Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Corporate Transparency Act Update

The Corporate Transparency Act (“CTA”), with an effective date of January 1, 2024, is set to impose strict reporting guidelines on business owners throughout the country. The following provides a brief update on two aspects of the CTA ahead of its effectiveness next week.

The Second Wave of UnitedHealthcare's Prior Authorization Cuts Started in November

In August 2023, UnitedHealthcare released its plan to eliminate roughly one-fifth of its then-current prior authorization requirements. The first round of prior authorization cuts took effect on September 1, 2023. In that round, UnitedHealthcare eliminated the necessity for some prior authorizations for UnitedHealthcare Medicare Advantage, UnitedHealthcare commercial, UnitedHealthcare Oxford and UnitedHealthcare Individual Exchange plan members. The second and final round of prior authorization cuts began on November 1, 2023. The November 2023 Prior Authorization Cuts apply to the same plans as well as community plans (i.e., Medicaid managed care plans).

Legal Uncertainties Remain Following Passage of Issue 1 in Ohio

In the November 2023 General Election, Ohio voters passed Issue 1 which, among other things, “[e]stablish[es] in the Constitution of the State of Ohio an individual right to one’s own reproductive medical treatment, including but not limited to abortion”. Despite passage of Issue 1, questions persist about how its codification on December 7 affects previously passed legislation restricting abortion and related pending court cases.

NLRB Issues Final Rule on Joint-Employer Status

On October 26, 2023, the National Labor Relations Board (NLRB) issued its final rule on determining joint-employer status, departing from its prior 2020 standard. The final rule provides that two or more entities may be considered “joint employers” if each entity has an employment relationship with employees and if the entities share or codetermine one or more employees’ essential terms and conditions of employment. The final rule goes into effect on December 26, 2023, and will only be applied to cases filed after the effective date.

WEBINAR SERIES RECAP | Employment & Labor

BMD Partner and Co-Chair of the Employment & Labor Law Group, Bryan Meek, presented this four-part webinar series on trending topics in employment law.