Tips for Surviving a Federal HIPAA Audit

Being contacted by the Department of Health and Human Services (HHS) or the Office for Civil Rights (OCR) for a HIPAA audit can be a very scary situation. The best way to survive a federal HIPAA audit is ensuring that you have the proper procedures in place every single day on the job. A single employee who is non-compliant could cost your practice a lot. 

Make Sure It’s Valid

Unfortunately, some scammers try to take advantage of practices by pretending to be OCR representatives conducting an audit and asking practices to purchase “certification” services. OCR and HHS will only make contact with your practice via email or certified letter. You always have a right to respond to ask for proof of validity, and that will not be held against you during the audit process. There is no certifying body for HIPAA compliance in existence, so any organization that approaches you claiming that they are one is lying.

Educate Your Employees

One of the best prevention strategies is educating your employees of the serious consequences of a HIPAA violation.

  • A HIPAA violation that occurs without knowledge: $100-$25,000 violation
  • A HIPAA violation due to reasonable cause: $1,000-$50,000 violation
  • A HIPAA violation due to willful neglect, but fixed within 30 days: $10,000-$50,000 violation
  • A HIPAA violation due to willful neglect that is uncorrected or corrected after 30 days: $50,000 violation

Reminding employees of the steep cost associated with each violation regularly can help to ensure compliance.

Tips for Survival

When preparing for a federal HIPAA audit, ask yourself the following:

  • Are our HIPAA policies and procedures regularly updated and effective? You should have things like a Breach Notification policy on hand and in effect.
  • Is our HIPAA training regularly updated and effective? How do we know it’s working? Every practice is required to hold HIPAA trainings for employees that are up-to-date, as well as maintain detailed records showing when employees attended the training and tests or surveys showing they understood the content.
  • Has our practice completed a risk assessment? This aspect of HIPAA often lies under the radar, but it’s a requirement as part of the HIPAA security management processes.
  • Have we had HIPAA breaches? If you have had a breach, you should make sure that all documentation has been properly completed.

Keep Your Practice HIPAA-Compliant with Vetters Enterprises

Vetters Enterprises specializes in practice management, private practice business support and revenue cycle optimization. We can perform in-depth assessments of your practice or facility and identify potential issues. Let us keep your business as healthy as you keep your patients! Give us a call at (443) 352-0088.

Patient Payments Simplified

Most practitioners don’t know that you are 50% less likely to recoup a patient copay if they leave your office without paying.  This impacts your cash flow more than you know.

I wanted to share with you a great idea from a great company – Payspan.  Some folks who work with Medical Assistance or any of the Beacon Health Options carriers may be very familiar with logging on to Payspan to pick up their EOPs but they have a great program for helping you get that payment up front that you need.  Check out this webinar if you can.

 

Webinar: Simple Techniques for Accelerating Patient Payments

Join us Thursday, October 6th for the Simple Techniques for Accelerating Patient Payments Webinar

If you missed Simple Techniques for Accelerating Patient Payments Webinar join usOctober 6th, 2016 and let us help you accelerate patient payments.

The abundance of high-deductible health plans is presenting unique revenue challengesfor healthcare providers, and many practices are struggling to quickly and accurately collect patient financial responsibility dollars. There are simple tips and solutions every practice can adopt to increase patient revenue and improve operational efficiency.

SAVE YOUR SEAT TODAY
Please join us on Thursday, October 6, for a complimentary webinar titled, “Simple Techniques for Accelerating Patient Payments.” We will be speaking about:

  • Best practices for dealing with the increase in patient responsibility and high-deductible health plans;
  • Best practices for accelerating patient payments; and
  • Innovative patient payment solutions that will get your practice where it needs to be today.

With the shift to new reimbursement models and the increase in out-of-pocket patient responsibility, it is more important than ever for providers to adopt innovative tools in order to stay financially viable. If you are interested in maximizing revenue in today’s evolving healthcare economy, join us at 2:00pm, EDT on October 6th, 2016.

Sincerely,

The Payspan Team

Image Title
ABOUT PAYSPAN
With the largest healthcare network in the U.S., we provide payment automation services that improve administrative efficiency, meet regulatory requirements, and enable payers and providers to manage new reimbursement strategies. We bring together healthcare expertise with proven financial services technology to empower a new generation of healthcare economics. CONTACT US

 

Message from the CEO of Compliancy Group

Today I want to talk about the odds of being audited.

It’s been all over the news lately that OCR has finally launched their Phase 2 audit program, ushering in a series of 200 desk and onsite audits that will be completed by the end of the year. If you consider the odds of being randomly selected for one of these Phase 2 audits, you wouldn’t be alone in thinking that the chances are slim. It’s a claim we’ve seen time and again.

But set aside these Phase 2 audits for a moment and consider that two of the largest fines ever–totaling $5.5 million–were levied against North Memorial Health System of Minnesota and the Feinstein Institute for Medical Research just a few weeks ago. In each of these cases, an OCR investigation was triggered by a PHI breach. And in each case, OCR discovered a lapse in the organization’s HIPAA compliance which lead to these behemoth fines.

So while the odds of being selected for a Phase 2 audit are relatively slim, the odds of having a breach and triggering OCR investigation are as high as they’ve ever been.

If you need help with your compliance efforts, reach out to VE Cycle Management today.  We can get you on track wth Compliancy Guard, the tool that saves you more than money.

Read on to check out some of the content we’ve put out this month, and some of the free educational webinars we have slated for the weeks ahead. And remember that Compliancy Group is here to give you compliance with confidence.

Marc Haskelson 

President, CEO

The Importance of HIPAA and HITECH Compliance

Meaningful Use

Did you properly attest?

What happens if you falsely Attest to Meaningful Use?

Recently, the former CFO of the Shelby Regional Medical Center, Joe White, has been sentenced to 23 months in federal prison and ordered to pay $4.5 million in restitution.  White oversaw the hospital’s implementation of electronic health records (EHR) and was responsible for Meaningful Use attestation to obtain incentive payments. He pleaded guilty to making a false statement about the hospital’s status as a meaningful user of EHR when, in fact, the hospital failed to meet the requirements. As a consequence of the ensuing turmoil, Shelby Regional Medical Center has permanently closed.

What message does this send?  

Although this is a more severe example of dishonesty, the underlying warning is still there for recipients of Meaningful Use incentives. Falsely attesting or failure to meet requirements could result in civil penalties, refund of incentive money, and could lead to criminal charges.

Does attesting for Meaningful Use mean you’re HIPAA compliant?

Attesting for Meaningful Use does not exempt you from the obligation to comply with HIPAA regulations. Regardless of whether you are applying for Meaningful Use or not, you are still required to be HIPAA compliant. The HITECH Act has served to strengthen HIPAA security and privacy provisions by adding greater fines and penalties for non-compliance. Bottom line, if your services involve Protected Health Information (PHI) you are required to be HIPAA compliant.

 HITECH?

The HITECH Act was established with the intent to promote the adoption of health information technology. This was promoted and incentivized by the Government through the Meaningful Use program. Providers can obtain incentive payments by attesting and proving that they are using certified EHR technology to improve patient care.  

 Do you think you are compliant?

According to HHS, 70% of the healthcare industry is not HIPAA compliant while CMS states that 79% of Meaningful Use Audits have resulted in failure. The two prevalent factors were incomplete risk assessments and misconceptions about the differences between HIPAA and HITECH. If you are unsure of your compliance with HIPAA, HITECH or Meaningful Use you need to take corrective action immediately.

  Become Compliant Now And Protect Your Practice

100% Of Our Clients Have Passed Their Audits

Find out how you can quickly become HIPAA compliant, prove your due diligence, satisfy Meaningful Use, and protect your organization’s reputation from irreparable damage and financial penalties.

Seal of HIPAA Compliance

Why The Guard?
  • HIPAA, HITECH, Meaningful Use, and Omnibus compliance
  • Expert HIPAA Coaches
  • Risk Analysis, Gap Identification and Remediation Plans
  • Built-in Training, Policies & Procedures
  • BA Agreement Templates & Tracking
  • HIPAA Hotline Support
  • Over 1,000 Satisfied CEs & BAs

CoffeeChat #2 Is up on our YouTube Channel

Take a listen to our latest CoffeeChat https://youtu.be/zMKxGhcfdVY here on our YouTube channel.  This episode talks about how just getting a HIPAA Risk Assessment is not enough to be HIPAA compliant according to HITECH and OMNIBUS regulations.  Use the contact us page to find out how CompliancyGuard can help your practice Achieve, Illustrate and Maintain HIPAA compliance.

How can CompliancyGuard help you avoid HIPAA fines?

Well I will tell you how…

CompliancyGuard is like an insurance policy that protects you from failing HIPAA audits and the excessive fines that can come with those.

The fact is that over 70% of Covered Entities (CEs) will fail their HIPAA audits.  And while the reasons for such failures can be all over the place, primarily it will be because of inadequate preparation to achieve complete HIPAA compliance and the inability to maintain compliance after initial risk assessment.

What CompliancyGuard does for you and your practice is simply and effectively provide you a “One-Stop-Shop” solution that sets you up for success and allows you to Achieve, Illustrate and Maintain HIPAA compliance so that it is completely taken off your plate.  It is a HIPAA compliance officer in a box.  Check out these case studies and tell me you don’t want to have this solution in your back pocket when the HIPAA auditors come knocking!

http://compliancy-group.com/hipaa-case-studies/

Thinking of starting your own practice?

With over 70% of hospital employees getting out and getting back into private practice whether they have done it before or doing it for the first time this article has the top 5 things we recommend our providers do before starting out on their own.  They don’t teach you this in med school!

http://www.kareo.com/gettingpaid/2014/09/the-5-first-steps-to-start-a-new-medicalpractice/

Now of course we recommend outsourcing as many activities as you can, and we can help you with cost effective solutions and personal service that a national company can’t compete with.  Please consider us as a source to help you in improving your reimbursement and gaining efficiencies in your office!

ICD 10 Delayed – Again

The Centers for Medicare and Medicaid Services posted in August 2014 that the road to ICD-10 compliance will be another year longer.  The new date for conversion is 10/1/2015.  As we’ve published before, this conversion is long over due and WILL be coming at some point even if they keep pushing back the date.

This conversion was not a part of the Affordable Care Act, so if you are thinking that if the ACA goes away so will this conversion and that is just simply “head in the sand” thinking.  This is an implementation of a international coding standard and we here in the US are just behind the curve with the rest of the western world in using this new classification system.  We do need to catch up and we eventually will.  Don’t let this conversion scare you out of your practice!  I have had a lot of providers tell me that they will quit first before converting, and that just isn’t practical.  ICD-10 will benefit the medical community by increasing the accuracy of diagnosis coding and allow entitlement programs and insurance carriers to gain more specificity in tracking diagnosis populations.  With more specificity comes more attention which leads to more reimbursement for the provider.

If you are a small practice, I urge you to check out the CMS website for the “Road to 10” implementation map

Road to 10: CMS Online Tool for Small Practices

CMS has released Road to 10, an online resource built with the help of providers in small practices, is now available. This tool is intended to help small medical practices jumpstart their ICD-10 transition.

“Road to 10” includes specialty references and gives providers the capability to build ICD-10 action plans tailored for their practice needs.

Also, VE Cycle Management specializes in providing solutions that are already ICD-10 ready.  We can help!  Contact us today!

So.. Hey, we are looking for funding!

Well, we have made a lot of contacts since Tracy and I really hit the pavement to keep doctors in private practice from being taken over by hospital and insurance conglomerates.  It’s been a rocky road; the recent government shutdown kept the hubby at home and within the last few weeks another contract I’d had has reduced my hours, so I decided that I believe so much in what we are doing, I am not too proud to beg….

As a result, here is our campaign on Indiegogo http://igg.me/at/vecycle/x/1859127 and our campaign on gofundme.com http://www.gofundme.com/vecycle

Our perks are pretty good if I do say so myself!  Go get yourself a T-Shirt or an iPad Mini!!

2070875_orig