Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

FAQs:  Administrative Fees Under Medicare

Client Alert

Late patients, last-minute cancellations, and difficulty in collecting fees are all common complaints from our healthcare clients.  As such, it is no wonder that a common topic among our healthcare clients revolves around what administrative fees can be charged to patients and related issues.  We thought it would be interesting to share some of the most frequently asked questions we receive in this area. 

Please note that this article is not legal advice, and readers are advised to seek legal counsel concerning their specific facts and circumstances.  All answers are based on Medicare laws and regulations.  Many commercial payers will follow Medicare guidelines in their own policies, but a provider will need to check with each specific commercial payer to confirm their policies.  Additionally, practices that are “cash-pay only” would not be subject to Medicare regulations or commercial payer policies, because they don’t bill third-party payers.  Finally, every state has unique laws, so it is imperative to confirm whether your state law addresses any of these topics. 


Q1: Can a physician practice require patients to pay a deposit for an appointment or scheduled procedure?

        A: Yes, practices can require deposits in order to secure appointments. However, some insurers may explicitly forbid your practice from doing so. Additionally, best practice is to inform patients upfront about the fee.


Q2: What about hospitals? Are they permitted to collect deposits?

        A: Chapter 2 (Section 10.3) of the Medicare Claims Processing Manual does not permit requiring prepayment as a condition of admission. However, Section 10.4 does state that “[t]he provider may collect deductible or coinsurance amounts only where it appears that the patient will owe deductible or coinsurance amounts and where it is routine and customary policy to request similar prepayment from non-Medicare patients with similar benefits that leave patients responsible for a part of the cost of their hospital services.”

 

Q3: Can my physician practice charge appointment cancellation fees to patients who do not cancel within 24 hours of their appointment?

        A: Yes, charging a fee is permitted by Medicare if it is in the practice’s written policy. However, Medicare is clear that these late fees can be charged ONLY to Medicare patients, and Medicare will not pay for the missed appointment, so it must be charged to the patient directly.

 

Q4: Can hospitals charge hospital inpatients a missed appointment fee?

        A: No, this would violate 42 CFR 489.22.

 

Q5: Can my practice keep patient credit cards on file?

        A: Yes, practices can keep patient credit cards on file, provided that certain safeguards are put in place to protect card information. Additionally, you should check with your credit card processing company to assure that they permit cards to be kept on file, as well as check with any applicable insurance carriers that would cover identity theft, credit card fraud, or other issues involving the practice’s credit card transactions.

 

Q6: What requirements does my physician practice need to follow in order to safeguard patient credit card information?

       A: Both the Payment Card Industry Data Security Standard (“PCI DSS”) and the Health Insurance Portability and Accountability Act (“HIPAA”) apply to practices that store patient credit card information. As such, practices should have a policy in place outlining the requirements for each.

PCI DSS lists twelve (12) safeguards that must be met when storing credit card information:

(1) Install and maintain a firewall configuration to protect cardholder data;

(2) Will not use vendor-supplied defaults for system passwords and other security parameters;

(3) Protect stored cardholder data;

(4) Encrypt transmission of cardholder data across open, public networks;

(5) Use and regularly update anti-virus software or programs;

(6) Develop and maintain secure systems and applications;

(7) Restrict access to cardholder data by business need to know;

(8) Assign a unique ID to each person with computer access;

(9) Restrict physical access to cardholder data;

(10) Track and monitor all access to network resources and cardholder data;

(11) Regularly test security systems and processes; and

(12) Maintain a policy that addresses information security for all personnel.


Additionally, HIPAA lists certain standards for disposing of patient payment information. For example, safe disposal would include card information being placed into locked shred bins, and all employees who are responsible for disposing of such information receive training in proper disposal.

If you have questions about rules or policies governing administrative fees charged to patients, please contact Member and General Counsel Jeana Singleton by email at jmsingleton@bmdllc.com, by phone at (330) 253-2001 or another member of the Healthcare & Hospital Law Department of Brennan Manna & Diamond.

 


ChatGPT for Legal Research

How trustworthy and beneficial is ChatGPT for legal research? What are the benefits and drawbacks of using this tool in the legal system.

Supreme Court Rules that Employers Must Show Substantial Increased Costs to Legally Decline Employees’ Religious Accommodation Requests

On June 29, 2023, the Supreme Court ruled in Groff v. DeJoy that under Title VII of the Civil Rights Act of 1964 (“Title VII”) employers must show, in order to decline religious accommodations, that the burden of granting religious accommodations to employees will result in substantial increased costs in relation to the conduct of an employer’s particular business, thus amending the prior, simple standard of a “de minimis” undue hardship.

Recent HIPAA Breach Settlements - Lessons Learned

According to the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR), the consequences for providers may include settlements of $30,000 to $240,000. OCR recently released two settlements for improper breaches of protected health information (PHI) that are good examples of the major monetary penalties that can result from common HIPAA mistakes.

Supreme Court Issues Major False Claims Act Decision

Telehealth Flexibility Updates: HIPAA, DEA, and CMS

The Covid-19 Public Health Emergency (PHE) officially ended on May 11, 2023. But what does that mean for telehealth, a field that expanded exponentially during the PHE? Fortunately, many of the flexibilities will remain intact, at least temporarily. This client alert presents a brief overview of the timelines that providers need to follow, but for a more comprehensive review of telehealth flexibilities and when they will end