Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Time to Update Your HIPAA Compliance Plan for Telehealth Policies and Procedures

The delivery of healthcare in this country may be forever changed following the COVID-19 pandemic. Providing services through telehealth technologies initially allowed providers to connect with patients in a safe and socially distant manner and helped keep vital hospital beds free for COVID-19 care. Now, while still a safe, socially distant option, telehealth allows patients to access healthcare services in an efficient manner, decreases the likelihood of cancellations, and expands access to services that do not require an in-person encounter (i.e., surgery, procedure, or test). Telehealth is now widely reimbursed by both federal and commercial payors and more provider types are able to provide telehealth services within their licensed scope of practice.

The SEC Amends Accredited Investor and Qualified Institutional Buyer Definitions

The SEC Amends Accredited Investor and Qualified Institutional Buyer Definitions

Landlord Alert: CDC Issues Temporary Halt in Residential Evictions

On September 1 the Centers for Disease Control and Prevention (“CDC”) issued a nationwide temporary halt on all residential evictions through December 31, 2020. With the July 24, 2020 expiration of the prior moratorium established under the CARES Act, the CDC based the new moratorium on the need to protect public health and the likely increase in the spread of COVID-19 if mass evictions take place.

BMD Obtains Supreme Court Victory on Behalf of Sterilite of Ohio, LLC

Columbus, Ohio – On August 26, 2020, the Supreme Court of Ohio issued its opinion in Lunsford v. Sterilite of Ohio, LLC, Slip Op. No. 2020-Ohio-4193. The Supreme Court’s 4-3 decision reversed an Ohio Court of Appeals ruling that had reinstated a putative class action against Sterilite brought by a group of current and former employees claiming that Sterilite’s use of “direct observation” urinalysis screening violated their common law right to privacy.

Provider Relief Fund Phase 2 & Reporting Requirement Updates – Deadline to Request Phase 2 Funds is August 28, 2020

On July 31, 2020, the Department of Health and Human Services (“HHS”) announced that certain Medicare, Medicaid (managed care and fee-for-service), CHIP, and other providers would be given another opportunity to receive additional Provider Relief Fund payments. HHS has allocated around $15 billion for Phase 2 distribution. Providers are eligible for these new distributions if they fulfill the following criteria and have not yet received a Provider Fund payment equal to approximately 2% of their revenue from patient care.