Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Tax Savings Potentially on the Chopping Block under President Biden’s American Jobs Plan and American Families Plan

Recently, President Biden has proposed several tax law changes in his American Jobs Plan and American Families Plan. Outlined below, are a few of the tax savings that could be significantly changed or eliminated under Biden’s plans.

Here are the Final Candidates for Mayor of Cleveland

Earlier this year, current Cleveland Mayor, Frank Jackson, announced he would not run for re-election this fall. With no need to beat an incumbent, the Cleveland mayoral race suddenly became competitive. Thirteen individuals declared their intent to run for mayor. The City of Cleveland, however, has a difficult qualification requirement to run: 3,000 valid signatures from Cleveland residents. The deadline to file a petition to run, with the 3,000 valid signatures, had to be submitted by June 16 (yesterday).

What Happens to a Pandemic Stimulus Payment Upon Death?

On January 1, 2021, the federal government issued stimulus payments (also known as Economic Impact Payments) to American citizens – on paper. However, many of the stimulus payments were not received until several months later. Sometimes the stimulus payments did not arrive until after an individual died.

The Masks Are Back: New OSHA Regulations for Healthcare Employers

Employment Law After Hours is back with a News Break Episode. Yesterday, OSHA published new rules for healthcare facilities, including hospitals, home health employers, nursing homes, ambulance companies, and assisted living facilities. These new rules are very cumbersome, requiring mask wearing for all employees, even those that are vaccinated. The only exception is for fully vaccinated employees (2 weeks post final dose) who are in a "well-defined" area where there is no reasonable expectation that any person with suspected or confirmed COVID-19 will be present.

New OSHA Guidance for Workplaces Not Covered by the Healthcare Emergency Temporary Standard

On June 10, 2021, OSHA issued an Emergency Temporary Standard (ETS) for occupational exposure to COVID-19, but it applies only to healthcare and healthcare support service workers. For a detailed summary of the ETS applicable to the healthcare industry, please visit https://youtu.be/vPyXmKwOzsk. All employers not subject to the ETS should review OSHA’s contemporaneously released, updated Guidance on Mitigating and Preventing the Spread of COVID-19 in the Workplace. The new Guidance essentially leaves intact OSHA’s earlier guidance, but only for unvaccinated and otherwise at-risk workers (“at-risk” meaning vaccinated or unvaccinated workers with immunocompromising conditions). For fully vaccinated workers, OSHA defers to CDC Guidance for Fully Vaccinated People, which advises that most fully vaccinated people can resume activities without wearing masks or physically distancing, except where required by federal, state, or local laws or individual business policies.