Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


In Cybersecurity– A Good Offense is the Best Defense

2021 has been a watershed moment for cybersecurity incidents as cybercrime has become a frequent headline and cyber criminals have thrived on unsuspecting and/or unprepared businesses and institutions. For example, the Solar Winds attack exposed sensitive data from top companies like Microsoft as well government agencies[1] and the Colonial Pipeline attack substantially disrupted the petroleum supply chain[2]. We have seen an almost 20% increase in data breaches and attacks since last year.

Changes to Medicare’s Physician Fee Schedule and Outpatient Prospective Payment System

Come the beginning of 2022, both the Medicare Physician Fee Schedule (“MPFS”) and Outpatient Prospective Payment System (“OPPS”) will look a little different. As a refresher, the MPFS lists the fees associated with reimbursement of services to providers at certain facilities, taking into account geography and costs. By contrast, OPPS sets reimbursement rates for hospitals and community mental health centers for outpatient services, which are determined in advance. A summary of some of the more pertinent changes to each rule will be outlined below.

CMS to Once Again Reprocess Outpatient Clinic Claims

The Hospital Outpatient Prospective Payment System (OPPS) Rule was passed in November 2018, which was intended to prevent the Centers for Medicare and Medicaid Services (CMS) from paying more for services rendered in outpatient settings than what they paid for the same services rendered in physician offices that are simply owned by hospitals or health systems.[1]

New Vaccine Requirement for Select CMS-Participating Facilities

On November 4, 2021, the Centers for Medicare and Medicaid (“CMS”) released a new rule requiring certain healthcare facilities to implement policies requiring employees to be vaccinated against COVID-19. It does not matter if a staff member does not perform patient treatment services, they must still be vaccinated if an employee of an applicable facility.

OSHA COVID-19 EMERGENCY TEMPORARY STANDARD (ETS) Vaccination, Testing, Recordkeeping, and Reporting

The Occupational Safety and Health Administration has issued its long-awaited COVID-19 Emergency Temporary Standard (ETS). Note that the ETS does not apply to employers covered under the Safer Federal Workforce Task Force COVID-19 Workplace Safety: Guidance for Federal Contractors or Subcontractors (see here), or to settings where employees provide healthcare services subject to OSHA’s ETS for the healthcare industry (see here).