Contact Us
Categories
- Part 2
- Data Privacy
- Department of Health and Human Services' Office of Civil Rights
- Medical Malpractice
- Medical Cannabis
- Workplace health
- Workplace Violence
- Assisted Living Facilities
- EMTALA
- FDA
- Reproductive Rights
- Roe v. Wade
- SCOTUS
- COVID-19
- Prescription Drugs
- Telemedicine
- Medical Spas
- Code Enforcement
- Corporate
- United States Department of Justice ("DOJ")
- Employee Contracts
- Non-Compete Agreement
- Compliance
- HIPAA
- Kentucky Board of Nursing
- Managed Care Organizations (“MCOs”)
- Anti-Kickback Statute
- False Claims Act
- KASPER
- Kentucky Board of Medical Licensure
- Kentucky’s Department for Medicaid Services
- Medicaid
- Mental Health Care
- Office for Civil Rights ("OCR")
- Office of Inspector General of the United States Department of Health and Human Services (OIG)
- Physician Assistants
- Primary Care Physicians ("PCPs")
- Qui Tam
- Stark Laws
- Accountable Care Organizations (“ACO”)
- Affordable Care Act
- APRNs
- Centers for Medicare & Medicaid Services (“CMS”)
- Charitable Hospitals
- Data Breach
- Electronic Protected Health Information (ePHI)
- Federally Qualified Health Centers (“FQHCs”)
- Health Information Technology for Economic and Clinical Health Act (HITECH Act)
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Health Professional Shortage Area ("HPSA")
- Hospitals
- HPSA
- HRSA
- Medicare
- Mid-Level Practitioners
- Patient Protection and Affordable Care Act (“ACA”)
- Pharmacists
- Rural Health Centers (“RHCs”)
- Rural Health Clinic
- Telehealth
- Business Associate Agreements
- Compliance Programs
- Fraud
- Hospice
- Overpayments
- Part D
- Appeal
- Electronic Health Records (“EHR")
- ERISA
- Advanced Practice Registered Nurses
- Business Associates
- Denied Claims
- Division of Regulated Child Care
- Employee Agreement
- Fair Labor Standards Act (FLSA)
- Licensed practical nurses (LPN)
- Licensure Requirements
- Nurse practitioners (NP)
- Part A
- Part B
- Patient Autonomy
- Personal Health Information
- Personal Service Entities
- Physician Payments
- Qualified Health Plan ("QHP")
- Registered nurses (RN)
- Abuse and Waste
- Occupational Safety and Health Administration (“OSHA”)
- Department of Health and Human Services (HHS)
- Health Insurance
- Healthcare Regulation
- Health Care Law
McBrayer Blogs
When HIPAA Says Yes but Part 2 Says No, Part Two: When Investigators Contact Your Employees
In this three-part series, we investigate the duties of SUD providers under Part 2 in the face of subpoenas and investigations. Part One discussed the contours of the duties in the face of a subpoena, while Part Two walks you through what happens when your employees are contacted by investigators.
In a Medicaid fraud investigation, it is common for investigators, whether from a state attorney general’s office, an inspector general, or another agency, to contact your employees directly. They may show up at your facility, call staff members, or request informal interviews with your employees outside the work environment. Just as it is important to train employees on HIPAA compliance, SUD program employees must also be trained on Part 2.
- Your Employees Are Bound by Part 2
Every employee of a Part 2 program has a legal obligation to protect the confidentiality of SUD patient records and patient information. Part 2’s prohibitions apply to the program, its employees, its independent contractors, and agents. An employee cannot verbally confirm whether a person is or was a patient, discuss treatment details, or hand over records, even in a face-to-face conversation with a law enforcement officer or investigator, without proper legal authorization (patient consent or a qualifying court order plus subpoena).
- What Your Employees Should Do
If an investigator contacts an employee of your program, your employees should be trained to:
- Notify the SUD program immediately.
- Be polite but firm. Employees should not be hostile, but they should not volunteer information either.
- Decline to answer questions about patients. Even confirming or denying a patient’s identity or treatment status can violate Part 2.
- Not hand over any records or divulge information. No records should be produced without authorization from program leadership and legal counsel.
- Direct the investigator to the appropriate person. Designate a single point of contact, typically the program director, compliance officer, or legal counsel, to handle all investigative requests.
- Document the contact. Note the investigator’s name, agency, badge or ID number, what was asked, and what (if anything) was said in response.
- Contact legal counsel immediately. The program’s attorney should be notified as soon as possible after any investigative contact.
Please join us tomorrow for Part Three of this series to discover proactive steps to take if your program is under investigation.
Lisa English Hinkle is a Member of McBrayer and chairs the healthcare law practice. Ms. Hinkle is based in the Lexington office. You can contact her at lhinkle@mcbrayerfirm.com or (859) 551-3668.
Valerie Michael is a Member at McBrayer's Lexington office. Ms. Michael focuses her area of practice on healthcare law, handling a wide variety of matters, such as healthcare professional licensure defense, compliance, and regulatory issues. Ms. Michael can be reached at vmichael@mcbrayerfirm.com or (859) 551-3624.

