Client Alerts, News Articles & Blog Posts

Everything you need to know about BMD and the industry.

CLIENT ALERT: Ohio Incentivizes Cybersecurity Measures

On November 2, 2018, Ohio’s Data Protection Act (“DPA”) went into effect.  The DPA incentivizes Ohio businesses to proactively address cybersecurity and data protection by providing an affirmative defense/safe harbor for claims related to data breach. However, the safe harbor is only applicable if the organization can prove “reasonable compliance” to the DPA.

Brennan Manna Diamond (“BMD”) can assist your business by creating written policies that demonstrate compliance with Ohio law in the spirit of the DPA.  Additionally, BMD can educate your organization as to implementing and adhering to those policies.

The DPA is the culmination of Ohio’s efforts to foster a legal, technical, and collaborative cybersecurity environment to help businesses thrive. The only way to reap this benefit is to meet its requirements.

How to Comply

Any organization maintaining personal information of Ohio residents can be subject to Ohio’s breach notification laws and potential civil liability for data breach compromising such information.  The DPA rewards proactivity vs. reactivity by incentivizing businesses to implement policies and procedures to protect the security and confidentiality of personal/restricted information, protect against any anticipated threats or hazards to the security or integrity of the personal/restricted information and protect against unauthorized access of information that is likely to result in a material risk of identity theft or other fraud. Businesses should take the following steps:

  • Businesses must determine “reasonable” security measures. Such analysis must consider:
    •  The size of the business;
    • The nature, sensitivity and use of information;
    • The resources available to the business; and
    • The cost to implement and maintain the reasonable security measures to protect against a breach of security relative to the business’ resources.
  • Businesses must implement a cybersecurity framework and the DPA recognizes certain existing frameworks of which businesses can utilize in order to qualify for safe harbor. These include:
    • Industry recognized cybersecurity frameworks, (i.e., those recommended by administrative bodies, like the National Institute of Standards and Technology (NIST);
    • Regulatory frameworks required by federal or state law (i.e., HIPAA, Gramm-Leach-Bliley); or
    • A framework that combines the payment card industry (PCI) data security standard with a current version of an applicable industry recognized cybersecurity framework.
  • Businesses must create and maintain written cybersecurity policies and procedures. Such policies and procedures must contain administrative, technical, and physical safeguards for the protection of personal/restricted information.
  • Businesses must periodically review changes in regulations and framework updates and must likewise update its cybersecurity program.

BMD's Solution

In addition to implementing industry standard cybersecurity frameworks, prudent businesses will create and maintain written policies as it relates to cybersecurity and data protection. BMD can assist in crafting the policies and identifying proper security frameworks so that your business qualifies for the safe harbor. The Ohio legislature was mindful not to be hyper-technical with the regulations so that businesses can still qualify for the safe harbor by demonstrating reasonable efforts to comply. BMD can help navigate these regulations.

In today’s ever-changing cybersecurity landscape, data breaches are at times, inevitable. BMD can also provide post-breach solutions including meeting applicable reporting requirements and litigation defense. As now enacted by Ohio, perhaps the best defense involves proactively investing in front end compliance.

For more information, please contact Brandon T. Pauley. 

CLIENT ALERT: Medicare Trust Fund to Run Out of Funding Beginning in 2026, Likely to See an Increase in Audits, Overpayment Demands and Extrapolations

Pursuant to a Medicare Trustee Report released on June 5, 2018, the Medicare trust fund will run out of funding beginning in 2026, which is three years earlier than previously expected. Although the Trustee’s report requests that Congress and the President act with urgency to remedy this problem, in the short term, we expect to see an increase in government payer audits, overpayment demands, and extrapolations.

CLIENT ALERT: The European Union's New Data Privacy Law Goes Into Effect

On May 25, 2018, the European Union’s (“the EU”) new data privacy law went into effect. The General Data Protection Regulation (“GDPR”) concerns the processing of personal data that can be searched according to specified criteria such as geographical scope.

CLIENT ALERT: Class Action Waivers in Employment Contracts Upheld by Supreme Court

On May 21, 2018, in a 5-4 decision and a major win for employers, the United States Supreme Court upheld the legality of waivers in employment contracts that prohibit employees from grouping claims together in collective or class actions in favor of individual arbitration proceedings. See Epic Sys. Corp. v. Lewis, ___U.S.___ (2018).

CLIENT ALERT: Prohibition on Recoupment Prior to Exhaustion of Administrative Remedies

In April, the Fifth Circuit Court of Appeals, in Family Rehabilitation, Inc. v. Azar No. 17-11337 (5th Cir. 2018), held that district courts are authorized to enjoin the Centers of Medicare & Medicaid Services (“CMS”) and its contractors from recouping alleged overpayments prior to the completion of the administrative appeal process.

CLIENT ALERT: Low Volume Appeals Settlement for RAC Appeals

In April, the Centers for Medicare & Medicaid Services (“CMS”) issued a new settlement proposal to providers with outstanding appeals at the Office of Medicare Hearings and Appeals (“OMHA”) and the Medicare Appeals Council (“MAC”). Essentially, CMS is offering to pay up to 62% of the claim to the provider for qualifying claims that are currently in the appeal process. Interested providers may submit an Expression of Interest (“EOI”) to CMS by June 8, 2018. Providers should explore this settlement opportunity and submit an EOI to receive an offer of settlement. Providers may decline the offer after the EOI is submitted. Brennan, Manna & Diamond, LLC’s Provider Relations, Audit, and Appeals Unit, a division of its Healthcare Department, is able to assist providers with filing the EOI, analyzing the outstanding claims subject to the settlement, and reviewing the Administrative Agreement that is offered by CMS.