Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Should I Apply for Phase 3 Funds? Important Considerations Every Provider Should Know

On October 1, 2020, the Department of Health and Human Services (“HHS”) announced an additional $20 billion in new funding for providers through a Phase 3 distribution. Importantly, providers that previously received HHS Provider Relief Funds or already received payments of approximately 2% of annual revenue from patient care are eligible to apply. Eligible providers have until November 6, 2020 to apply for these Phase 3 Funds. However, the question from providers continues to be: Should I Apply for Phase 3 Funds?

CISA Ransomware Practices

On October 28, 2020, the United States Cybersecurity and Infrastructure Security Agency (CISA) issued an alert warning of imminent threats to US hospitals and healthcare providers. The specific threat involves RYUK Ransomware attacks. RYUK is a novel ransomware that goes undetected by commercial anti-virus/malware detection programs. Once deployed, RYUK encrypts all data and disables systems. In short, it cripples all functionality down to phone systems and automated doors. Healthcare providers should alert their employees to remain hyper-vigilant and report any suspicious activity seen in email or on networks. It has been reported healthcare providers in New York, Pennsylvania and Oregon have been targeted in the last 48 hours. If your organization encounters issues, BMD can assist in mobilizing a response team and has contacts with forensic IT firms that are familiar with RYUK. It is advisable to engage professionals with experience dealing with this specific threat.

HHS Announces an Additional $20 Billion In Provider Relief Grants

The U.S. Department of Health and Human Services (“HHS”) announced an additional $20 billion in new funding for providers on October 1, 2020. Eligible providers include those that have already received Provider Relief Fund payments as well as previously ineligible providers, such as those who began practicing in 2020, and an expanded group of behavioral health providers confronting the emergence of increased mental health and substance use issues exacerbated by the pandemic. The new Phase 3 General Distribution is designed to balance an equitable payment of 2% of annual revenue from patient care for all applicants plus an add-on payment to account for revenue losses and expenses attributable to COVID-19.

DOL Proposes New Rule Regarding Independent Contractor Status - But How Will the Election Affect Its Future?

On September 22, 2020, the U.S. Department of Labor announced a new proposed rule regarding employee and independent contractor status under the Fair Labor Standards Act. The full text of the proposed rule is available here. The rule's drafters intend to reduce uncertainty and enhance the precision and predictability of the long-standing "economic reality" test, which currently relies on a multifactor balancing test.

Major Change to Franklin County, Ohio Eviction Process: Landlord Testimony Required

Although there is currently a nationwide temporary halt on all residential evictions through December 31, 2020 in place, the eviction process in Franklin County – which processes the highest number of evictions in the State of Ohio at approximately 18,000 a year – recently changed significantly.