Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


2021 EEOC Charge Statistics: Retaliation & Impact of Remote Work

The U.S. Equal Employment Opportunity Commission (EEOC) released its detailed information on workplace discrimination charges it received in 2021. Unsurprisingly, for the second year in a row, the total number of charges decreased as COVID-19 either shut down workplaces or disconnected employees from each other. In 2021, the agency received a total of approximately 61,000 workplace discrimination charges - the fewest in 25 years by a wide margin. For reference, the agency received over 67,000 charges in 2020, and averaged almost 90,000 charges per year over the previous 10 years.

Ohio’s Managed Care Overhaul Delayed – New Implementation Timeline

At the direction of Governor Mike DeWine, the Ohio Department of Medicaid (ODM) launched the Medicaid Managed Care Procurement process in 2019. ODM’s stated vision for the procurement was to focus on people and not just the business of managed care. This is the first structural change to Ohio’s managed care system since the Centers for Medicare & Medicaid Services' (CMS) approval of Ohio’s Medicaid program in 2005. Initially, all of the new managed care programs were supposed to be implemented starting on July 1, 2022. However, ODM Director Maureen Corcoran recently confirmed that this date will be pushed back for several managed care-related programs.

Laboratory Specimen Collection Arrangements with Contract Hospitals - OIG Advisory Opinion 22-09

On April 28, 2022, the Department of Health and Human Services, Office of Inspector General (“OIG”) published an Advisory Opinion[1] in which it evaluated a proposed arrangement where a network of clinical laboratories (the “Requestor”) would compensate hospitals (each a “Contract Hospital”) for specimen collection, processing, and handling services (“Collection Services”) for laboratory tests furnished by the Requestor (the “Proposed Arrangement”). The OIG concluded that the Proposed Arrangement would generate prohibited remuneration under the federal Anti-Kickback Statute (“AKS”) if the requisite intent were present. This is due to both the possibility that the proposed per-patient-encounter fee would be used to induce or reward referrals to Requestor and the associated risk of improperly steering patients to Requestor.

Property Owner Protection from Tax Valuation Challenges

New legislation provides significant new protections for commercial property owners against challenges to valuation primarily by local school boards and prohibiting side agreements to avoid tax valuation changes. The Ohio Legislature has approved House Bill 126 which will go into effect July 2022 but will effectively apply to the 2023 tax valuation year.

No Surprises Act Update: The IDR Portal is Open

The No Surprises Act (“NSA”) became effective January 1, 2022, and has been the subject of lawsuits and criticisms since its inception. The goals of the No Surprises Act are to shield patients from surprise medical bills, provide to uninsured and self-pay patients good faith estimates of charges, and create a process to resolve payment disputes over surprise bills, which arise most typically in emergency care settings. We have written about Part I and Part II of the NSA previously. This update concerns the Independent Dispute Resolution (“IDR”) procedure created by Part II but applicable to claims covered by Part I. The Centers for Medicare & Medicaid Services (“CMS”) finally opened the Portal for providers to submit disputes to the IDR process following some updated guidance regarding the arbitration process itself.