Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Ohio Loan Programs to Boost Minority-Owned Businesses

Ohio has created two new loan programs to enhance growth of minority and women owned businesses in Ohio. The Ohio 2022-2023 operating budget includes the Women’s Business Enterprise Loan Program and Ohio Micro-Loan Program.

Supreme Court Upholds CMS Vaccination Mandate for Health Care Providers

Last week, the U.S. Supreme Court struck down the COVID-19 vaccine-or-test mandate for employers with more than 100 employees (the OSHA ETS) and upheld the COVID-19 vaccination mandate for employees of health care providers who receive Medicaid or Medicare funding (the CMS rule).

Federal and Ohio Laws on Surprise Billing

Beginning in January 2022, Ohio providers and healthcare facilities will need to comply with both the federal No Surprises Act (“NSA”) and the state surprise billing law (HB 388), which are both designed to protect patients from unexpected medical bills.

New Year, New Laws, Old Form Documents? Exhibit A: Changes in Florida’s Real Estate Contracts

Settling into a New Year often brings renewed energy into setting and pushing new goals of building business relationships, increasing sales, and moving Letters of Intent and negotiations into final, signed agreements. It’s all too easy to grab a form document off the Internet (Google, anyone?), or to pull the last document in your files as a template for your next agreement. However, changes in the law can take effect at the beginning of the calendar year, as well as mid-year or fiscal new year, and sometimes on a random date in between. Your awareness – or lack of awareness – in changes in the law can mean the difference between keeping you and your business operating within the law or putting you at great financial and legal risk for not complying with the law. It can also result in financial and time savings or additional burden in time and costs.

Sports Betting Legal in Ohio

Ohio has made sports betting legal with Governor DeWine signing House Bill 29 into law on December 22, 2021. The Casino Control Commission will regulate sports betting in Ohio and estimates that the launch date for sports betting will be January 1, 2023.