Contact Us
Categories
- Department of Health and Human Services' Office of Civil Rights
- Medical Residents
- EMTALA
- FDA
- Reproductive Rights
- Roe v. Wade
- SCOTUS
- Medical Spas
- medical billing
- No Surprises Act
- Mandatory vaccination policies
- Workplace health
- Coronavirus Aid, Relief and Economic Security Act
- Code Enforcement
- Department of Labor ("DOL")
- Employment Law
- FFCRA
- CARES Act
- Nursing Home Reform Act
- COVID-19
- SB 150
- Acute Care Beds
- Clinical Support
- Coronavirus
- Emergency Medical Services
- Emergency Preparedness
- Families First Coronavirus Response Act
- Family and Medical Leave Act (“FMLA”)
- KBML
- medication assisted therapy
- Department of Health and Human Services
- Legislative Developments
- Corporate
- United States Department of Justice ("DOJ")
- Employee Contracts
- Non-Compete Agreement
- Opioid Epidemic
- Sexual Harassment
- Health Resource and Services Administration
- Litigation
- Medical Malpractice
- House Bill 333
- Senate Bill 79
- locum tenens
- Physician Prescribing Authority
- Senate Bill 4
- Chronic Pain Management
- HIPAA
- Prescription Drugs
- "Two Midnights Rule"
- 340B Program
- EHR Systems
- Hospice
- Kentucky minimum wage
- Minimum wage
- Skilled Nursing Facilities (“SNFs”)
- Uncategorized
- Drug Screening
- Electronic Health Records (“EHR")
- HIPAA Risk Assessment
- ICD-10
- KASPER
- Mental Health Care
- Office for Civil Rights ("OCR")
- Primary Care Physicians ("PCPs")
- Urinalysis
- Accountable Care Organizations (“ACO”)
- Affordable Care Act
- Affordable Insurance Exchanges
- Anti-Kickback Statute
- Centers for Medicare & Medicaid Services (“CMS”)
- Certificate of Need ("CON")
- Compliance
- Data Breach
- Department of Health and Human Services (HHS)
- Electronic Protected Health Information (ePHI)
- False Claims Act
- Federally Qualified Health Centers (“FQHCs”)
- Fee for Service
- Fraud
- Health Care Fraud
- Health Information Technology for Economic and Clinical Health Act (HITECH Act)
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Hospitals
- HPSA
- Kentucky Board of Medical Licensure
- Kentucky’s Department for Medicaid Services
- Medicaid
- Medical Staff By-Laws
- Medicare
- Office of Inspector General of the United States Department of Health and Human Services (OIG)
- Part D
- Patient Protection and Affordable Care Act (“ACA”)
- Pharmacists
- Physician Assistants
- Qui Tam
- Rural Health Centers (“RHCs”)
- Stark Laws
- Telehealth
- Alternative Payment Models
- American Telemedicine Association (“ATA”)
- Charitable Hospitals
- Criminal Division of the Department of Justice (“DOJ”)
- Health Care Fraud Prevention and Enforcement Action Team (“HEAT”)
- Health Professional Shortage Area ("HPSA")
- HRSA
- Kentucky Board of Nursing
- Limited Services Clinics
- Medically Underserved Area ("MUA")
- Mid-Level Practitioners
- Qualified Health Care Centers (“FQHC”)
- Rural Health Clinic
- Telemedicine
- APRNs
- Hydrocodone
- Kentucky Pharmacists Association
- United States ex. Rel. Kane v. Continuum Health Partners
- Webinar
- Agreed Order
- All-Payer Claims Database ("APCD")
- Chain and Organization System (“PECOS”)
- Chiropractic services
- Clinical Laboratory Improvement Amendments of 1988 (“CLIA”)
- Douglas v. Independent Living Center of Southern California
- Drug Enforcement Agency ("DEA")
- Emergency Rooms
- Enrollment
- Hinchy v. Walgreen Co.
- ICD-9
- Jimmo v. Sebelius
- Kentucky Senate Bill 7
- Maintenance Standard
- Medicare Part D
- Minors
- Ophthalmological services
- Overpayments
- Physician Compare website
- Re-validation
- Texting
- Vitas Innovative Hospice Care
- 2014 Medicare Physician Fee Schedule (“PFS”)
- 501(c)(3)
- Affinity Health Plan
- Appeal
- Cadillac tax
- Centers for Disease Control and Prevention
- Chronic Care Management
- Community health needs assessment (“CHNA”)
- Compliance Officer
- Compounding
- Condition of Participation ("CoP")
- CPR
- Denied Claims
- Dispenser
- Drug Quality and Security Act (“DQSA”)
- Essential Health Benefits
- Federation of State Medical Boards (“FSMB”)
- Food and Drug Administratio
- Form 4720
- Grace Period
- HealthCare.gov
- Home Medical Equipment Providers
- House Bill 3204
- Individual mandate
- Inpatient Care
- Kentucky Medical Practice Act
- Kindred v. Cherolis
- Kynect
- Licensure Requirements
- Long-term care communities
- Long-Term Care Providers ("LTC")
- Medicare Shared Saving Program (MSSP)
- Mobile medical applications ("apps")
- Model Policy for the Appropriate Use of Social Media and Social Networking in Medical Practice (“Model Policy”)
- National Drug Code ("NDC")
- National Institutes of Health
- New England Compounding Center ("NECC")
- Nonprofit hospitals
- Outsourcing facility
- Personal Service Entities
- Physician Payments
- Ping v. Beverly Enterprises
- Power of Attorney ("POA")
- Prescriber
- Qualified Health Plan ("QHP")
- Social Media
- Spousal coverage
- State Health Plan
- Sustainable Growth Rate (“SGR”)
- UPS
- “Superuser”
- "Plan of Correction"
- Advanced Practice Registered Nurses
- Arbitration
- Audit
- Autism/ASD
- Business Associate Agreements
- Business Associates
- Call Coverage
- Daycare centers
- Decertification
- Department of Medicaid Services’ (“DMS”)
- Division of Regulated Child Care
- Doe v. Guthrie Clinic
- EHR vendor
- Employer Group Health Plans
- Employer Mandate
- ERISA
- Fair Labor Standards Act (FLSA)
- False Billings
- Group Purchasing Organizations ("GPO")
- Health Professional Shortage Areas (“HPSA”)
- Health Reform
- Home Health Prospective Payment System
- Hospitalists
- House Bill 104
- Intermediate Sanctions Agreement
- Kentucky Health Benefit Exchange
- Kentucky House Bill 159
- Kentucky House Bill 217
- Licensed practical nurses (LPN)
- List of Excluded Individuals and Entities
- LLC v. Sutter
- Low-utilization payment adjustment ("LUPA")
- Meaningful use incentives
- Medicare Administrative Coordinators
- Medicare Benefit Policy Manual
- Network provider agreement
- Nonroutine medical supplies conversion factor (“NRS”)
- Nurse practitioners (NP)
- Office of the National Coordinator for Health Information Technology (“ONC”)
- Part A
- Part B
- Patient Autonomy
- Patient Privacy
- Payors
- Personal Health Information
- Physician Recruitment
- Physician shortages
- Provider Self Disclosure Protocol
- Quality reporting
- Registered nurses (RN)
- Residency Programs
- Self-Disclosure Protocol
- Senate Bill 39
- Senate Finance Committee Report
- State Medicaid Expansion
- Statement of Deficiency ("SOD")
- Trade Association Group Coverage
- Upcoding
- Abuse and Waste
- Center for Disease Control
- Compliance Programs
- Consumer Operated and Oriented Plan programs (“CO-OPS”)
- Critical Access Hospitals (“CAHs”)
- Essential Health Benefits (“EHBs”)
- Genetic Information Nondiscrimination Act ("GINA")
- Healthcare Information and Management Systems Society (HIMSS)
- Kentucky Cabinet for Health and Family Services
- Kentucky Health Care Co-Op
- Kentucky Health Cooperative (“KYHC”)
- Kentucky Primary Care Centers (“PCCs”)
- Managed Care Organizations (“MCOs”)
- Medicare Audit Improvement Act of 2012
- Occupational Safety and Health Administration (“OSHA”)
- Recovery Audit Contractors (“RAC”)
- Small Business Health Options Program (“SHOP”)
- Sunshine Act
- Employee Agreement
- Free Conference Committee Report
- Health Care Fraud and Abuse Control Program
- House Bill 1
- House Bill 4
- Kentucky “Pill Mill Bill”
- Pain Management Facilities
- Health Care Law
- Health Insurance
- Healthcare Regulation
McBrayer Blogs
Showing 51 posts in Health Insurance Portability and Accountability Act of 1996 (HIPAA).
Healthcare Entities: HIPAA's Privacy Rule Exceptions in Light of COVID-19
While the HIPAA Privacy Rule protects the privacy of patients’ health information (PHI), it is balanced to ensure that appropriate uses and disclosures of the information still may be made when necessary to treat a patient, to protect the nation’s public health, and for other critical purposes. More >
Tough Issues: Privacy and COVID-19
Now more than ever, healthcare providers face important issues about HIPAA and patient privacy requirements for patients being evaluated for COVID-19, for those being treated for it, and for those exposed to it. Patient privacy issues are complicated and if not handled correctly create risks for healthcare providers and healthcare employees, including financial penalties. Even in times of emergency, the protections of the Privacy Rule are not set aside. With the public wanting to know who has been exposed, who has been tested, and who has COVID-19, as well as all the details about individual patients and their families, healthcare providers need to know what can be disclosed in a manner consistent with HIPAA’s Privacy Rule. Healthcare workers must also know that they are not authorized to disclose information on individuals even when they think that it is in the best interest of the public. HIPAA privacy standards still apply even when disclosures are permitted. Thus, now more than ever, healthcare providers must have strong policies and procedures in place that their employees know and follow. From clinicians to maintenance staff, healthcare providers should make sure that individual staff members understand their obligations and HIPAA’s privacy protections.
Lisa English Hinkle is a Member of McBrayer law. Ms. Hinkle chairs the healthcare law practice and is located in the firm’s Lexington office. Contact Ms. Hinkle at lhinkle@mcbrayerfirm.com or (859) 231-8780, ext. 1256, or reach out to any of the attorneys at McBrayer.
Services may be performed by others.
This article does not constitute legal advice.
New Kentucky Law Provides More Access to Telehealth
Thanks to recently passed legislation going into effect July 1, 2019, Kentucky providers will have more access to patients via telehealth. Previously, telehealth visits were limited to doctors and high-level practitioners, with patients required to be in a clinical setting for the visit. The new law will allow commercial insurance and Medicaid to pay for telehealth visits in the home as well as pay mid-level providers for telehealth visits. More >
OCR Updates HIPAA Audit Protocol for Phase 2
Recently, the Office of Civil Rights (“OCR”) provided an updated protocol that it will use when assessing compliance with HIPAA rules. OCR recently began Phase 2 of its HIPAA compliance audits, extending coverage of these audits to Business Associates (“BAs”) as well as Covered Entities (“CEs”). Both BAs and CEs should pay particular attention to these revised audit protocols, as they indicate exactly what OCR will be looking for when conducting these audits. More >
HHS Finalizes Exception to HIPAA Privacy Rule for Firearm Background Checks
In January of 2016, the Department of Health & Human Services (“HHS”) issued a final rule modifying the HIPAA Privacy Rule.[1] This modification allows certain covered entities to disclose the identities of certain individuals to the National Instant Criminal Background Check System (“NICS”), a database maintained by the FBI. The information disclosed by the entities would pertain to an individual’s mental health, preventing those subject to a federal “mental health prohibitor” from possessing or receiving a firearm. Such a disclosure naturally creates a tension in the patient-provider relationship, however, and critics contend it could potentially discourage mentally ill individuals from seeking treatment.
New Guidance Maps HIPAA Security Rule to NIST Cybersecurity Framework to Help Providers Manage Cybersecurity Risk
In a world of looming data breaches and significant penalties for the release of protected health information, the complexities of cybersecurity and compliance with the HIPAA Security Rule can be incredibly daunting. In 2014, in response to the growing threat of data breaches, the National Institute of Standards and Technology (“NIST”) released the Framework for Improving Critical Infrastructure Cybersecurity (“the Framework”) as a means to standardize best practices in cybersecurity across organizations. To assist providers with implementing the Framework while remaining in compliance with the HIPAA Security Rule, the Department of Health and Humans Services Office for Civil Rights (“OCR”) published a HIPAA Security Rule Crosswalk (“the Crosswalk”) to tie the standards together and help strengthen cybersecurity preparedness. More >
NIST standards provides an oasis of mobile device security in the EHR desert
The healthcare industry has long awaited some certainty in the arena of mobile devices in light of the continued push for electronic health records (“EHR”) and coordinated care. The prevalence, convenience, and speed of such devices is beyond discussion. According to the 2015 HIMSS Mobile Technology Survey, found that 90% of healthcare providers use them in their organizations. Mobile devices provide clinicians with quick access to information at the point of care. However, the use of mobile devices brings a mountain of security risks for covered entities, including the loss or theft of the mobile device and unsecure exchange of health information. When every individual entering a facility has a mobile device, the large number of mobile devices using a facility’s network can overload the system. More >
An Analysis of Urine Toxicology — Considerations for Health Providers
Urine toxicology, also referred to as urine drug screening, is an important procedure that health providers use for several reasons: to monitor patients’ medication compliance, detect drug abuse, or identify the presence of disease. There are numerous implications that accompany a urine toxicology examination though, and health providers are sometimes left wondering if they should hand over the cup to patients. More >
Plan for the Worst, Hope for the Best: Why You Must Have a HIPAA Risk Assessment
“The single biggest and most common compliance weakness is the lack of a timely and thorough risk analysis.” More >
Issues Concerning Substance Abuse Patient Confidentiality Laws
It was with the best of intentions that Congress passed the Federal Confidentiality of Alcohol and Drug Abuse Patient Records Law over forty years ago. The patient privacy regulations (“Part 2”) spawned by this law reflected a sensitivity to the stigma that can accompany substance abuse, preventing highly vulnerable patients in need from seeking appropriate treatment.[1] In the interim, however, the field of behavioral health care has experienced seismic shifts in coordinated patient care while the regulations concerning these patient records have failed to adapt to changing standards such as electronic health records or health information exchanges. Due to this inflexibility, providers and patients are now facing a host of impediments in the provision of behavioral healthcare. More >