Contact Us
Categories
- Medical Spas
- medical billing
- No Surprises Act
- Mandatory vaccination policies
- Workplace health
- Coronavirus Aid, Relief and Economic Security Act
- Code Enforcement
- Department of Labor ("DOL")
- Employment Law
- FFCRA
- CARES Act
- Nursing Home Reform Act
- COVID-19
- SB 150
- Acute Care Beds
- Clinical Support
- Coronavirus
- Emergency Medical Services
- Emergency Preparedness
- Families First Coronavirus Response Act
- Family and Medical Leave Act (“FMLA”)
- KBML
- medication assisted therapy
- Department of Health and Human Services
- Legislative Developments
- Corporate
- United States Department of Justice ("DOJ")
- Employee Contracts
- Non-Compete Agreement
- Opioid Epidemic
- Sexual Harassment
- Health Resource and Services Administration
- Litigation
- Medical Malpractice
- House Bill 333
- Senate Bill 79
- locum tenens
- Senate Bill 4
- Physician Prescribing Authority
- Chronic Pain Management
- HIPAA
- Prescription Drugs
- "Two Midnights Rule"
- 340B Program
- EHR Systems
- Hospice
- ICD-10
- Kentucky minimum wage
- Minimum wage
- Primary Care Physicians ("PCPs")
- Skilled Nursing Facilities (“SNFs”)
- Uncategorized
- Drug Screening
- Electronic Health Records (“EHR")
- KASPER
- Mental Health Care
- Urinalysis
- Affordable Insurance Exchanges
- Compliance
- Department of Health and Human Services (HHS)
- Fraud
- Health Care Fraud
- HIPAA Risk Assessment
- HPSA
- Kentucky Board of Medical Licensure
- Kentucky’s Department for Medicaid Services
- Office for Civil Rights ("OCR")
- Office of Inspector General of the United States Department of Health and Human Services (OIG)
- Pharmacists
- Physician Assistants
- Qui Tam
- Stark Laws
- Accountable Care Organizations (“ACO”)
- Affordable Care Act
- Alternative Payment Models
- Anti-Kickback Statute
- Centers for Medicare & Medicaid Services (“CMS”)
- Certificate of Need ("CON")
- Charitable Hospitals
- Data Breach
- Electronic Protected Health Information (ePHI)
- False Claims Act
- Federally Qualified Health Centers (“FQHCs”)
- Fee for Service
- Health Information Technology for Economic and Clinical Health Act (HITECH Act)
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Health Professional Shortage Area ("HPSA")
- Hospitals
- HRSA
- Limited Services Clinics
- Medicaid
- Medical Staff By-Laws
- Medically Underserved Area ("MUA")
- Medicare
- Mid-Level Practitioners
- Part D
- Patient Protection and Affordable Care Act (“ACA”)
- Rural Health Centers (“RHCs”)
- Rural Health Clinic
- Telehealth
- American Telemedicine Association (“ATA”)
- Criminal Division of the Department of Justice (“DOJ”)
- Health Care Fraud Prevention and Enforcement Action Team (“HEAT”)
- Kentucky Board of Nursing
- Qualified Health Care Centers (“FQHC”)
- Telemedicine
- Hydrocodone
- Kentucky Pharmacists Association
- United States ex. Rel. Kane v. Continuum Health Partners
- Webinar
- Agreed Order
- APRNs
- Chain and Organization System (“PECOS”)
- Douglas v. Independent Living Center of Southern California
- Drug Enforcement Agency ("DEA")
- Emergency Rooms
- Hinchy v. Walgreen Co.
- Jimmo v. Sebelius
- Maintenance Standard
- Overpayments
- Vitas Innovative Hospice Care
- 2014 Medicare Physician Fee Schedule (“PFS”)
- All-Payer Claims Database ("APCD")
- Chiropractic services
- Chronic Care Management
- Clinical Laboratory Improvement Amendments of 1988 (“CLIA”)
- Compliance Officer
- CPR
- Enrollment
- Essential Health Benefits
- ICD-9
- Kentucky Senate Bill 7
- Medicare Part D
- Minors
- Ophthalmological services
- Physician Compare website
- Re-validation
- Sustainable Growth Rate (“SGR”)
- Texting
- 501(c)(3)
- Affinity Health Plan
- Appeal
- Cadillac tax
- Centers for Disease Control and Prevention
- Community health needs assessment (“CHNA”)
- Compounding
- Condition of Participation ("CoP")
- Denied Claims
- Dispenser
- Drug Quality and Security Act (“DQSA”)
- Federation of State Medical Boards (“FSMB”)
- Food and Drug Administratio
- Form 4720
- Grace Period
- HealthCare.gov
- Home Medical Equipment Providers
- House Bill 3204
- Individual mandate
- Kentucky Medical Practice Act
- Kindred v. Cherolis
- Kynect
- Licensure Requirements
- Long-term care communities
- Long-Term Care Providers ("LTC")
- Mobile medical applications ("apps")
- Model Policy for the Appropriate Use of Social Media and Social Networking in Medical Practice (“Model Policy”)
- National Drug Code ("NDC")
- National Institutes of Health
- New England Compounding Center ("NECC")
- Nonprofit hospitals
- Outsourcing facility
- Personal Service Entities
- Physician Payments
- Ping v. Beverly Enterprises
- Power of Attorney ("POA")
- Prescriber
- Qualified Health Plan ("QHP")
- Social Media
- Spousal coverage
- State Health Plan
- UPS
- "Plan of Correction"
- Advanced Practice Registered Nurses
- Arbitration
- Audit
- Call Coverage
- Daycare centers
- Decertification
- Department of Medicaid Services’ (“DMS”)
- Division of Regulated Child Care
- Doe v. Guthrie Clinic
- EHR vendor
- Employer Group Health Plans
- Employer Mandate
- ERISA
- Fair Labor Standards Act (FLSA)
- False Billings
- Group Purchasing Organizations ("GPO")
- Health Professional Shortage Areas (“HPSA”)
- Health Reform
- Home Health Prospective Payment System
- Hospitalists
- House Bill 104
- Inpatient Care
- Intermediate Sanctions Agreement
- Kentucky Health Benefit Exchange
- Licensed practical nurses (LPN)
- List of Excluded Individuals and Entities
- LLC v. Sutter
- Low-utilization payment adjustment ("LUPA")
- Meaningful use incentives
- Medicare Administrative Coordinators
- Medicare Benefit Policy Manual
- Medicare Shared Saving Program (MSSP)
- Network provider agreement
- Nonroutine medical supplies conversion factor (“NRS”)
- Nurse practitioners (NP)
- Office of the National Coordinator for Health Information Technology (“ONC”)
- Part A
- Part B
- Patient Privacy
- Payors
- Physician Recruitment
- Physician shortages
- Provider Self Disclosure Protocol
- Quality reporting
- Registered nurses (RN)
- Residency Programs
- Self-Disclosure Protocol
- Statement of Deficiency ("SOD")
- Trade Association Group Coverage
- Upcoding
- “Superuser”
- Autism/ASD
- Business Associate Agreements
- Business Associates
- Genetic Information Nondiscrimination Act ("GINA")
- Kentucky House Bill 159
- Kentucky House Bill 217
- Kentucky Primary Care Centers (“PCCs”)
- Managed Care Organizations (“MCOs”)
- Patient Autonomy
- Personal Health Information
- Senate Bill 39
- Senate Finance Committee Report
- State Medicaid Expansion
- Abuse and Waste
- Center for Disease Control
- Compliance Programs
- Consumer Operated and Oriented Plan programs (“CO-OPS”)
- Critical Access Hospitals (“CAHs”)
- Essential Health Benefits (“EHBs”)
- Healthcare Information and Management Systems Society (HIMSS)
- Kentucky Cabinet for Health and Family Services
- Kentucky Health Care Co-Op
- Kentucky Health Cooperative (“KYHC”)
- Medicare Audit Improvement Act of 2012
- Occupational Safety and Health Administration (“OSHA”)
- Recovery Audit Contractors (“RAC”)
- Small Business Health Options Program (“SHOP”)
- Sunshine Act
- Employee Agreement
- Free Conference Committee Report
- Health Care Fraud and Abuse Control Program
- House Bill 1
- House Bill 4
- Kentucky “Pill Mill Bill”
- Pain Management Facilities
- Health Care Law
- Health Insurance
- Healthcare Regulation
McBrayer Blogs
Showing 5 posts in HIPAA.
Healthcare Entities: HIPAA's Privacy Rule Exceptions in Light of COVID-19
While the HIPAA Privacy Rule protects the privacy of patients’ health information (PHI), it is balanced to ensure that appropriate uses and disclosures of the information still may be made when necessary to treat a patient, to protect the nation’s public health, and for other critical purposes. More >
Tough Issues: Privacy and COVID-19
Now more than ever, healthcare providers face important issues about HIPAA and patient privacy requirements for patients being evaluated for COVID-19, for those being treated for it, and for those exposed to it. Patient privacy issues are complicated and if not handled correctly create risks for healthcare providers and healthcare employees, including financial penalties. Even in times of emergency, the protections of the Privacy Rule are not set aside. With the public wanting to know who has been exposed, who has been tested, and who has COVID-19, as well as all the details about individual patients and their families, healthcare providers need to know what can be disclosed in a manner consistent with HIPAA’s Privacy Rule. Healthcare workers must also know that they are not authorized to disclose information on individuals even when they think that it is in the best interest of the public. HIPAA privacy standards still apply even when disclosures are permitted. Thus, now more than ever, healthcare providers must have strong policies and procedures in place that their employees know and follow. From clinicians to maintenance staff, healthcare providers should make sure that individual staff members understand their obligations and HIPAA’s privacy protections.
Lisa English Hinkle is a Member of McBrayer law. Ms. Hinkle chairs the healthcare law practice and is located in the firm’s Lexington office. Contact Ms. Hinkle at lhinkle@mcbrayerfirm.com or (859) 231-8780, ext. 1256, or reach out to any of the attorneys at McBrayer.
Services may be performed by others.
This article does not constitute legal advice.
Healthcare Entities: How is Your Cyber Security?
In an evolving world of cyber terrorism where individuals such as Edward Snowden grab headlines by stealing national secrets, it should come as no surprise that protected healthcare information (“PHI”) kept by providers has become a “target rich environment” for foreign governments and individual hackers alike. In addition to threats from outside entities, healthcare providers must also realize and appreciate that state and federal regulatory and statutory requirements govern the creation, maintenance and protection of PHI, including through but not limited to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the Health Information Technology for Economic and Clinical Health (“HITECH”) Act. Failure to abide by these complex and stringent rules can lead to significant penalties. More >
HHS Finalizes Exception to HIPAA Privacy Rule for Firearm Background Checks
In January of 2016, the Department of Health & Human Services (“HHS”) issued a final rule modifying the HIPAA Privacy Rule.[1] This modification allows certain covered entities to disclose the identities of certain individuals to the National Instant Criminal Background Check System (“NICS”), a database maintained by the FBI. The information disclosed by the entities would pertain to an individual’s mental health, preventing those subject to a federal “mental health prohibitor” from possessing or receiving a firearm. Such a disclosure naturally creates a tension in the patient-provider relationship, however, and critics contend it could potentially discourage mentally ill individuals from seeking treatment.
New Guidance Maps HIPAA Security Rule to NIST Cybersecurity Framework to Help Providers Manage Cybersecurity Risk
In a world of looming data breaches and significant penalties for the release of protected health information, the complexities of cybersecurity and compliance with the HIPAA Security Rule can be incredibly daunting. In 2014, in response to the growing threat of data breaches, the National Institute of Standards and Technology (“NIST”) released the Framework for Improving Critical Infrastructure Cybersecurity (“the Framework”) as a means to standardize best practices in cybersecurity across organizations. To assist providers with implementing the Framework while remaining in compliance with the HIPAA Security Rule, the Department of Health and Humans Services Office for Civil Rights (“OCR”) published a HIPAA Security Rule Crosswalk (“the Crosswalk”) to tie the standards together and help strengthen cybersecurity preparedness. More >