Selected Major Issues in Employer Responses to HIPAA Privacy, at Two Weeks Before the Deadline Jon Neiditz March 28, 2003.

Slides:



Advertisements
Similar presentations
H OGAN & H ARTSON, L.L.P.
Advertisements

HIPAA In Relation to Other Federal Laws Professor Peter P. Swire Ohio State University Consultant, Morrison & Foerster LLP Glasser LegalWorks/HIPAA Conference.
The HIPAA Privacy Rule And Its Impact On Agents And Employers National Association of Health Underwriters Capitol Conference March 23, 2003 Joseph T. Holahan,
Pennsylvania Bureau of Workers’ Compensation Conference December 4, 2003 Beth L. Rubin  2003 Dechert LLP HIPAA Privacy Rule Basics.
HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
Frequently Asked Questions…. …about HIPAA Notice of Privacy Practices and Acknowledgement.
ERISA Essentials and What to Advise Clients to Avoid Audits and be ACA Compliant.
“YOU TAKE CARE OF YOUR PROFITS AND WE’LL TAKE CARE OF YOUR PEOPLE”
HIPAA Compliance: from an Employer’s Perspective Presented by VGM Mark J. Higley Vice President, Development.
Presented by Elena Chan, UCSF Pharm.D. Candidate Tiffany Jew, USC Pharm.D. Candidate March 14, 2007 P HARMACEUTICAL C ONSULTANTS, I NC. P RO P HARMA HIPAA.
HIPAA: Privacy, Security, and HITECH, Oh My! Presented by Stephanie L. Ganucheau, Special Assistant Attorney General.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Protecting Enrollees’ Health Information under HIPAA Presented by the Michigan Department of Civil Service Employee Benefits Division Employee Benefits.
HIPAA Privacy Rule Training
Copyright Eastern PA EMS Council February 2003 Health Information Portability and Accountability Act It’s the law.
HIPAA Privacy Training Your Name Here. © 2004 MHM Resources Inc.2 HIPAA Background Health Insurance Portability and Accountability Act of 1996.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
P E N N S Y L V A N I A C O A L I T I O N A G A I N S T D O M E S T I C V I O L E N C E P E N N S Y L V A N I A C O A L I T I O N A G A I N S T RAPE HIPAA.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
Changes to HIPAA (as they pertain to records management) Health Information Technology for Economic Clinical Health Act (HITECH) – federal regulation included.
1 Student Health Director Briefing Frequently Asked Questions HIPAA May 23, 2012.
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
HIPAA The Hidden Beast June Kissinger Director, Risk Management Support Services March 12, 2003.
HIPAA Understanding Medical Privacy in the Work Place © Copyright 2005 The Nugent Law Firm, P.C. All Rights Reserved.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
HIPAA How It Is Affecting Information Systems Within Companies Around Us.
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
ITEC 6324 Health Insurance Portability and Accountability (HIPAA) Act of 1996 Instructor: Dr. E. Crowley Name: Victor Wong Date: 2 Sept
HIPAA Health Insurance Portability and Accountability Act.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
HIPAA Compliance Strategies for Employers, METs, MEWAs and Taft Hartley Union Trust Funds The HIPAA Colloquium at Harvard University Presented by: Melissa.
HIPAA PRIVACY AND SECURITY AWARENESS.
Copyright South-Western College Publishing Module Why Study Employee Benefits? Benefits are a tool used by human resource management to attract.
Joanne Hayden UVA Health Plan Ombudsman 1.
Health Insurance Portability and Accountability Act (HIPAA)
2012 Audits of Covered Entity Compliance with HIPAA Privacy, Security and Breach Notification Rules Initial Analysis February 2013.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
Advanced HIPAA Issues for Biotech and Life Sciences Companies: Mark E. Schreiber Palmer & Dodge LLP 111 Huntington Avenue Boston, MA
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Solving the Puzzle Disability and Family Leave, ADA, Workers Compensation When Employees Are Out of Work: Solving the Puzzle Disability and Family Leave,
HIPAA and Employer Group Health Plans: Nothing is Simple Beth L. Rubin March 26, 2003  2003 Dechert LLP.
Davis Wright Tremaine LLP Case Study: Small Group Health Plan HIPAA Privacy Compliance for Employers September 15, 2003 Speaker Jason Froggatt Becky Williams.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
Reflections on the State of Privacy Risk Management in Health Care Benefits Administration (one year and counting …) Mark Lutes, Esq. Partner Epstein Becker.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
OHCAs, ACEs and Hybrid Entities Paul Smith Davis Wright Tremaine LLP One Embarcadero Center Suite 600 San Francisco, CA (415)
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
September 17, 2002© Michael Best & Friedrich LLC1 Iowa State Association of Counties HIPAA Training September 17-18, 2002 Legal Issues presented by: Ryan.
HIPAA Privacy Rules: What Are Plan Sponsors Required to Do?
LLP 50 Beaver Street Albany, New York (518) (Phone) (518) (Fax)
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
HIPAA TRIVIA Do you know HIPAA?. HIPAA was created by?  The Affordable Care Act  Health Insurance companies  United States Congress  United States.
The Medical College of Georgia HIPAA Privacy Rule Orientation.
New Hire HIPAA Orientation. HIPAA Overview HIPAA is an acronym that stands for the Health Insurance Portability and Accountability Act of HIPAA.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
Today’s webinar will begin shortly
HIPAA Privacy Rule Training
DOL Employee Benefit Plan Audits & How to Prepare
Iowa State Association of Counties
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
Chapter 12 Employee Benefits.
HIPAA SECURITY RULE Copyright © 2008, 2006, 2004 by Saunders an imprint of Elsevier Inc. All rights reserved.
An Overview of HIPAA’s Applicability to Employers, and of Employer Responses (Beyond Fear and Loathing) Jon Neiditz October, 2002.
HIPAA Do’s and Don'ts: What is Really Behind Protected Health Information (PHI) and Health Care Privacy Rules Paul Sisler, Director, Information Services;
WELCOME.
Presentation transcript:

Selected Major Issues in Employer Responses to HIPAA Privacy, at Two Weeks Before the Deadline Jon Neiditz March 28, 2003

2 Balancing Priorities Information Privacy/ Security Risks Business Requirements Ease of Administration Cost Containment Productivity Valuable Information Labor Relations Employee Relations Media Exposure Civil Liability Compliance Risks Contractual Risks Accepted Controls

3 HR & Benefits AdvocacyIntroduction What is a local HR managers role when she discusses a health care claim problem with the employee who has the problem? Is she speaking for the group health plan? Is she speaking for the Company as plan sponsor? Is she actingas alwaysas a representative of the Company as employer, and as a participant in decisions to promote, discipline or terminate the employee? Is she merely trying to help the employee get the claim paid? In almost all the cases in which Ive asked the question of HR representatives, the last of these four options has been chosen. However, in no cases Ive seen has that role ever been clarified to the employee before. HIPAA requires such a clarification.

4 Role of HR in Benefits Advocacy 1 Option 1: Limit HRs role to occasional benefits advocacy, and processing enrollment and eligibility information Keeps HR outside of the firewall between plan administration and employment functions, controlling HIPAA training and compliance costs and HR privacy-related risk The need for advocate authorizations –The TPAs, the Call Center and/or the Benefits Department wont disclose PHI unless they receive a signed advocate authorization –HR is trained on: »the covered plans or components (e.g. medical, prescription drug, dental, vision, long term care, health care spending account, personal health accounts, and perhaps the employee assistance program, executive physical program and/or wellness program) VERSUS »The non-covered programs or components (e.g., short-term and long-term disability, AD&D, workers compensation, ADA, FMLA, fitness-for-duty exams, drug testing, work-life benefits, leaves of absence, life insurance, auto medical) –General HIPAA risk management training (Dos and Donts, scenarios) –How are the authorizations and the PHI retained? To what extent do HIPAA rules (and training and compliance monitoring) apply?

5 Role of HR in Benefits Advocacy 2 Option 2: Prevent HR access to any PHIusually, again, with the exception of enrollment and eligibility informationfrom the TPAs, the Call Center and the Benefits Department Need to train on covered and non-covered functions as in Option 1 Fewer complexities to the risk management training than for Option 1 No problems associated with PHI received by local HR The need to assure that adequate mechanisms exist for resolving claims issues with the TPAs, Outsourcer and/or Benefits Call Center –Can be problematic if the Outsourcer is one of those that refuses to be a business associate Not the option for the old, very decentralized manufacturing company or the high-tech company needing to provide high-touch service to retain employees We havent seen all of the pushbacknot only from HR but from employees watching anxiously for benefits take-awaysresulting from attempts to implement this option yet. Stay tuned….

6 Role of HR in Benefits Advocacy 3 Option 3: Bring some functions of local HR within the plan administration firewall Significant additional training and compliance burdens for the Privacy Officer –Education and compliance monitoring necessary on many of the detailed rules of HIPAA –Systems, physical and administrative safeguards necessary at the local level »Driven not just by compliance requirements but by risks associated with PHI kept by local HR acting on behalf of the group health plans Common to all 3 options above: Enrollment and eligibility information is treated as subject toat least lesser protection than claims-related information, and is available to local HR –Based in part on the argument that this information is generated by the employer or sponsor rather than the group health plans, as an employer or settlor function

7 HR Privacy Beyond HIPAA If not HIPAA privacy, should broader privacy rules apply to local HR, employee health services, and non-covered programs (e.g., disability, leaves of absence)? The likelihood of confusion CAUSED in part by HIPAA Notices of Privacy Practices about the privacy of other health information such as disability, workers comp, employee health services, drug-testing, work-related physicals, FMLA and ADA drives a focus on the privacy of employee HEALTH information more broadly than HIPAA. –The most common non-HIPAA HR privacy policies focus on health information Yet since 9/11, HR privacy legislation in the states and privacy litigation have generally not been focused on health issues at all. Rather they have dwelt primarily on broader workplace privacy issues such as screening, surveillance and background checks. –So will we see movement in this country toward privacy policies focused on the privacy of PERSONAL information as in the European Union? »Or is that issue too French for us?

8 Governmental Employers and HIPAA Suddenly, ERISA concepts like plan, plan sponsor and plan documents that have never applied to governmental and church plans before are imposed on both Is the plan a separate entity, as are private ERISA plans? If not, is the plan merely a covered component of a hybrid entity? –If so, need the plan documents be amended? Is the government as a whole the sponsor, or is the agency that administers the plan? –If the government as a whole, need the plan documents be amended? Is the agency that administers the plan a business associate of the plan? –If so, need the plan documents be amended?

9 Change at the Fringes: Typical Borderline Cases Employee Assistance Program (EAP) Is it a welfare plan, and therefore a group health plan? –Does it provide short-term counselling, or just information and referral services? If it is a group health plan, does its management referral process involve an invalid (coercive) authorization given by the EAP to the employee at intake? Will the EAP: –Accept responsibility as an independent covered entity? –Insist on business associate status? –Deny that HIPAA applies at all? Can the EAP respond to requests for access, amendment, accounting of disclosures? Executive Physical Programs Is it a welfare plan, and therefore a group health plan? –Is it mandatory, like a drug screening, or a benefit? Is information concerning fitness for duty disclosed to HR/management?

10 A Few of the Many Questions for After April 14th What will happen to the self-funded employersif anythat dont even issue a Notice of Privacy Practices or take a stab at the other public-facing indicia of HIPAA compliance? How many employees, covered dependents or attorneys will assert HIPAA privacy rights? Who are the enforcers to watch? What is the political appetite for broader privacy regulation than HIPAA? Standard Transactions: Given that the 834 and 820 are not regarded as required for employers, will they begin to look generally attractive as platforms for consumer-directed healthcare or interchangeability of benefits more generally, once there are tested solutions? Security: How big a burden will it be for plan sponsors that receive PHI? Due to the absence of cross-certificates, most plan sponsors that get PHI send it by unencrypted .

11 For more information on the content of this presentation, please contact: Jon Neiditz (678)