Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Banking and Cannabis: Is it Legal

Marijuana is still a Schedule 1 drug and is illegal under federal law. However, I am not aware of any federal banking law or regulation, or any other federal law or regulation, which explicitly makes it illegal for banks and other financial institutions to provide their traditional services to state legal cannabis businesses.

Protections Under Federal and Ohio Law for Bona Fide Prospective Purchasers of Contaminated Property

Most industrial/commercial property developers are generally aware of the Comprehensive Environmental Response, Compensation, and Liability Act (“CERCLA”), often also referred to as “Superfund”. CERCLA, a United Stated federal law administered by the U.S. Environmental Protection Agency, was created, in part, because the U.S. Environmental Protection Agency recognized that environmental cleanup could help promote reuse or redevelopment of contaminated, potentially contaminated, and formerly contaminated properties, helping revitalize communities that may have been adversely affected by the presence of the contaminated properties. Commercial property developers should be aware that CERCLA provides for some important liability limitations for landowners that own contaminated property impacted by materials hazardous to the environment. It can also assist with landowners concerned about the potential liabilities stemming from the presence of contamination to which they have not contributed. In particular, CERCLA provides important liability limitations for landowners that qualify as (1) bona fide prospective purchasers (BFPPS), (2) contiguous property owners, or (3) innocent landowners.

Puerto Rico Is Open For Business

Puerto Rico has the highest vaccination in the nation. More than 73% of the total population is fully vaccinated. The U.S. national average is just over 57%. The ports opened in June 2020 and San Juan held it first live concert this past summer. It is important to remember that Puerto Rico is a U.S. territory and there is no need for visas, the banking systems is almost identical to the mainland and the Island uses the U.S. postal service and U.S. dollar as its currency. There are thousands of flights from the U.S. to Puerto Rico daily and all main airlines fly to the Island.

Ohio Medical Board Changes Telemedicine Rules

A SCMS News Article by Scott Sandrock.

The Rising Threat from Insiders – Get Your House in Order

As its name implies, an ‘Insider Threat’ originates inside an organization. An ‘insider’ is any person who has or had authorized access to or knowledge of an organization’s resources, including personnel, facilities, information, equipment, networks, and systems. ‘Insider threat’ can manifest from malicious, complacent, negligent or unintentional acts that negatively affect the integrity, confidentiality, and availability of the organization, its data, personnel, or facilities. Certainly, ‘Insider Threat’ can be an activity by a bad actor employee, but can also arise from an inadvertent or unknowing action inside an organization (such as an employee who unintentionally opens a phishing email or clicks on a malicious link).