Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Ohio Medical Board Releases New Telehealth Rules

On Tuesday, February 21, 2023, the State Medical Board of Ohio released its final telehealth rules to implement Ohio’s telehealth statute (O.R.C. 4743.09) for physicians, physician assistants, dieticians, respiratory care professionals and genetic counselors. Ohio’s advanced practice registered nurses (“APRNs”) should also take note of these rules. While the Medical Board does not govern APRNs directly, those APRNs who are required to have a collaborating physician and standard care arrangement (namely nurse practitioners, certified nurse midwives, and clinical nurse specialists) are still affected by the rules. Generally, if an APRN’s collaborating physician is limited in their practice, then the APRN will also be limited.

The End of the Public Health Emergency is (Finally) Here

The COVID-19 Public Health Emergency (“PHE”) that has been in effect for over three years is finally slated to end on May 11, 2023.[1] With the end of the PHE will come many changes for healthcare providers to be aware of; however, some changes may not come until much later.

Multi-340B Contract Pharmacy Locations on the Brink? The Third Circuit’s Ruling Gives a Hint.

The 340B drug discount program requires pharmaceutical manufacturers to offer to sell their products at significant discounts to safety net providers called “covered entities.” In 1996, the Health Resources and Services Administration (HRSA) issued guidance authorizing covered entities to enter into a contract pharmacy arrangement with a single third-party contract pharmacy, to which the manufacturer would ship 340B medications but bill the covered entity. In 2010, HRSA issued revised guidance permitting covered entities to enter into an unlimited number of contract pharmacy arrangements.

Five Opportunities for Operations and Compliance Excellence in 2023

With the holidays behind us and the rest of the year ahead, now is the perfect time to get your operational/compliance house in order! Though your list might be a mile (or an inch) long, here are five places to start.

The Pregnant Workers Fairness Act - What Employers Need to Know

Effective June 27, 2023, the Pregnant Workers Fairness Act (PWFA) will require employers with at least 15 employees to provide reasonable accommodations for qualified employees with pregnancy-related restrictions unless doing so would impose an undue hardship on the employer.