PricewaterhouseCoopers Administrative Simplification Overview HIPAA Summit West II San Francisco, CA March 14, 2002 William R. Braithwaite, MD, PhD “Dr.

Slides:



Advertisements
Similar presentations
HIPAA Security Presentation to The American Hospital Association Dianne Faup Office of HIPAA Standards November 5, 2003.
Advertisements

HIPAA and Public Health 2007 Epi Rapid Response Team Conference.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 1 The Goal of HIPAA: Administrative Simplification HIPAA for Allied Health.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
Health Insurance Portability and Accountability Act (HIPAA)HIPAA.
HIPAA Administrative Simplification Final Rule for Transactions Code Sets Stanley Nachimson
ITEC 6324 Health Insurance Portability and Accountability (HIPAA) Act of 1996 Instructor: Dr. E. Crowley Name: Victor Wong Date: 2 Sept
Reviewing the World of HIPAA Stephanie Anderson, CPC October 2006.
HIPAA Privacy Rule Compliance Training for YSU April 9, 2014.
H IPAA PRIVACY WORK GROUP FOR EYE BANKS EBAA HIPAA PRIVACY WORK GROUP Christina W. Strong, Esq., Facilitator.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
HIPAA TRANSACTIONS HIPAA Summit IV 2002 UPDATE. HHS Office of General Counsel l Donna Eden l Office of the General Counsel l Department of Health and.
HIPAA COMPLIANCE IN YOUR PRACTICE MARIBEL VALENTIN, ESQUIRE.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Implementing and Enforcing the HIPAA Privacy Rule.
1 HIPAA Security Overview Centers for Medicare & Medicaid Services (CMS)
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 5 HIPAA Enforcement HIPAA for Allied Health Careers.
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
PricewaterhouseCoopers Transaction Compliance Date Extension & Privacy Standards NPRM Audioconference April 19, 2002 HIPAA Administrative Simplification.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Copyright Fleisher & Associates A HIPAA PRIMER FOR PUBLIC HEALTH PEOPLE CPHA-N Conference 2003 January 30, 2003 Presented by: Steven M. Fleisher,
Health Insurance Portability and Accountability Act (HIPAA)
Compliance and Enforcement of the Privacy Rule. HHS/OCR February/March Compliance Date  April 14, 2003 – Compliance for all but small health plans.
HIPAA TRANSACTIONS 2002 UPDATE. HHS Office of General Counsel l Donna Eden l Office of the General Counsel l Department of Health and Human Services.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
Eliza de Guzman HTM 520 Health Information Exchange.
PricewaterhouseCoopers 1 Administrative Simplification: Privacy Audioconference April 14, 2003 William R. Braithwaite, MD, PhD “Doctor HIPAA” HIPAA Today.
The Culture of Healthcare Privacy, Confidentiality, and Security Lecture d This material (Comp2_Unit9d) was developed by Oregon Health and Science University,
1 HIPAA Administrative Simplification Standards Yesterday, Today, and Tomorrow Stanley Nachimson CMS Office of HIPAA Standards.
OHCAs, ACEs and Hybrid Entities Paul Smith Davis Wright Tremaine LLP One Embarcadero Center Suite 600 San Francisco, CA (415)
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
HIPAA Transactions Testing Update Kepa Zubeldia, M.D. September 13, 2004.
HIPAA Health Insurance Portability and Accountability Act of 1996.
PricewaterhouseCoopers 1 Administrative Simplification: Strategic Thinking in Compliance National HIPAA Summit Washington, DC April 25, 2002 William R.
Standard Unique Health Identifier for Health Care Providers April 9, th Annual HIPAA Summit Gail Kocher Highmark.
HIPAA Certified LLC 1 6th National HIPAA Summit JCAHO and NCQA and HIPAA Business Associates Friday, March 28, 2003.
HIPAA History March 3, HIPAA Ruling Health Insurance Portability Accountability Act Health Insurance Portability Accountability Act Passed by Congress.
HIPAA Security John Parmigiani Director HIPAA Compliance Services CTG HealthCare Solutions, Inc.
Configuring Electronic Health Records Privacy and Security in the US Lecture b This material (Comp11_Unit7b) was developed by Oregon Health & Science University.
Systems, Data and HIPAA from a Medicaid Perspective Rick Friedman, Director Division of State Systems Center for Medicare and Medicaid US Dept Health &
PricewaterhouseCoopers 1 Administrative Simplification: Strategic Thinking in Compliance National HIPAA Summit V Baltimore, MD October 31, 2002 William.
1 Administrative Simplification: The Last Word National HIPAA Summit 8 Baltimore, MD March 9, 2004 William R. Braithwaite, MD, PhD “Doctor HIPAA”
Extending Your Compliance Deadline for Transactions & Codes Sets Developing your Compliance Plan for a Smoother Transition and to Avoid Potential Medicare.
AND CE-Prof, Inc. January 28, 2011 The Greater Chicago Dental Academy 1 Copyright CE-Prof, Inc
 Health Insurance and Accountability Act Cornelius Villalon Jr.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
HIPAA Yesterday, Today and Tomorrow? Dianne S. Faup Office of HIPAA Standards Centers for Medicare & Medicaid Services.
HIPAA Privacy Rule Training
What is HIPAA? HIPAA stands for “Health Insurance Portability & Accountability Act” It was an Act of Congress passed into law in HEALTH INSURANCE.
HIPAA CONFIDENTIALITY
HIPAA Administrative Simplification
The Centers for Medicare & Medicaid Services
The Centers for Medicare & Medicaid Services
HIPAA Security Standards Final Rule
National Congress on Health Care Compliance
THE 13TH NATIONAL HIPAA SUMMIT HEALTH INFORMATION PRIVACY & SECURITY IN SHARED HEALTH RECORD SYSTEMS SEPTEMBER 26, 2006 Paul T. Smith, Esq. Partner,
HIPAA Compliance Services CTG HealthCare Solutions, Inc.
Compliance and Enforcement of the Privacy Rule
HIPAA Compliance Services CTG HealthCare Solutions, Inc.
Presentation transcript:

PricewaterhouseCoopers Administrative Simplification Overview HIPAA Summit West II San Francisco, CA March 14, 2002 William R. Braithwaite, MD, PhD “Dr. HIPAA” HIPAA

PricewaterhouseCoopers 1996: HIPAA Passes Administrative Simplification Tags Along

PricewaterhouseCoopers Administrative Simplification Subtitle The Health Insurance Portability and Accountability Act of 1996 (HIPAA) Signed into Law August 21, 1996 Administrative Simplification Subtitle

PricewaterhouseCoopers Administrative Simplification Purpose Save money by setting standards and requirements for electronic transmissions. –Public responsibility imposed additional purpose: Protect security and privacy of individually identifiable health information.

PricewaterhouseCoopers 3 Parts to Administrative Simplification 45 CFR Subtitle A, Subchapter C PART 160PART 160 – General Administrative Requirements Scope, common definitions, enforcement. PART 162PART 162 – Administrative Requirements Transaction, code set, [and identifier] standards. PART 164 – Security And Privacy Privacy [and security] rules.

PricewaterhouseCoopers You wanted HHS to lead!

PricewaterhouseCoopers HHS Required to Adopt Standards: Electronic transmission of specific administrative and financial transactions (including data elements and code sets) List includes claim, remittance advice, claim status, referral certification, enrollment, claim attachment, etc. Others as adopted by HHS. Unique identifiers (including allowed uses) Health care providers, plans, employers, & individuals. For use in the health care system. Security and electronic signatures Safeguards to protect health information. Privacy For individually identifiable health information.

PricewaterhouseCoopers Federal Register Publications Transactions NPRM - 5/7/98 –Final Rule - 8/17/00 –Compliance plan by 10/16/02 –Testing by 4/16/03 –Compliance by 10/16/03 Privacy NPRM - 11/3/99 –Final Rule - 12/28/00 –Guidance issued 7/6/01. –Compliance by 4/14/03 National Provider ID NPRM - 5/7/98 Employer ID NPRM - 6/16/98 Security NPRM - 8/12/98

PricewaterhouseCoopers There is a lot beneath the surface.

PricewaterhouseCoopers HIPAA Standards Philosophy To save money: every payer must conduct standard transactions. no difference based on where transaction is sent. Standards must be industry consensus based (whenever possible). national, scalable, flexible, and technology neutral. Implementation costs must be less than savings. Continuous process of rule refinement: Annual update maximum (for each standard) to save on maintenance and transitions.

PricewaterhouseCoopers Consultations Required Consult with: 4 groups named in the statute (NUBC, NUCC, WEDI, ADA). “Appropriate Federal and State agencies and private organizations.” “Rely on the recommendations of the National Committee on Vital and Health Statistics (NCVHS).” Many opportunities for individual input: participate in open SDO processes, participate in WEDI (SNIP), NCVHS hearings, comment during rulemaking comment periods, communicate with HHS Secretary or staff.

PricewaterhouseCoopers Scope: Who is Covered? Limited by HIPAA law to ‘covered entities’: “A health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter.” –Providers get a choice; made by conducting electronic transactions (or getting a business associate to). “A health care clearinghouse.” –clearinghouses get no choice. “A health plan.” –Explicitly including government plans such as Medicaid & Medicare, VA, DoD, CHAMPUS, IHS, etc. –All health plans are covered (or $ cannot be saved). –Exceptions for some not primarily “health” plans. –e.g., workers comp, property & casualty.

PricewaterhouseCoopers Business Associates Only covered entities are subject to the rules. this limit doesn’t make sense –because healthcare uses outsourcing extensively and –these other entities would not be required by law to safeguard our health information … … so ‘business associate agreements’ were invented to obligate outsource agents, vendors, and contractors to safeguard the health information they need to do their jobs.

PricewaterhouseCoopers Transaction/Code Set Standards Transaction standards developed and maintained by industry consensus through SDOs. DSMOs to integrate requests and responses for new/modified standards. Likewise, national code sets continue to be maintained by current developers and maintainers. Emphasis by HHS on open processes. No regulation of mechanism (licensing) for funding continuous development and maintenance.

PricewaterhouseCoopers Implementation Specifications Published by SDO (some with HHS support) and incorporated into regulation by reference. SDOs are writing actual language of regulation. If you don’t like it, there is an open process to change it. Trading partner agreement cannot change the meaning or intent of the implementation specification(s). If a covered entity conducts an electronic transaction with another covered entity (or within the same covered entity) for which the Secretary has adopted a standard, it must be conducted as a standard transaction. Transactions are defined without regard to whether they are within or between entities. In some cases, the from and to entities are specified in the definition.

PricewaterhouseCoopers How do you tell one HIPAA from the rest?

PricewaterhouseCoopers Identifiers Identifiers should contain no ‘intelligence’. Characteristics of entities are contained in databases, not imbedded in construction of identifier. Identifiers should be all numeric. For easy telephone and numeric keypad data entry. Identifiers should incorporate an ANSI standard check digit to improve accuracy. Exception for Employer Identification Number [EIN]. –Already exists and supported.

PricewaterhouseCoopers Security Requirements Covered Entities shall maintain reasonable and appropriate administrative, technical, and physical safeguards -- to ensure integrity and confidentiality to protect against reasonably anticipated –threats or hazards to security or integrity –unauthorized uses or disclosures taking into account –technical capabilities –costs, training, value of audit trails –needs of small and rural providers

PricewaterhouseCoopers Key Security Philosophy Identify & assess risks/threats to: Availability Integrity Confidentiality Take reasonable steps to reduce risk.

PricewaterhouseCoopers BE REASONABLE!

PricewaterhouseCoopers Security Issues Covers transmitted data plus data at rest. Involves policies/procedures & contracts with business associates. For most security technology to work, behavioral safeguards must also be established and enforced. –requires administration commitment and responsibility. Electronic signatures: Final rule will depend on industry progress on reaching consensus on a standard.

PricewaterhouseCoopers HIPAA Enforcement: Watching, Listening

PricewaterhouseCoopers Enforcement Philosophy Preemption of state law wherever feasible. not politically possible for privacy. Enforcement by investigating complaints. not HIPAA police force -- OCR not OIG. “The Secretary will, to the extent practicable, seek the cooperation of covered entities in obtaining compliance” The philosophy is to improve the health care system by helping entities comply, not by punishing unintentional mistakes.

PricewaterhouseCoopers Excuses from civil penalties (from law) NONCOMPLIANCE NOT DISCOVERED the person did not know, and by exercising reasonable diligence would not have known. FAILURES DUE TO REASONABLE CAUSE. the failure was due to reasonable cause and not to willful neglect; and the failure is corrected within 30-days (which may be extended as determined appropriate by the Secretary based on the nature and extent of the failure to comply.) the failure was because the person was unable to comply REDUCTION If the failure is due to reasonable cause, any penalty may be waived …

PricewaterhouseCoopers Penalties Civil: any person who violates a provision of [the privacy regulations]: $100 per violation. Capped at $25,000 for each calendar year for each requirement or prohibition that is violated. Criminal: A person who knowingly and in violation of [the privacy regulations]: Up to $50,000 & 1 year imprisonment for knowingly disclosing IIHI. Up to $100,000 & 5 years if under false pretenses. Up to $250,000 &10 years if intent to sell or for commercial advantage, personal gain, or malicious harm. Enforced by Department of Justice.

PricewaterhouseCoopers HIPAA: The race to compliance …

PricewaterhouseCoopers Extension Law Administrative Simplification Compliance Act, aka H.R May file a compliance plan with HHS by 10/16/2002 –Testing must be planned to start by 4/16/2003 For those who file plans –new compliance date for transactions 10/16/2003. No delay for privacy compliance 4/14/2003. All Medicare claims must be in standard electronic form by 10/16/2003 –exception for very small providers.

PricewaterhouseCoopers Don’t get left behind …

PricewaterhouseCoopers Expected Final Rules and NPRMs Transactions and Code Sets –1 st Modifications NPRM expected soon. Privacy –Modifications NPRM expected soon. Employer ID –Final Rule expected soon. Security –Final Rule expected in Summer. Claim Attachment –NPRM expected in Summer. National Provider ID NPRM - 5/7/98 –Final Rule expected in Fall. Health Plan ID –NPRM expected in Fall.

PricewaterhouseCoopers The Cost, Quality, Standards Relationship Standards-based automation of routine functions lowers rate of rising costs (labor). Only possible if accompanied by process redesign. Could allow increased investment in clinical IT support. Standardized data increases its usefulness for quality improvement studies. –Knowing what’s best can improve quality, but doesn’t prevent error. –4 th leading cause of death: medical errors! Standards for clinical information will allow more cost-effective introduction of IT support at point of clinical decision making. Which in turn, will lead to fewer errors, higher quality care, and lower costs (e.g. e-Rx, CPOE). NCVHS recommendations for PMRI standards.

PricewaterhouseCoopers Resources Administrative Simplification Web Site: –posting of law, process, regulations, and comments. instructions to join Listserv to receive notification of events related to HIPAA regulations. submission of rule interpretation questions. National Committee on Vital and Health Statistics ncvhs.hhs.gov Centers for Medicare and Medicaid Services Workgroup on Electronic Data Interchange snip.wedi.org

Pwc