Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Updated FAQs for the No Surprises Act - Good Faith Estimates

The No Surprises Act (“NSA”) became effective January 1, 2022. Meant to protect consumers from surprise medical bills, the new law is good for consumers, but vexatious for health care providers and facilities. One particular source of frustration is the operationalization of the Good Faith Estimate (“GFE”) requirement, governed by Part II of the regulations that implement the NSA. The GFE requirements apply broadly to all healthcare providers and facilities that practice within the scope of their state-issued license.

IMPORTANT PRF UPDATE! HRSA Allows Providers the Opportunity to Correct Missed Period 1 Reporting

Late Wednesday, April 6, HRSA announced that it was going to allow providers with extenuating circumstances that prevented them from preventing a completed Period 1 Report to submit a Request to Report Late Due to Extenuating Circumstances.

Advanced Practice Providers and Telemedicine Start-Up Surge

Throughout the COVID-19 pandemic, we heard a lot about “surges” that happened all over the country regarding the virus. One of the other interesting “surges” we have followed is the “surge” in new healthcare business start-ups, particularly businesses owned by advanced practice providers, such as nurse practitioners, physician assistants, certified nurse midwives, clinical nurse specialists, and certified registered nurse anesthetists (“Advanced Practice Providers” or “APPs”). One of the hottest areas in the healthcare start-up surge has been the creation of practices that are telemedicine focused.

Ohio Department of Health Releases Updated Charge Limits for Medical Records

Under Ohio law, a healthcare provider or medical records company that receives a request for a copy of a patient's medical record may charge an amount in accordance with the limits set forth in Ohio Revised Code Section 3701.741. The allowable amounts are increased or decreased annually by the average percentage of increase or decrease in the consumer price index for all urban consumers, prepared by the United States Department of Labor, Bureau of Labor Statistics, for the immediately preceding calendar year over the calendar year immediately preceding that year, as reported by the Bureau. The Director of the Ohio Department of Health makes this determination and adjusts the amounts accordingly. The list is then published, here.

No Surprises Act Compliance (Published by NAMAS, 2/25/22)

The Department of Health and Human Services published three parts to the No Surprises Act towards the end of 2021, which took effect January 1, 2022. The Act is intended to protect consumers from “balance billing,” which occurs when a patient receives a bill with a higher price than they may have anticipated because they did not have knowledge that the provider or facility was out-of-network. The purpose of this article is to note certain requirements that compliance employees will need to be aware of at their facilities, including notice and consent, good faith estimates, and public disclosures.