Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Ohio Supreme Court Clarifies Medical Statute of Limitations

The Ohio Supreme Court issued a decision in late December that clarifies and finalizes the Ohio law regarding the period of time in which patients can assert claims for medical malpractice. The Court was examining the interplay between three different statutes being the statute of limitations, the statute of repose, and the savings statute.

Ohio Hospitals and Healthcare Clinics: It’s Time to Revisit Your Billing and Collection Practices

According to a recent Cuyahoga County case, certain healthcare entities may not be protected from liability when engaging in unfair or deceptive billing acts. This decision is consistent with the growing trend across the country to encourage price transparency and eliminate unfair surprise billing practices by health care organizations. Now is the time for hospitals and other health care organizations to revisit their billing and collection policies and procedures to confirm that they are legally defensible and consistent with best practices.

HIPAA Business Associate Agreements: Why These Contracts Matter

No one loves drafting, reading or negotiating HIPAA Business Associate Agreements (BAAs). Yet many of us need to do so, and some of us do so daily. They are often boring, dense and technical, but BAAs are important from both a legal and a business perspective, and they deserve our attention. Failure to enter a BAA when one is required can constitute a HIPAA violation that results in substantial liability, as demonstrated by certain recent Department of Health & Human Services (HHS) settlements.1 A business associate who makes a disclosure that is not authorized by the applicable BAA or required by law can be subject to civil and, in some cases, criminal penalties. Further, parties are often presented with BAAs that contain onerous one-sided indemnification and other provisions that can be devasting to an organization in the event of a HIPAA breach. The significance of a BAA is often not fully understood by the parties until something goes wrong (e.g., a HIPAA security incident or breach, an Office of Civil Rights (OCR) audit or a fracture in the relationship between the parties) and, at that point, there is limited opportunity to mitigate legal and business risk. Ideally, attention should be given at the commencement of the business associate relationship, when the parties are able, to thoughtfully addressing regulatory requirements, planning and preparing for potential adverse events and appropriately allocating risk among the parties. As with most healthcare regulatory compliance initiatives, a proactive approach with respect to BAAs is preferable. This article provides a broad overview of certain BAA requirements and some practical negotiating tips for the parties involved.

“I’m Out Of Here!” Now What?

We all know that the healthcare industry is experiencing a wave of integration. This trend has been evident for many years. Fewer physicians are willing to assume the legal, financial and other business risks associated with owning their own practices. More and more physicians, including anesthesiologists, are becoming employed by large physician groups, health systems and national providers. This shift necessarily involves not only entry into new employment arrangements but also the termination of existing relationships. And those terminations are often governed by written employment agreements, state and federal healthcare laws and employer benefit plans and other policies and procedures. Before pursuing their next opportunity, physicians should pause for a moment and first attend to the arrangement that they are leaving. Departing physicians need to understand their legal rights and obligations when leaving their current employment relationships in order to avoid unintended consequences and detrimental missteps along the way. Here are a few words of practical advice for physicians contemplating an exit from their current employment arrangements.

Investment Training for the Second and Third Generations

Consider this scenario. Mom and Dad started the business from the ground up. Over the decades it has expanded into a money-making machine. They are able to sell the business and it results in a multimillion-dollar payday for their labors. The excess money has allowed Mom and Dad to invest with various financial advising firms, several fund management groups, and directly with new startups and joint ventures. Their experience has made them savvy investors, with a detailed understanding of how much to invest, when, and where. They cannot justify formation of a full family office with dedicated investors to manage the funds, but Mom and Dad have set up a trust fund for the children to allow these investments to continue to grow over the years. Eventually, Mom and Dad pass. Their children enjoy the fruits of their labors, and, by the time the grandchildren are adults, Mom and Dad's savvy investments are gone.