Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Important Update: New Advanced Beneficiary Notice in Effect for Medicare on June 30, 2023

On April 4, 2023, the Office of Management and Budget (OBM) approved an updated Advance Beneficiary Notice of Non-coverage (ABN) form CMS-R-131.[1] Providers can continue using the current ABN form with an expiration date of June 30, 2023.[2] However, all providers are mandated to use the new ABN starting on June 30, 2023, which has an expiration date of January 31, 2026.

Ohio Recovery Housing (ORH) Repairs Fund Application Open for Eligible Applicants

The Ohio Recovery Housing (ORH) Repairs Fund Application is open for eligible organizations and/or operators of recovery housing facilities throughout the state of Ohio!

Pregnant Employee Protections - New Requirements for Employers

New protections are coming to the workplace for pregnant employees in 2023! In the most sweeping changes since the Pregnancy Discrimination Act of 1978, two new federal laws were recently passed: (1) the PUMP for Nursing Mothers Act (otherwise known as the Pump Act), and (2) the Pregnant Workers Fairness Act. The requirements of these statutes will require employers with more than 15 employees to implement new policies for their handbooks.

Five Common Pitfalls for Employers to Watch Out for Under the Fair Labor Standards Act

The Fair Labor Standards Act (FLSA) sets forth requirements for employers including, but not limited to, minimum wage, overtime pay, and recordkeeping for covered employees. These requirements are not as simple as they may appear on their face, which leads many employers to fall into compliance issues that they did not realize even existed.

The NLRB Limits the Reach of Confidentiality and Non-Disparagement Provisions in Severance Agreements Overruling Trump-Era Policies

Employers should exercise caution and closely examine the content of severance agreements to ensure compliance with a recent National Labor Relations Board (“NLRB”) decision.  On February 21, 2023, the NLRB restricted the breadth of permissible language of confidentiality and non-disparagement clauses when it issued its decision in McLaren Macomb and overruled its Trump-era decisions in Baylor University Medical Center and IGT d/b/a International Game Technology.