Lobbying Affiliate: MML&K Government Solutions
{ Banner Image }

Healthcare Law Blog

Comprehensive Healthcare law services.
It's kind of our bag.

Contact Us

250 Character(s) Remaining
Type the following characters: three, six, mike, hotel, foxtrot

* Indicates a required field.

Categories

McBrayer Blogs

Related Blogs

Showing 16 posts from 2014.

The Walmart List: Milk, Eggs, and a Doctor Visit?

By January 2015, Walmart will be operating dozen primary care clinics across the U.S. Six of these have already opened in South Carolina and Texas. Currently, some Walmart stores include acute care clinics that are operated through leases with local hospital operators. The new primary care clinics are distinct from the existing ones in several ways. The new clinics will be fully-owned by Walmart, offer a broader range of services, and be open seven days a week with longer operating hours. Walmart is partnering with QuadMed nationally to operate the clinics, rather than with local partners. The primary care clinics will be staffed primarily by nurse practitioners and medical assistants and will be supervised by a physician. More >

Reminder: Update Your “Grandfathered” HIPAA Business Associate Agreements Now!

In January 2013, the Department of Health and Human Services (“HHS”) published its Final Rule, which significantly increased the privacy and security responsibilities for the “business associates” of “covered entities,” as those terms are defined by HIPAA. A provision within the Final Rule mandated that all covered entities and their business associates revise their business associate agreements to reflect the new responsibilities. Specifically, a business associate must now, among other things: More >

Health Care Industry Familiar with HIPAA Breaches, Not So Much Hackers

Community Health Systems (“Community”), which operates 206 hospitals in 29 states, recently notified 4.5 million of its patients that online hackers had stolen personal data information from its systems in a period between April and June 2014. The data included names, addresses, birthdates, telephone numbers and Social Security numbers—all of which are protected under HIPAA. According to Community, the data did not include financial or medical information.

It has been reported that the hackers responsible for the attack are a group of cybercriminals from China that traditionally go after intellectual property, including medical device and equipment development data.  They used malicious software to obtain the data, which has since been removed by Community from the network. Further remedial efforts are already underway, including notifying affected patients and offering them identity theft protection services.

Hospitals should be accustomed to protecting data against privacy breaches as part of their HIPAA obligations, but outright cybertheft is a threat that many providers have not likely considered. The FBI, which is now investigating the Community incident, said in April that health care providers typically do not use the same high levels of security technology as companies in other industries (such as banking or retail). This makes providers an easy target for hackers. If a leading hospital system like Community can be breached, then hospitals of every size are at risk.

It is crucial that HIPAA-covered entities (and their business associates) understand and identify potential threats to their secured information. The importance of HIPAA risk analysis cannot be stressed enough; in fact, a risk analysis is required as the first step in HIPAA Security Rule compliance. While it may be impossible to build an impenetrable fortress of secured online information, it is evident that health care providers must continue to make it a top priority to protect patient records – both from HIPAA breaches and hackers.

Services may be performed by others.

This article does not constitute legal advice.

New Part D Regulations Face Increased Scrutiny from Advocacy Groups & Congress

On March 10, 2014, the Centers for Medicare & Medicaid Services (“CMS”) issued a memorandum to Part D Plan Sponsors and Medicare Hospice Providers entitled, "Part D Payment for Drugs for Beneficiaries Enrolled in Hospice – Final 2014 Guidance" (“Guidance”).   The Guidance, effective since May 1, 2014, requires a prior authorization process for Hospice and Part D providers to determine their respective responsibility for drug coverage. The Guidance followed a 2012 OIG report entitled "Medicare Could Be Paying Twice for Prescription Drugs for Beneficiaries in Hospice,” which found that Medicare Hospice patients’ medications were sometimes paid for by Part D rather than by the patient’s Hospice program. More >

Have You Reviewed Your Existing Business Associate Agreements?

Pursuant to the HIPAA Final Omnibus Rule (“Final Rule”), covered entities and their business associates were required to enter into new business associate agreements (“BAAs”) or modify existing BAAs by Sept. 23, 2013. However, existing BAAs that (i) were entered into on or before Jan. 25, 2013; (ii) met the requirements that were applicable prior to the promulgation of the Final Rule; and (iii) were not modified after March 26, 2013, have until Sept. 23, 2014 to be updated. That deadline is quickly approaching. More >

Tips for New Enrollment & Revalidation for Participation in Medicare & Medicaid

The new enrollment and revalidation requirements for providers and suppliers for Medicare/Medicaid participation was previously  detailed on this blog. As promised as a follow-up, this blog post will describe enrollment best practices and tips for ensuring that enrollment or revalidation is properly accomplished. Not only is initial enrollment now more onerous, but revalidation is required for all physicians and other providers/suppliers who were enrolled before March 25, 2011, which generally means that all physicians and physician groups must complete the re-enrollment process. A failure to re-enroll means that CMS will de-activate payment until a successful re-enrollment process is completed. In some cases, CMS may even revoke participation. Thus, it is crucial that physicians, providers, and suppliers get it right the first time. More >

Time to “Face” The Risks

In 2011, the U.S. Centers for Medicare and Medicaid Services (“CMS”), as part of the reform instituted by the Affordable Care Act, required that home health agencies and hospice patients receive a face-to-face visit (at specified time periods) by a physician or nurse practitioner to ensure that they continue to meet Medicare and Medicaid eligibility criteria. More >

All Eyes on Hospice Care

In 2013, the Department of Justice (“DOJ”) and Office of Inspector General (“OIG”) charged the nation’s largest for-profit hospice chain, Vitas Innovative Hospice Care (“Vitas”), with false Medicare billings, inappropriately admitting patients with “aggressive marketing tactics,” and misleading patients and families about Medicare hospice benefits. This suit is just one of many recently filed against hospice providers, indicating that they are being watched keenly by enforcement authorities and government agencies. More >

Important Reminder for Association Group Health Plans

In Kentucky, most trade association-sponsored health plans renew on July 1, 2014. Now is an excellent time for trade association executives to review association and Health Plan materials to ensure compliance with applicable Federal and State requirements prior to renewal. More >

Voluntary Surrender of DEA Registration: Proceed With Caution

All too often, the Drug Enforcement Agency (“DEA”) asks a physician to surrender his or her DEA registration when the physician enters into a prescribing-related Agreed Order with the applicable state licensing authority. A DEA registration is important because, in order to write prescriptions for controlled substances or dispense controlled substances in-office, physicians must be registered with the DEA. More >

Lexington, KYLouisville, KYFrankfort, KYFrankfort, KY: MML&K Government Solutions