Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Value-Based Care Advances – CMS Issues New Final Rules for Stark and Anti-Kickback Statutes

The Centers for Medicare & Medicaid Services (“CMS”) and the Department of Health and Human Services (“HHS”) Office of the Inspector General (“OIG”) issued two highly anticipated (and quite extensive) Final Rules to reform the Stark Law and Anti-Kickback Statute (“AKS”) regulations. The Final Rules generally take effect on January 19, 2021. The Final Rules include new safe harbors for the AKS and new exemptions to the Stark Law to allow for greater flexibility. According to the HHS, the goal of updating both laws is to make it easier for providers to engage in care coordination and value-based care programs without running afoul of the statutes. Please note that this client alert could not cover the full extent of the Final Rule changes so please contact your BMD Healthcare attorney with questions.

Mandatory Filings Under CFIUS New Rules

On September 15, 2020, the Committee on Foreign Investment in the United States (“CFIUS”) promulgated a final rule modifying its mandatory declaration requirements for certain foreign investment transactions involving “TID US businesses” (sensitive U.S. businesses dealing in critical technologies, critical infrastructure and sensitive personal data) dealing in “critical technologies” – i.e., U.S. businesses that produce, design, test, manufacture, fabricate, or develop one or more critical technologies. The new rule also makes amendments to the definition of the term “substantial interest” (used to determine whether a foreign government has a substantial interest in an entity). The final rule became effective on October 15, 2020.

IRS Guidance on Employee Retention Credit

The Employee Retention Credit created under Section 2302 of the Coronavirus Aid, Relief, and Economic Security (“CARES”) Act is a refundable tax credit against certain employment taxes equal to 50 percent of the qualified wages an eligible employer pays to employees after March 12, 2020, and before January 1, 2021. Since the adoption of the CARES Act, employers have expressed concern that if one employer acquires another employer that previously received a PPP loan, the acquirer’s entire aggregated group may no longer be eligible to claim the Employee Retention Credit.

International Sales Contracts - COVID-19 Pandemic and Force Majeure

Identity Protection PIN Available to ALL Taxpayers in January

Beginning in January 2021, the IRS will allow all taxpayers who can properly verify his/her identity to obtain an Identity Protection PIN. An Identity Protection PIN (“IP PIN”) is a six digit number assigned to a specific taxpayer to assist in preventing the misuse of a taxpayer’s social security number on fraudulent federal tax returns. Previously, only confirmed victims of identity theft who resolved his/her tax issues with the IRS were eligible for an IP PIN.