spouse or the ex spouses new wife or something like that, what do you do?
Raymond Ribble
So we have to be very careful. I think I mentioned this to many people. At SPHER, we’re not the HIPAA police. My tool that I make available to my clients, the SPHER dashboard and the alerts that you get, that’s where you start. We do the hard job of identifying areas that might be worthy of an investigation, you’re then looking at that data and determine is this meaningful information that SPHER is giving me and should I take action on it? Yes, or no. If it’s a normal action, you tell the system it’s normal and you won’t see that again. That becomes part of that person’s profile. However, in many instances, when people do identify and do the investigation, they’ve called us to say, hey, look, I just saw something here, I did an investigation, can you look at it with me, we have their permission to do so. And then we’re just looking with them to make sure that they’re interpreting the data correctly. Final decision is theirs, not ours. And as I say, whenever I speak, this is where they want to reach out to an organization like yours, Catherine, and have a conversation with somebody who’s like a HIPAA consultant, or like Rachel Rose, somebody who is a HIPAA law attorney, and have a discussion about how should I handle this going forward? We’ve had incidents where physicians have gone into the system and taken data that was so random that it showed up in the alert, and they were giving that data it turns out, to somebody else that used it, as part of your example, in a divorce proceeding for custody of the children. And the only way that that data could have been gotten on the wife in this instance, was through the medical record, because it was very private. How did he get it? Of course, somebody else took it out of the system, gave it to him, and he used it in a court of law. That was a no, no, and they should have thought about that before they did it but they did it anyways and so they got busted for that. I mean, think about the ramifications of a doctor in that in court.
So we do see real instances of people at very high levels going in and snooping or maliciously exfiltrating data for the purposes of something that might be legal in nature or monetary in nature. And we see that more often than you’d like to believe.
Catherine Short
If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Raymond Ribble, CEO and Founder at SPHER, Inc., on the topic of “Employee Snooping & Insider Threats.” Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.
I have a question then. How do you recommend to administrators and managers for balancing and creating a culture of compliance and then balancing this with the feeling for employees? When a new system is implemented, that they might feel like they’re being micromanaged.
Raymond Ribble
They’re very concerned, the administrators and the senior managers CISOs that we work with, they’re really concerned about that question that you’re asking. I want to do this but I don’t want to send a negative message to my employees. I don’t want to tell them I don’t trust them. I don’t want them to think that. Oh, you know, we’re watching everything they did – we are. How do I do this proactively? And so we’ve had some really creative organizations that have shared with us what they did do. That’s how I’ll answer your question, by sharing with you what I heard people do that I thought was very innovative
So they have a regular lunch, or they have a regular session that’s scheduled every month or every couple of months in the organization. They take some of the analytics that they’ve learned from SPHER and integrate that into the learning process. They talk about, hey, we’ve noticed over the last couple of years in the United States, that the threat vector in terms of breaches through phishing, and hackers and even insider threats, is increasing and as an organization, we want to do what we can to protect ourselves, protect our patients. So it’s a bit of a manipulation of the words, but they come up with a very creative way of saying, We’re doing this to protect the people who come in here in order to get healthy and you know, this is a team effort. It’s not a me looking at you effort. It’s us looking at what’s happening effort in order to make sure that we’re protecting our patients from any external threat. The byproduct is the internal threat gets addressed as well.
So they take it from a negative message to a positive message and they use different vehicles like team training, or the company lunch or some type of a newsletter that they have in the organization to start making that a regular part of the presentation, and maybe introducing incidents that happened in the past and the corrective action that the organization took. It sends a secondary message of, hey, I am looking and we are aware of these things, and if that happens to you, you might be the person or at least the incident’s going to be highlighted in the next newsletter or the next company meeting. So let’s watch our P’s and Q’s let’s be better at how we access data and what we share.
Catherine Short 15:44
I think that’s very helpful for everyone.
Raymond Ribble
You know, we always talk about penalties, we never talk about rewards. So if employees were to come to us with ideas on how we could improve our security posture, maybe there should be reward for them doing that versus penalties for somebody who does something wrong.
Catherine Short
Right, everyone likes to be rewarded. No one likes to feel like they’re a bad dog, you know, with a smack with a newspaper or worse, obviously
Raymond Ribble
I think it gets viewed by the team, the employees in a much more positive light, if this is something we’re doing together. Hey, and if you have an idea on how we can improve it, I’d love to hear it. We sat down with the doctors and I’m thinking about who we work with a lot of clinics that are somewhere in the range of say 100 to maybe 1000 employees. So they’re always looking for creative ways to incentivize everybody doing better, it’s performance based. So security becomes a performance metrics as well and providing better security and doing a better job of creating that culture should be something that can be rewarded within the organization.
Catherine Short
True. I have a question again about audit. So what’s the probability that someone would get audited? What are your thoughts on that?
Raymond Ribble
Yeah, broad question. I’m going to attack it based on just what I’ve seen. I live in California, Catherine. So last year, I think was last year, I lose track now, we passed the California Consumer Privacy Act. My understanding is within the next two years, if not all, almost all of the 50 states and territories will have some type of Consumer Privacy Act in place. In many instances, like in California, some of that law supersedes HIPAA, in terms of reporting, in terms of having to grant access to patient data to the consumer, to the patient, and that could result in punitive actions and or investigation. So when we think about audit, you and I, we probably focus more on OCR related, health and human services related activities. I think what’s happened is the landscape has changed. It’s gone from a Federal HHS issue, to include state level, privacy and security laws that now in many instances, again, can supersede what we have in terms of accountability, record keeping, documenting, and being able to prove that somebody did or didn’t do something within an organization. I think the probability of an audit today is much higher than the probability of an audit, say, two years ago or five years ago. It’s not a real number for you. That’s what people are faced with today. So I can’t give you a specific number. I don’t know one. But I know that that threat vector for us as organizations is increasing, not decreasing, because now we have federal and state that impact us. Does that make sense to you in the way that I’m stating that?
Catherine Short 18:45
Absolutely, actually, yes. And I’m glad you mentioned California, because California I know, I always think of being kind of like Europe with the GDPR and having more stringent laws, than federal
Raymond Ribble
A lot of other states flew into Sacramento and sat down with the state of California to see how they put that consumer privacy act together and in many instances, the other states, it’s a derivative of the California Privacy Act.
Catherine Short
Right. I have another question concerning security. What are your thoughts on the security of automatic logins on the computer like if it asks you if you want to save the password, and then you can just log in automatically next time? And then following up on that isn’t a problem when it asks you show your password? I always feel like I’m suspicious that someone out there might be capturing my screen. I might be extra paranoid, but at that, I think maybe not. I don’t think so. I feel like somebody’s watching
Raymond Ribble
Good question. I hate passwords. I bet you hate passwords too passwords. I’m a big advocate for at some point, I think we are going to move away from them, I think we’re going to move more towards biometrics, which I think is a better way to secure the data anyways, then whether it’s a fingerprint or a voiceprint, or an eyeball, whatever the case may be, I think they’re coming up with some really innovative solutions that we can incorporate. And I think we’re gonna see the MacBooks in the Microsoft workstations out there start to incorporate that technology in the years to come. That will allow us to move away from passwords. So your question is about having those passwords saved? Because I know that in a Microsoft and in an Apple world, you find online they will say, Oh, do you want to save this password? and it gives you the username and the password and boom, it’s sitting there. So if somebody were to break into your PC, they can go find that file, it’ll tell them every application that you have access to and what the login and password is. So is that dangerous? Yes, it is.
I guess if you’re really smart, you know what you’re using? Don’t do it. Your question, you kind of answered your question in the way that you asked it, don’t do it. Is it a risk? Yes, it’s a risk. I would start by saying, make sure your PC is encrypted, make sure you actually have a sophisticated login process to get into your PC itself. Because there’s only a few barriers of deterrent between your PC and all that data that we’re talking about. So please make sure you have a real stringent password in place that you can remember, that’s not written down, by the way that one doesn’t get saved into that file, and you’re gonna have to remember that, right? otherwise, you’d have to do a jailbreak to get into your own machine. So you know, you’ve probably had those instances, and they’re like, well, you don’t know the password and we’ve got to break into it, kind of a thing. So that’s a real problem.
The first part of my answer is, yeah, I think that is a risk. I know I have some there, I tried to think about which ones I want to have saved on there versus the ones that do. So I don’t want my bank information on there. I don’t want access to any sensitive materials on there. I don’t even want my Amazon account on there because God forbid somebody gets on Amazon and my cards already loaded into Amazon and they go on a shopping spree right? It might seem innocuous, but it actually can be very damaging to you. If you if you can avoid doing it, please do. And your applications on whether you’re using Chrome or whatever says, hey, do you want to store it? And you’re like, sure why not? That way, one more, I don’t have to remember. The problem is, the bad guys know how to find that file probably faster than you and I could.
Catherine Short
Right. That’s why I’m asking
Raymond Ribble
But the reality is, no, you don’t want to use it. If you can avoid using it, you want to create sophisticated passwords, which I think is the solution to that. Your username is usually your email, I mean, it’s almost 90% of the bar. And then sophisticated passwords, I always use the example and is just an example. I like the Boston Red Sox count that out in terms of the number of characters, anything longer than 12 characters, is really sufficient at defeating the algorithms that the hackers or a malicious insider might use in order to run against your machine to break the password code and get in. Most of the algorithms that they use are looking for an eight character based password. Once you move from eight to nine, nine to ten, ten to twelve, twelve to whatever, the time it takes for it to break into your machine grows exponentially. We’ll come back to why it’s taking too long, I don’t want to get into it. Now if they’re really hell bent on breaking into your PC or into your server, they’re going to do it because they’re happy to sit there hours, days, weeks to break into your PC will, you’re dead in the water. But most incidents are not that way. Another thing I might throw in here, just as a side note, Catherine, don’t use your PC at Starbucks or the local coffee shop because there are too many unscrupulous people out there using very simple $20 devices that can hack into your machine while you’re logged in. So, you know, if you’re on your phone, be careful what you’re looking at. Don’t do that kind of work, and don’t access those applications when you’re out in public. Keep that to your house and again, make sure you encrypt your PC and to the extent that you can avoid putting those passwords on your PC. There’s a long answer to an easy question, but sorry.
Catherine Short
Okay, very sound advice. I very much appreciate that. Well, I think that we are just about out of time here. Have you thought of any words of advice that you wanted to leave with our listeners?
Raymond Ribble
No, I don’t think so. I think what I try to do in my presentations, Catherine is the salient points that I’m trying to get across. I think for me, it’s upgrading your systems and making sure that the patches are properly up to date. It’s talking to your teams about security, I think it’s that simple. If they know that you’re thinking about it, they’ll think about it. If you don’t talk about it, they’re not going to be worried about it, talk about security, start talking about what can we do to improve security and work with my IT team to make sure that we have systems in place that allows us to regularly and properly monitor what’s happening within our system, not about trusting or not trusting your employees, we don’t know who’s surrounding them, we don’t know what’s happened in their life in terms of some life changing incident, that may move them from being the regular employee to be willing to do something that we might judge as malicious. And it could be again, for that personal gain but more importantly, it could be a reason for financial gain. If somebody is in a situation where they need to get money really fast, and the wrong person approaches them and tells them that, hey, some of those medical records would be worth thousands of dollars to me, you go from a very good employee to a very bad employee and sadly, it happens a lot. I’ve sat down with the FBI, I’ve sat down with OCR investigators, and they’ve heard enough stories about those types of situations, to know that it’s very real, that it’s that one incident that’s kind of broke the camel’s back and allowed or encouraged somebody to go do something that for many, many years they’ve never done before. So yeah, we trust our employees. I think we all do I do, I trust all the employees in my office, but having some type of regular and appropriate system that’s documented, that I can demonstrate to an outside party, defense lawyer during an audit or during a deposition that, hey, we do these things to protect our office and therefore, it’s not about not trusting my employees, it’s just making sure that we’ve done everything to protect our patients, I tend to look at it that way, Catherine
We had an organization who, using our technology, identified a user who had been with them for 17 years, who is going in and modifying records after the fact during lunch. Now, they were new to SPHER so they caught this with SPHERE. They radically looked at it, they started going back in the records, and they found that she’d been doing it for 10 years. Why? for financial gain. She was taking a little bit off the top and when we sat down with the doctor as part of the investigation, they indicated that Oh, wow, every year, we always seem to be coming up short in different areas and we thought it was really bad. We even changed our organization that did our collections for us a couple of times thinking that they were the ones doing it wrong. We never once considered there might have been somebody internally that was doing this.
Catherine Short
Oh, wow! that’s actually very sad. You never know.
Raymond Ribble
You never you never know. I don’t think you should feel bad about monitoring your end users. We’re just protecting our business from some event that could be catastrophic in terms of everybody losing their jobs because of a breach. With SPHER, we look at 100% of all the activity of all the users every day because you couldn’t possibly do that. Our users can read easily, and intuitively say oh, yeah, that’s a problem. I can see why SPHER flag that and let me investigate that. Bam. Make sense?
Catherine Short 28:22
Yes. Okay. Well, I think we’re about ready to wrap up our presentation then. So I wanted to thank you again, so much for sharing your time with us and your expertise. So thank you for being with us today.
Raymond Ribble
Thank you for having me today. It’s always a pleasure and good luck to everybody out there.
Catherine Short
And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.
Iliana L. Peters, Shareholder at Polsinelli PC will be leading this engaging webinar. These days, data is more valuable than oil. And health data is the most valuable of all data! Companies of all types should consider the legal risk with data valuation, data ownership, and data sharing agreements. Data sharing projects take many forms and address many important issues, including improvements in patient safety, fraud and abuse, population health, research, and costs to the health care system. That said, the contractual, state, federal, and international regulatory requirements applicable to such data sharing projects are significant. As such, health care entities may be particularly vulnerable to legal risk related to data sharing projects involving health data. Specifically, health care entities should consider contractual obligation, HIPAA, state privacy laws, and other requirements, as well as discuss risk assessment, data sharing agreements, key provisions, and business associate relationships. The presentation offers best practices for these important issues and projects.
This webinar will cover the following objectives:
1st Talk Compliance features guest Lauren Moak Russell, Counsel at Young Conaway Stargatt & Taylor, LLP in Wilmington, Delaware, on the topic of “A Harassment-Free Workplace vs the Right to Engage in Concerted Activity.” Lauren joins our host Catherine Short to discuss how the National Labor Relations Board under the Biden Administration has expressed a renewed interest in expanding its influence into non-unionized work forces. This includes reviewing and–in the right circumstances challenging–employers’ use of workplace civility, confidentiality, and anti-harassment policies. Listen as we discuss what you need to know to safely navigate the National Labor Relations Act while ensuring that your employees enjoy a safe and respectful work environment.
Catherine Short: 0:01
Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.
On today’s episode, we are speaking with Lauren Moak Russell, Counsel at Young Conaway Stargatt & Taylor, LLP in Wilmington, Delaware, on the topic of a harassment free workplace versus the right to engage in concerted activity. The National Labor Relations Board under the Biden administration has expressed a renewed interest in expanding its influence into non-unionized workforces. This includes reviewing and in the right circumstances, challenging employers use of workplace civility, confidentiality, and anti-harassment policies. Listen as we discuss what you need to know to safely navigate the National Labor Relations Act while ensuring that your employees enjoy a safe and respectful work environment.
Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals, and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Sharon Miller, administrator at Gulf Coast Dermatopathology Laboratory. Sharon says “patient care is paramount and by creating a culture of caring, compassion and respect, we have succeeded in all we do. We try to promote a family atmosphere which in turn translates to ultimate patient care”. Congratulations, Sharon. Our team is honored to have the privilege of working with you.
Well, thank you so much, Lauren, for being on First Talk Compliance. Thank you for being here.
Lauren Russell 2:16
My pleasure. Thank you for having me.
Catherine Short 2:18
Today, we’re talking about workplace civility, and also about the National Labor Relations Board. Can you get us started in talking about how things have changed as opposed to the previous administration?
Lauren Russell 2:34
Absolutely. So I think that the first thing that listeners really need to understand is that the National Labor Relations Board is not just for unionized workforces, that it has a role in regulating nonunion workforces, particularly where employer policies impact what we call section seven rights, and that’s really employee’s rights to talk about the terms and conditions of their employment. This is an area where we see a lot of ebb and flow between Republican and Democratic administrations at the federal level. I know it’s not a popular thing to talk politics these days, it’s oftentimes very inflammatory, but the reality is that the board changes its conduct very significantly between administrations. And so we had under the Trump administration, a board that really saw its role as very limited in terms of just regulating the relationship between organized labor, which is what we call a unionized workforce and management. To a Biden administration and a board that really sees its role as very expansive and is very focused on ensuring that even in a non-organized workforce, so a non-unionized workforce, that employers are conducting themselves in a way that does not adversely impact employees, what we call Protected Concerted Activity. So their ability to talk about the terms and conditions of employment. This includes a lot of things that make employers uncomfortable, including wages, compensation, comparing how much I make to how much you make, masking, vaccination requirements, anything that keeps a manager up at night, is something that almost certainly touches on Protected Concerted Activity and that can be protected by the National Labor Relations Board.
Catherine Short 4:33
So, employees have the right then to discuss their pay with each other. Is that correct?
Lauren Russell 4:41
Yes, it is. This is something that makes employers really uncomfortable. I understand. I come from a family where we don’t talk about money because I think a lot of us do, right? It’s very crass.
Catherine Short 4:59
Yeah. I never asked my parents or if I did, I was shut down right away. You know, like what you don’t talk about, you don’t ask people how much they make, what’s wrong with you?
Lauren Russell 5:09
Even at 40, I don’t know how much my parents made at any point in their lives. So no, it’s not just about being a child. It doesn’t change. That was very much the way of things. In my parent’s generation, it was simply something that wasn’t done, and certainly my grandparents never, never, never, never, in a million years, never. But wages are really the heart of the terms and conditions of employment, that is the most essential thing. So, the National Labor Relations Board for a very long time predating my practice, starting back in 2009, well before that, the National Labor Relations Board has said policies that prohibit employees from discussing and comparing wages are a violation of the National Labor Relations Act. It does not matter if you have a unionized or a non-unionized workforce, you still may not have policies like this. It’s hard, it does create resentment and frustration and questions and gossip among employees. We have to look at it from the flip side, from the public policy perspective. On that side, employees can’t know if they’re being treated unfairly unless they’re able to talk about wages. That’s really the impetus for these policies and I think that it’s helpful, it keeps employers from getting really angry when we look at it from the public policy perspective. Then you can say, well, it makes my life more difficult. I guess I can understand that women or minorities or individuals with disabilities, they couldn’t discover that they were being treated differently if they were never, ever under any circumstance allowed to talk about their wages with other employees. That’s the way we figure this stuff out.
The Obama administration was very focused on the expansion of the role of the National Labor Relations Board, the Trump administration, I had a much more conservative view of the role of the federal government, and really pared back the enforcement activities that the board was engaged in. Now that we are back under a Democratic administration, that role is expanding, again. I happen to be somebody who thinks that predictability is a very important thing for business. So, whether you are going to have an expansive view or a retracted view of the board’s role, and there are grounds to argue for both, it’s not that one side is patently wrong and the other is patently right. It’s really a matter of philosophy, on whatever the case may be, it is good for businesses to know what the expectations of them are. The National Labor Relations Board swings much more broadly than any other federal enforcement agency. That’s a tough thing for employers to cope with so this is really a problem for both sides of the aisle. I don’t think that anybody is conducting themselves, necessarily in the way that provides the most predictability for business. The best we can do here on the outside is to make sure that employers are educated and know that these risks are out there. I’m certainly talking about it a lot more because I am seeing and I was in practice, under the Obama administration, the Trump administration, and now under the Biden administration, I have never seen as much effort to enforce against the private sector, as I am seeing now. So, Biden has held true to his promise to be the most labor friendly president that many of us will see in our lifetimes. So, even though the Obama administration expressed an interest in pursuing these matters, we’re seeing the enforcement drive from the Biden administration that perhaps was not quite so present before.
Catherine Short 9:19
Okay, so it sounds like there’s a lot of reason to be concerned. And I know this from talking to a lot of our administrators, like hospital administrators, practice administrators, all kinds of CEOs and CFOs, etc., that they have a lot on their plates right now and so much to be concerned about. It feels probably for some, that this is just another thing that they need to be worried about, right? If you could give one piece of advice to businesses and if they can only do one thing, what should it be?
Lauren Russell 9:52
I would take a really careful look at handbooks. That is an area that almost every business I represent neglects because, it’s there and this other thing is an emergency and I’ve got to put out that fire. And to your point, everybody has a tremendous amount of work on their plates right now. This is the most difficult environment to operate and that I’ve ever seen. It is truly amazing that people are able to get up and soldier on every morning. That’s from the management side and from the labor side, everybody’s got a lot on their plate. If we could move the handbook to the top of your non-emergency stack, that’s what I would do. Handbooks should really get a thorough going over every couple of years anyway. If you haven’t taken a careful look at your handbook in the last two years, to update it and make sure that it’s compliant with your current labor and employment laws, that’s a great thing to do. And take a look at those things: workplace civility, social media, and make sure that you’re really focused on illegal behavior and not just that employee shouldn’t say things that make us unhappy. Any policy that’s designed to keep employees from saying embarrassing things in public is going to likely be a problem. We should really be focused on: do not engage in illegal behavior, if you are on Facebook with a picture of you and your favorite marijuana paraphernalia that’s something we can prohibit. We can prohibit harassment and discrimination and defamation. Defamation is illegal behavior. That is it’s a tort, it is unlawful. You can prohibit defamatory conduct. But when we’re talking about general civility and being nice and be courteous, that’s a tough thing to enforce.
Catherine Short 11:44
If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Lauren Russell, Council at Young Conaway Stargatt & Taylor, LLP, on the topic of a harassment free workplace versus the right to engage in concerted activity.
Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.
Okay, could you talk to us about the National Labor Relations Board or the NLRB’s current enforcement policies?
Lauren Russell 12:35
Yeah, I mean, as I said a few minutes ago, there’s really been a focus on expanding their role in the private sector non-unionized workforce. When we’re looking at that, the driving force behind this is the current general counsel for the board, Jennifer Abruzzo. She is a brilliant woman. There has been a sense at times that she may be a little bit more aggressive than even sometimes the unions are comfortable with. But she is the driving force behind these priorities, and they include a couple of things.
She certainly is very focused on lowering barriers to unionization in the workforce. And so she’s looking to bring back certain on administrative policies from the Obama era that either got stalled out or were challenged in court, including lowering thresholds to union organizing, and in a non-unionized workforce. And then also making it harder to oust a union, once it’s in. She is looking to reverse past decisions by the National Labor Relations Board under the Trump administration. It’s helpful to understand a little something about the composition of the board. The board consists of five individuals, five members who are appointed. Under a Democratic administration, it’s usually three Democrats, two Republicans, under a Republican administration, it’s usually three Republicans and two Democrats, and then the general counsel is a presidential appointee. So, she was appointed by Biden, after he terminated her predecessor, who was a Trump appointee who refused to step down. So, there’s a bit of a kerfuffle there. The board changes its orientation very promptly upon a change in administration. You usually have to wait for some for one of the members to come to the end of their tenure, but then you have a very rapid switch, and so the board can completely flip from a Democratic and Republican administration. With that in mind, with that background, she’s looking to reverse precedent on a couple of things including when an employee is engaged in Protected Concerted Activity. She wants to reverse some case law that held that an employee is not engaged in protected activity when other employees don’t join in complaint or offended by the complaint. This is really designed to protect individuals who are expressing unpopular opinions. She wants to reverse past case law that gave employers discretion, she wants to limit employers’ ability to impose confidentiality in the course of internal investigations and in settlement agreement and challenge that, because it impacts an employee’s freedom to speak about the terms and conditions of employment.
Then she really wants to focus on limiting what an employer can do in a handbook. So, limiting a handbook policies that in any way, on their face, would make a cautious employee less likely to engage in their section seven rights. By that I mean to talk to other coworkers about terms and conditions of employment. When we’re looking at those kinds of policies, we’re looking at confidentiality, non-disparagement, social media, media communications, civility, and respectful workplace policies, offensive language prohibitions, and no cameras at work rules. All of those things, when they are applied in just the right way can make a cautious employee and that’s the standard she wants. Not an average employee. Usually in the law, we look at a reasonable person, right? That is an imaginary reasonable person is who we look at when we decide what the legal standard is. She says, no, I don’t want you to think about a reasonable person. I want you to think about a cautious employee. That is our standard. If they feel like an employer policy, inhibits their ability to speak freely to coworkers about terms and conditions of employment her position is that handbook policy gotta go
Catherine Short 17:20
Can you expand a little bit more on what her definition of what a cautious employee might be?
Lauren Russell 17:25
Well, it’s certainly not a defined concept. But I’ll tell you a cautious employee is one that complains to the board.
Catherine Short 17:31
In my mind, a cautious employee would be somebody who’s super careful, but who would not complain, who would be really careful about what they say. Cautious to me is caution.
Lauren Russell 17:42
Keep in mind that the National Labor Relations Board, like every other federal agency has very limited resources. So as a general rule, they do not have a practice of auditing, non-unionized workplaces. The board would not knock on the door at First Healthcare Compliance and say “we’d like to see your employee handbook, please show it to us”. Similarly, they would not do that at my firm. So what has to happen is an employee has to go to the board and say, I think this, this handbook is discouraging. It’s somebody who’s not necessarily complaining internally and that is very frustrating to employers as well. How was I supposed to know you felt discouraged? I didn’t intend to discourage you. You never told me you felt discouraged. Instead, you went off and filed a charge. That’s the cautious employee.
Catherine Short 18:38
Okay. All right. Interesting. Okay, let’s talk about social media for a second. Can you explain a little bit about what is expected concerning social media at this time?
Lauren Russell 18:52
Social media is my nightmare.
Catherine Short 18:56
And for a lot of employers. You have some employees who don’t engage in social media whatsoever, and then some employees who are extremely engaged. So what’s the role right now?
Lauren Russell 19:07
Yeah. Certainly, you can expect employees to be lawful online. That is a perfectly reasonable expectation to say. Believe it or not, I’ve got clients who have to have a policy that says, Please do not post photos of unlawful activity. You should not have open containers of alcohol in a vehicle. You should not post photos of your marijuana paraphernalia. You should not post racist diatribes on Facebook. Depending on your workforce that may or may not be something you need to say. All of that behavior is something that you can expressly prohibit. What you can’t prohibit and what a lot of social media policy say is that you may not post anything online that criticizes the company or its customers client, patients etc. Now, in the healthcare context, we have some additional overlays. Most employees have HIPAA obligations, and you can absolutely say you may not post anything online that violates your duty of confidentiality under HIPAA. You cannot say Mrs. Smith was in today and she was a raging you-know-what, and I hate her and I hope she never comes back to this practice.
Catherine Short 20:26
I know perhaps some people like to go on diatribes on social media, personally, as themselves not as representative of their company and say, all kinds of things.
Lauren Russell 20:38
When we’re talking about where the board wants to flex its authority, it comes in two places. One is the policy itself. If you have no social media policy, then then there’s nothing for them to look at. The other is, when we apply the policy, are we adversely impacting Protected Concerted Activity. Going on Facebook and saying every member of the Green Party is an unmitigated idiot is not protected concerted activity, it’s not about the workplace, it’s about the world out there. So you can absolutely and if a patient or a coworker comes in and says, your receptionist on Facebook called me an idiot, and I don’t want to deal with them anymore, if you don’t fire them, I’m going to leave the practice. That’s okay. You can fire the employee, because their social media conduct has adversely impacted the business and they have tied themselves to the business in some way. Very frequently this happens because somebody tagged themselves to your company’s Facebook page, or they have a picture of themselves wearing a First Healthcare Compliance T shirt, and so they associate themselves online, and then somebody figures it out. They say, so and so was saying offensive things on the internet, I see they’re wearing their shirt, I went to your website and see that they work for you and I think you should know about that. I have had those cases and that person’s gone. They were the ones who tied themselves to your company on the internet and that’s their fault.
When we’re talking about actual concerted activity or the impact on the workplace, and this does happen, somebody posts on the internet, for example, something inflammatory about undocumented immigrants that borders on racist right on or says every member of the Republican Party is a racist, you can’t be Republican and not be racist, and you have a Republican employee who says, this is outrageous. This person is calling me racist on the internet, I’m deeply offended, I don’t feel comfortable working with them anymore. Again, that behavior is not protected, concerted activity. They’re talking about Republicans out in the world, they’re not saying the Republicans I work with are racists, they’re saying all of them in their totality. That is again, behavior that creates a hostile environment, it makes people deeply uncomfortable, and you can discipline that behavior, or you can terminate the employee. In the same way if somebody was posting racist or sexist messages, so instead of calling somebody else racist, I am posting deeply inappropriate things on the internet, jokes and memes about women should be barefoot and, in the kitchen, right? Because a female coworker comes in and says, I am deeply offended. I am a working woman and a mother, and this person thinks my only worth is to be at home. Like that’s, that’s offensive to me. Okay, we can discipline that behavior.
Where the board gets interested, is when an employee goes on social media and criticizes the employer. If I go in on social media and say, my manager at XYZ company is racist, he will not denounce police violence in the country. Or he is paying female employees less well than male employees. That is Protected Concerted Activity. I have gone into a public environment and on behalf of myself and other workers have criticized management and said, this is an illegal environment, or there were unlawful behaviors happening here. I don’t know a single manager that I’ve ever met, who wouldn’t be deeply offended and upset that somebody took that to Facebook instead of talking to them first. And so the gut reaction is always fire them, discipline them. They took internal business to Facebook, they never talked to me. I had no chance to deal with this and now they’re defaming us on social media that’s Protected Concerted Activity and that is a real risk to the business if you discipline.
Catherine Short 24:47
So I have a question about employee expectations and labor rights perhaps do they extend to part time contract employees and also interns?
Lauren Russell 24:57
They apply to part time employees. Yes. Contractors? No. When you have independent contractors who are regularly working on your site like temporary staffers, the answer is often Yes because there’s a joint employment relationship. Interns, it depends. But generally if they’re paid interns like a summer intern, yes, they’re going to be covered. If it’s a volunteer, like at a hospital, you often have individuals who come in to read to sick children, or they will sit with the elderly patients. Those are not employees of any stripe, they’re volunteers. And even if it’s sort of a summer internship candy striper situation, it’s really more on the nature of volunteerism, and not within the scope of the board’s authority.
Catherine Short 25:47
Okay, well, I think we’re just about out of time. Did you have any other words of advice or things that you wanted to discuss that we didn’t talk about? Perhaps,
Lauren Russell 25:59
No solid guidance, but I will tell you anecdotally that I have watched businesses unionized, and I have watched them vote out unions. The key distinction is a level of basic respect between management and labor. You know, there’s a lot of research out there on healthy marriages. The marriages that succeed are ones where there’s mutual respect between spouses. If there’s a lack of respect, if spouses roll their eyes at each other, that’s a sure sign that one day they’re going to be divorced. That same guidance applies to labor management relations. You don’t have to agree on everything, and they oftentimes don’t. But when you can have dignity and respectful communications, that is a workforce where you are much less likely to see unionizing efforts generally, and specifically where you’re going to see even in non-unionized workforces, where you’re going to see charges brought before the board. When employees feel respected, and like their partners, you are always going to be in better stead. It’s a hard thing to do, but cultivating respect, making sure that even your low-level employees feel like they are a critical part of your success, and that they help you to have a voice in how decisions are made. It’s hard to do, but that makes a huge difference. Okay,
Catherine Short 27:33
Well, I want to just thank you so much. Lauren, did you have any other words of advice that you wanted to leave us with today?
Lauren Russell 27:39
Tolerance, kindness. I will tell you that you run into union problems when both sides of the equation management and employees are not able to take a deep breath and say, hey, I really need you to hear me but I could have said that nicer. I keep seeing these news headlines about how mean people are right now, that people are just hit their limits and they are mean. I hear that anecdotally from clients too. I think we’ve got to take a deep breath and be a little less mean. When there was a sense of respect and dignity between labor and management you really avoid the vast majority of these issues. So kindness.
Catherine Short 28:22
Great. That’s always wonderful advice. I wanted to thank you so much for being here today.
Lauren Russell 28:27
Very happy to be here. Thank you for the opportunity.
Catherine Short 28:31
And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.
1st Talk Compliance features guest Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “A Business Associate Agreement? Tell Me More!” Rachel joins our host Catherine Short to discuss how Business Associate Agreements (BAA) are not new; however, some individuals are new to healthcare and others never understood what a BAA is exactly. A BAA is a contract that fundamentally gives assurances that the parties are complying with the Security Rule and Privacy Rule, setting parameters in the event of a reportable security incident or a breach, and states how the sensitive data will be returned and destroyed at the end of the relationship. Some of the items in a BAA are required, while others are optional but common. This presentation not only seeks to dispel myths about why certain language is prevalent in nearly all BAAs, but also provides insight into other provisions, and items for consideration, in light of the 21st Century Cures Act.
Catherine Short: 0:01
Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.
On today’s episode, we are speaking with Rachel V Rose, JD MBA principal with Rachel V. Rose Attorney at Law PLLC Houston, Texas on the topic of appreciating the content of a business associate agreement. Business Associate Agreements a BAA is a contract that fundamentally gives assurances that the parties are complying with the Security Rule and Privacy Rule, setting parameters in the event of a reportable security incident or a breach and states held the sensitive data will be returned and destroyed at the end of the relationship. Some of the items in the BAA are required, while others are optional, but common. This presentation not only seeks to dispel myths about why certain language is prevalent in nearly all BAAs, but also provides insight into other provisions and items for consideration in light of the 21st Century Cures Act.
Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Wendy Mulkey, Business Development Marketing at Emerald Coast Neurology. Wendy says “I am a lifelong learner. Working at Emerald Coast Neurology has allowed me to continue to grow and learn. I feel my contributions are making a positive impact for the staff and patients. At the end of the day, I just want to make a difference. I feel like I’m accomplishing that at Emerald Coast.” Congratulations, Wendy, our team is honored to have the privilege of working with you.
Catherine Short
So hello, Rachel, thank you so much for joining me today on First Talk Compliance to speak about BAAs.
Rachel V Rose
Thank you Catherine. It’s always my pleasure to collaborate with you and First Healthcare Compliance in order to hopefully provide meaningful content to the listeners.
Catherine Short
Thank you. So how about some background? First, can you give us an overview of exactly what a BAA or Business Associate Agreement is and who it involves?
Rachel V Rose
Absolutely. Not surprisingly, that is a very detailed question. As your introduction mentioned, a business associate agreement, which is referred to in 45 CFR 160.504(e) as a business associate contract is just that. It’s an agreement between two parties to do three primary things. First, ensure that both parties are utilizing the appropriate technical, administrative and physical safeguards in order to ensure that the confidentiality, integrity and availability of the protected health information remains intact. Additionally, it relates to the Privacy Rule, the entire security role and the breach notification rules being adhered to. The second element that always jumps out at me is the notification to the other party and then potentially, to HHS, patients and the media in breaches of 500 or more individuals, and making sure that the parties designate the timeline that party A, the typically the party the breach occurred on, tells party B about this and then what transpires after that. The last main requirement or part of a business associate agreement is what to do when the relationship between the parties terminates. Now that might seem simple. Oh, I just need to either return and or destroy the data in a manner that complies with the HIPAA Security Rule and preferably with NIST. That’s part of it. But as we all know, there are situations where we can’t just return or destroy information. Some of those may be obligations of a legal hold or a government investigation or a lawsuit that might be in place. Under federal HIPAA, it applies to covered entities, which are healthcare providers, healthcare claims clearing houses and insurance companies and their business associates, and then a subcontractor of that business associate.
Catherine Short
Okay. What is a primary purpose or purposes of a BAA?
Rachel V Rose
So as I mentioned, there are typically three main areas. First, you need to define who the parties are at the very top, and which one assumes what role whether it’s a covered entity and business associate or business associate and subcontractor. All of that is exceptionally important. So just something to be conscientious about there. Then you delve into the three overarching areas or purposes behind the Business Associate Agreement. A) To ascertain that both parties each had been given reasonable assurances that the technical, administrative and Physical Safeguards as well as the privacy rule, security rule and Breach Notification Rule compliance and requirements are being met. Another item that relates to that now is the 21st Century Cures Act and the ability to give patients their medical records in formats such as smartphone apps that weren’t necessarily available before. Along with that related to information blocking are situations where a provider or a business associate may say, the general rule is that we have to provide this but this is not an app that is secure, or that we’re familiar with, and for the safety of the entire IT infrastructure, we’re not going to provide that. So it’s important now to reference state laws and other relevant laws such as a 21st Century Cures Act. The next main area, it has to do with notification to the other party of a reportable cybersecurity incident, typically known as a breach in accordance with the Breach Notification Rule. There are really two steps to that. First, you want to have a timeframe set out between the parties as to when party A if they’re the breaching party has to notify party B that there has been a breach. That’s important because their IT department needs to take appropriate steps in order to safeguard certain things or go to plan B or to go to backups. So it’s really mutual in nature along those lines. The second part of a reportable breach would then be under the Breach Notification Rule, to report to HHS, to report to the patients, and to report to the media if the breach itself affects 500 individuals or more.
Catherine Short
Okay, great. Is there any party or person or entity that a facility works with that it’s perhaps safe not to have a BAA with?
Rachel V Rose
So that’s a great question, Catherine. First, I will go to what’s known as the conduit exception. That’s something that was highlighted in the Final Omnibus Rule, which is published at 78 Federal Register 5566 on January 25, of 2013. The conduit exception expressly states that there are certain entities and they are very limited, but they are for example, your internet provider would be one, your UPS carrier, whether it’s the United States Postal Service, DHL, UPS, FedEx any one of those types of carriers, so long as none of their entities did anything other than deliver the package, right? They are just transporting data from point A to point B, and that’s it.
So having said that, and by way of contrast, I think it’s important to note that data centers are considered Business Associates and do not fall within that exception. Another entity that is considered a Business Associate is a cloud computing provider. So whether you utilize AWS or Microsoft Azure, for example, those are still business associates, and that’s why when you go onto their website, you will see their Business Associate Agreements, as well as some commentary on HIPAA and other data privacy laws. Another one that is often a question, so to speak, is is a lawyer a business associate? The answer there is it depends. Even in my own practice, there are times when I contract with a covered entity. If I’m just reviewing physician contracts, I’m not delving into protected health information, I’m not looking at financials, I’m not looking at anything that would tie any individual back to the past, present or future diagnosis, treatment or financial information associated with any of those items. However, the minute they asked me to look at something that contains PHI, that is absolutely a covered entity, business associate situation, which would require a Business Associate Agreement.
Catherine Short
Okay, so example, the custodial company perhaps would not need a business associate, but medical waste hauling would.
Rachel V Rose
The cleaning entities are very interesting, because if you think about it, they have access to everything, and typically when no one’s there to supervise them. So hopefully, the organization has all safeguards in place that when everyone goes home, there is no information that’s left on a computer or computers still not on they don’t have their past codes in their top drawer on a sticky note, right? And they have those bins that are locked, so that the information goes to Iron Mountain or another vendor to be shredded, and people can’t access that. I think there’s a distinction too between whether, for example, in a hospital, if the Environmental Services team is hired by the hospital as individual employees, then they are part of the workforce and they should undergo HIPAA training as part of the workforce, but they’re not an independent contractor. Does that make sense?
Catherine Short
Right. Yes, I was speaking of perhaps like an outside contract cleaning company or environmental company as opposed to employees of the hospital
Rachel V Rose
No, I think Catherine on that one there’s just so much potential liability there, they could let someone in the back door, right, because they have access and that’s something that I do advise people, maybe even to have a modified agreement, if not with all the bells and whistles, but just to ensure that they understand that if they steal something or if there’s an issue, they need to know what to do and what their potential liability is.
Catherine Short:
So if you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “A Business Associate Agreement? Tell Me More!” Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also find us on all other social media.
Okay, can you explain reasonable assurances in relation to business associate agreements and maybe tell us a little bit more what reasonable assurances are?
Rachel V Rose
Sure, absolutely. Basically, it comes up in a lot of different areas of law. Reasonable assurances in HIPAA would be the following because the first part of the Business Associate Agreement should have both parties, giving assurances that they meet the technical, administrative and physical safeguards in order to ensure the confidentiality, integrity and availability of the data. What would give someone peace of mind is the way I like to think of it and also give them something legally, that they could say, you know what, we know that we do not have a right to go in and inspect everything. So what I do is I have my clients get a signature on an ad test station. The purpose behind it, it’s very short, it’s about half a page in length and all it says is that these reasonable assurances are being provided in order to give peace of mind that the party is adhering to the requirements of HIPAA in the High Tech Act. If people can answer these five questions in earnest, you should walk away with a good feeling that they’re doing everything that needs to be done. The first question is, does the party undergo an annual risk analysis that is comprehensive? Second, do they train their workforce annually? Third is PHI insensitive PII encrypted both at rest and in transit? Fourth, are Business Associate Agreements in place, and are they recorded? And lastly, are policies and procedures at least reviewed annually, and are they comprehensive? So with that, that is A) how I define and think of a reasonable assurance? And secondly, how I advise my clients to protect themselves and then lastly, the types of reasonable assurances are those five that I hone in on.
Catherine Short
Okay, great. What are indemnification provisions and what language should be used in indemnification provisions?
Rachel V Rose 17:30
That’s a loaded question. I’m going to point kind of in jest, but kind of not in jest, and suggest that people listen to our webinar on indemnification. But in all seriousness, it’s typically thought of as a contractual obligation of one party to compensate the loss incurred to the other party, due to certain acts of the indemnitor or any other party. The duty to indemnify is usually but not always, coexisting with the contractual duty to hold harmless or safe, harmless. So let’s step back for a moment. First, before you draft an indemnification provision, you want to make sure that you have an appreciation of a variety of different state laws, whether it is derived from common law, or whether it is like California set forth in a statute. Typically, the way a lot of indemnification provisions are written are to indemnify defend and hold harmless. If you don’t have that exact language, depending on the jurisdiction that you’re in, you may or may not have to defend someone and pay for those costs. It’s so specific to the facts and circumstances in general that I’m trepidatious just to throw out any language surrounding that, but I will say that it’s important to appreciate the significance of an indemnification provision. Some indemnification provisions I read and I’m like, Oh, my gosh, I would not advise anyone to sign that it’s because it’s so one sided, that only one party is held harmless. And in the event of a breach, regardless of whether or not for example, a Business Associate cause the breach some of these indemnification provisions, read that the Business Associate is responsible for all of the costs. So that should be one of the provisions that any person reads very, very carefully because it could A) contradict with your other contracts that you have in place, B) you can be shouldering all of the liability, even if you’re not responsible for the breach or the bad act. So when I write them, I typically make them mutual that if one’s being indemnified, the other one’s going to indemnify if they’re at fault. So it’s mutual defend is the key term that I discuss with the party. And typically, the party will go back to the other entity if they are in a negotiation. and oftentimes, they’ll say, we’ll just agree to be responsible for our own attorney’s fees on this. So that’s what will happen there. And then the last part of that, that something I’ve been doing for a few years now is to really carve out and there there are two schools of thought. When I carve out specific indemnification provisions related to a breach, it’s the breaching party that has the obligation to pay for the notification to government entities, to the media and to the individual patients. But that’s where the liability end so there’s no payment of attorneys fees, there’s no payment of ransomware. There’s no paying for a deductible on an insurance policy, or anything like that. What my clients and actually when I’ve been on the phone with opposing parties as well, what they’ve said is that we like this, because we know upfront what we’re responsible for, and it’s limited to this, and it’s balanced for both of us. So there’s no cookie cutter way to draft an indemnification provision, you just have to literally take it word by word with the parties that you’re dealing with.
Catherine Short
Okay, I’ve got another question that has some defining in it, and then some explanation. What is a material breach, for those that don’t know? And can you tell us what MSA stands for? And then how can a material breach of the MSA affect the MSA or other contracts?
Rachel V Rose
MSA is typically your Master Service Agreement. That’s typically what I have seen, but obviously, it’s your main contract. If you are contracting with an IT provider, typically your MSA is your main contract. If you think about how a breach is defined in HIPAA section 164.402. Basically, it’s “the acquisition, access use or disclosure of protected health information in a manner that is not permitted, which compromises the security or privacy of the protected health information.” So basically, when you think of what a material breach is, one can really think of that, as was the incident one that triggered the following A) requires us to do a root cause analysis to determine whether or not it’s a reportable breach. And then if it is a reportable breach, then how does that impact the underlying contracts? So it’s a little misleading Catherine and this is a great question for this reason. If we’re thinking about ransomware, or what we think about in cybersecurity, a breach means that definition that I just read in 164.402, but that has to do with a breach of the information. What flows from that breach of the information can be a material breach of either the Business Associate Agreement and or the Master Service Agreement, depending on how things are worded.
Catherine Short
Okay, so what if an entity doesn’t fit into one of the HIPAA buckets of covered entities, business associates and or subcontractors. Do they still have potential liability?
Rachel V Rose
There is potential liability. The three ways that potential liability may arise are A) under state law. For example, I mentioned Texas that has the definition of a covered entity, which is any person who creates, receives, maintains, or transmits PHI. So while that does include the three federal HIPAA buckets, it actually goes beyond that. That’s one way. Another way is through the Federal Trade Commission. I know in the Related webinar, I delved into that in some detail but basically, the Federal Trade Commission has its own Breach Notification Rule that says if you’re not obligated under HIPAA, you may still have an obligation to report a breach of PHI to consumers from their pursuant to the Federal Trade Commission Act Title Five, courts have held that the Federal Trade Commission does in fact have enforcement authority in that situation. So that’s where you could get another government enforcement action.
The last way would be through either a class action lawsuit or a common law negligence lawsuit for a HIPAA breach. So those are really the three ways that someone can be held liable.
Catherine Short
Okay. Is a BAA a binding contract?
Rachel V Rose
It is a binding contract and it is binding for a multitude of reasons, but it is per the regulations considered a contract and if you are creating, receiving, maintaining or transmitting protected health information between the covered entity, business associate and sub-contractor, you do have an obligation to enter into a contract.
Catherine Short
Okay. Well, thank you so much, Rachel. I think we’re just about out of time. Did you have any other any other thoughts that you wanted to share with us?
Rachel V Rose
Just be aware that BAAs are not cookie cutter. However, there are certain terms and certain provisions, which you’ll see over and over again and that’s because they’re required by the statute and then recommended by HHS on their website.
Catherine Short
I really wanted to thank you, Rachel, for coming on to 1st Talk Compliance on our show today and discussing this important subject. So, thank you so much.
Rachel V Rose
You’re welcome, Catherine, and as always, thank you for having me.
Catherine Short 26:21
Me too. Thank you so much and thanks to our audience as well for tuning in today to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and then your voice to the conversation on Twitter @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.
1st Talk Compliance features guest Trey Scott, Coordinating Attorney at Kennedy, Attorneys & Counselors at Law, on the topic of “Have a Breach? Reporting Requirements with the OCR.”Trey joins our host, Catherine Short to discuss the reporting requirements for a data breach of a healthcare provider, the definition of a breach, different timelines for reporting breaches, as well as how to complete a breach reporting form from the Office of Civil Rights.
Catherine Short: 0:01
Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.
On today’s episode, we are speaking with Trey Scott, Coordinating Attorney at Kennedy Attorneys and Counselors at Law on the topic of “Have a breach? Reporting requirements with the OCR.” We will discuss the reporting requirements for a data breach of a health care provider, learn about the definition of a breach, understand the different timelines for reporting breaches, as well as how to complete a breach reporting form from the Office of Civil Rights.
Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition.For this episode, we’re spotlighting Super Ninja, Gail Little-Osberg, Practice Manager at Attachment and Trauma Center of Nebraska. Gail says what she enjoys most about working there is the variety of taking care of a practice, working with a great team of therapists and of course, staying up to date on HIPAA and compliance. Congratulations Gail, our team is honored to have the privilege of working with you.
So, thank you, Trey, for joining me on 1st Talk Compliance. It’s a pleasure to have you on.
Trey Scott 2:10
Yes, thank you glad to be here. Glad to talk compliance to your listeners.
Catherine Short 2:16
Great. Do you think you could give us a little bit of an overview of what we’re going to be talking about and discussing on today’s program.
Trey Scott 2:28
So what we’re talking about here is we’re talking about reporting to the OCR (Office of Civil Rights) whenever there is a breach. Whenever you have a breach, regulations require you to do certain things. If a breach involves more than 500 individuals, you need to report that to the Office of Civil Rights, within 60 days of date of discovery of the breach. You also have certain things you need to do as far as notification of individuals, notification to the media but that’s that’s not really what I want to talk about here. If you have a breach that is less than 500 individuals or less, it ends up being 60 days from the beginning of the new year. If you have a breach that occurs in September, you have until 60 days from the beginning of the new year to report to the secretary now you’re probably wondering, well, this notification, I need to notify the secretary. How do I go about doing that? Well, the Secretary has made it really easy to report. What you do is you go to the HHS Office of Civil Rights. And they have a really, really nice web portal that allows you to report a breach. It asks you a bunch of questions that you answer as you go through. A lot of them are you a covered entity reporting a breach on behalf of yourself? Are you a business associate that has experienced a breach and you are reporting on behalf of a covered entity? Or are you a covered entity reporting on behalf of a business associate who has had a breach? You select those and you go through, you enter contact information for whatever the three options you selected. Then it will start asking you about the breach. It’ll ask you what safeguards you had in place, what information was breached, when the breach occurred, what the discovery date was.
The discovery date is when you found out about the breach because there are instances where a breach might occur due to a hack early in the year, and you just don’t discover it for whatever reason until the middle of the year. Well, the date you discovered the breach, that’s the discovery date and it’s when you knew or should have known about the breach. Then the portal questions will ask about the details of the breach, what happened, whether it was an inappropriate disposal of medical records, for example, whether it was the loss of a laptop, whether it was hacked, and then it will ask more details about it and you’ll be able to provide that underneath. Then it will ask what you’ve done following the breach. Have you notified the individuals? Did you have to notify the media? What other additional training have you done? Things of that nature. It’ll go through, and it will ask all of those questions. Finally, the breach portal will ask for an attestation to essentially say that everything you’ve reported here is accurate to the best of your knowledge, you’re not lying about anything, you’re not lying about the breach date, you’re not lying about notifying individuals, you’re not lying about when the discovery date occurred to give yourself more time.
Based on information provided, if it’s larger than 500 individuals, then the Secretary will take that information and post it to their website with the list of offenders who have had large breaches, if you go there, you’ll see breaches in the million, because for example, a Florida Health Plan got hacked and I think you will see there 3.5 million or 35 million individuals were affected. So if it’s over 500, you end up on that list, unfortunately. That’s really the process of reporting to the secretary in a nutshell.
Catherine Short 7:39
Okay, so we had talked about Civil Monetary Penalties existing. What about criminal penalties? I know you had talked about willful neglect, or you mentioned it, so I assumed that would go under criminal penalties. Could you explain that maybe a little bit more?
Trey Scott 7:56
Yes, I can. So whenever the Office of Civil Rights receive all of these breach notifications, if they rise to a level, then the Office of Civil Rights will actually conduct their own investigation. And through the process of their own investigation, if they do, in fact determine willful neglect or neglect that have not been corrected, there is the possibility that they can refer these breaches to the Department of Justice, and they can in fact, pursue criminal actions against the healthcare provider. So yes, it is very possible that a breach could result in criminal penalties if the investigation by OCR shows that.
Catherine Short 8:55
Okay, all right. How about an addendum? How long do you have to file an addendum if that’s what you choose?
Trey Scott 9:04
I don’t believe there is actually a deadline for when an addendum runs out. What you really need to do is ultimately determine if it’s still part of the same breach that you have already reported, or if it is, in fact, a new breach. So that’s really the key with an addendum. Most of the time, an addendum is used for things like including additional training that your team may have undergone, adding more patients to the total number, if it gets it from the below 500 to over 500 mark. That would be what an addendum is used for. If it was a hacked initially, and you reported that, but you also end up discovering that somehow your email was also hacked as part of that. That’s really what an addendum is for. There really isn’t a timeframe for how long you have to add to an addendum, but you just need to make sure it is still part of the same initial breach and isn’t a new breach.
Catherine Short 10:29
Could you expand on that a little bit? At what point would you consider it a new breach and not an addendum? Where’s that line?
Trey Scott 10:38
The line to me is, if it involves the same incident, if it is a situation where, for example, going back to the email and the hack, if your team can determine that that was all part of one incident, then you can add it to an addendum. But if you have a situation where, for example, a hack occurred on March 3, and you didn’t discover it until April 3, but then during your investigation, related to the March 3 hack, you find out there was another hack in between, that would be a separate incident. That wouldn’t be part of the same breach even though you may have discovered it around about the same time as the first breach. That would be completely separate and you would need to do a new breach notification and not just an addendum.
Catherine Short: 11:41
So if you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Trey Scott, Coordinating Attorney at Kennedy Attorneys and Counselors at Law on the topic of “Have a breach? Reporting requirements with the OCR.” Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also find us on all other social media.
How about recommendations to avoiding a breach? What do you recommend?
Trey Scott 12:30
Most breaches occur due to poorly trained employees and employee carelessness. So my recommendation to avoid a breach is to make sure that your employees are trained on record security, are trained on not clicking email links that you’ve received, are trained on making sure to not save passwords and EHRs, not save passwords for laptops, make sure you have procedures in place to routinely change access codes for EMRs and building codes. Doing that and making sure it limits the risk of the employee inadvertently disclosing or inadvertently allowing unauthorized access. That’s my main recommendation. Make sure your employees are as trained as possible, because I know hacks, sounds scary and everything and they’re the ones that get the news, whether it’s for example, hacking, a large health plan or whether it’s hacking, even target has been hacked in the past. Those end up getting news because of how many people are affected but the reality is, hacking is more rare whenever it comes to the breaches, than you would necessarily think. A lot of the breaches that we have dealt with involve carelessness, inadvertent disclosures by employees. So make sure your employees are trained, make sure you have a good compliance program in place and that should limit a lot of the risk.
Catherine Short 14:45
Right? And even with training, you have to have it as second nature. You get these phishing, either phone calls or emails sometimes, first thing in the morning.
Trey Scott 14:57
Right. Example, we had is a client received a document from an email address that they thought was a patient of theirs. If you looked at the actual email address, it was nowhere near anything close to what the patient’s email address was but if you looked at the email display name, it was the patient’s name. The provider clicked on the document and by doing that, they allowed a virus and to get into their system. That ended up being a breach that was completely avoidable by just taking a few seconds to realize, to check the actual email address against what they have on file. It does take a additional step, but making sure your staff is trained to do things like that, or making sure yourself, you’re trained to take those additional steps can prevent a can prevent a breach.
Catherine Short 16:11
Right? It’s funny the other day, I had a phone call, and I often screen my calls, you get so many commercial calls, etc. But it said the name of a famous bank calling me and even though I didn’t have a credit card with them, I thought hmm, I wonder why they’re calling me. I answered the phone and what was funny was, so this was the first odd thing. They said, we’re calling from your cell phone company from the fraud department, and I thought, well, that’s odd. I wonder why it says the name of this famous bank on the name coming in from the call. They said, well, we’re calling from such and such phone from your phone company, we’re going to have to shut your phone down, etc. because there’s been some kind of breach or whatever. I was thinking, well, that’s weird. I go into my account fairly often and I can see what’s going on. In fact, I can go into my account right now and look. I said, Well, why does it say bank of such and such on the phone call? And they said, Well, we’re calling from the fraud department. And I said, Well, really? I said, Why doesn’t it say such and such phone company? And I kept asking them that and then they hung up the phone. So obviously, this was some kind of fraud kind of phishing type of thing. I’m sure they wanted me to give them account information, all this kind of stuff.
Trey Scott 17:35
Right!
Catherine Short 17:36
It was really bewildering, because when the phone call came in, it looked like some kind of legitimate type of call. Only two things that were really odd were, number one, I don’t have an account or a credit card at this bank, and why would this bank be associated with this phone company? Those two things were just really odd, but they’re very widely used.
Trey Scott 18:01
Right. That’s why it’s important to make sure you’re checking things like that. Essentially, your first line of defense against breaches are your employees. You need to make sure they are aware of these attempts, like you just described and make sure they’re extra diligent.
Catherine Short 18:27
Yeah. And that their ears are perked, that they they’re trained and ready for these kinds of phishing type of things. I have a question here. Now people being who they are and trying to avoid things, but do we really need to report all breaches, even if it’s only one patient?
Trey Scott 18:45
Our recommendation is yes. And the reason why is because the regulations require that anytime there is a breach you obviously need to notify the patient that there was in fact, a breach. So because you’re going through the process of notifying the patient that their information was breached, even if it’s one patient, you need to go ahead and take the next step of notifying the secretary as well, because the worst thing that could happen is that the patient find out that their information was breached, and then the patient reports that their information has been breached, and they want to do something about it to the Office of Civil Rights, and you haven’t reported. That could lead to an investigation by OCR and once they start digging around, they may find more things and it can potentially end up a situation where they ultimately determine what you did was willful neglect, and you can end up with a large penalty. You don’t want to end up doing that. My recommendation is to report everything. I think that is what the rule of notification to the Secretary is saying, because it’s saying, you shall report to the Secretary and isn’t saying that you could, it isn’t saying that if you want to, and isn’t saying that it’s if it’s less than 10 patients, you don’t have to, it’s saying that if a breach occurs, you shall, which means must. I would recommend to all your listeners, if they don’t have one, obviously, make sure you have a compliance program in place because a good compliance program has prevented a lot of our clients from facing those penalties by the Office of Civil Rights. If you have a great program in place that you’re actually using, because it’s almost worse to have a compliance program in place and not use it, than it is to just not even have one. Make sure you have a good compliance program in place and make sure you’re actually following it and using it. If you do have a breach, that will really limit potential penalties that you’re going to be facing,
Catherine Short 21:21
If we report a breach are there any financial penalties we might face?
Trey Scott 21:26
Yes, yeah, thank you. There are tiers. Tier one, that’s where it was a lack of knowledge, it was not really anything that was too egregious of a breach, you could face a fine of $100 to $50,000 per incident. If you had reasonable cause to know that the breach was possible to occur, then you can face a fine of $1,000 to $50,000 per event. Then there is willful neglect. That’s tier three, that is when you just straight up don’t have any procedures in place, you have no compliance program, you have nothing in place, then that can be a fine of $10,000 to $50,000 per event. The last category is neglect. This is not having a compliance program in place and then you end up having a breach and you still don’t have a compliance program in place after the breach, then that is just straight up neglect, that is not corrected. That’s category four, and that is $50,000 per violation. These numbers are actually adjusted for inflation. I don’t know what the current totals are, but they are adjusted for inflation.
Catherine Short 23:01
Okay, how about this? In your opinion, what is the main cause of a data breach? Is it hackers, ransomware or something else? What’s your opinion on that?
Trey Scott 23:12
Employees are the main cause of data breaches, whether it’s loss of laptops, whether it’s of theft of laptops, leaving it in a car while you go eat at a restaurant, and someone breaks in and steals it, cell phones, use of email to send medical records that aren’t encrypted, not changing access codes, having an easy password, clicking on links in email that they shouldn’t, which allows a hacker to get into your system. All of that it’s the main cause of breaches our employees. For example, going back to the improper disposal, the reason that breach occurred was because an employee, the office manager, in charge of paying for the storage facility, forgot to pay for the storage facility for several months, and they ended up throwing away all the records. The number one cause of avoidable HIPAA breaches are employees and and why training is so important and why you need a compliance program in place in your organization.
Catherine Short 24:31
Trey, I wanted to thank you again so much for being here today. So thank you.
Trey Scott 24:36
Yes, thank you. Thank you to all the attendees out there. I definitely appreciate getting to speak with you about OCR reporting. Hopefully this was beneficial. I know there were some areas we didn’t necessarily cover like notification to individuals and notifications to media, and just some other nuances about doing a risk assessment, things of that nature, but hopefully if you do have a breach this will allow you to report to OCR and if you want to get an attorney involved to help you report to OCR, feel free to give us a call.
Catherine Short 25:12
Very good. Thank you so much for being on our show today Trey and for helping out our listeners.
Trey Scott 25:19
Yes, thank you for having me. It’s always a pleasure. I’m glad I was able to talk about this and hopefully, it’s helpful to the listeners out there. And obviously, if you have any more questions that think up after listening to this, then I’m sure you can reach out to First Healthcare Compliance and they can get in touch with me or if you want to reach me directly, you can email me at trey@markkennedylaw.com. My direct line is 214-998-3825. So if you want to chat over the phone, because you have a really lengthy question, feel free to give me a call.
Catherine Short 26:15
Yeah, so thank you so much for being here. It was a true pleasure.
Trey Scott 26:18
Definitely can say the same!
Catherine Short 26:21
Me too. Thank you so much and thanks to our audience as well for tuning in today to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and then your voice to the conversation on Twitter @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.
Expert attorneys Sean McKenna, Lauren Nelson, and Vincent Aiello of Spencer Fane LLP will present this dynamic webinar. They will discuss the interplay between enforcement and liability proceedings with asset protection, explore how government and private litigation matters can impact healthcare companies, clinicians, and executives, and provide tips and preventative strategies to preserve income and assets prior to such action to ensure business continuity and succession planning.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents this very timely and fascinating subject for us. A former nurse was charged, criminally prosecuted, and in March 2022, convicted of gross neglect of an impaired adult and negligent homicide for a 2017 fatal drug error. The purpose is to inform participants of a myriad of items so that facilities can evaluate and implement appropriate safeguards, train nurses and other staff, and take corrective actions before an adverse patient outcome occurs. What happened here is preventable and nurses should not flee the profession, especially because of the compassion shown by the judge.
1st Talk Compliance features guest Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “How New Legislation Impacts Privacy.” The Dobbs Opinion repealed fifty years of precedent under Roe. The implications of the Opinion extend beyond women’s reproductive rights and impact the privacy rights of all Americans. The purpose of this episode is to explain the key aspects of the Dobbs Opinion related to privacy from both the Majority and the Dissent’s perspective, address the current legislative initiatives, HHS Guidance, and Executive Orders, as well as appreciate the role HIPAA plays in navigating Dobbs.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents this very timely subject for us.The Dobbs Opinion repealed fifty years of precedent under Roe. The implications of the Opinion extend beyond women’s reproductive rights and impact the privacy rights of all Americans. The purpose of this webinar is to explain the key aspects of the Dobbs Opinion related to privacy from both the Majority and the Dissent’s perspective, address the current legislative initiatives, HHS Guidance, and Executive Orders, as well as appreciate the role HIPAA plays in navigating Dobbs.
1st Talk Compliance features guest John Shegerian, Chairman and CEO of ERI, the largest cybersecurity-focused hardware destruction and electronic waste recycling company in the United States and co-author of the cybersecurity book, "The Insecurity of Everything" on the topic of “The Insecurity of Everything: The Vital Importance of Hardware Data Security.” He will share some of the latest information about the very real problem of hardware hacking in the world of healthcare and beyond and how that issue became even more serious during the pandemic, with so many people working from home. He will also be explaining critical information for health-related businesses to help them keep their private data – and the data of their patients and customers – protected!
Lauren E.M. Russell, Counsel at Young Conaway Stargatt & Taylor, LLP leads this hot-topic webinar. The National Labor Relations Board under the Biden Administration has expressed a renewed interest in expanding its influence into non-unionized work forces. This includes reviewing and--in the right circumstances challenging--employers' use of workplace civility, confidentiality, and anti-harassment policies. Learn what you need to know to safely navigate the National Labor Relations Act while ensuring that your employees enjoy a safe and respectful work environment.
1st Talk Compliance features guest William J McBorrough, co-Founder and Chief Security Advisor at MCGlobalTech, a D.C.-based Information Security Consulting Firm on the topic of “Combatting Ransomware in Healthcare.” William joins our host, Catherine Short to examine how ransomware attacks have impacted thousands of organizations worldwide with the healthcare sector having been the most targeted. Join us in a discussion of the state of ransomware in the healthcare sector and best practices to prepare your organization from the inevitable attacks.
1st Talk Compliance features guest Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “HIPAA and Beyond: Documentation Retention & Legal Holds.” Rachel joins our host, Catherine Short to review a multitude of laws, including HIPAA, requires certain types of documents be kept for a certain period of time. How does document retention play out for public companies subject to SOX and what should companies do in the event of a legal hold or a preservation request? This presentation addresses laws that are relevant to healthcare industry participants, as well as compliance suggestions, and steps to take when either a legal hold or a preservation request arrives.
Raymond Ribble is the CEO and Founder at SPHER, Inc. a market-leading compliance analytics, cyber-security solution addressing: HIPAA compliance, State Privacy Laws, and ePHI security threats and our presenter for this webinar. Snooping and Insider threats are exactly why user monitoring and ePHI access strategies are vital to the security of sensitive patient information and data protection. While it is an unsettling thought, not all cybersecurity incidents are traced from employee negligence. With so much attention and money surrounding cybersecurity in the healthcare industry, malicious employees may decide to purposefully disclose patient information. Since employees and contractors may have knowledge of your network setup, vulnerabilities, and access codes, snooping employees with malicious intent hold the key to exposing your organization to a series of unwanted risks and threats.
1st Talk Compliance features guest Kathleen W. McNicholas, MD, JD, CHC, CCEP, Consultant and Patient Advocate with Medical Legal Patient Advocacy Inc., on the topic of “Medical Error & Patient Advocacy - How Can We Have More Candor?” Kathleen joins our host, Catherine Short to review medical error and provide an approach to harmed patients. The CANDOR program of Communication and Optimal Resolution will be explained. CANDOR is well established and has been successfully adopted by many medical centers. Without CANDOR in place, patients may benefit from the use of the principles and the help of a board-certified patient advocate.
1st Talk Compliance features guest Catherine Walters, a partner at BYBEL RUTLEDGE LLP and management-side labor and employment attorney representing employers of all sizes, on the topic of “Employment and Labor Law Digest.” Catherine joins our host, Catherine Short to update employers and human resources professionals on recent employment and labor law developments and discuss specific hot topics.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents this very timely subject for us. Durable medical equipment, prosthetics, orthotics and supplies (DMEPOS) includes an "entity or individual, including a physician or a Part A provider, which sells or rents Part B covered items to Medicare beneficiaries." There are special payment rules associated with DMEPOS. DMEPOS products have to meet quality standards, DMEPOS suppliers need to be accepted by Medicare to participate (similar to providers), and are subject to fraud, waste, and abuse laws. The purpose of this webinar to provide an overview of participation and quality requirements, relay the latest compliance and requirements updates, and address False Claims Act cases involving DMEPOS companies.
First Healthcare Compliance hosts C. Trey Scott, Coordinating Attorney at Kennedy, Attorneys & Counselors at Law, for an interactive discussion on “Under Pressure: Reporting Requirements with OCR for Breaches.” Attendees will learn the reporting requirements for a data breach of a healthcare provider.
Catherine Short converses with Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX and Bruce J. Lynskey, Co-Founder at ePrevenir, on the topic of “Negotiations in Healthcare and Technology.” Negotiating occurs in every facet of business and law. From contractual negotiations through settlement negotiations, it is a delicate dance. There are a variety of classic negotiation techniques, which include extreme posturing and “anchoring”. Healthcare and cybersecurity present unique challenges because of the looming exposure to a government investigation and either a civil and/or criminal action, even if a settlement is reached between two private parties. Here we will discuss approaches when negotiating contracts, settlements, and other items, which arise in healthcare and the cybersecurity industries.
First Healthcare Compliance hosts Catherine Walters, Esq., Partner at BYBEL RUTLEDGE LLP a management-side labor and employment attorney representing employers of all sizes, for an interactive discussion on “Employment and Labor Law Round-up With 2022 Forecast and Other HOT Topics.” During 2021 as the COVID pandemic raged on and the new Administration faced unprecedented challenges, extensive changes occurred in the employment and labor law landscape, and even more extensive changes are anticipated for 2022. This program will provide a quick update of 2021's most important developments and forecast what employers can expect in 2022. Attend this program to catch up on the Biden Administration's progress on its labor agenda, relevant Supreme Court decisions and how they affect employers, DOL agency activities, issues to worry about in 2022 and other hot topics, including OSHA, vaccination rules/policies, wage and hour issues, remote workplace tips, cannabis, restrictive covenants, to name a few.
Catherine Short speaks with Shauna Itri, Partner at Seeger Weiss LLP on the topic of “Fraud, Healthcare, COVID-19 and the False Claims Act.” A whistleblower or qui tam action can provide financial rewards to individuals who have information that a company/individual has committed fraud. The primary statutes under which this relief may be sought are the federal and state False Claims Acts (“FCAs”). In addition to the FCAs, there are other statutes which apply to tax fraud, securities fraud, and in California, fraud on private insurance companies. This episode will provide an overview of the False Claims Acts, the knowledge and skills to be able to recognize a potential whistleblower case, and understand the unique procedures utilized in filing whistleblower cases/tips. We will also delve into recent trends in cases brought (or that could be brought) under the False Claims Act including cases involving mined data and potential fraud related to COVID-19.
John Shegerian, Co-Founder and Chairman/CEO of ERI and co-author of the cybersecurity book, "the Insecurity of Everything" will be presenting a talk about cybersecurity titled “The Insecurity of Everything: How Hardware Data Security is Becoming the Most Important Topic in the World” and will share some of the latest information about the very real problem of hardware hacking in the world of healthcare and beyond and how that issue became even more serious during the pandemic, with so many people working from home. He will also be explaining critical information for health-related businesses to help them keep their private data – and the data of their patients and customers – protected!
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents this very timely subject for us. Effective January 1, 2022, the No Surprises Act has implications for patients, providers, and insurance companies alike. The impetus behind the legislation, as well as the regulations, is to prevent patients from receiving bills for certain services that were performed or delivered by providers out of their plan's network. The scope is limited and providers and plans alike need to take steps to understand the appeal process when a payment or claim is challenged. The purpose of this presentation is to provide a brief overview of the evolution of the United States' healthcare system and its relevance to the No Surprises Act. From there, the No Surprises Act and regulations will be explained, along with the appeal process. Finally, compliance tips will round out the presentation.
Catherine Short speaks with Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “The No Surprises Act - What You Need to Know.” Effective January 1, 2022, the No Surprises Act has implications for patients, providers, and insurance companies alike. The impetus behind the legislation, as well as the regulations, is to prevent patients from receiving bills for certain services that were performed or delivered by providers out of their plan's network. The scope is limited and providers and plans alike need to take steps to understand the appeal process when a payment or claim is challenged. The purpose of this episode is to provide a brief overview of the evolution of the United States' healthcare system and its relevance to the No Surprises Act. From there, the No Surprises Act and regulations will be explained, along with the appeal process. Finally, compliance tips will round out the show.
Melody W. Mulaik, MSHS, FAHRA, CRA, RCC, RCC-IR, CPC, CPC-H is the President of Revenue Cycle Coding Strategies LLC and our esteemed presenter. 2022 was scheduled to be the the official implementation date for AUC/CDS implementation but the 2022 Proposed Rule threw everyone a little curve ball. While a delay will occur it does not change the direction of the program or the need to prepare and test. As providers continue to either prepare their own practices or bridge the gap with imaging facilities, it is important that everyone be on the same page throughout the CMS implementation and remaining testing period.
Catherine Short speaks with Melody Mulaik, President of Revenue Cycle Coding Strategies, a dynamic company that works with physician practices, healthcare systems, billing companies and other industry stakeholders to provide auditing, education and other collaborative consulting solutions to meet their coding and compliance needs. First Healthcare Compliance is a proud partner of Revenue Cycle Coding Strategies and our clients have enjoyed many webinars and previous podcasts by this team of experts. Melody joins us to address a current hot topic, “AUC – Delayed but not Gone.” 2022 was scheduled to be the official implementation date for AUC/CDS implementation but the 2022 Proposed Rule threw everyone a little curve ball. While a delay has occurred, it does not change the direction of the program or the need to prepare and test. As providers continue to either prepare their own practices or bridge the gap with imaging facilities, it is important that everyone be on the same page throughout the CMS implementation and remaining testing period.
First Healthcare Compliance hosts Sheba Vine, Attorney and Senior Manager in the Global Privacy Office at Exact Sciences Corporation, for an interactive discussion on “Recent Developments in Health Information Privacy: HIPAA Right of Access, NPRM, & Information Blocking.” This presentation will review recent developments including OCR Enforcement Highlights, HIPAA Right of Access & Ciox Health Decision, NPRM, and 21st Century Cures Act Information Blocking Regulation.
Catherine Short speaks with Sheba Vine, Attorney and Senior Manager in the Global Privacy Office at Exact Sciences Corporation, on the topic of “Recent Developments in Health Information Privacy: HIPAA Right of Access.” We will review recent developments including OCR Enforcement Highlights, HIPAA Right of Access & Ciox Health Decision, NPRM, and 21st Century Cures Act Information Blocking Regulation.
First Healthcare Compliance hosts William J McBorrough, co-Founder and Chief Security Advisor at MCGlobalTech, a Washington, D.C.-based Information Security Consulting Firm for an interactive discussion on “Combating Ransomware in Healthcare.” Ransomware attacks have impacted thousands of organizations worldwide. The healthcare sector has been the most targeted. Join in to discuss the state of ransomware in the healthcare sector in 2021 and best practices to prepare your organization from the inevitable attacks.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents this highly informative webinar. A multitude of laws, including HIPAA, require that certain types of documents be kept for a certain period of time. How does document retention play out for public companies subject to SOX and what should companies do in the event of a legal hold or a preservation request? This presentation addresses laws that are relevant to healthcare industry participants, as well as compliance suggestions, and steps to take when either a legal hold or a preservation request arrives.
This webinar will cover the following objectives:
Catherine Short speaks with Rebecca L. Rakoski, managing partner at XPAN Law Partners and Saj Naseem, Chief Information Security Officer (CISO) from NJ Courts on the topic of “Why Healthcare Organizations Need to Take a New Approach to Cybersecurity & Data Privacy Training.” On this episode, we will discuss how training, using traditional methods can cause greater liability and threats to an organization.
First Healthcare Compliance hosts Iliana L. Peters, Shareholder at Polsinelli PC, for an interactive discussion on “Recent Attacks on Data Security: The Stuff of Nightmares!” This presentation will include information on state law protections and expansions, thoughts regarding recent developments in cyber security issues like ransomware, and analysis of the greatest data privacy and security risks to companies in the current legal and regulatory environment.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX and Bruce Lynskey, Co-Founder, Director, and Chief Executive Officer at ePrevenir will be presenting with us. Negotiating occurs in every facet of business and law. From contractual negotiations through settlement negotiations, it is a delicate dance. There are a variety of classic negotiation techniques, which include extreme posturing and “anchoring”. Healthcare and cybersecurity present unique challenges because of the looming exposure to a government investigation and either a civil and/or criminal action, even if a settlement is reached between two private parties. The purpose of this presentation is to provide approaches when negotiating contracts, settlements, and other items, which arise in healthcare and the cybersecurity industries.
Catherine Short speaks with Iliana L. Peters, Shareholder at Polsinelli PC on the topic of “What's New in Data Privacy and Cyber Security.” We will be discussing new developments in data privacy protections and cyber security threats and this episode will include information on state law protections and expansions, thoughts regarding recent developments in cyber security issues like ransomware, and analysis of the greatest data privacy and security risks to companies in the current legal and regulatory environment.
First Healthcare Compliance hosts Kathleen W. McNicholas, MD, JD, CHC, CCEP, Consultant and Patient Advocate with Medical Legal Patient Advocacy Inc., for an interactive discussion on “Medical Error, CANDOR/candor, and Patient Advocacy.” Dr. McNicholas will review medical error and provide an approach to harmed patients. The CANDOR program of Communication and Optimal Resolution will be explained. CANDOR is well established and has been successfully adopted by many medical centers. With CANDOR in place, patients may benefit from the use of the principles and the help of a board-certified patient advocate.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents this timely webinar. It's hard to believe that it's been 25 years since HIPAA was signed into law on August 21, 1996! Over the past two and a half decades, there have been a multitude of changes in the healthcare industry and technology. The three items that remain constant are preserving the confidentiality, integrity, and availability of a patient's protected health information.
Catherine Short speaks with Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “HIPAA Celebrates 25 Years - A Synopsis of the Law's Evolution.” It's hard to believe that it's been 25 years since HIPAA was signed into law on August 21, 1996! Over the past two and a half decades, there have been a multitude of changes in the healthcare industry and technology. The three items that remain constant are preserving the confidentiality, integrity, and availability of a patient's protected health information.
Shauna Itri, Partner at Seeger Weiss LLP will be presenting for us today. A whistleblower or qui tam action can provide financial rewards to individuals who have information that a company/individual has committed fraud. The primary statutes under which this relief may be sought are the federal and state False Claims Acts (“FCAs”). In addition to the FCAs, there are other statutes which apply to tax fraud, securities fraud, and in California, fraud on private insurance companies. This practical Course will provide an overview of the False Claims Acts, the knowledge and skills to be able to recognize a potential whistleblower case, and understand the unique procedures utilized in filing whistleblower cases/tips. The second half of the Course will go into recent trends in cases brought (or could be brought) under the False Claims Act including cases involving mined data and potential fraud related to COVID-19.
Sean McKenna, Partner at Spencer Fane, LLP in Dallas, TX and Mike McCarthy, Deputy General Counsel at The Cooper Health System in Camden, NJ, will be presenting on these newly updated regulations. Discussion will cover the new Stark, AKS, and other pertinent rules affecting healthcare providers.
Rebecca L. Rakoski, managing partner at XPAN Law Partners and Sajed Naseem, Chief Information Security Officer (CISO) from NJ Courts are presenting this engaging webinar. Employees are one of an organization's greatest strengths, but also its greatest weaknesses. For years cybersecurity and data privacy advocates have been arguing that training employees is the only way to safeguard the organization. This is especially true in the healthcare arena where HIPAA training is required. However, these same healthcare organizations engage in training for their employees only to stare down the barrel of a data breach caused by one of those trained employees.The question becomes, why do we continue to repeat the same exercise expecting a different outcome?
Catherine Short converses with Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C. and Don Barbo, Managing Director with VMG Health, on the topic of “New Stark Law and AKS Final Rules -Valuation Considerations.” On January 19, 2021, a new era was ushered in as the CMS Stark Law Final Rule and the HHS-OIG Anti-Kickback Statute Final Rule became effective. The impetus behind the new Final Rules is value-based care and care coordination. In light of the advent of Value-Based Arrangements, which include Value-Based Enterprises, as well as the continuing importance of fair-market value and commercial reasonableness, we will focus on these aspects of the respective Final Rules, which must be read in conjunction with each other.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX and Don Barbo, Managing Director with VMG Health are presenting this timely webinar. On January 19, 2021, a new era was ushered in as the CMS Stark Law Final Rule and the HHS-OIG Anti-Kickback Statute Final Rule became effective. The impetus behind the new Final Rules is value-based care and care coordination. In light of the advent of Value-Based Arrangements, which include Value-Based Enterprises, as well as the continuing importance of fair-market value and commercial reasonableness, this presentation focuses on these aspects of the respective Final Rules, which must be read in conjunction with each other. Additionally, a portion of the presentation will be dedicated to the nuances of balance sheets, income statements, and valuations in relation to both the healthcare industry and the aforementioned laws.
Catherine Short speaks with Warren Cook, President and Co-Founder of SymbianceHR . The topic of today’s program is “How Workplace Communication Mitigates Harassment.” We will explore the various communication strategies and practices necessary to develop a culture that inherently minimizes harassing behavior in the workplace, including various communication techniques and activities that lead to engagement and empowerment while simultaneously creating an inclusive environment that builds trust and respect.
Raymond Ribble, founder of SPHER, Inc. a leading SaaS-based compliance analytics solution addressing PHI protection and cybersecurity in healthcare, leads this informative webinar. This presentation takes the audience through a series of scenarios and lessons learned that can assist in securing the employee "endpoint" either in the office or at a Home Office. The presentation highlights key security measures a person can deploy to create a better security environment in order to protect their personal and professional documents from unauthorized access.
Courtney Tito, Member of the Health Law group at McDonald Hopkins, LLC in its West Palm Beach office will be presenting this informative webinar. This presentation will provide the participants with an overview of the bases for Medicare Revocations and what types of issues can be addressed now to hopefully avoid a revocation action in the future. Additionally, Courtney will provide some thoughts on how best to respond to a notice of revocation and the impact of September 2019 Final Rule on the effect of revocation
C.Trey Scott, Coordinating Attorney at Kennedy, Attorneys & Counselors at Law leads this webinar. Waivers and discounts are normal business activities that occur throughout the US daily as a way to reward customers or to assist when an invoice or bill may too expensive. However, in a healthcare context, the normal rules for waivers and discounts don't apply. This presentation will highlight what waivers and discounts are, how they work, and when they are problematic/illegal.
Catherine Short speaks with Jennifer Gimler Brady, Partner at Potter Anderson & Corroon LLP, about “COVID-19: Workplace Safety, OSHA Updates, and Return to Work Issues.” On January 29, 2021, OSHA issued new guidance for COVID-19 workplace safety programs. Among other things, the guidance recommends several essential elements of an effective COVID prevention program. We will discuss the OSHA guidance, as well as other important considerations that employers should take into account when planning for returning employees to the workplace, including the pros and cons of mandatory COVID vaccines.
Melody W. Mulaik, MSHS, FAHRA, CRA, RCC, RCC-IR, CPC, CPC-H is the President of Revenue Cycle Coding Strategies LLC and our presenter. Every organization needs to ensure correct coding and billing practices to optimize appropriate reimbursement and adhere to payer and CMS guidelines. Whether the providers are responsible for coding or the organization employs coding professionals there are steps every organization should take to ensure correct processes. This session will break down the key areas of concern and provide realistic solutions to efficiently and effective validate current processes and identify areas of potential concern.
Donald A. Balasa, JD, MBA, Chief Executive Officer and Legal Counsel of the American Association of Medical Assistants (AAMA) leads this timely and informative webinar. The medical assisting profession has risen to the occasion as the United States and the world have been dealing with the most serious health crisis in the last 100 years. Medical assistants have been asked by public health officials, managers of health systems, and licensed providers to assume expanded roles and perform tasks beyond their normal scope of work.
Catherine Short speaks with Donald A. Balasa, JD, MBA, CEO and Legal Counsel of the American Association of Medical Assistants (AAMA), on the topic of “Expanded Roles and Duties for Medical Assistants during the COVID-19 Era.” The medical assisting profession has risen to the occasion as we have been dealing with the most serious health crisis in the last 100 years. Medical assistants have been asked by public health officials, managers of health systems, and licensed providers to assume expanded roles and perform tasks beyond their normal scope of work. Because of the breadth of their education and training, medical assistants have been able to adapt quickly to these new responsibilities. They have been called upon to work in nontraditional settings under the authority and supervision of a dedicated array of clinicians and administrators with whom they had not previously practiced. During this episode, we will discuss the laws that establish the scope of practice for medical assistants, and to delineate the expanded tasks that may be delegated under these laws.
Jennifer Gimler Brady, Partner at Potter Anderson & Corroon LLP will be presenting this timely webinar. On January 29, 2021, the Occupational Safety and Health Administration ("OSHA") issued new guidance for COVID-19 workplace safety programs. Among other things, the guidance recommends several essential elements of an effective COVID prevention program. This presentation will discuss the OSHA guidance, as well as other important considerations that employers should take into account when planning for returning employees to the workplace, including the pros and cons of mandatory COVID vaccines.
Catherine Short speaks with Rebecca L. Rakoski, Co-founder and Managing Partner at XPAN Law Partners, about “Vendor Management in Healthcare: The High Cost of Failing to Triage Your Vendors.” We will be discussing the importance of vendor management in the healthcare industry, explore recent vendor- related data breaches and the threat vendors can pose, discuss the issues presented by COVID-19, and explain the regulatory framework- healthcare-related businesses need to understand.
Catherine Walters, Partner at BYBEL RUTLEDGE LLP is a management-side labor and employment attorney representing employers of all sizes and will be presenting this timely webinar. A new President and a new DOL promise major changes for both employers and employees. We will discuss anticipated labor and employment policy changes under the new Biden Administration, including changes already in effect and changes yet to come.
Catherine Short converses with Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “The New AKS and Stark Laws Final Rules - Key Take-Aways.” On November 20, 2020, the Centers for Medicare and Medicaid Services (CMS) issued a Final Rule related to the Medicare Physician Self-Referral Law (Stark Law). Nearly simultaneously, the Office of the Inspector General, Department of Health and Human Services (HHS-OIG), released a Final Rule, which amends various safe harbors to the Federal Anti-Kickback Statute (AKS). The changes appear to be based, in large part, on value-based healthcare delivery and payment systems. On this episode, we will highlight the key changes, along with the similarities and differences in the language between the two Final Rules, examine the new AKS safe harbors and Stark Law exceptions, compare and contrast critical items found in both Final Rules, and appreciate the risks of non-compliance.
Cindy Groux, CHBME/Board Member at HBMA and CEO, President and Owner of Health Care Practice Management, will address new CPT codes for 2021 to include prolonged services and clinical staff services, documentation changes to reduce the administrative burden, decreased needs for audits and how to promote coding consistency, and new rules for time billing.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents. Throughout the pandemic, HHS-OCR has announced the use of its enforcement discretion when bringing forth HIPAA-related enforcement actions. This trend appears to be continuing as the vaccine roles out. Additionally, proposed changes to the Privacy Rule were released in December 2020 and OCR continues to enforce violations against providers for not providing a patient with his/her medical records. This presentation provides a timely overview of these items, as well as addressing key terms such “reasonable” and “good faith” in the context of protecting the confidentiality, integrity, and availability of protected health information.
Stephen Bittinger, partner with K&L Gates in the firm’s Charleston office and a member of the health care/FDA practice group, is presenting with us on the brief history of use of big data in investigating and proving False Claims Act liability. He will offer an explanation of the government agencies and contractors involved in gathering health care data for investigation of fraud and abuse. We will look into the increased risk of fraud investigations due to regulatory changes implemented in response to COVID-19, and give practical ways to use data to reduce risk of investigation and liability.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents. “As part of the Department’s effort to fully protect patients’ health information and their rights under HIPAA, OCR has issued this important new fact sheet clearly explaining a business associate’s liability,” said OCR Director Roger Severino. In 2013, under the authority granted by the HITECH Act, OCR issued the Final Omnibus Rule that, among other things, identified provisions of the HIPAA Rules that apply directly to business associates and for which business associates are directly liable. One of the most notable items is the Business Associate Agreement. The presentation highlights enforcement actions, as well as key compliance items business associates and subcontractors need to focus on.
Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents on these new updates. On November 20, 2020, the Centers for Medicare and Medicaid Services (CMS) issued a Final Rule related to the Medicare Physician Self-Referral Law (Stark Law). Nearly simultaneously, the Office of the Inspector General, Department of Health and Human Services (HHS-OIG), released a Final Rule, which amends various safe harbors to the Federal Anti-Kickback Statute (AKS). The changes appear to be based, in large part, on value-based healthcare delivery and payment systems. The purpose of this presentation is to highlight the key changes, along with the similarities and differences in the language between the two Final Rules.
Presented by Feisal Nanji, CEO and Executive Director at Techumen LLC. We are moving to a Data-based quality care where vast amounts of data move at high speeds with little to no governance of the data. This presentation will discuss key controls for data analytics, identify potential threats, and balancing risks versus rewards.
Catherine Short converses with Bob Chaput, Founder and Executive Chairman of the Board of Clearwater, a provider of healthcare compliance and cyber risk management software and consulting services, on the topic of “Healthcare’s Enterprise Cyber Risk Management Imperative.” Healthcare organizations continue to see escalating numbers of cyberattacks. It is no longer a matter of if your organization will be targeted, but when. What is at stake? Everything.
Catherine Short speaks with Melody Mulaik, President of Revenue Cycle Coding Strategies to address a current hot topic, “Appropriate Use Criteria: What you Need to Know.” 2021 is also going to be an official CMS testing year for AUC/CDS implementation. This episode will identify specific areas of concern for your organization regarding AUC/CDS implementation, help you to facilitate discussions with all stakeholders to ensure all perspectives are heard and addressed, and assist in designing actions that can be taken to facilitate a successful implementation to ensure revenue is not negatively impacted.
First Healthcare Compliance hosts Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, for an interactive discussion on “HIPAA Compliance for Business Associates.” The July 2020 monetary payment of over $1 million dollars by a health system to HHS-OCR serves as a reminder to covered entities and business associates alike that HIPAA violations can be costly. The focus of this presentation is on business associates and subcontracts and the potential threats that can exploit vulnerabilities and trigger costly reporting to government agencies, as well as private lawsuits. Risk mitigation strategies will also be discussed, as well as some key items that should not be overlooked during the COVID-19 Pandemic.
Objectives:
Catherine Short speaks with Dr. Chris Hobson, Chief Medical Officer for Orion Health. The topic of today’s program is “Why payers can’t ignore the interoperability rules and should comply sooner rather than later.” The Interoperability and Patient Access final rule approved by CMS and ONC is intended to advance patient participation through access to their health information and to drive advanced interoperability and innovation across the U.S. These rules will have significant impact on payer organizations who are currently facing unprecedented times.
First Healthcare Compliance hosts Trevor Brown, Vice President of Business Development at Relatient, for an interactive discussion on “Hybrid Patient Care Models: How Medical Practices Thrive After COVID-19.” The COVID-19 pandemic complicated healthcare delivery as healthcare organizations limited procedures and in-office visits to essential care only and quickly spun up Telehealth services to treat patients remotely, protecting both patients and staff. Now, as medical practices, hospitals, and health systems have welcomed their patients back, they face new challenges, including increased gaps in care, staying prepared for future disruptions big and small, and meeting new patient expectations that shifted during the pandemic's crisis points. Hybrid care models are helping medical providers meet the need by combining in-office and Telehealth visits with digital workflows that streamline the patient journey, get patients engaged in their care again, and maintain best practices learned during COVID-19. In this presentation, we'll take a look at hybrid care models in action, strategies for powering them effectively, and steps for getting started or refining what's already in place.
Objectives: 1. Identify the effects of the COVID-19 pandemic and the response from medical providers on patient expectations. 2. Evaluate hybrid patient care models, including what they are, why they are needed, and best practices for sustaining them long-term. 3. Offer strategies for implementing a hybrid patient care model in the outpatient setting, including digital workflows that power hybrid care models and leveraging existing patient engagement strategies to further support the model.
First Healthcare Compliance hosts Rebecca L. Rakoski, co-founder and managing partner at XPAN Law Group, for an interactive discussion on “Vendor Management In Healthcare: The High Cost of Failing to Triage Your Vendors” There will be a discussion on the importance of vendor management in the healthcare industry, recent vendor- related data breaches, unique issues presented by COVID-19, along with an overview of the regulatory framework healthcare-related businesses need to understand. We will also provide a three-step process to address vendor management.
This webinar will cover the following objectives: 1. Understand the threat vendors pose in healthcare 2. Understand the regulatory framework 3. Understand how to create a vendor management program that works.
First Healthcare Compliance hosts Grant Elliott, President and CEO of Ostendio, for an interactive discussion on “HIPAA: A Timely Overview & Update.” This webinar will cover in-depth all aspects of HIPAA and why it is relevant today. Starting with the history of HIPAA and how it came about we will move on to discuss the core elements of HIPAA and why they are important. The presentation will discuss the intent of HIPAA and what it means to businesses. We will discuss other common security regulations and how they compare to, or differ from, HIPAA. The presentation will close with recommendations for organizations who need to adhere to HIPAA requirements.
Objectives: 1. Provide history of HIPAA 2. Teach core elements and intent of HIPAA 3. Explain security compliance and how to approach it.
Catherine Short speaks with Trey Scott, Coordinating Attorney for Kennedy, Attorneys & Counselors at Law located in Dallas, TX. The topic of today’s program is “Steering Clear of Legal Liability.” The discussion will help the audience navigate the choppy waters of potential legal actions that often arise in the world of healthcare. We will start with a basic overview of the typical steps leading up to the filing of a lawsuit. Listeners will also learn how to prepare for potential future litigation, and how to avoid simple mistakes that can later prove costly in a lawsuit.
First Healthcare Compliance hosts Feisal Nanji, CEO and Executive Director at Techumen LLC, for an interactive discussion on “Why are Security & Governance for Health Data Analytics Vital?” Data analytics can substantially help reduce costs by analyzing vast amounts of payor, patient, and provider data. In using data analytics, everyone in the health care supply chain must be ready to securely manage vast patient data sets that will move in high volume and at high velocity. If such activities are not governed correctly, a breach of a single data set will result in a very large breach and a serious dent to reputation and the possibility of severe sanctions. The second webinar in this series is entitled "Securing Your Data Analytics Program" and will happen on December 15th.
This webinar will cover the following objectives: 1. Overview of data analytics, including where and how it is used 2. Discussion of security issues presented by data analytics, including data governance, secure management of infrastructure, and secure management of applications and databases 3. Future of data analytics and security
First Healthcare Compliance hosts Warren Cook, President and Co-Founder of SymbianceHR, for an interactive discussion on “How Workplace Communication Mitigates Harassment.” This webinar explores the various communication strategies and practices necessary to develop a culture that inherently minimizes harassing behavior in the workplace.
Specifically examined are various communication techniques and activities that lead to engagement and empowerment while simultaneously creating an inclusive environment that builds trust and respect.
Business leaders will gain insight into what works and how to maximize current efforts, including why it's important to launch new initiatives to mitigate harassment while improving overall organizational success.
Objectives: 1. Review various communication mediums and strategies that lead to enhanced engagement, trust and respect in the workplace 2. Understand the risks and liabilities associated with poor communication practices creating an environment capable of sustaining harassment and learn new strategies to enhance their workplace culture 3. Attendees will learn practical tips, strategies and practices necessary to achieve an inclusive work environment that limits risk and liability while empowering the workforce for continued success
Catherine Short speaks with Markus P. Cicka, J.D., LL.M. (Health Law), owner of the Law Office of Markus P. Cicka, LLC, a law firm based in Saint Louis, Missouri, about the topic of “Billing for Chronic Care Management: What Are the Problematic Issues?” We will discuss what is chronic care management, have an understanding of who exactly can bill for providing chronic care management services, and discover what are recent chronic care management billing issues that have been flagged by the OIG.
First Healthcare Compliance hosts Emily A. Johnson, and Courtney Tito, Members, at McDonald Hopkins LLC, for an interactive discussion on “Federal Healthcare Fraud and Abuse Framework.” This webinar reviews the Federal Anti-Kickback Statute, Stark Law, Anti-Markup Rule, EKRA, and False Claims Act. Additionally, there will be a discussion on state fraud and abuse laws, and an overview of fraud and abuse compliance in light of COVID-19.
Educational Objectives: 1. Understand the Federal Anti-Kickback Statute, Self-Referral Law, Anti-Markup Rule, EKRA, and False Claims Act. 2. Understand state fraud and abuse legislation and private payor considerations. 3. Understand how fraud and abuse compliance has been impacted by COVID-19.
First Healthcare Compliance hosts Melody W. Mulaik, MSHS is President of Revenue Cycle Coding Strategies LLC for an interactive discussion on “Diagnosis Coding: The Cost of One and Done.” The documentation of detailed clinical information should result in the assignment of accurate and hopefully reimbursable diagnosis codes. As practices look to streamline documentation and coding processes it is critical to practice continual quality improvement.
The goal should always be to minimize additional work for providers while ensuring that the patients’ needs are being addressed clinically and financially. This session focuses on key areas of concern to balance compliance with operational efficiency. Understanding how diagnosis codes are utilized by insurance payers and other industry stakeholders is vital to ensuring that your organization receives appropriate recognition and credit for quality care.
Objectives: 1. Identify when there are enough codes to release a charge. 2. Explain the impact of diagnosis coding on the future of quality-based payment models. 3. Discuss ways to communicate the necessity of clinical data to physicians and other clinical staff generating the medical record.
Catherine Short speaks with Warren Cook President and Co-Founder of SymbianceHR on the topic of “Building an Engaging Company Culture and Avoiding HR Minefields at Work-Related Events.” Company culture is a factor that can lead to sustained success or unexpected failure. For this reason, leadership should pay special attention to the design, development, implementation and management of company culture to ensure it is sustainable and beneficial to the business. This episode will review the concept of business culture, explain the various constructs that form these standards, and provide strategies to improve workforce engagement to support the desired values for your business. We will also identify employment practice risks and liabilities when planning company-sponsored events to ensure you consider critical factors as you plan these inclusive events for your company.
First Healthcare Compliance hosts Steven S. Wilder, BA, CHSP, STS, Senior Consultant & COO of Sorensen, Wilder & Associates for an interactive discussion on “Training Your Staff: The Active Shooter in a Healthcare Facility.” A healthcare facility is one of the easiest "soft targets" the active shooter can find...countless open doors on the perimeter make it an easy target. Staff must be prepared to recognize the event, respond properly, and recover afterward. And, in the COVID-19 world, that risk may move to an even higher level.
Educational Objectives:
Explain five steps to minimize the losses that result from an active shooter event in a healthcare facility. Explain the "Four Outs" of response to an active shooter event in a healthcare facility. Discuss the decision-making process between personal safety and patient safety for the healthcare professional.
First Healthcare Compliance hosts Emily A. Johnson, and Courtney Tito, Members, at McDonald Hopkins LLC, for an interactive discussion on “COVID 19: Testing, Reimbursement, and Provider Relief Funds.” There will be a discussion of laboratory testing for COVID-19, including the types of tests available, requirements for testing, operational and business considerations for offering testing, employer-mandated testing, and reimbursement for testing. Additionally, this program will discuss the Provider Relief Funds issued pursuant to the CARES Act and enforcement of the terms and conditions of that program. Educational Objectives: 1. Understanding of types of COVID-19 testing available and business considerations when performing testing. 2. Overview of serology vs. PCR testing and implications of the same on employer-mandated testing. 3. Discussion of reimbursement for COVID-19 testing and discussion of the Provider Relief Funds program and enforcement of such program.
Catherine Short speaks with Dr. Mary Hoppa, MD, MBA, senior consultant with The Greeley Company which provides solutions through consulting, education, interim staffing, credentialing management, and external peer review to healthcare organizations nationwide, about “The Do’s and Don'ts of Designing an Aging Physician Policy.” We will be discussing how to identify and address competency issues among senior physicians and best practices to prevent potential safety incidents that could have long-term consequences for both patients and practitioner. We will also learn how to recognize age related impairments that affect a healthcare professional’s ability to safely administer care, look at how to design a fair aging policy to protect both practitioners and patients, as well as focusing in on how to address competency issues and when privileging needs to be reassessed or revoked.
First Healthcare Compliance hosts Lauren E.M. Russell, Counsel, for Young Conaway Stargatt & Taylor, LLP, for an interactive discussion on “Returning to Work Safely: What You Need to Know in the “New Normal”.” Protecting your employees and your business as we find our new normal, during the coronavirus pandemic. Objectives: 1. Recalling your employees to avoid claims of discrimination, leave interference, and work-related injury 2. Addressing the interplay between recall and unemployment benefits 3. Effectively addressing workplace safety concerns
First Healthcare Compliance hosts Melody W. Mulaik, MSHS is President of Revenue Cycle Coding Strategies LLC for an interactive discussion on “Appropriate Use Criteria: What you Need to Know.” 2020 is the official CMS testing year for AUC/CDS implementation. As organizations continue to bridge the gap with imaging facilities, it is important that everyone be on the same page throughout the CMS implementation and testing period. Additionally, any physician practices that perform and bill for diagnostic services must ensure compliance through correct billing practices. Working through the charge capture processes and identifying where gaps currently exist will ensure that plans can be quickly implemented to address these concerns and ensure that the Jan. 1, 2021 implementation date is successful and that no one's revenue is disrupted. In addition, the speaker will also share implementation stories for the group's benefit. Educational Objectives: 1. Identify specific areas of concern for your organization regarding AUC/CDS implementation. 2. Facilitate discussions with all stakeholders to ensure all perspectives are heard and addressed. 3. Design actions that can be taken to facilitate a successful implementation to ensure revenue is not negatively impacted.
Catherine Short speaks with Stephen Bittinger, Health Care Reimbursement Partner at K&L Gates, about the topic of “The Biggest Recent Health Care Scams & How to Avoid Being a Target.” We will be learning the mechanics of some of the largest recent health care fraud scams, how many providers became victims of these scams, and how to avoid these types of risks in the future. We will study the mechanics of health care fraud scams and the impact on providers caught in them, discover how to identify health care fraud scams and discuss resources for providers to educate themselves, and learn from other providers' mistakes on how to avoid health care fraud scams and decrease risk to revenue cycle.
First Healthcare Compliance hosts Patricia M. Clendening, President of HR Strategies, LLC for an interactive discussion on “Navigating COVID-19 and Preparing for Reentry to the Workplace.” This presentation will help your organization navigate the current pandemic as well as prepare for reentry to the new normal. Topics covered will include: COVID’s Impact on your Business We have FFCRA, now what? OSHA Compliance, Preparing for Reentry Unemployment Highlights, ADA & HIPAA Compliance, and Best Practices. Educational Objectives: 1. COVID-19's impact on your business; 2. COVID-19's impact on the business if an owner becomes incapacitated; 3. How to prepare for reentry - business needs that must be addressed before fully opening up including preplanning, general requirements, cubicles and offices, bathrooms, common areas, mailrooms, kitchens, elevators and policies that may need to be modified or added to your handbook.
First Healthcare Compliance hosts Andrea Tinianow, Chief Legal Officer and Tom Allen, Healthcare Director of Transparency Registry (TR), an online platform that tracks distressed consumer debt to ensure compliance with HIPAA and debt collection regulations, for an interactive discussion on “Medical Debt: The Good, The Bad and The Ugly.” The presentation will explain the issues and opportunities related to medical debt, including the regulatory framework that serves as a backdrop to the discussion. The presentation will explore the options available to doctors and health care facilities regarding debt collection, delving into the advantages and disadvantages of each. This will not be a theoretical discussion. The presenters will discuss real world experiences and challenges involving medical debt. Objectives: 1. Understand the regulatory issues surrounding medical debt. 2. Identify the options for healthcare providers that seek to collect and capture value from their medical debt. 3. Consider the advantages and disadvantages related to medical debt.
Catherine Short speaks with Courtney Tito, Esq., Member of the Health Law group at McDonald Hopkins, LLC in its West Palm Beach office about “Payor Disputes and Audits: Observations & Strategies.” Our discussion will help listeners better understand the payor audit process and prepare the organization to respond. We will talk about the payor audit process from the government perspective and compare and contrast typical government audits with typical commercial audits. Finally, we will identify some best practices that providers can implement now to prepare for payor audits.
First Healthcare Compliance hosts Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, for an interactive discussion on “HHS Final Rules, Patient Access to PHI & Health Apps Intersect.” On March 9, 2020, HHS announced the promulgation of two final rules - the ONC Final Rule and the CMS Final Rule. The fundamental objective is to expand an individual patient's control over his/her health data. One aspect requires insurance plans to share health data with their patients in a format suitable for their phones or other device of choice. How does this impact provider liability in light of the Healthcare Apps Guidance issued by HHS? Educational Objectives: 1. Explain the two new final rules, as well as the potential impact on providers. 2. Review the Healthcare Apps Guidance, which relates to HIPAA liability. 3. Provide suggestions for integrating the new rules while continuing to strive towards HIPAA compliance.
First Healthcare Compliance hosts Channing D. Sheets, MSEd, RVT, RBP, is a Senior Safety Engineer and Epidemiologist at Cal OSHA, for an interactive discussion on “Aerosol Transmissible Disease Standard (ATD) using California Standards as a Model.” This presentation will briefly describe the elements of an ATD plan and include some published case studies. Educational Objectives: 1. Elements of Aerosol Transmissible Disease Plan 2. Implementing an Exposure Control Program 3. Exposure Investigation: Case Studies
Catherine Short converses with Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “New HHS Rules, PHI, and Health Apps in the Age of COVID-19.” On March 9, 2020, HHS announced the promulgation of two final rules - the ONC Final Rule and the CMS Final Rule. The purpose is to expand an individual patient's control over their health data. It requires insurance plans to share health data with their patients in a format suitable for their phones or other device of choice. How does this impact provider liability in light of the Healthcare Apps Guidance issued by HHS? During this program, Rachel will explain the two new final rules, as well as the potential impact on providers; review the Healthcare Apps Guidance, which relates to HIPAA liability; and provide suggestions for integrating the new rules while continuing to strive towards HIPAA compliance.
First Healthcare Compliance hosts Neil Johnson, Managing Partner, & David Opalek, Director of Lawrence, Evans & Co., LLC, for an interactive discussion on “Healthcare Funding in the Time of COVID-19.” This webinar will provide a discussion on the current financial markets and impact of businesses during COVID-19. It will include a summary of CARES Act funding and its impact on healthcare facilities and providers, where to go to take advantage of government financing and include a discussion on alternative financing options.
Objectives: 1. Understanding business issues on healthcare companies as a result of COVID-19 2. Strategic alternatives for funding during COVID-19, lines of credit, factoring, bank loans, private loans, bonds, sale-leaseback 3. Highlights of the recently passed CARES Act and funding available
First Healthcare Compliance hosts Sonal Patel, Health Care Coder and Compliance Consultant at Nexsen Pruet, for an interactive discussion on “Compliant Coding & Billing For TeleHealth During COVID-19.” This webinar is based on both the March 31, 2020 unpublished Interim Final Rule, as well as the Interim Final Rule officially published in Federal Register on April 6, 2020 to provide clarity, and to dispel confusion providers, practice managers, coding and billing personnel have encountered over the past few weeks since CMS has relaxed the previous, and pre-COVID-19 rules and regulations for TeleHealth services.
Objectives:
First Healthcare Compliance hosts Channing D. Sheets, MSEd, RVT, RBP, is a Senior Safety Engineer and Epidemiologist at Cal OSHA, for an interactive discussion on “COVID-19 for Healthcare Workers.” This presentation provides background information on the virus, its etiology, quarantine measures, and control measures for the healthcare setting.
Educational Objectives: 1. Discuss COVID-19 Etiology and Epidemiology 2. Discuss COVID-19 Quarantine Measures 3. Discuss Precautions for Healthcare Workers
First Healthcare Compliance hosts Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, for an interactive discussion on “Coronavirus and Its Impact on HIPAA, Telecommuting, and Patient Care.” In 2014, our presenter, Rachel Rose, who also teaches bioethics to medical students at Baylor College of Medicine (Houston, Texas), wrote an article, Ebola Misdiagnosis Raises Liability Concerns and was quoted by MedPage Today as an expert in the article Point of Contention: The Law and Ebola Quarantines – How might court actions on the Ebola quarantines affect public health?
This webinar focuses on Coronavirus pandemic and its application to HIPAA, Telecommuting and Force Majeure provisions. The particular areas, which will be covered are as follows: (1) brief overview of the Coronavirus, quarantine and the allocation of resources from a bioethics perspective; (2) HIPAA – Privacy and Security Rule Requirements; (3) teleworker requirements; & (4) force majeure contractual provisions. At the end of this one-hour program, participants should have a semblance of the following:
Educational Objectives: 1. HIPAA - the parameters of disclosing a coronavirus diagnosis, as well as maintaining Privacy Rule and Security Rule compliance when requiring employees or contractors to work from home. 2. Force majeure contractual clauses and potential interpretations during a pandemic. 3. Government mandated quarantine – individual rights versus public health, as well as the allocation of resources.
First Healthcare Compliance hosts Stephen Bittinger, attorney with Nexsen Pruet’s Health Care Practice Group., for an interactive discussion on “The TeleHealth Revolution to Fight COVID-19.” Learn the sweeping changes that occurred in TeleHealth across all payors to fight COVID-19 and how to implement these services.
Objectives: 1. Learn the Major CMS Changes to TeleHealth 2. Learn the Major Private Payor Changes to TeleHealth 3. Learn the Essentials of Implementing COVID-19 TeleHealth Changes
First Healthcare Compliance hosts Bob Chaput, Founder and Executive Chairman of the Board of Clearwater, for an interactive discussion on “How to Conduct an OCR-Quality Risk Analysis.” This webinar has been designed to help covered entities and business associates understand and act on the specific Risk Analysis requirements included in the HIPAA Security Final Rule and OCR Final Guidance. We take the mystery out of risk analyses and risk management.
Objectives:
Catherine Short speaks with John Shegerian Cofounder and Executive Chairman of ERI the largest fully integrated IT and electronics asset disposition provider and cybersecurity-focused hardware destruction company in the United States. Today, we are discussing “Hardware Hacking: The Overlooked CyberCrime. Is Your Data Safe?” Today, the recycling of electronics in the healthcare sector faces a huge obstacle in the form of digital privacy. Many organizations are reluctant to recycle their old or unwanted electronics for fear that their proprietary and patient data will be compromised. And the fears are not without merit. The recycling of e-waste has indeed become an issue that transcends environmental responsibility – still the principle motivation - and has moved into the realm of privacy and regulatory issues. We will discuss how things have changed in terms of data contained on end-of-life devices and what can and should be done about it. We will learn about the data that is still stored on devices even after those devices have been "wiped,” about the kinds of devices that store data (now more than ever), and explore how responsible data protection AND sustainability need not be mutually exclusive.
First Healthcare Compliance hosts Stephen Bittinger, Esq. of Nexsen Pruet, for an interactive discussion on “The Biggest Health Care Scams in 2019 and How to Avoid Being a Target in 2020.” Attendees will learn about the mechanics of some of the largest health care fraud scams of 2019, how many providers became victims of these scams, and how to avoid these types of risks in the future.
Objectives: 1. Learn the mechanics of 2019 health care fraud scams and impact on providers caught in them. 2. Learn how to identify health care fraud scams and resources for providers to educate themselves. 3. Learn from other providers' mistakes on how to avoid health care fraud scams and decrease risk to revenue cycle.
First Healthcare Compliance hosts John Shegerian, cofounder and Executive Chairman of ERI, for an interactive discussion on “Health Industry Data Protection in the Age of Hardware Hacking.” ERI is the largest fully integrated IT and electronics asset disposition provider and cybersecurity-focused hardware destruction company in the United States will be leading our webinar. Today, the recycling of end-of-life electronics faces a huge obstacle in the form of digital privacy. Many entities in the world of healthcare – huge multinational corporations, hospital systems and government agencies included – are now faced with major issues pertaining to their electronics for fear that their private or personal data will be compromised. As a result, the recycling of data-storing devices when they are no longer needed has become an issue that transcends environmental responsibility, moving into the realm of privacy and security.
In this inspiring presentation, John Shegerian will discuss how data management in healthcare is at a crossroads of dual responsibility – keep old devices out of landfills WHILE responsibly and efficiently achieving data destruction that meets and exceeds compliance and regulatory goals. It can be done and he’ll explain how.
Objectives:
Learn how sustainability goals and data privacy and protection goals need not be mutually exclusive. Learn how the data management landscape has dramatically changed in the last few years and what it means in terms of the technology we use (and no longer use). Learn about the data that is stored on end-of-life devices... even after they have been "wiped" clean.
Catherine Short speaks with Reid Kiser, MS, founder and chief consultant of Kiser Healthcare Solutions, LLC where he applies his innovation, leadership, and industry experience to build collaborative solutions for clients associated with quality measurement, analytics and reporting tools, and business systems. We will discuss “Understanding the Healthcare Quality Measurement Data Landscape: "Data is the New Oil".” Through our discussion, we will have a deeper understanding of the general healthcare quality and performance measurement landscape, define the various measurement types and categories, explore the data source types for quality measurement reporting including the strengths and weaknesses of each, as well as explore what the future holds based on current trends and insights.
First Healthcare Compliance hosts C. Trey Scott, an associate attorney in the Dallas office of Lewis Brisbois and a member of the Healthcare Practice, for an interactive discussion on “I Fought The Law: What To Do When Facing A Potential/Actual Lawsuit.” The presentation will help healthcare organizations understand important actions that happen when facing a potential lawsuit and what to do when a suit is filed.
Objectives: 1. Organizations will know what to do when an incident that could be the basis of a suit/investigations occurs. 2. Importance of saving documents. 3. Organizations will learn that just because a suit happens, they can overcome it.
First Healthcare Compliance hosts Markus Cicka, Esq., owner of the Law Office of Markus P. Cicka, LLC, for an interactive discussion on “Making Your Referral Sources Legal.” Marketing and referral sources are the catalysts of a successful healthcare business. Making sure your marketing activities and referral sources are compliant with federal and state laws is complex but ultimately rewarding. In this presentation, we will discuss the various federal and state laws impacting your marketing and referral source activities, as well as discuss the application of federal and state law to specific provider types.
Objectives: 1. Provide an overview of federal and state law impacting marketing activities and referral sources. 2. Discuss the application of federal and state laws to various providers and scenarios, including the use of marketing companies, entering into medical directorships and signing rental/leasing agreements with referral sources. 3. Discuss EKRA and its impact on marketing for clinical laboratories.
Catherine Short speaks with Sarah Reiter, Vice President Strategic Partnerships, Health eFilings, about the topic of “Maximizing Medicare Reimbursements by Optimizing your MIPS Score.” The MIPS compliance landscape is very challenging and confusing. Understanding the requirements to earn points will significantly impact your Medicare reimbursements. We will learn how best to approach MIPS compliance, discuss how MACRA is driving the transformation in healthcare, why compliance is critical, how the financial implications of MIPS are significant, why MIPS is complicated, discuss Health eFilings Advantages versus a Registry and versus EHR.
First Healthcare Compliance hosts Raymond Ribble, founder of SPHER Inc. and co-founder of Fusion Systems Co., Ltd., for an interactive discussion on “Surviving an OCR Audit.” An overview of what steps a Covered Entity and Business Associate must take to prepare their groups to respond to an OCR or external audit of their privacy and security procedures.
Objectives: 1. An introduction to the types of audits that exist 2. Tips to prepare your group for an external audit 3. Tools and techniques to help assess your readiness
First Healthcare Compliance hosts Warren Cook, President and Co-Founder of SymbianceHR, for an interactive discussion on “Avoiding HR Issues at Company Events & Building an Engaging Culture.” Company culture is a factor that can lead to sustained success or unexpected failure. For this reason leadership should pay special attention to the design, development, implementation and management of the company culture to ensure it is sustainable and beneficial to the business. This webinar will review the concept of business culture, explain the various constructs that form culture, and provide strategies to improve engagement with the workforce to support the desired culture for your business.
As this webinar is scheduled during the holiday season, we wanted to identify employment practice risks and liabilities that may be difficult to prepare for when planning holiday related company sponsored events. We will begin this webinar by providing you practical tips and strategies to ensure you consider critical factors as you plan these events for your company.
Objectives:
Catherine Short speaks with Elizabeth Sullivan, Esq. and Emily A. Johnson, Esq., Members, of McDonald Hopkins LLC , about the topic of “Eliminating Kickbacks in Recovery Act (EKRA).” In October 2018, the Eliminating Kickbacks in Recovery Act (EKRA) was signed into law as part of the larger SUPPORT Act. It is an important piece of legislation impacting the healthcare industry, as a violation is punishable by a fine of up to $200,000 and/or imprisonment of up to 10 years for each occurrence. We will discuss a wide range of topics related to EKRA including an overview and understanding of the Eliminating Kickbacks in Recovery Act, talk about the similarities and differences between EKRA and the federal Anti-Kickback Statute, and obtain an understanding regarding prohibited compensation structures.
First Healthcare Compliance hosts Cristin Gardner, Director of Consumer Products & Markets, at Life Image, Inc., and David Schoolcraft, Partner and Chair of Digital Health Law Group, at Ogden Murphy Wallace, for an interactive discussion on “Upholding HIPAA Compliance and Streamlining Patient Access to Medical Data in Today’s Digital, Consumer-Driven Environment.” Patients expect their medical records to be available through digital formats, including mobile applications and have a growing number of digital tools available to them. In addition to pressure from patients, the federal government has recently made significant movement to make healthcare more consumer-friendly by creating easier access to ePHI through technology and giving patients more control of their health information. These changes represent the modernization of healthcare, and have a significant impact on compliance regulations and practices.
If you rely on outdated technology like CD’s, and faxes to deliver this data to patients, or if you do not know how your organization shares PHI, this session will strengthen your knowledge regarding government mandates and practice changes to meet increased patient demand to share information in digital formats using secure, HIPAA-compliant channels that will catalyze change while maintaining compliance.
Objectives: 1. Consumer trends are forcing healthcare to modernize. Consider compliance practice changes to conform to changing demands from patients. 2. Understand OCRs updated guidance on sharing ePHI with third-party mobile applications. Identify common practices to avoid that can result in significant penalties for violation. 3. With impending regulatory changes, recognize implications on current practices and identify necessary adjustments.
Host Catherine Short live from the MGMA Annual Conference 2019 in New Orleans with guests Melody Mulaik and Rene' Comire.
Catherine speaks with Melody Mulaik, MSHS, President of Revenue Cycle Coding Strategies, a First Healthcare Compliance partner, about “Appropriate Use Criteria Consultations Requirements – 2021 and Beyond.” Melody discusses the Appropriate Use Criteria and its regulatory requirements, reviews expectations for ordering providers, and evaluates what is necessary for performing providers.
Next, Catherine interviews a long time First Healthcare Compliance client, Rene’ Comire, CMPE, Practice Manager at Manchester Ob/Gyn Associates in New Hampshire. Rene' discusses the challenges and opportunities at Manchester Ob/Gyn Associates, a typical day in the life of a Practice Manager, and how she manages to keep it all organized while ensuring compliance!
First Healthcare Compliance hosts George W. Bodenger of the Law Offices of George W. Bodenger, LLC, for an interactive discussion on “Telemedicine - Key Legal and Business Issues.” The presentation will highlight key legal and business issues in telemedicine. It will focus on (1) why telemedicine is so important to our healthcare delivery system; (2) how telemedicine has developed from a federal and state legislative perspective; (3) the different technologies used in telemedicine and their application in healthcare services delivery; and (4) the manner in which certain primary bodies of law in healthcare apply to telemedicine services.
Objectives:
Enhance understanding of attendees regarding the evolution of telemedicine in health services delivery. Assist attendees to develop a fundamental understanding of the types of technologies used and services provided in telemedicine. Educate attendees on the primary bodies of law affecting telemedicine.
Catherine Short chats with Rachel V. Rose, JD, MBA, principal of Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, about the topic of “HIPAA and Health Apps.” As technology evolves and features are adopted by healthcare consumers, so does the need for either new regulations and/or guidance on existing regulations. This radio show highlights the Privacy Rule and the Security Rule in the context of PHI sales and marketing, as well as addressing the recent HHS FAQs on Health Apps. We will learn to appreciate privacy and security concerns related to the marketing and/or sale of PHI, address the recent HHS FAQs on Healthcare Apps, and learn risk-mitigation tips to reduce legally liability.
First Healthcare Compliance hosts Robert Hopton, Chief Executive Officer and Sarah Reiter, Vice President Strategic Partnerships of Health eFilings, for an interactive discussion on “How to Manage the Challenges of MIPS Reporting.” The presenters will provide insight into the MIPS program, what it means, and what you can do to maximize Medicare reimbursements. Health eFilings, a CEHRT (Certified EHR Technology), is a national leader in MIPS compliance and data management.
MIPS requires providers to transition from a volume to value-based care model or else face significant financial penalties and even reputational harm. The stakes have been raised every year and it is even more complex than it has been in the past, further increasing the stress, burden and financial risk to providers. It is critical to understand what reporting methods will optimize your MIPS score. And, since the focus is always on the bottom line, it's imperative to know what tangible steps can be taken to increase the financial payouts from the program without requiring any additional resources or time.
Objectives:
The elements, and complexities, of each of the four MIPS categories and how to navigate them. The fundamental, but critical, differences between reporting methodologies. The advantages of using a technology-based compliance solution vs. a manual one to earn points and optimize your MIPS score.
First Healthcare Compliance hosts Stephen Bittinger, Esq. of Nexsen Pruet, for an interactive discussion on “The New, Personal Audit Threat: Targeted Probe and Educate (TPE) Audits.” Attendees will learn about the new Medicare Administrative Contractor (MAC) Targeted Probe and Educate (TPE) audits and significant risks to not only reimbursement by provider's Medicare credentialing and licensing.
Objectives: 1. Learn the TPE process. 2. Learn how to pass a TPE audit. 3. Learn the significant risks of failing a TPE audit.
First Healthcare Compliance hosts Courtney Tito, Esq., Member, of McDonald Hopkins LLC, for an interactive discussion on “Payor Disputes and Audits: Observations & Strategies.” This presentation will help participants better understand the payor audit process and prepare the organization to respond. From recognizing the significance of initial correspondence, to responding effectively to initial and subsequent rounds of review, the presentation will take participants through the payor audit process from a government perspective and compare and contrast typical government audits with typical commercial audits. Finally, the presentation will identify some best practices that labs can implement now to prepare for payor audits.
Objectives: 1. Describe the government audit process - from initial correspondence through the various stages of appeal and share speakers’ experience with respect to commercial payor audits – what is similar and what is different from government audits. 2. Discuss the provider's responsibilities with respect to the medical necessity of testing for which it is submitting claims. 3. Identify steps providers can take to prepare for audits prior to an audit being initiated.
The Joint Commission Disclaimer: This presentation is current as of September 24, 2019. The Joint Commission reserves the right to change the content of the information as appropriate.
First Healthcare Compliance hosts Chad Larson, Executive Director of the Hospital Accreditation Program in the Division of Accreditation and Certification Operations at The Joint Commission for an interactive discussion on “The Joint Commission (JCAHO): Inspiring ealthcare Excellence.” Aimed at providing hospital administrators, compliance officers, physician and nurse staff and others an update as to how The Joint Commission is making their mark in healthcare as a performance improvement organization and not just an accreditation organization.
Educational Objectives:
To provide an overview of who we are today through our work as a performance improvement organization. Inform listeners of the most common trends of non-compliance from on-site surveys of hospitals. Provide an overview to listeners of complimentary resources and tools that The Joint Commission offers to enhance the value of achieving and maintaining our Gold Seal of Accreditation.
Catherine Short speaks with Cristin Gardner, Director of Consumer Products & Markets at Life Image a healthcare network for exchanging clinical and operational information including medical images, about “Upholding HIPAA OCR Compliance & Streamlining Patient Access to Medical Data.” Digital innovation is transforming healthcare. The federal government has recently made significant pushes to make healthcare more consumer-friendly by creating easier access to health information and ePHI through technology. Healthcare providers have an obligation to conform to HIPAA regulations and guidance from the HHS, Office of the National Coordinator for Health IT around sharing data with patients that evolve alongside changes in the healthcare and technology landscape. The vast majority of providers have moved to electronic records but still rely on outdated technology like CD’s, and faxes to deliver this data. This is often due to a misunderstanding of HIPAA, coupled with outdated institutional policies and practices. We will identify common practices that can result in significant HHS OCR violation penalties and we will discuss ways in which healthcare and compliance have changed with the rise of consumerism.
First Healthcare Compliance hosts Reid Kiser, MS, is the founder and chief consultant of Kiser Healthcare Solutions, LLC, (KHS), for an interactive discussion on “Understanding the Healthcare Quality Measurement Data Landscape: "Data is the New Oil."” This presentation provides a deeper understanding of the healthcare quality measurement landscape and is specifically focused on the various data sources available and frequently used. An overview of the different measure types will be tied to the different data sources that may be used as well as understanding the strengths and weaknesses of each data type. In closing, a glimpse into the future of what quality measurement may look like will be provided by the presenter based on current trends and insights.
Educational Objectives:
First Healthcare Compliance hosts Elizabeth Sullivan, Esq. and Emily A. Johnson, Esq., Members, of McDonald Hopkins LLC, for an interactive discussion on “Eliminating Kickbacks in Recovery Act (EKRA): Summary and Status.” In October 2018, the Eliminating Kickbacks in Recovery Act (EKRA) was signed into law as part of the larger SUPPORT Act. It is an important piece of legislation impacting the healthcare industry, as a violation is punishable by a fine of up to $200,000 and/ or imprisonment of up to 10 years for each occurrence. We will be discussing a wide range of topics related to EKRA
Educational Objectives: 1. Overview and understanding of Eliminating Kickbacks in Recovery Act 2. Understand the similarities and differences between EKRA and the federal Anti-Kickback Statute 3. Obtain an understanding regarding prohibited compensation structures.
Catherine Short speaks with Gene M. Ransom, III, CEO of the largest and oldest physician organization in Maryland, MedChi, The Maryland State Medical Society. As MedChi’s chief executive, Ransom spearheads MedChi’s mission as an advocate for physicians, patients, and the public health of Maryland. Today, we will be discussing “Medical Cannabis - How it’s Working in Maryland & Nationally.” We will be examining the use of Medical Cannabis in Maryland, review the legal framework regarding its use, and discuss the practical aspects of the dispensing of medical cannabis from the healthcare provider’s perspective, including the unique role of the recommender.
First Healthcare Compliance hosts Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, for an interactive discussion on “HIPAA and Health Apps.” As technology evolves and features are adopted by healthcare consumers, so the need arises for either new laws and/or guidance on existing laws. This webinar highlights the Privacy Rule and Security Rule in the context of the marketing and sale of PHI and addresses the new HHS FAQs on Health Apps. Finally, risk mitigation techniques for executives and board members alike round out the presentation.
Educational Objectives: 1. Identify privacy and security concerns related to the marketing and/or sale of PHI. 2. Provide an overview of the recent HHS FAQs on Healthcare Apps. 3. Learn risk-mitigation techniques to avoid legal liability.
First Healthcare Compliance hosts Lauren E.M. Russell, attorney for Young Conaway Stargatt & Taylor, LLP, for an interactive discussion on “Managing Drug Use in the Workplace.” A summary of relevant considerations when managing employee drug use in the workplace, whether legal or illegal.
Educational Objectives:
Understand the various employment laws that impact an employer's management of drug use in the workplace.
Identify common mistakes made in addressing unacceptable drug use.
Learn about the essential elements for an enforceable drug policy.
Catherine Short speaks with Warren Cook co-founder of SymbianceHR, an HR consulting partner that uses direct experience and best practices for solving human resource challenges, about the topic of “Got Diversity? Get Inclusion! And the Pending FLSA Changes.” We will review building an inclusive workforce through application of strategies and out of the box thinking that creates competitive advantage. We will dismiss the myths, explore the facts, and provide guidance you can use today. We will also briefly cover the pending proposed changes in the FLSA that may impact your business, talk about understanding what diversity is, and what it is not, learn strategies to build a culture of inclusion to create a competitive advantage and enhance engagement, and learn what the pending FLSA changes are and how this might impact your business.
First Healthcare Compliance hosts Warren Cook, President and CEO of SymbianceHR for an interactive discussion on “Got Diversity. Get Inclusion! and the Pending FLSA Changes.” Attendees will enjoy learning about building an inclusive workforce through application of strategies and out of the box thinking that creates a competitive advantage. We dismiss the myths, explain the facts, and provide guidance that you can use today. The audience will also benefit from a brief overview of the pending FLSA changes and the impact on your business.
Educational Objectives: 1. Attendees will understand what diversity is, and what it is not. 2. Attendees will learn about building a culture of inclusion to create a competitive advantage and enhance engagement. 3. Attendees will learn about the pending FLSA regulatory changes and strategies to protect your business from risk.
First Healthcare Compliance hosts Patricia M. Clendening, President of HR Strategies, LLC for an interactive discussion on “How to Navigate the Ever-Changing Anti-Harassment Regulations.” New regulations are impacting employers regarding discrimination in employment and more specifically harassment prevention. How can employers learn about these changes and what do they need to do to ensure they provide a workplace that is harassment-free? What are the training requirements, if any. What are the reporting requirements, if any? What additional resources are available for alleged victims and what can employers do to be proactive, address offensive behaviors and conduct impartial investigations? Join us for this informative webinar and have these and other questions answered.
Educational Objectives: 1. Gain an understanding of new regulations. 2. Gain an understanding of an employer's responsibilities regarding the prevention and correction of harassment. 3. Understanding the legal prohibition against retaliation and ensure that companies are in compliance with new regulations
Catherine Short speaks with Charlie Vincent, Executive Director of Spur Impact about the topic of “Medicine, Mindfulness, & Millennials: Health and Wellness for the Next Generation.” We are also pleased to be joined by Kate Smith, Program Manager at Delaware Academy of Medicine, and Jess Ruggieri, health coach at the University of Delaware. As healthcare costs skyrocket, it is increasingly important for millennials to be proactive about their health and wellbeing, and find meaningful ways to integrate healthy habits and preventative measures into their routine as young adults. The Millennial Summit, one of the largest young professionals conferences in the nation, features many speakers and breakout sessions that highlight these issues, and incorporates physical activity into the day of the conference itself. We will discuss preventative healthcare & healthy habits, retention and recruitment of millennials, and ideas and incentives for wellness in the workplace.
First Healthcare Compliance hosts William McBorrough, Co-Founder and Chief Security Advisor at MCGlobalTech for an interactive discussion on “Best Practices for Implementing PHI Security.” This presentation will review security trends in the healthcare industry over the last year and present current top cybersecurity threats to healthcare organizations and patients. The audience will also learn strategies and best practices for combating those threats and protecting patients.
Educational Objectives: 1. Provide audience with insight into healthcare industry security trends. 2. Educate audience on top security threats to healthcare providers and patients. 3. Educate audience on best practices for managing security threats and protecting patients.
First Healthcare Compliance hosts Steven S. Wilder, BA, CHSP, STS, Senior Consultant & COO of Sorensen, Wilder & Associates for an interactive discussion on “Recognizing & Defusing Aggressive Behavior Before Violence Erupts.” As acts of violence against healthcare workers continues to increase at epidemic rates, every healthcare worker must be trained to recognize and defuse aggression before they become a victim of violence.
Educational Objectives: 1. Identify six common changes in behavior a person commonly goes through from "Calm" to "Physically Violent" 2. For each of these behaviors, identify proven deescalants that can be used to restore a state of calm 3. Explain the techniques used in the triangle approach to verbal de-escalation
Catherine Short speaks with Steve Wilder, Chief Operating Officer of Sorensen, Wilder & Associates about the "Active Shooter in the Healthcare Facility.” As active shooter events continue to escalate across the nation, experience has proven that no location is immune to the risk. He is here to help identify the steps in developing an active shooter plan for your facility, explain the Four Outs that are available to a healthcare facility as options during an active shooter event, and identify common resources needed for recovery assistance after an event occurs.
First Healthcare Compliance hosts Jennifer Gimler Brady, Partner and General Counsel at Potter Anderson & Corroon LLP for an interactive discussion on “The Role of Boards in Healthcare Compliance.” Jennifer will discuss the compliance function of boards of healthcare entities during this presentation.
Educational Objectives: 1. The presentation will review the primary functions, responsibilities and duties of boards of healthcare entities. 2. The presentation will highlight the compliance and oversight role of healthcare boards. 3. The presentation will discuss institutional and individual liability issues pertinent to boards of healthcare entities
First Healthcare Compliance hosts Shivhon Adkins, MPA, Founder of Medical Receptionist Network for an interactive discussion on “Front Desk Success with Medical Receptionist Engagement.” Improve your front desk with a primary focus on the actions, independence, and abilities of your Medical Receptionists. Begin using feedback to enhance teamwork and shared goals while maintaining a successful environment by eliminating issues at the source and supporting your front desk team.
Educational Objectives: 1. Improve workflows and processes to improve front desk efficiency 2. Demonstrating great customer service and organization to improve the overall patient experience 3. Keeping Medical Receptionists focused on top priorities with consistency, redirection, and clear expectations
First Healthcare Compliance hosts Gene M. Ransom III, CEO of MedChi, The Maryland State Medical Society for an interactive discussion on “Medical Cannabis: Legal and Practice Considerations.” MedChi, The Maryland State Medical Society, is the largest physician organization in Maryland.
Educational Objectives:
An overview of Medical Cannabis issues
A focus on how Maryland has implemented its Medical Cannabis statute
A brief overview of some of the legal issues around Medical Cannabis
Catherine Short talks with Stan Szpytek, President of Fire and Life Safety, Inc. about “Fire & Life Safety Compliance: Trends & Topics in Health Care Facilities.” On this episode, new requirements, trends and best practices will be reviewed to help providers understand the critical importance of a safe and compliant environment of care. We will review specific code requirements (NFPA 101 and 99) that apply to regulated health care facilities by CMS and other authorities having jurisdiction, highlight new code requirements that are now being enforced by CMS including annual Fire Door Assembly Inspection and the NFPA 99 Risk Assessment. We will process, and motivate and educate listeners to understand the critical importance of life safety compliance in regulated health care facilities and strategies for survey success.
First Healthcare Compliance hosts Stan Szpytek, President of Fire and Life Safety, Inc, for an interactive discussion on “Fire & Life Safety Compliance in Health Care Facilities.”
Mr. Szpytek will offer a vital webinar on Fire & Life Safety Compliance in health care facilities with focus on NFPA 101, The Life Safety Code (2012) and NFPA 99, The Health Care Facilities code (2012). New requirements, trends and best practices will be reviewed to help providers understand the critical importance of a safe and compliant environment of care.
Educational Objectives: 1. Review specific code requirements (NFPA 101 and 99) that apply to regulated health care facilities by CMS and other authorities having jurisdiction.
Highlight new code requirements that are now being enforced by CMS including annual Fire Door Assembly Inspection (FDAI) and the NFPA 99 Risk Assessment process.
Motivate and educate attendees to understand the critical importance of fire & life safety compliance in regulated health care facilities and strategies for survey success
Catherine Short chats with Lauren Russell, attorney at Young Conaway Stargatt and Taylor about how to "Combat Workplace Sexual Harassment in the #MeToo Era.” We will review some of the key issues in sexual harassment in the workplace, touch on identifying what behavior may constitute sexual harassment, understand key steps in avoiding and addressing sexual harassment claims, and how to address more general concerns of workplace civility.
First Healthcare Compliance hosts Pam Joslin, MM, CMC, CMIS, CMOM, CMCO, CEMA, CMCA-E/M of Innovative Healthcare Consulting, for an interactive discussion on “Compliance Program Effectiveness: Auditing and Monitoring.”
The OIG (Office of Inspector General) states, “One of the seven critical elements of a compliance program is ongoing auditing and monitoring.” The OIG has noted that organizations should incorporate independent reviews and compliance program effectiveness evaluations to identify compliance gaps and evince that the compliance program is effective. This webinar will look at the distinct differences and also the relationship with the roles and responsibilities between the two functions to ensure that your organization is fully compliant.
Educational Objectives: 1. Define unique differences between “auditing” and “monitoring” 2. Review live case studies, risks, penalties for top 2018 violations. 3. Discover how “best practices” are implementing auditing and monitoring. (Who does what?)
Catherine Short talks with Matt Georgov, COO at Choice MedWaste, a medical waste hauler about “Trash Talking: Medical Waste FAQ.” We will review some of the questions around medical waste handling, sorting, transportation and disposal. We will also touch on some hot topics in the industry, learn how to properly package medical waste, how it is safely treated and then disposed of, and what to do with home generated medical waste from your patients.
First Healthcare Compliance hosts Catherine Walters, Esq., partner at Bybel Rutledge LLP and Chair of the firm's Employment/Labor Law Group, for an interactive discussion on “Navigating the Background Check & FCRA Compliance Minefield.”
Many employers perform pre-employment background checks, whether required by law, business needs or both. As employer needs expand, compliance requirements escalate, becoming more and more complex as new statutes are passed. Now, even a minor error can result in major liability for an employer. This program will provide employers with information, tools and tips on compliance with background check laws, including criminal background checks, the Fair Credit Reporting Act, state credit check laws, "Ban-the-Box" laws and similar prohibitions.
Educational Objectives:
First Healthcare Compliance hosts Gavin Baker, President of Baker Labs, a digital healthcare marketing firm, for an interactive discussion on “How to Handle Negative Patient Reviews.”
This webinar will cover the importance of reviews to today's modern doctor and patient, and what to do about a negative review.
Educational Objectives:
Catherine Short talks with Gavin Baker, President of Baker Labs about “How Medical Marketing Has Changed and How to Succeed in 2019.” We'll discuss the last decade in healthcare marketing, we'll cover how it has changed significantly, and what you need to be doing now to be successful in the future. We will also discuss what your budget should be, how to choose between marketing channels, and what is the right marketing mix.
First Healthcare Compliance hosts Andrew B. Wilson attorney and legislative specialist in Morris James LLP’s Health Care Industry and Government Relations Groups for an interactive discussion on “Telemedicine Compliance Primer - Using Delaware as a Model.”
Telemedicine is booming nationwide. Practices of all sizes - from the solo practice to the hospital system - are grappling with the new tools and reading tea leaves as the payment landscape evolves to value based payment. This presentation will highlight areas for compliance staff and counsel to be aware of and unresolved areas and challenges for telemedicine. While we will be using Delaware as an example, the issues will be applicable to any jurisdiction.
Educational Objectives:
Catherine Short talks with Eileen Grena, Assistant Dean and Executive Director of GICLS a/k/a Graduate, International, Compliance and Legal Studies and Pam Beech, Director of Graduate Programs of Widener University Delaware Law School about “Legal Degree Program Possibilities for Compliance Professionals.” We will talk about available legal education for compliance professionals at the graduate-level. These compliance degrees are completed entirely online with no residency requirement. We will discuss how a compliance education can help boost a career and educate the public about the compliance degrees available for both lawyers and non-lawyers at Delaware Law School.
First Healthcare Compliance hosts Stephen Dickens, attorney and Vice President of Medical Practice Services at SVMIC for an interactive discussion on “When It Just Is Not Working: Progressive Discipline & Termination.”
This presentation outlines the importance of providing effective employee feedback including performance improvement plans. Outlining best practices for documentation the simplest method for termination are addresses.
Objectives: 1. Recognize the importance of progressive discipline 2. Identify best practices for documentation 3. Discover the most effective way to conduct performance improvement plan and termination
First Healthcare Compliance hosts Donald A. Balasa, JD, MBA, Chief Executive Officer and Legal Counsel of the American Association of Medical Assistants (AAMA) for an interactive discussion on “The Role of Medical Assistants in Medicare CCM and TCM.”
The Medicare Chronic Care Management (CCM) and Transitional Care Management (TCM) programs are relatively new and are growing quickly. Individuals who are part of the Medicare Fee-For-Service program and meet certain criteria are eligible for CCM or TCM services provided by physicians and non-physician practitioners. These providers are permitted to delegate certain CCM and TCM tasks to unlicensed clinical staff such as medical assistants and receive reimbursement for such tasks as incident to the services of the provider.
The purpose of this webinar is to clarify what CCM and TCM tasks are and are not delegable to medical assistants, and what types of provider supervision are required. Citing explicit language from the CPT Code Book and the Medicare Benefit Policy Manual, the presenter will disprove the misconception that all CCM and TCM tasks may only be delegated to licensed professionals (such as RNs and LPNs).
Educational Objectives:
First Healthcare Compliance hosts Karna W. Morrow, CPC, RCC, CCS-P, AHIMA-approved ICD-10-CM Trainer, Director Consulting at Coding Strategies, Inc. for an interactive discussion on “Is Your 2019 Compliance Plan Ready?” Resources are limited in every medical practice. Time for audits and other coding/billing compliance related tasks is necessary but can frequently be scheduled for "tomorrow." This session will highlight the key components and assist in determining what needs to be done vs. what you've always spent time doing.
Educational Objectives:
Catherine Short talks with Trey Scott, attorney at Kennedy, Attorneys and Counselors at Law, a health law boutique in Dallas, Texas about “Good with God: An Overview of Stark, Anti-Kickback, and False Claims Act.” On this episode we will discuss important definitions, review exceptions and safe harbors, and provide an understanding of penalties for violations.
First Healthcare Compliance hosts Wendy Stirnkorb, President & CEO of Stirnkorb Consulting, LLC for an interactive discussion on “Scanning the Unscannable: Improving Patient Flow in MRI.” Let's Slay the Myth that MRI safety practices come at the expense of throughput. What if there were a better way to provide safe MR imaging to patients, in a practical way, that increased volumes and revenues with minimal investment? Would that interest you?
Educational Objectives:
First Healthcare Compliance hosts Raymond Ribble, founder of SPHER Inc. and co-founder of Fusion Systems Co., Ltd. for an interactive discussion on “HIPAA Security Rule - How to Manage Adherence.” Raymond leads this webinar on approaching a Security Risk Assessment and understanding the benefits and impact the audit has within your organization.
Educational Objectives:
Catherine Short talks with Matt Kelly, CEO of Radical Compliance, about “Whistleblower Hotlines, Retaliation, and Building a Speak-Up Culture.” We will discuss the current state of whistleblower hotline law, specifically anti-retaliation; and how a compliance officer can use a whistleblower hotline more productively to support a stronger speak-up culture across the board. We will also talk about the current state of anti-retaliation law, and the implications of the Digital Realty Trust v. Somers ruling from the US Supreme Court; and discuss how hotlines fit into the greater scheme of employees speaking up about misconduct.
First Healthcare Compliance hosts Stephen A. Dickens, attorney and Vice President of SVMIC for an interactive discussion on “Delivering Exceptional Patient Experience.” As trends away from patient satisfaction toward the patient experience, it is important for physicians, practice executives and staff to understand how this shift in ideology will affect their practice. Influencing patient experience begins with an understanding of the patient mindset and their barriers in understanding the healthcare environment.
Educational Objectives:
First Healthcare Compliance hosts Jonathan M. Fialkov, MD, FACS, President and Founder of Rational Surgical Solutions, LLC, for an interactive discussion on “Building the Bridge: Effective Use of Digital Media in Patient Education and Informed Consent.”
New approaches to patient education and standardization of the informed consent process utilizing cutting-edge technology create opportunities to strengthen the patient-doctor relationship, improve patient safety and experience, and support shared decision making initiatives.
Objectives: 1. Become familiar with the challenges and shortcomings of electronic health records in facilitating communications between patients and their healthcare team and the strategies for overcoming those barriers. 2. Understand the components of an effective informed consent/shared decision making process as well as the benefits. 3. Learn to utilize digital media to enhance patient safety and experience.
Catherine Short talks with Kristy Grant-Hart, Founder and CEO of Spark Compliance Consulting about her brand-new book, “How to have a Wildly Successful Career in Compliance.” We will discuss the how her book is great for those who are curious about becoming part of the compliance profession, but don’t know what the options are, or how to get to a place in the profession where they want to go.
First Healthcare Compliance hosts Pam Joslin, MM, CMC, CMIS, CMOM, CMCO, CEMA, CMCA-E/M, consultant with Innovative Healthcare Consulting for an interactive discussion on “Understand CERT Findings and What Your Organization Should Be Monitoring.” Since 1996, Centers for Medicare and Medicaid Services (CMS) implemented several initiatives to prevent improper payments. CMS' goal is to reduce payment errors by identifying and addressing billing errors concerning coverage and coding. The Medicare FFS Improper payment rate for 2017 was estimated at 36.2 billion dollars.
Educational Objectives:
Introduction to CERT Process: This webinar will educate you on the CERT process and how your organization can be proactive in identifying your improper payment categories to maintain compliance. The improper payment rates are categorized by type, specialty and geographical location. This is a great opportunity to see how your practice measures up to these national stats and information on how to respond if you receive a medical record request.
Review improper payment categories by specialties and geographical area
Review improper payment categories; how to respond to CERT medical record requests; and recognize the CERT timelines for documentation submission.
First Healthcare Compliance hosts Nathan Fish of Greenberg Traurig, LLP, Sean McKenna of Law Office of Sean McKenna, PLLC, and Brad Smyer of Alston & Bird LLP for an interactive discussion on “Healthcare Conflicts of Interest 101: Fraud and Abuse Examples and Recent Trends from AKS and Stark to Private Enforcement.” These attorneys present an excellent overview of healthcare fraud and abuse laws and discussion of recent enforcement trends.
Educational Objectives: 1. Identify significant federal and state fraud and abuse laws, including AKS and Stark and their state counterparts 2. Discussion of recent enforcement trends, including private enforcement of fraud and abuse laws 3. Provide high-level tips on ensuring compliance
Catherine Short talks with David T. Womack, President and Chief Executive Officer of Practice Management Institute about “The Terrific Need for Continuing Education and Training in Healthcare at all Levels.” As we know, continuing education for administrative employees is an important aspect of running a successful medical office. Changing codes, compliance guidelines and federal regulations can become landmines if the practice is not up to speed on current standards. We discuss the need for staff education for the good of the practice in terms of compliance and profitability, how staff education leads to higher morale and confidence in their skills, and address some examples of types of regulations that impact a medical office.
First Healthcare Compliance hosts Nadia Sawaya-Gauckler from InterCultural Communications LLC, for an interactive discussion on “National Standards for Culturally and Linguistically Appropriate Services (CLAS).” Nadia has developed and implemented CLAS strategic interventions across organizations such as Mayo Clinic, Johns Hopkins Medicine, New York City Health and Hospitals Corporation and DaVita HealthcarePartners. This presentation offers participants an overview of the CLAS Standards.
Educational Objectives: 1. What are CLAS- Background/Context and Compliance 2. Why are CLAS important- Impact on health care delivery 3. How to implement CLAS- resources and tools to promote and implement CLAS in health care settings
First Healthcare Compliance hosts Warren S. Cook, Co-Founder, President & CEO of SymbianceHR, for an interactive discussion on “Risk Management of Employment Practices.” He will educate and inform your management and supervisors on best practices and strategies to minimize risk and liability in your employment practices. This interactive webinar will engage your people leaders to promote a more holistic perspective in how they carry out their duties and responsibilities in your business. The entire employee life cycle and the employment risks at each stage will be discussed, including how to improve your human resource management of the workforce and equip your managers and supervisor with the knowledge they need to be successful people leaders.
Educational Objectives:
On this month's podcast, Catherine Short (@1sthcc) talks with Allyson Britton DiRocco (@MorrisJamesLLP), attorney at Morris James LLP, about “ADA: Important Issues and Trends for Employers.” Join us for this episode as we provide insight into the legal analysis of ADA claims brought by employees from the employer viewpoint, including what is protected and what qualifies as a disability under the ADA, and how to handle a reasonable accommodation request from an employee.
First Healthcare Compliance hosts Stephen Bittinger of Nexsen Pruet, LLC, for an interactive discussion on “The UPIC Revolution: CMS Integrity Auditors 2.0.” This webinar is a summary of the CMS UPIC program, the key differences from prior integrity audits, and tools to prepare and defend.
Educational Objectives:
First Healthcare Compliance hosts Grant Elliott, President and CEO of Ostendio, for an interactive discussion on “Concerned about GDPR compliance? If you already operate in line with HIPAA you may be closer than you think.” On May 25, 2018, the General Data Protection Regulation (GDPR) came into effect, impacting how businesses collect and process data from individuals.
If you currently have or plan to have website or app visitors who are in the EU, or if you process any form of data, ePHI included, on individuals from the EU, you need to comply with GDPR. The good news is that if you’re already operating in line with HIPAA, you may be closer than you think!
Educational Objectives:
First Healthcare Compliance hosts Trey Scott, attorney at KENNEDY, Attorneys and Counselors at Law, for an interactive discussion on “Moneytalks: Medicare Part A and Part B Appeals.” This webinar will discuss the appeals process for Medicare Part A and Part B under 42 C.F.R. Sec. 405.900 et seq. It will also discuss the delays in the process and case law discussing the delays.
Educational Objectives: 1. Providers will understand the appeals process and each step after completion of the webinar. 2. Providers will understand what options are available to them if they experience a delay in the appeals process. 3. Providers will understand the special initiatives that are available to them at the ALJ level.
Catherine Short (@1sthcc) talks with Jill Longo, Associate Corporate Counsel for health insurer Medical Mutual of Ohio (@medmutual) about Durable Medical Equipment compliance. We will have a discussion around the proper documentation and billing procedures in order to distribute DME from your practice, how to implement compliance measures in your practice with regard to DME, and what to do if you are audited or investigated for #DME billing.
First Healthcare Compliance hosts William Simpson, COO of Identillect Technologies, for an interactive discussion on “Cybersecurity Educational Series 2.0: Email Protection & Preventive Measures.” This webinar takes a look at cyber security best practices for a preventative approach to security with regards to email communications and mobile devices in today’s digital environment.
Educational Objectives: 1. Email Communications: How it functions & its vulnerabilities 2. Email Compliance: What to document and implement for compliant email communications 3. Mobile Devices/Social Media: Security concerns and best practices
Catherine Short talks with Stan Szpytek president of Fire and Life Safety, Inc. (FLS), a consulting firm that provides life safety, risk management and emergency preparedness programs for providers of all types with special focus on health care, long-term care facilities and senior services, and a founding member of the Emergency Management Alliance (EMA) about Emergency Preparedness in Health Care Facilities in Consideration of CMS Requirements of Participation.
First Healthcare Compliance hosts William Simpson, COO of Identillect Technologies, for an interactive discussion on “Cybersecurity Educational Series 1.0: Threats Overview & Password Policies.” This webinar identifies current social engineering and malware threats, password policies and best practices to protect your organization.
Educational Objectives: 1. Threats Overview: Malware, phishing and social engineering 2. Password Policies: Best Practices; 2FA and how to use it 3. Email Spoofing: Identifying and preventing it
First Healthcare Compliance hosts Kelly Ogle, BSDH, MIOP, CMPM®, CHOP® an OSHA and HIPAA Specialist from DoctorsManagement, for an interactive discussion on “Ergonomics for Medical and Dental Professionals.” Ms. Ogle will give a complete overview of what ergonomics is and what is caused by not using proper precautions in your job. There will be a review of Muscular Skeletal Disorders and aids that can be used to prevent these disorders.
Objectives: 1. Define Ergonomics and the risk factors in your job 2. Recognize Muscular Skeletal Disorders and what can be done to prevent them 3. Identify aids for ergonomic issues in the workplace
In this episode, our host, Catherine Short, talks with Jennifer Gimler Brady, Partner and General Counsel at the law firm of Potter Anderson & Corroon in Wilmington, DE, about Employee Handbooks: Basics and Must-Haves- discussing why employers of all sizes should utilize employee handbooks. They also discuss key employment laws that should be addressed in handbook policies, and some "best practice" recommendations.
Jennifer concentrates her practice in the areas of health, labor and employment law, and commercial litigation. She regularly advises long- term care providers, physician practices and other health care providers on a variety of issues, including licensing and certification, fraud and abuse laws, medical privacy and confidentiality, and litigation matters. Jennifer also counsels employers on labor and employment issues, including unionization and collective bargaining, employee supervision, discipline and discharge, sexual harassment, and employment discrimination.
First Healthcare Compliance hosts Pam Joslin, MM, CMC, CMIS, CMOM of Practice Management Institute, for an interactive discussion on “Keys to Optimizing Your Revenue Cycle.”
Statistics tell us that "90% of denials are preventable and 67% are recoverable." The efficiencies of your Revenue Cycle Team have a critical impact on the financial success of your organization. Creating and maintaining an experienced and well-trained team is significant in obtaining your financial goals. Join this presentation and learn the value of performing your gap analysis to see "where you are" and set goals for "where you want to be."
Objectives: 1. Tips on how to spend less time worrying about your billing 2. Key areas of focus for your revenue cycle 3. Value of having the "right person" in the right place on your revenue cycle team
First Healthcare Compliance hosts Karna Morrow, Director of Consulting at Coding Strategies, —CPC, RCC, CCS-P, AHIMA Approved ICD-10-CM Trainer, for an interactive discussion on “Auditing For the Right Reasons, the Right Way.” Every practice knows the value of an internal audit. Resources are limited and it is important to ensure the task is being performed for the right reasons and in a way that ensures positive results in the practice.
Objectives: 1. Recognize that the reason for an audit drives the process 2. Identify ways to incorporate audit results into practice patterns 3. Learn what not to do with audit results
First Healthcare Compliance hosts Sean McKenna, Esq., Shareholder, of Greenberg Traurig, LLP and Michael McCarthy, Esq., Associate General Counsel for Cooper University Health Care, for an interactive discussion on “Trendspotting--False Claims Act Enforcement in Health Care.” Both are former health care fraud AUSAs. Now, Sean is in private practice and Michael is in-house at a health system. These two presenters will use their diverse professional backgrounds to analyze False Claims Act enforcement trends.
Educational Objectives: 1. learn how the Supreme Court's decision in Escobar has been interpreted by federal district and appeals courts 2. gain a better understanding of how law enforcement uses the Yates Memo in civil and criminal investigations 3. learn what health care services will be targeted for enforcement in 2018
First Healthcare Compliance hosts Lauren Russel, Associate Attorney at Young Conaway Stargatt & Taylor, LLP, for an interactive discussion on “Sexual Harassment in the #MeToo Era: What You Need to Know to Protect Your Business.” A new wave of sexual harassment complaints is anticipated by employers across the country. The focus on workplace harassment efforts is shifting from protecting the business to eradicating workplace misconduct so that we prevent claims from being filed in the first place. This webinar will focus on what businesses need to do to come into line with business expectations in the current era.
Objectives:
Understand what behavior constitutes unlawful sexual harassment. Identify seemingly benign workplace conduct that may be the seed of a future harassment claim. Identify affirmative steps to bring workplace policies and reporting/investigation procedures into line with current practices.
First Healthcare Compliance hosts Bridget Smudrick, a CLIA Specialist for Doctors Management, for an interactive discussion on “Current Inspections - What to Expect When the Surveyor Arrives”. Laboratory inspections are always evolving. Learn the latest emphasis and how to prepare in advance.
Objectives:
Learn what the surveyors are currently focusing on. Know how to prepare in advance. Understand how to respond to deficiencies.
First Healthcare Compliance hosts Todd Sexton, CEO of Identillect Technologies, for an interactive discussion on “Red Flag Rule - HIPAA Compliance.”
This webinar will be covering the specifics of The Red Flag Rule which expands upon HIPAA compliance requirements, as well as covering the requirements of secure/compliant digital communications.
Objectives: 1. Familiarize attendees with the specifics of the Red Flag Rule 2. Familiarize attendees with current HIPAA requirements for digital communications 3. Walk through the vulnerabilities inherent to digital communications, and how to properly address them
Catherine Short, Partnership Marketing Specialist at First Healthcare Compliance, hosts Reid Kiser, Founder and CEO of Kiser Healthcare Solutions, LLC, strategic and business operations consulting services to healthcare industry stakeholders, for an interactive discussion on “Quality Measurement in Practice.”
This podcast will provide attendees with an increased understanding of quality measurement so that they can effectively identify and use measures to improve the quality of care, while keeping in mind industry’s value-based goals.
Objectives:
Define quality measurement and today’s drivers of measurement
Describe the types of quality measures and practical uses for measures
Discuss opportunities to maximize improvement with quality measurement
Catherine Short, Partnership Marketing Specialist at First Healthcare Compliance, hosts Tae Seangpeoam, Founder of Neztec Solutions Inc., a company that enables corporations to meet regulatory compliance and delivery of corporate messaging by delivering real-time, visual communications in the area of safety and compliance, for an interactive discussion on “Emergency Crisis Defense.”
In this podcast, Tae Seangpeoam, lead engineer of EZpass and 9/11 disaster recovery, will speak about the importance of having a more proactive emergency evacuation plan, especially in large public spaces such as hospitals, high-rise buildings, and complex facilities. With his experience, Tae now runs an advanced compliance communications company to minimize exposure in the 21st Century workplace.
Objectives:
Why most existing communications at the workplace are failing.
Why it is important to have a more proactive emergency evacuation plan in place.
How to prepare your workplace to be ready for uncertain situations.
Catherine Short, Partnership Marketing Specialist at First Healthcare Compliance, hosts Steve Wilder, President and COO of Sorensen, Wilder and Associates, a safety and security consulting group, for an interactive discussion on “Security Management in Healthcare Facilities.”
This podcast focuses on how "security" can mean a lot of different things, with a lot of different influences and caveats. In this program, Steve Wilder, a nationally recognized healthcare security consultant, will look at different ways of addressing security in different types of facilities.
Objectives:
First Healthcare Compliance hosts Dawn Cooper, Manager for Diversity and Cultural Competency at The Arc of the United States, for an interactive discussion on “Strategic Planning To Action: Becoming a Culturally Competent Organization.” Diversity has long been viewed as a way for organizations to leverage talent to meet organizational objectives, however, man initiatives fail to yield results because diversity is approached as a numbers game (how many diverse people should I hire) instead of a systems change, i.e. what kind of organization do we need to be successful and meet the needs of our constituents? The Arc’s 2010-2016 Diversity Strategic Action Plan focuses our efforts to become an even more powerful advocate for people with I/DD. Join us as we talk about how to position your diversity initiative for success and achieve your organizational mission and vision.
Objectives: 1. Review the strategic purpose of diversity, inclusion and cultural competency 2. Review the need for a sound organizational imperative 3. Learn key steps to successfully implementing a change strategy around diversity within your chapter
Catherine Short, Partnership Marketing Specialist at First Healthcare Compliance, hosts Ray Ribble, founder of SPHER Inc. a healthcare cybersecurity company, for an interactive discussion on “Addressing Unauthorized Access - Knowing who is looking at your PHI.”
This podcast focuses on a discussion of the current landscape as it relates to unauthorized access of patient PHI within the healthcare community. Ray guides us to what measures can be deployed to protect and detect unwanted eyeballs.
Objectives: 1. Review status of PHI Protection 2. How is PHI monitored today 3. What can I do to protect my patients PHI from unauthorized access?
Sheba Vine, JD, CPCO, talks about Qualifying Events that Trigger COBRA Benefits. COBRA is a federal law and is short for the Consolidated Omnibus Budget Reconciliation Act of 1985. COBRA applies to employers with 20 or more employees that offer group health plans. COBRA provides the right to continue coverage in an employer group plan in certain instances. If an individual elects COBRA coverage, then he or she is required to pay the full premium at the group plan rate. In addition to the premium, the employer can charge a 2% administration fee. When determining if an employer has to comply with COBRA, it must have at least 20 employees. To determine this, both full-time and part-time employees are counted. A part-time employee only counts as a fraction, equal to the number of hours that the part-time employee worked divided by the hours an employee must work to be considered full time. If the employer doesn’t have 20 employees, then it is exempt from COBRA. But many states have a continuing coverage law that is similar to COBRA. These are referred to as the mini-COBRA laws. Under COBRA only qualified beneficiaries have the benefits of COBRA. A qualified beneficiary is anyone that participates in the employer sponsored group health plan. This includes all employees that participate in the group plan, spouses and any dependent children. It is important to note that the individual must be covered by the plan on the day before an event that causes loss of coverage. There are instances where COBRA benefits would not apply such as an employee who is not eligible to participate or an employee who has declined to participate in the health plan. There are notices that the employer is required to provide under COBRA. A general notice of COBRA rights must be provided to covered employees and spouses, within the first 90 days of coverage under the plan. Employers usually include this notice in the Summary Plan Description. There is also the election notice, which describes the right to COBRA continuation coverage and how to make an election when there is a qualifying event that causes an employee and his or her family members to lose health coverage. A qualifying event triggers the right to COBRA coverage which includes: 1) an employee’s voluntary or involuntary termination of employment, unless it is due to the employee’s gross misconduct. Although COBRA does not define what counts as gross misconduct, many states refer to the definition provided under the respective state’s unemployment laws; 2) reduction in hours of employment if it effects their eligibility under the health plan; 3) divorce or legal separation of the spouse from the covered employee; 4) an employee’s entitlement to Medicare; 5) the death of a covered employee; and 6) the loss of dependent status, for example, when a dependent reaches an age that no longer qualifies them for coverage under the parent’s health plan. An individual that elects coverage under COBRA can stay on the employer’s group health plan for a maximum of 18 or 36 months, depending on the type of qualifying event. Now that we know what events trigger COBRA, let's talk about COBRA and FMLA. FMLA applies to employers with 50 or more employees and it provides up to 12 weeks unpaid job protected leave for an employee’s serious health condition, for the birth, adoption, or foster of a child, or for the employee to care for a family member’s serious health condition. It also applies for qualifying military leaves which provides for 26 weeks of unpaid job protected leave. For an employee to be eligible for these FMLA benefits, the employee must have worked for the employer for 12 months and have worked at least 1250 hours. During any FMLA leave, an employer must maintain the employee’s coverage under any group health plan. Employer contributions must be the same as if the employee had continued to work his/her normal schedule. This means that if the health plan requires an employee to work 30 hou...
First Healthcare Compliance hosts David M. Sommers, MD, JD, LLM, Medical Director and Chief Compliance Officer at Medsome LLC, for an interactive discussion on “The Second Victim Conundrum: Recognition, Intervention, and Protection of Peer Support.”
This webinar reviews the literature dealing with "second victims," who are clinicians involved in a patient safety incident often as a result of medical errors. New programs providing care for these caregivers have developed and the legal protections of these efforts are discussed.
Attendees will learn the impact errors have on clinicians, review literature involving medical errors and the new support programs that have developed to aid these caregivers, and discuss of the legal protections for these support programs and statements made by second victims in addressing the patient safety event.
Objectives: 1. Identification of the impact errors have on clinicians. 2. Review of the literature involving medical errors and the new support programs that have developed to aid these caregivers. 3. Discussion of the legal protections for these support programs and statements made by second victims in addressing the patient safety event.
First Healthcare Compliance hosts Nathan Fish, and Somer Hayes, associates at Greenberg Traurig, LLC in Dallas, Texas, for an interactive discussion on “Private Enforcement of Healthcare Fraud & Abuse Laws”. They counsel health care clients on a wide range of regulatory issues, including fraud and abuse, Stark and AKS. This will be a discussion of private enforcement and fraud abuse laws, including kickback prohibitions, and the legal theories used by private individuals and entities to enforce state and federal fraud and abuse laws.
Objectives:
Background on federal and state fraud and abuse laws Overview of legal theories used by private individuals and entities to enforce state and federal fraud and abuse laws Recent examples of private enforcement of fraud and abuse laws
First Healthcare Compliance hosts Tina Colangelo, CEO of Colangelo Consulting, for an interactive discussion on “MACRA,MIPS and APMs- The New Era of Medicine”. This webinar will give attendees everything they need to know about MACRA's Quality Payment Program all in one place! It will cover a brief overview of the reason for the shift from fee-for-service to value-based care, important terms to know, timelines of payment adjustments, important dates to remember, the pitfalls of MIPS 2017, and reporting strategies.
Objectives: 1. 3 Keys on Training for MACRA success 2. Tips on all four performance categories 3. Pitfalls of MIPS 2017
An interview with Kelly Anderson, National Inside Sales Manager at First Healthcare Compliance.
Kelly, can you start by telling me a little bit about yourself and your role here?
Thank you for talking with me today, I’m excited to tell you about our sales team here at First Healthcare Compliance. My career in sales started many years ago selling solutions to my customers in the carpet industry while working for the DuPont Company. Over the years I had different roles in both sales and marketing management at DuPont and later Koch Industries when they acquired that business. Those experiences allowed me to work with many different customers, all of different sizes and needs. My role here at First Healthcare Compliance is to ensure our sales team delivers the best healthcare compliance solutions available in the marketplace to a wide range of healthcare providers; anywhere from private practices, hospitals, long term care facilities etc. We even have solutions specifically for billing companies.
Tell us about the First Healthcare Compliance sales team:
Our sales team is awesome! Although we are all quite different in personality and background, we all have one important thing in common, we are problem solvers. I always say that the clients we engage with are the busiest people I have ever worked with. I have called on CEO’s that have less stress than most of these administrators. Healthcare is dynamic, with different fires to put out everyday and those issues tend to land on our client’s desks. We know regulatory compliance is a struggle for many because it has become pretty complex and it’s always evolving and changing. Our sales team works with those responsible for compliance in their organization to identify what areas they are finding challenging and then educating them on our solutions to ease those burdens. It’s really great selling something that you know solves problems for these folks and makes their jobs less stressful.
What new things are happening in the sales department, what can clients expect to see in the future:
As a company, we are always looking to add value to our solutions to address client’s needs and challenges. We strive to listen to client’s “pain points” and then address them as quickly as possible with innovative, yet easy to use and implement solutions.
We use social media platforms to push our solutions out to the market: Facebook, YouTube, Twitter etc, so folks can learn about new initiatives. Go on any of those platforms and you’ll learn about our new Fundamentals course and book for folks who are looking for a base fundamentals understanding of compliance without investing in full on compliance certification curriculum.
First Healthcare Compliance hosts Karna Morrow, Director of Consulting for Coding Strategies for an interactive discussion on “ICD-10-CM Updates for 2018” and learn from an auditing expert!
This webinar will highlight the key changes to ICD-10-CM, effective 10/1/2018. We will focus on identifying changes to existing codes that may require additional specificity, learning which new codes may impact an individual practice, and reviewing guideline changed that may impact existing codes.
Objectives:
Identify changes to existing codes that may require additional specificity Learn which new codes may impact an individual practice Review guideline changes that may impact existing codes
First Healthcare Compliance hosts Jim Cucinotta, CEO of Halo Health International for an interactive discussion on “Educate Your Patients into Action.” The key to getting patients to comply with treatment plans is to make them well-informed about the benefits and pitfalls of not following it. This webinar will give you some strategies on engaging and energizing patients through the use of health and wellness education technologies that are easy to use and implement.
Objectives:
Understand how to Increase Patient Engagement through better communication Learn how to Improve Patient Satisfaction through integration of patient education platforms Understand how to Improve Patient Adherence of treatment plans by being a source of information and inspiration
First Healthcare Compliance hosts Shannon DeConda of NAMAS and DoctorsManagement for an interactive discussion on “Making the Complexities of E&M Auditing Simplistic in Approach and Understanding for Complete Physician Buy-In.” During this session, we will take actual medical records and break them down from an auditing analysis point of view. We will walk through records, identifying gray areas within documentation guidelines, and why different elements may or may not be counted. This was originally a hands-on session and attendees were provided with the medical record and a laminated reusable auditing grid, putting them in the driver’s seat for auditing analysis during this session.
Objectives of this webinar: 1. Defining the history of the E&M and how it SHOULD project the severity of the patient according to the patient 2. Defining the Exam and Work of the physician as tools used by the provider for reasonable patient assessment 3. Identifying how the MDM should include the assessment of the provider of the patients clinical severity according to his analysis and interpretation all to portray the patient's true complexity of care.
The presentation will examine the importance of Background Checks and Exclusion Screening in the context of Risk Management and Health Care Compliance principles. First, it will examine the intersection of risk management and compliance in terms of their shared goals and objectives; second, the presentation will demonstrate how the vast majority of costs and risks in health care are closely linked to an organization’s employees; third, the presentation will explain why background checks and exclusion screening is so critical to the process of selecting employees, and last, the presentation will discuss how background checks and exclusion screens can be defeated and the best ways of responding.
Hello, this is Catherine Short with First Healthcare Compliance. I’m here with Karen Blanchette, PAHCOM Association Director, at the 29th Annual PAHCOM conference.
Hi Catherine! It’s a pleasure to be speaking with you. The conference is phenomenal, as you’ve seen first hand.
It is wonderful here at Clearwater Beach! The weather has been just beautiful. Why don’t you tell us more about “Leader of the Pack” and the wonderful conference that we are having here?
Our conference services medical office managers and administrators from across the country- all different specialties. We gather here every year, lately here in Clearwater Beach. And today we are at the beautiful Wyndham Grand Hotel. It's a brand new facility and we’re so so thrilled to be here. The best part is that all of these managers get together to share knowledge. Our “Leader of the Pack” theme identifies how each of these managers has to really take control over their career and their practice. And to make sure that they are bringing the best of medical practice management to their towns when they leave the conference and go back to serve their doctors and their patients.
We really appreciate this conference! Can you tell us more about the PAHCOM certification process and why they would want to be certified?
Certification helps to identify that they are knowledgeable. And PAHCOM, whether you are certified or not, is a fabulous resource. It puts together all of these managers- we get to share knowledge. That’s what PAHCOM is founded on. For 29 years, we’ve been sharing knowledge. We bring managers together so that we can help managers be successful in their practices. But certification helps to identify those who really do have the knowledge that they need to be successful in the practice. There are so many facets- nine domains actual- of practice management that are important to be successful. Everything from revenue management to human resources and compliance. And all of these areas are critical to a successful practice. And the certified medical manager credential helps to articulate those people who carry that credential and are actually knowledgeable in those areas. Some people interview well, but they don't actually know what they’re doing. And how do physicians, how do fellow managers know, how do you know? One of the things that we find are the managers who have been doing this job for thirty years know so much. And they may not have a formal college education or maybe they do have some college, but maybe not a degree. But their knowledge of practice management is exemplary. And the certification helps to identify those people. Because they are really bringing value to the practice. They are bringing money in the door, making sure that the practice is protected legally, they are making sure that the patients are getting the best service possible. All of these things are really really critical to a successful practice and we help to identify who those people are. And if you’re not one of those people- that’s okay. PAHCOM gives you the resources that you need in order to become somebody that can be certified. So either you have the knowledge and it’s time to identify that you do, or you work with us and we help to mentor you and get you the information you need, access to resources, education, and training. Some of which First Healthcare Compliance offers! And we are able to turn out very experienced and very well educated practice managers. We’re building the industry.
We certainly value the association and partnership that we have together with PAHCOM. Thank you so much, we really appreciate it.
We really appreciate you being here because support from groups like First Healthcare Compliance helped to bring the whole complete picture together. If we didn’t have experts like yourselves out there offering the training and education like you do, we wouldn’t be able to pull this off. It’s such a multifaceted plan with the practice ma...
Join First Healthcare Compliance and Shauna Itri, Esq of Berger & Montague for a discussion of False Claims Act Liability And Whistleblower Laws in the healthcare setting.
A whistleblower or qui tam action can provide financial rewards to individuals who provide information that a company or individual has defrauded the government. The primary statutes under which this relief may be sought are the federal and state False Claims Acts (“FCAs”). State and federal governments pay hundreds of billions of dollars each year for pharmaceutical drugs, medical devices, hospital care, and nursing home care through Medicare, Medicaid, and other programs. Thus, the False Claims Acts are often applied in the health care industry to fight fraud, . Whistleblowers who report this fraud receive 15-25% of the amount recovered.
Learning Objectives 1.Recognize how the False Claims Act (or Whistleblower Laws) are used as fraud enforcement tools by incentivizing whistleblowers with rewards. 2. Discuss prosecutorial trends and examine recent cases brought under the False Claims Act. 3. Detect fraud and understand reporting mechanisms to protect yourself and your company.
Health care providers often have a difficult time trying to determine when co-payments and deductibles may be properly waived. Similarly, the extension of "professional courtesy" continues to be a problem in many practices. In this session, we will cover the risks you face when waiving co-payments and / or deductibles involving government and private payor plans.
This webinar will cover essential concepts pertaining to the disaster management continuum including preparedness, mitigation, response and recovery. The presentation will focus on the necessity of “All Hazards Planning” and utilization of a trusted emergency management model known as the Incident Command System (ICS) as it pertains to health care facilities. The program will also include a brief overview of new CMS conditions of participation regarding emergency preparedness. Objectives: 1. Promote the importance of "All Hazards" Emergency Management and how it relates to the health care environment. 2. Review essential concepts of emergency management including Hazard Vulnerability Assessment (HVA) and the Incident Command System (ICS) 3. Illustrate the key elements of new CMS conditions of participation pertaining to Emergency Preparedness and the impending compliance deadline of 11/15/17.
Today we have a very special guest joining us! Regina Miller is our Client Services Team Lead here at First Healthcare Compliance.
Regina, can you start by telling me a little bit about yourself and your role here?
Sure. I have been in the healthcare arena in various leadership roles for over thirty-three years. And the majority of that has been in the client experience roles and responsibilities. Here at First Healthcare Compliance, I am the team leader of an awesome Client Services Division. Each member of my team is dedicated and committed to our clients and to doing all that needs to be done to ensure they have a successful experience when they contact us.
As part of that, what is your favorite part about working with our clients?
That’s pretty easy! We have a great, comprehensive healthcare compliance solution. It’s affordable, it's scalable, and it’s applicable to the various healthcare segments. So what I really enjoy most is working with such a diverse client base. One moment I can be talking to a physician's practice that has ten employees, and the next moment I can be talking to a healthcare system that has thousands. So there’s a lot of diversity in the scale of the practices and the organizations that we speak with. But there’s also a uniqueness to how applicable our program is to the various healthcare segments. I can be talking to a billing practice or a medical waste provider, as well as a skilled nursing facility. There’s a vast range to the areas of the healthcare market where our solution is applicable.
Definitely. I think one of the great parts about that too, is the personal connection our team is able to end up creating with our clients. Our team is working with each person to help develop their compliance program and utilize the tools we provide. You spend so much time working with our clients that they really do become friends as well as clients.
That absolutely is true. We certainly work to build relationships and friendships with our clients- as well as partnerships. We want them to see us as a partner in their compliance success.
In your role as the Team Leader for our Client Services department, I know you have a lot of vision about how to develop the team as we move forward. What are some of the ideas that you have in mind to help our clients even more?
I think that Client Services and the services we provide is a differentiator. We are looking at ways that we can be more proactive in our solutions for the clients. We want to think about what you need before you need it. That’s a big part of my vision. Secondly, I want every experience, whether you are a small practice or a large healthcare network, to be a great experience. You won’t get one experience if you are a small practice and another if you are a large healthcare network. The overall experience should be one of excellence. You can count on us no matter how small the question or how large the problem and solution is. Thirdly, at every touch point we have with each client, we want to provide what they need, when they need, and how they need it. We aren’t just hitting them with what they need without consideration for how they need it. I want to make sure we are comprehensive in how we deliver our solutions and our assistance to our clients.
You guys have really done a great job with that already, so I’m excited to see what more you are able to do to improve our client experience in the future as well. Was there anything else you wanted to share with our listeners?
I just want to let them know what a great Client Services team we have. They are always available and accessible and will work tirelessly to make sure that your solutions and needs are met at every encounter.
Once people offered their opinions and recommendations about surgeons and physicians in person. Today, people grab their smart phones and instantly post their thoughts, reviews, and opinions online for countless others to see. Is your practice equipped to manage its reputation online? Join us as we discuss how to manage your practice's online reputation.
Objectives: What reputation means in today's world Why medical professionals should be aware of their online reputation How to protect, maintain and build your practice's reputation
The CDC has officially declared prescription drug abuse in the US an epidemic - 100 people die from drug overdoses every day, most caused by prescription drugs. As a result, healthcare risk managers are strongly encouraged to mitigate exposure for providers and organizations facing the increasing regulatory and legal consequences of inappropriately prescribing and monitoring controlled substances.
The PCI Basics webinar will cover the history of PCI, why it is important to comply with PCI, and how to become compliant.
An interview with Valora Gurganious, Partner and Senior Management Consultant at DoctorsManagement, LLC.
What is DoctorsManagement and what do you offer?
DoctorsManagement, LLC (DM) is a leading provider of business solution services to a wide variety of organizations including leading academic institutions, integrated delivery health systems, physician owned and managed groups, and more than 30 law firms that represent these various organizations. Our firm is an independent provider of healthcare financial, regulatory compliance and operational management consulting services assisting clients to effectively address the complex challenges they face. DM ensures that our clients deliver superior customer and market performance through integrated strategic, operational, and organizational change.
DoctorsManagement has been in business since 1956 and under the same president (Paul L. King) since 1987, and we believe our name says it all. We are focused on empowering healthcare providers through our business of medicine services.
While competing firms may have divisions or departments dedicated to other industries, we are an organization with a sole focus on healthcare.
What do you see as the biggest need in the healthcare industry?
Today more than ever, providers need a trusted advisor to help them to navigate these uncertain times. In the US, providers and insurance companies are dealing with political upheaval and volatility associated with the debates over the Accountable Care Act and the Better Care Reconciliation Act.
While this debate continues, the practice must remain current, compliant and efficient to respond to shrinking reimbursements, pay-for-performance payment models, stricter compliance regulations and narrower margins. A management consultant can help the practice to position itself to be lean and agile, while optimizing its financial and quality performance.
Medical practices are small businesses, and despite their mission to deliver superior healthcare, each provider typically produces over a million dollars of annual revenue, they control one-quarter to one-half million dollar payrolls, and treat thousands of patients each year. Like it or not, they must run their practice as a business if they hope to stay in business. Our firm's mission is to help physicians thrive within the business of medicine.
What is your favorite part about working in the healthcare industry?
My favorite part of working with DoctorsManagement is its people. DoctorsManagement continues to lead the healthcare industry with over 80 professionals equipped with the skills and expertise specifically designed to address the full range of business issues related to healthcare. DM professionals are MBAs, JDs, CPAs, Analysts, Compliance Specialists and Auditors, and each adheres to the highest standards of ethics and apply technical knowledge and experience to help our clients achieve their goals. These goals include increasing profits, enhancing patient satisfaction, increasing employee morale, and reducing the stress of doctors and administrators.
Our company is strategically organized into eight (8) business segments, all of which specifically address the needs of the physician-owner. These include Practice Management, Regulatory Compliance, Financial/Accounting, Human Resources, OSHA/HIPAA/CLIA, Credentialing, Data Analytics, and “Power Buying” (our in-house GPO).
Our professionals not only offer analysis and advice to our clients, we work with our clients to IMPLEMENT those process improvement strategies and ADJUST those plans, as necessary, in response to changing circumstances. DoctorsManagement’s motto says it all: “leave the “business of medicine” to us”. We are committed to our client’s success in this constantly changing healthcare environment.
A discussion covering the issues and misconceptions surrounding the implementation of security measures within the framework of a healthcare practice.
First Healthcare Compliance hosts Jennifer Kirschenbaum of Kirschenbaum & Kirschenbaum for a discussion on what information is protected by HIPAA, how you can use protected information, how to protect against a breach and what to do if a breach happens.
An Interview with Karen Graver Toohey, founder of the Graver Toohey Group. What Is The Graver Toohey Group and What Do You Offer? My background is in healthcare internal auditing, as well as public accounting. The goal of The Graver Toohey Group is to provide healthcare compliance and internal audit services to clients, whether they are hospitals or physician practices. My passion and desire is to work in healthcare compliance. What is great about working with us, is that The Graver Toohey Group is flexible, whether you are looking for someone to create one or a few new compliance related policies, auditing compliance with those policies, or helping you create an entire compliance program, we are here to meet your needs. In my opinion, healthcare compliance is all about implementing the seven (7) elements of an effective compliance program. If you are not familiar with what those 7 elements are, you can go to my website where each one is explained in greater detail. More importantly, the website outlines how The Graver Toohey Group can help you implement each element of the compliance program. Often, when implementing a program, there is a need for someone with a specific expertise. For example, the OIG has been spending time reviewing providers’ use of electronic health records. They have concerns that providers may be cloning or cutting and pasting health record information from one visit to another, or from one patient to another. The industry is also focusing on how providers are using social media to communicate patient information. Are providers taking appropriate measures to protect health information? If you are concerned about these specific risks or others, I have a great network of experts, that can help you address those specific needs, if we are unable to support you. I have recently joint ventured with Victor Prospero of Prospero Consulting. Prospero Consulting has been in business for over 20 years, and offers a variety of accounting services where their primary focus is on providing interim CFO and Controller services; performing special accounting work; and helping clients implement new information systems to name a few. Prospero Consulting provides a great complement to the services offered by The Graver Toohey Group, and I am excited about the partnership that we have created. I believe there are many hospitals and physician practices that can benefit from services offered by both companies. How many service providers do you know that can serve your accounting, auditing and compliance needs? This is clearly a unique relationship, and the value of integrating services offerings by well-seasoned professionals such as Victor and myself will become clear to those who choose to use our services. What Do You See as The Greatest Need in The Healthcare Industry? I think one of the greatest needs we have in the healthcare industry is to develop more service providers that are focused on providing reasonably priced compliance services to clients. Due to the continued growth and complexity of healthcare regulations, this is not an easy task. Certainly, First Healthcare Compliance has been very successful in accomplishing it. The Graver Toohey is committed to doing the same. Additionally, there is a growing need for continued education of the regulatory changes that impact compliance. These changes can lead to many in the industry, including physician practices, feeling overwhelmed. I think there is a need for service providers to provide structured periodic training sessions so that healthcare providers are not left wondering whether they have received the appropriate education through the myriad of sources of information coming their way. Along with this education, service providers can support clients develop a roadmap to ensure compliance with regulations within appropriate timeframes. This a service that The Graver Toohey Group can certainly provide to clients.
The seminar will include examples of best practices for policies and language for employers to include in their Employee Handbook.
Attendees will learn how to: provide information to employers regarding employee handbooks, discuss different types of policies to include in employee handbooks, and discuss employer's use of the handbook can help in defending against employee actions.
This informative webinar will provide a comprehensive overview of common Life Safety Code (NFPA #101) deficiencies that are identified in health care facilities and provide guidance on maintaining a safe and compliant environment of care. The program will also focus on significant regulatory changes in health care facilities in accordance with the newly adopted editions of NFPA 101 and 99 (2012 editions).
An interview with Brian Johnson, Senior Director of Online Education at 4Med Approved.
Who is 4Med Approved? 4Med Approved is a leading content developer and educational resource on topics for health industry professionals. It was founded in early 2010 to address the increasing need in the medical community for clear, unbiased resources and online learning on topics relating to health information technology, compliance, government incentives, patient outcomes and more.
We provide unique online e-learning, certification and career gap training programs fully accredited by ACCME and ANCC for medical professionals, including providers, consultants, practice managers and their staff.
Our training is developed by leading Subject Matter Experts (SME’s) in the healthcare industry and updated regularly with the most current regulatory and compliance information.
How do your training courses work? All of our training is presented entirely online through self-paced or instructor-led programs and is fully accredited for students, nurses, coders, physicians, H&S and others. Courses are available in modular learning blocks or as pre-bundled course titles. Online training allows for flexible scheduling, fast credentialing, and targeted learning. Your CEU/CME is included, and you won’t find a more convenient commute!
What kind of training do you offer? Our training catalog includes fully accredited training and professional certificates in focused industry categories. We cover everything you need to stay current with government incentive programs, health IT, compliance, patient outcomes, and more. We offer three different levels of learning, based on what each student needs. Professional Certification courses are the most in depth, requiring approximately 9-15 Hours to complete. Specialty Certificates are a moderate length course option, most taking 4-9 Hours at a self paced rate. Proficiency Certificate Courses are perfect to brush up on the basics or as an introduction to a new area of learning. They typically take 1-4 Hours. We add new titles monthly, so there is always new training available! 4Med training uses our unique 10/10/10 online training method. Students begin by covering a 10 minute reading module, followed by 10 minutes of audio narration and video review of the material. Finally, we assess and retain the knowledge with a 10 question quiz and interactive lessons. Each course includes 3-25 modules. This training method applies to both our Self-Paced training and our Instructor-Led LIVE webinar workshops which are offered on our most popular titles once or twice a month. We are also more than happy to bundle various training modules into one customized course for your organization!
Too often, healthcare professionals fail to recognize escalating behaviors until it is too late, and they are the victims of a violent attack. In this session, Steve Wilder, a nationally recognized healthcare safety and security consultant and co-author of the book "The Essentials of Aggression Management in Healthcare: From Talkdown to Takedown" will discuss the Aggression Continuum and ways to de-escalate aggressive behaviors before physical violence erupts.
Designed to help your medical or dental practice maintain compliance with the new Hazard Communication Standard, including a review of the SDS format and the pictograms.
This training will provide you and your employees with knowledge that can help reduce the risk of diseases such as Hepatitis B, Hepatitis C and HIV, which could be contracted as a result of exposure to bloodborne pathogens. Medical and dental practices can eliminate the costs associated with remediating illness and injury resulting from BBP exposure by ensuring that employees receive proper training.
Medical Decision Making and the Medical Necessity Link with Laurie Desjardins of Coding Strategies.
First Healthcare Compliance hosts Ben Moore, CEO of TelmedIQ for a discussion on why secure text messaging is failing in healthcare.
This webinar will go over the types of waste you may run into, discuss how you should dispose and package all of your waste, and review the medical waste industry and how it is evolving.
An interview with Kris Jones-Bartley of Healthcare Management Systems. What is the history of Healthcare Management Systems? I began my career in medical practice management while I was still in college. I worked my way through college in administrative positions in physician practices and developed my analytical and management skills to assist physicians in starting practices and helping struggling practices. I noticed the need for motivated, ethical, business-minded professionals to enhance medical practice profitability and morale by alleviating stress on physicians and their staff. In 1984, I founded Healthcare Management Systems to provide business solutions for medical practices. Over the last 30+ years, HCMS has been built into a multi-faceted medical practice management company with more than two dozen employees and clients nationwide. HCMS provides billing, management and subscription services for primary care and sub-specialty practices. HCMS manages every phase of a medical practice, from start-up to retirement, and including the recovery of practices “on the brink” of insolvency. How is Healthcare Management Systems different from other billing companies? Healthcare Management Systems (HCMS) believes in customized business solutions. There is no “one size fits all”. We assess each client’s practice and create an individualized plan of recommendations to increase profitability, efficiency, effectiveness and/or retention. Clients can choose to adopt the entire HCMS recommended plan, or choose from our menu of a la carte business services. HCMS creates a customized service plan for each client based on their needs AND budget. We do not have fixed rates. HCMS employees receive continuous training and education to stay current in the ever-changing medical billing, contracting and related issues. Our turnover rate is incredibly low. HCMS treats our team like we treat our clients – as the individuals they are. HCMS technology is cutting edge. We run nearly 95% paper free. We are 100% HIPAA compliant. Customer service is top priority – with HCMS team members on both coasts and in-between, we are proud to offer enhanced availability for our clients. Every client is assigned an account manager they communicate with directly. Should a Supervisor be needed, HCMS has a clear chain of command laddering all the way to the top. As true partners in business, HCMS works to continuously educate our clients on billing changes, and shifts in healthcare in private and public sectors. Tactically, HCMS sees the end game (claims being paid or denied) and we can help clients understand trends in payer activity – this helps our clients prevent wasted resources and time. What does the future of HCMS look like? HCMS has been in business for over 30 years. Our success is built on motivation, work ethic, and intellect, as well as our continuous eye on the state of the industry. We adapt to the industry - not the other way around – this is our responsibility to HCMS clients. What types of providers do you partner with? This is a great question – we work with all types of providers: surgeons, specialists, psychiatrists, concierge, primary care, direct primary care. Concierge-style medicine is a segment of the provider population in need of specialized billing services due to the “white glove” services model. HCMS is well-suited to fill that need with service and technology. How do we sign up? Call HCMS office at 707-255-8825 and speak with President Kris Jones-Bartley, or Ami Tucker, HCMS Director of Revenue Cycle Management. Read more at www.hcmsnapa.com.
Presenter: Ila Rothschild, MA, JD, CPHRM
Join Ila Rothschild, MA, JD, CPHRM and First Healthcare Compliance for a discussion on why EMTALA was enacted and the various legal, ethical and regulatory changes to the law 1. Participants will learn the legal, ethical and regulatory history of EMTALA. 2. Partipants will learn about the current EMTALA regulations 3. Participants will learn risk management issues relating to EMTALA.
Join Yvette Duzaro MA, ACC of Unitive Consulting and First Healthcare Compliance for this workshop on how to prevent conflicting interaction with others by learning key skills that will empower you to have influence in your environment and with your relationship with others.
Join Yvette Durazo of Unitive Consulting and First Healthcare Compliance for a discussion of prevention of hostility in your workplace and conflict management.
Join Richard Chasinoff, MBA, MHA, CVA of Veralon and First Healthcare Compliance and for a discussion on demystifying Fair Market Value
Cristina Loayza, Product Manager of Precheck covers the basics of what every healthcare employer should know about exclusion screening and reviews the best practices for maintaining compliance with the Department of Health and Human Services Office of Inspector General (DHHS-OIG), the Affordable Care Act, and more.
Join Karna Morrow, CPC, RCC, CCS-P, AHIMA Approved ICD10 CM Trainer, Manager of Consulting for Coding Strategies and First Healthcare Compliance for a discussion on the upcoming changes for ICD 10 2017.
Join Tal Givoly, CEO and Founder of Medivizor and First Healthcare Compliance for a discussion of how to deal with the abundance of health information available on-line for patients and healthcare providers.
Join Stephen Bittinger, Esquire and First Healthcare Compliance for a discussion on Medicare Audits: OIG Work Plan FY 2015
Join Spiros Mantzavinos, Founder of The Mantzavinos Group, Public Affairs & Communication and First Healthcare Compliance.
Join Rhonda Granja BS, CMA, CMC, CMIS, CMOM, CPC and First Healthcare Compliance in discussing HIPAA compliance for the Front Desk Team.
Join Joseph Weidner, Jr. MD and Lenore Tietjens-Grillo MD from Health-Mirror, LLC and First Healthcare Compliance for a discussion of ways to disseminate multi-media patient education at point of care, pre and post visit.
Mary Beth Gettins, Esq of Gettins' Law discusses how to identify common privacy and security risks, outlines the HIPAA requirements and enumerates best practices for information privacy and security.
Steve Wilder of Sorensen, Wilder, and Associates discusses how a healthcare facility is one of the easiest "soft targets" the active shooter can find...countless open doors on the perimeter make it an easy target. Staff must be prepared to recognize the event, respond properly, and recover afterwards.
Mike Midgley of Swiss Re discusses how Enterprise Risk Management (ERM) is an essential strategic business discipline providing healthcare organizations with a approach to maximize value protection and creation by managing risk and uncertainty. In order to succeed in today's challenging environment, healthcare organizations need to be looking into the windshield instead of the rear view mirror. Join us to learn more about the fundamentals of ERM in healthcare, analyze a risk decision based on ERM principles and evaluate the benefits of operating under an ERM model.
First Healthcare Compliance's Janice Jones discusses Billing for Incident-to Services: Preparing for OIG Review as part of the preparation Affordable Care Act
First Healthcare Compliance discusses the risks associated with Electronic Health Records in their March 2013 lunchtime webinar.First Healthcare Compliance discusses the risks associated with Electronic Health Records in their March 2013 lunchtime webinar.
HIPAA Business Associates: What To Do Now Monthly Lunchtime Webinar with Karen E. Davidson, Esq., Founder of Mackarey & Davidson
Karen E. Davidson, Esq., a Founder of Mackarey & Davidson, P.C., Healthcare Attorneys to the Provider Community joins First Healthcare Compliance for a discussion of Notice of Privacy Practices under Omnibus.
HIPAA Omnibus Breach Notification Lunchtime webinar with Karen Davidson , Esq., a Founder of Mackarey & Davidson, P.C.
Does the Sunshine Act Apply to You? James A. Dwyer and Dan Gilman of RxVantage with First Healthcare Compliance.
Shauna Itri, Esq., of Berger & Montague, PC discusses The False Claims Act (Whistleblower Actions) with First Healthcare Compliance.
Confidentiality and Release of Information Review with Diane E. Ferry, MS, RHIA, President and CEO of Star-Med.
Steve Rutkovitz, President and CEO of ChoiceTech joins First Healthcare Compliance to discuss the importance of a risk assessment for a medical practice.
Vu Do, VP of Compliance at PreCheck joins First Healthcare Compliance to discuss "5 Essentials for Your HR Background Screening Checklist"
Jennifer Kirschenbaum, Esq. of Kirschenbaum and Kirschenbaum, P.C. joins First Healthcare Compliance to discuss Controlled Substance Safeguards.
Lani Nelson-Zlupko, PhD., LCSW of LNZ Consulting joins First Healthcare Compliance to discuss Effective Communication in the Workplace
First Healthcare Compliance welcomes Ray Ribble, Managing Partner of All Medical Solutions/SPHER to discuss monitoring e-PHI access.
Your Medical Liability Carrier Can Help presented by Mike Nolen, Vice President of Nolen Associates, Inc. and First Healthcare Compliance
First Healthcare Compliance hosts Jennifer Gimler Brady, Esq of Potter, Anderson, Coroon LLP for a discussion on what you need to know about business associates, essential terms of business associate agreements and lessons the Office of Civil Rights Phase 2 Audits and enforcement actions.
An interview with Stephen Bittinger of Bittinger Law.
What makes Bittinger | Law unique among healthcare law firms?
We have developed a specialized practice that focuses almost entirely on healthcare reimbursement defense and compliance. This area of law leads into several main areas of work. The first and most frequent is the defense of audits by federal, state, and private payors. Needless to say, protracted audits can chock the life out of a practice, and we have developed very successful strategies for bringing them to swift resolutions and mitigating damages significantly. The second major arena that we work is reimbursement compliance, and we wish more clients would come to us before there were problems. Legal payor compliance is not only coding and medical policy adherence but contract, regulation, and structural compliance as well. The third major area is the myriad of pitfall processing that result from failures of reimbursement compliance such as OIG or FBI investigations, de-credentialing proceedings, payor litigation, False Claims Act litigation, and other difficult processes.
Our firm is unique, in that our knowledge framework always begins and ends with reimbursement and the legal framework around those processes. Many large healthcare law firms list these areas of law among the many others that they handle (e.g. healthcare transactions, physician contracting, etc.), but we live and breath the law as it applies how providers get paid for services and protect their revenue. Since we are so focused, we are on the forefront of the ever-evolving world of law and policy that surrounds healthcare reimbursement.
How do you define the legal side of healthcare reimbursement defense and compliance?
The easiest way to define the legal side of healthcare reimbursement is to describe the layers. To begin with, you have the coding of services. The rules and authorities that create, change, and implement the codes all have varying basis of legal grounds for their positions. The second is the legal construct of the payor. For private payors, the primary basis is the provider’s participating contract and the incorporate payor manual and medical policies. Note, that most all private payors default to CMS standards where their policies are silent. For federal and state payors, you have the dark abyss of “contracts” for participation, manual and medical policies, federal and/or state regulations, and federal and/or state statutes. Needless to say, the complexity, and frequent conflict, between all these layers of duties, rights, and responsibilities often overwhelm private medical practices.
What types of legal matters do you help providers and practices with?
As briefly mentioned above, our predominate work is in audit defense and compliance, but the heart of our reimbursement knowledge has taken us into some very interesting arenas. We represent individual providers in state board defense when a payor has accused them of unethical billing. We defend against healthcare fraud investigations by the FBI, OIG, HHS, and AG. We have both defended against and prosecuted False Claims Act cases. We have defended providers in de-credentialing and termination proceedings. We also very often appeal erroneous findings of overpayment with success. Generally, if it boils back down to something going wrong with the reimbursement, we’ve seen it.
When is the best time for a provider/practice to reach out to a healthcare attorney and why?
Always beforehand. Please let me say that again. Providers should always at least know of a firm like ours before the trouble comes. I have many times stopped the terrible effects of a federal fraud audit by receiving a call on the day the audits show up unannounced at the practice. This is only possible if you know my number before that day.
Why is education such an important part of the healthcare reimbursement process?
Education kills fear.
An interview with Jim Cucinotta, CEO of Halo Health International.
Who is Halo Health and why should anyone care?
Halo Health is a digital content management company that helps healthcare professionals explain to their patients the key questions of what do they do, when and where do they perform their services, how these services help their patients and why this is important to improving their patients’ lives. Halo Health uses four main patient education platforms to achieve this: waiting room or exam room education systems, a tablet based application, in patient TV channels, and direct to patient applications. These platforms are customized for the practice, health system or provider specialty, focus on their staff, services, and health goals, and are advertiser free.
The waiting room/exam room platform includes monitors running specialized content that help the patient learn how to live better, avoid lifestyle based disease states, manage disease states like diabetes and COPD, and why this particular health system, practice or provider is the expert in helping you live a more productive life. The systems help patients navigate their health system by introducing specialists, medical centers, and other useful services that their current provider may refer them to see. Content changes frequently and is sourced from major medical associations.
The tablet based application is even more customized as it is meant for use between the provider, their staff and the patient to reinforce specific direction that the patient has received. Videos on how to use a glucometer, how to administer insulin and other important things a diabetic needs to learn are in the app as well as eating guidelines, exercises, and other encouraging videos.
The in-patient channels are segmented by disease state and focus on the “story” of helping a patient navigate their hospital and health. The content introduces the patient to their issue, explains the steps in recuperation and shows how their staff are the experts. Discharge planning tools can be introduced in these channels to help patients and their caregivers prepare for their return home.
Our marketing services enable a provider to increase their online presence and become the expert to their patients. Many times, patients are left to fend for themselves by searching online because their current professional does not provide the resources they need. Halo Health reduces that need and establishes the professional the expert that patients need to visit first. Tools like Facebook, Twitter, Pinterest, and their website get enhanced and their direct mail/email becomes more productive.
How does the provider benefit from Halo?
The provider must provide patient education. Halo Health helps the provider explain to the patient not only the nuts and bolts of healthcare but how they made a great choice in providers in a way that their patient is used to receiving information. Over 80% of people receive their news in a video format, but very few offices offer their patient education in a video format. The provider can feel confident that their patients are hearing the message that they want to them to hear, not a third party’s take on health. Most providers see an increase in revenue because patients are more engaged. They ask questions and give input on their state of health that help the provider treat them more accurately.
How does the patient benefit?
Having a patient navigate their health is one of the trickiest roads in healthcare. By explaining to the patient at their time of need where to go, what to do, and whom to talk to to improve their health is an invaluable tool. Our platforms enable a health system to manage the patient’s flow through the health system- telling them where to get an MRI, where the PT and Health Centers are, who the preferred pharmacies are, where their specialty offices are located- and they can tell them how to live with their disease st...
An interview with Sam Roden, Director of SMB Sales at SecurityMetrics.
Could you share the story of SecurityMetrics with us?
In 1998, CEO Brad Caldwell recognized the need for affordable data security for the masses after his former company’s website was hacked. At the time, the only organization qualified to help his business through the damaging compromise was extremely expensive. Caldwell realized organizations not only need affordable forensic investigations, but also simple tools to protect them from attacks in the first place.
Since its founding in 2000, privately-held SecurityMetrics has grown from a small security company specializing in vulnerability assessment scans to a global leader of data security and compliance solutions.
Why should every merchant become PCI compliant?
In 2016 there were a total of 873 tracked data breaches exposing 30 million records, per the Identity Theft Resource Center. All businesses that store, accept, maintain, transmit, process credit/debit/payment cards are required to comply with the Payment Card Industry Data Security Standard (PCI DSS), which is an important step in protecting sensitive data. Breaches and non-compliance can be very costly both financially and in brand damage.
What top tips would you give organizations to navigate PCI compliance?
What sets you apart from other PCI compliance providers?
We are one of only a handful of companies worldwide certified by the PCI Council to conduct all major PCI compliance validations. Not only are we certified to assist organizations of all types and sizes, our sales and customer support teams have won multiple awards for their ability to help merchants reach compliance and secure their data.
How do people get started with SecurityMetrics?
Getting enrolled with us is very simple. To start, you will call into First Healthcare Compliance’s personal account manager, Kaden Pope, and he or a member of his team will go over a series of questions with you to assess your PCI compliance needs. This call will help them define your specific requirements based on how you store, process, and transmit payment cards. After defining your requirements, they will be able to give a quote for the services and enroll you with SecurityMetrics. This quote includes a discount because of our relationship with First Healthcare Compliance Point.
An interview with Josh Plummer, President and CEO of PracticeWorx.
What does PracticeWorx do for healthcare practitioners and organizations?
We are credentialing experts that work with all types of practitioners and organizations who need to enroll as in-network providers with insurance plans. And for many of our clients, we become their own “in-house” credentialing department handling all their credentials-related needs: maintaining credentials such as licensure, certifications, hospital/facility privileges and CAQH profiles, as well as re-credentialing with insurers.
What is the most common misconception about provider enrollment and credentialing?
The length of time it takes to initially enroll/credential with an insurer. Although varied by insurance company, the average time to enroll a practitioner right now is 90 days, and that’s from the date a complete and correct application is submitted to the insurer. Commercial insurers are not held to any regulation when it comes to the credentialing of a new practitioner. So we have to stay in continual communication with the representatives from each insurer to make certain they are actively working the enrollment of our client.
What are the risks for not maintaining proper credentials?
The most frequently occurring risk is being dropped or termed as an in-network provider by an insurer, and thus the loss of patients and patient revenue. The accreditation standards for insurers require the insurers to continually monitor that all their network providers maintain current and active credentials. So it is vital for a practitioner to keep their CAQH profile up-to-date and respond to any re-credentialing requests from the insurer otherwise they run the risk of losing their in-network status.
What do you enjoy most about working with your clients?
Clients come to us because they need assistance with managing their credentials and enrolling with insurance companies. Knowing that we play a role in the success of their practice is why I enjoy what we do. And many times these practitioners are starting their very first practice. So I always try to go beyond the credentialing and payor enrollment to provide them with guidance and suggestions to make sure they set up their new practice correctly. Being able to provide this additional support to a very appreciative practitioner is very rewarding.
An interview with Matt Georgov, Vice President of Sales and Operations at Choice MedWaste.