Marketplace Data Deficiencies Signal Employer ACA Headaches

March 9, 2016

By: Cynthia Marcotte Stamer

Employers, health plans and individual taxpayers should be concerned about reports of deficiencies in the eligibility and enrollment tracking procedures of some health insurance exchanges or “marketplaces” created under the Patient Protection and Affordable Care Act (ACA) that are likely to identify individuals enrolling in health insurance coverage offered through the Healthcare.gov and certain state health insurance exchanges or “marketplaces” as eligible for subsidies who in fact are ineligible for subsidies.

As the Internal Revenue Service (IRS) and Department of Health & Human Services (HHS) rely upon Marketplaces’ eligibility and enrollment records to enroll Americans in health insurance coverage through the ACA created marketplaces, to help determine in individual Americans and employers are complying with the ACA shared responsibility rules, and to determine which individuals enrolling in coverage through marketplaces qualify for ACA subsidies, deficiencies in these practices and resulting errors in eligibility and enrollment records are likely to mean headaches for employer, health plans and individual Americans.

Marketplace Eligibility & Enrollment Data Critical To Administer ACA Reforms

Accurate eligibility and enrollment determination by marketplaces is critical to the administration of the ACA’s complicated web of reforms, including the determination the determination of whether the employee of a large employer who enrolls in coverage qualifies for a subsidy so as to trigger an obligation for the employer to pay an employer shared responsibility payment under IRC Section 4980H if the employee is not enrolled in group health coverage offered by the employer meeting ACA’s requirements.

As part of ACA’s massive restructuring of the health care payment system enacted by President Obama and the then Democrat-led Congress, most Americans now must pay an “individual shared responsibility payment” unless enrolled in “minimum essential coverage” one of the ACA-approved health coverage options. Along with this individual mandate, the ACA:

  • Dictates that all group and individual health insurance policies other than a narrow list of “excluded” plans include the rich and generally expensive package of ACA-mandated “essential health benefits,” pay a host of ACA-imposed taxes and assessments, and comply with a host of tight ACA market reforms;
  • Penalizes employers with 50 or more full-time employees (large employers) that fail to offer all full-time employees group health coverage for the employee and each of his dependent children (hereafter “dependent coverage”) through an employer-sponsored arrangement that provides minimum essential benefits at a cost not greater than 9.5 percent of the federal poverty level by providing that any large employer with at least 1 employee enrolled in subsidized health coverage offered through an ACA-established health insurance marketplace, to pay a monthly “employer shared responsibility payment” under Internal Revenue Code Section 4980H of:
    • For any large employer not offering any group health plan employee and dependent coverage providing minimum essential coverage to each full-time employee, $150 per full-time employee per month; or
    • For any other large employer, $250 per month for each full-time employee earning less than 400 percent of the federal poverty level enrolled in subsidized health insurance coverage through an ACA-established health insurance marketplace unless the employer shows the employer offered the employee the opportunity to enroll in employee and dependent coverage under a group health plan that provided the ACA-required minimum essential coverage at a cost not exceeding 9.5 percent of the employee’s adjusted gross income; and
  • Seeks to incentivize small employers (generally with fewer than 25 full-time and full-time equivalent employees) tax credits for offering minimum essential coverage under an employer-sponsored plan that meets the ACA requirements; and
  • Created a system of one federal and various state health care exchanges or “marketplaces” through which individual Americans and small employers can purchase an expensive package of “essential health benefits” from private health insurers offering “qualified health plans” (QHPs) through the their state “marketplace,” if any, or for Americans living in a state with that elected not to establish a state marketplace, the federal Healthcare.gov marketplace;
  • Uses federal tax dollars to subsidize a portion of the premiums paid by certain Americans earning less than 400% of the federal poverty level that enroll in coverage under a QHP through the marketplace applicable in their states unless the individual had the option to enroll in an employer-sponsored group health plan meeting the ACA’s “minimum essential coverage,” “minimum value” and “affordability” standards; and
  • Requires all employers, health plans and insurers and each Marketplace accurately and reliably to collect, maintain and report certain key data needed to coordinate and administer ACA’s individual coverage mandates, employer mandates and subsidy rules.

For proper administration and coordination with other plans and employers and the administration by the Internal Revenue Service of ACA tax subsidies payable to qualifying individuals obtaining coverage in a QHP through an exchange, HHS regulations require each marketplace to implement and administer reliably an application and enrollment process for enrollment in QHPs through the exchange.

To enroll in a QHP, an applicant must complete an application and meet eligibility requirements defined by the ACA. An applicant can enroll in a QHP through the Federal or a State marketplace, depending on the applicant’s State of residence. Applicants can enroll through a Web site, by phone, by mail, in person, or directly with a broker or an agent of a health insurance company. For online and phone applications, the marketplace verifies the applicant’s identity through an identity-proofing process. For paper applications, the marketplace requires the applicant’s signature before the marketplace processes the application. When completing any type of application, the applicant attests that answers to all questions are true and that the applicant is subject to the penalty of perjury.

After reviewing the applicant’s information, HHS expects the marketplace to determine whether the applicant is eligible for a QHP and, when applicable, eligible for insurance affordability programs. To verify the information submitted by the applicant, the marketplace is expected to use multiple electronic data sources, including those available through the Federal Data Services Hub (Data Hub). Data sources available through the Data Hub are the U.S. Department of Health and Human Services, Social Security Administration (SSA), U.S. Department of Homeland Security, and Internal Revenue Service, among others. The marketplace can verify an applicant’s eligibility for ESI through Federal employment by obtaining information from the U.S. Office of Personnel Management through the Data Hub.

Generally, when a marketplace cannot verify information that the applicant submitted or the information is inconsistent with information available through the Data Hub or other sources, HHS regulations require the marketplace to attempt to resolve the inconsistency in accordance with HHS regulations before treating the individual as ineligible. Because of the presumption of eligibility built into the system, individual’s who care not verified as ineligible are treated as eligible. As a result, inadequate verification practices by marketplaces are likely to result in the inappropriate characterization of individuals as eligible for enrollment with subsidies.

Audits Show Marketplace Eligibility & Enrollment Practices Deficient

Unfortunately, recent OIG reports raising concerns about the adequacy of the eligibility and enrollment verification procedures of various marketplaces are raising concerns about the reliability and adequacy of the eligibility and enrollment verification procedures and resulting data of various marketplaces. For instance, in its recently released report, Not All of the District of Columbia Marketplace’s Internal Controls Were Effective in Ensuring That Individuals Were Enrolled in Qualified Health Plans According to Federal Requirements, HHS OIG Report A-03-14-03301 (the ”D.C. Report”), OIG reports that OIG’s audit of 45 sample applicants from the enrollment period for insurance coverage in the District of Colombia’s exchange for calendar year 2014 revealed that District of Colombia’s health insurance marketplace had ineffective internal processes and controls for:

  • Verifying an applicant’s eligibility for minimum essential coverage (both employer-sponsored insurance and non-employer-sponsored insurance;
  • Maintaining application and eligibility verification data;
  • Maintain identity-proofing documentation for applicants who apply for QHPs;
  • Verifying annual household income in accordance with Federal requirements;
  • Maintaining documentation demonstrating that it verified whether an applicant was eligible for minimum essential coverage under an employment based health plan; and
  • Ensuring that its enrollment system maintains application, eligibility, and documentation, including all electronic eligibility verifications from the Data Hub.

Deficiencies Create Likely Headaches For Employers, Plans & Individual Taxpayers

Given the importance of accurate subsidy eligibility and other marketplace enrollment information, marketplace audit results recently reported by the OIG finding certain federal and state health insurance marketplaces are not using effective internal controls to verify and administer eligibility and enrollment processes raises concerns not only concerns for taxpayers generally, but also could signal added headaches for employers and health plans.

Large employers and individual Americans receiving subsidies are likely to experience the greatest impact because of the reliance upon the IRS on marketplace data to determine employer and individual shared responsibility payment liability.  However, all employers and health plans also could experience some fallout.

Large employers should be prepared to receive and defend against IRS assertions that the employer is liable for paying employer shared responsibility payment under IRC Section 4980H when an employee of the employer is one of those individuals that a marketplace improperly classifies as eligible to receive subsidies because of deficient marketplace eligibility or enrollment data collection and verification practices. In addition, all employers should be prepared to receive and respond to inquiries from marketplaces, the IRS or HHS seeking to investigate, verify and reconcile data relevant to the administration of the ACA market, subsidy, shared responsibility and other reforms of the ACA.

Meanwhile, employers, health plans and individual Americans alike should brace to receive inquiries from the IRS, HHS, marketplaces, health plans and others seeking to verify and reconcile marketplace data with data reported by health plans, employers and individual Americans.  While timely and appropriate response to legitimate requests from the IRS, HHS, a marketplace or other appropriate party is important,  all parties should be careful to verify the legitimacy of the request and the identity and credentials of the party making the request in light of the IRS and other agencies’ reports of the identity theft and other scams by opportunist criminals using the pretext of acting for the IRS or other legitimate purposes illegally to trick businesses or individuals into sharing sensitive tax, financial or other  information.   While all parties need to use care in responding to these requests, employers, health plans and their service providers also need to ensure that these procedures are appropriately conducted and documented to minimize their exposure to liability for violations of the confidentiality, privacy or data security requirements that may apply to the employer, health plan or other party under the IRC, the Health Insurance Portability & Accountability Act (HIPAA) or various other federal or state laws.

To help prepare for these potential inquiries, employers, health plans and other parties should ensure that their recordkeeping, enrollment and reporting practices under ACA are clean and ready to respond to these and other government or employee inquiries.

Employers and others concerned about the impact of these deficiencies on the liabilities of large employers, taxpayers or both may wish express concern to their elected representatives in Congress.

About The Author

Recognized as a “Top” attorney in employee benefits, labor and employment and health care law extensively involved in health and other employee benefit and human resources policy and program design and administration representation and advocacy throughout her career, Cynthia Marcotte Stamer is a practicing attorney and Managing Shareholder of Cynthia Marcotte Stamer, P.C., a member of Stamer│Chadwick│Soefje PLLC, author, pubic speaker, management policy advocate and industry thought leader with more than 28 years’ experience practicing at the forefront of employee benefits and human resources law.

A Fellow in the American College of Employee Benefit Counsel, past Chair and current Welfare Benefit Committee Co-Chair of the American Bar Association (ABA) RPTE Section Employee Benefits Group, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, an ABA Joint Committee on Employee Benefits Council Representative and Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, Ms. Stamer is recognized nationally and internationally for her practical and creative insights and leadership on health and other employee benefit, human resources and insurance matters and policy.

Ms. Stamer helps management manage. Ms. Stamer’s legal and management consulting work throughout her career has focused on helping organizations and their management use the law and process to manage people, process, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer helps public and private, domestic and international businesses, governments, and other organizations and their leaders manage their employees, vendors and suppliers, and other workforce members, customers and other’ performance, compliance, compensation and benefits, operations, risks and liabilities, as well as to prevent, stabilize and cleanup workforce and other legal and operational crises large and small that arise in the course of operations.

Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce management operations and compliance. She supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy. Well known for her extensive work with health care, insurance and other highly regulated entities on corporate compliance, internal controls and risk management, her clients range from highly regulated entities like employers, contractors and their employee benefit plans, their sponsors, management, administrators, insurers, fiduciaries and advisors, technology and data service providers, health care, managed care and insurance, financial services, government contractors and government entities, as well as retail, manufacturing, construction, consulting and a host of other domestic and international businesses of all types and sizes. Common engagements include internal and external workforce hiring, management, training, performance management, compliance and administration, discipline and termination, and other aspects of workforce management including employment and outsourced services contracting and enforcement, sentencing guidelines and other compliance plan, policy and program development, administration, and defense, performance management, wage and hour and other compensation and benefits, reengineering and other change management, internal controls, compliance and risk management, communications and training, worker classification, tax and payroll, investigations, crisis preparedness and response, government relations, safety, government contracting and audits, litigation and other enforcement, and other concerns.

Ms. Stamer uses her deep and highly specialized health, insurance, labor and employment and other knowledge and experience to help employers and other employee benefit plan sponsors; health, pension and other employee benefit plans, their fiduciaries, administrators and service providers, insurers, and others design legally compliant, effective compensation, health and other welfare benefit and insurance, severance, pension and deferred compensation, private exchanges, cafeteria plan and other employee benefit, fringe benefit, salary and hourly compensation, bonus and other incentive compensation and related programs, products and arrangements. She is particularly recognized for her leading edge work, thought leadership and knowledgeable advice and representation on the design, documentation, administration, regulation and defense of a diverse range of self-insured and insured health and welfare benefit plans including private exchange and other health benefit choices, health care reimbursement and other “defined contribution” limited benefit, 24-hour and other occupational and non-occupational injury and accident, ex-patriate and medical tourism, onsite medical, wellness and other medical plans and insurance benefit programs as well as a diverse range of other qualified and nonqualified retirement and deferred compensation, severance and other employee benefits and compensation, insurance and savings plans, programs, products, services and activities. As a key element of this work, Ms. Stamer works closely with employer and other plan sponsors, insurance and financial services companies, plan fiduciaries, administrators, and vendors and others to design, administer and defend effective legally defensible employee benefits and compensation practices, programs, products and technology. She also continuously helps employers, insurers, administrative and other service providers, their officers, directors and others to manage fiduciary and other risks of sponsorship or involvement with these and other benefit and compensation arrangements and to defend and mitigate liability and other risks from benefit and liability claims including fiduciary, benefit and other claims, audits, and litigation brought by the Labor Department, IRS, HHS, participants and beneficiaries, service providers, and others. She also assists debtors, creditors, bankruptcy trustees and others assess, manage and resolve labor and employment, employee benefits and insurance, payroll and other compensation related concerns arising from reductions in force or other terminations, mergers, acquisitions, bankruptcies and other business transactions including extensive experience with multiple, high-profile large scale bankruptcies resulting in ERISA, tax, corporate and securities and other litigation or enforcement actions.

Ms. Stamer also is deeply involved in helping to influence the Affordable Care Act and other health care, pension, social security, workforce, insurance and other policies critical to the workforce, benefits, and compensation practices and other key aspects of a broad range of businesses and their operations. She both helps her clients respond to and resolve emerging regulations and laws, government investigations and enforcement actions and helps them shape the rules through dealings with Congress and other legislatures, regulators and government officials domestically and internationally. A former lead consultant to the Government of Bolivia on its Social Security reform law and most recognized for her leadership on U.S. health and pension, wage and hour, tax, education and immigration policy reform, Ms. Stamer works with U.S. and foreign businesses, governments, trade associations, and others on workforce, social security and severance, health care, immigration, privacy and data security, tax, ethics and other laws and regulations. Founder and Executive Director of the Coalition for Responsible Healthcare Policy and its PROJECT COPE: the Coalition on Patient Empowerment and a Fellow in the American Bar Foundation and State Bar of Texas, Ms. Stamer annually leads the Joint Committee on Employee Benefits (JCEB) HHS Office of Civil Rights agency meeting and other JCEB agency meetings. She also works as a policy advisor and advocate to many business, professional and civic organizations.

Author of the thousands of publications and workshops these and other employment, employee benefits, health care, insurance, workforce and other management matters, Ms. Stamer also is a highly sought out speaker and industry thought leader known for empowering audiences and readers. Ms. Stamer’s insights on employee benefits, insurance, health care and workforce matters in Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, Modern Healthcare, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications. Ms. Stamer also regularly serves on the faculty and planning committees for symposia of LexisNexis, the American Bar Association, ALIABA, the Society of Employee Benefits Administrators, the American Law Institute, ISSA, HIMMs, and many other prominent educational and training organizations and conducts training and speaks on these and other management, compliance and public policy concerns.

Ms. Stamer also is active in the leadership of a broad range of other professional and civic organizations. For instance, Ms. Stamer presently serves on an American Bar Association (ABA) Joint Committee on Employee Benefits Council representative; Vice President of the North Texas Healthcare Compliance Professionals Association; Immediate Past Chair of the ABA RPTE Employee Benefits & Other Compensation Committee, its current Welfare Benefit Plans Committee Co-Chair, on its Substantive Groups & Committee and its incoming Defined Contribution Plan Committee Chair and Practice Management Vice Chair; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; current Vice Chair of the ABA TIPS Employee Benefit Committee; the former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division; on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. She also previously served as a founding Board Member and President of the Alliance for Healthcare Excellence, as a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early childhood development intervention agency, The Richardson Development Center for Children; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a member of the Board of Directors of the Southwest Benefits Association. For additional information about Ms. Stamer, see CynthiaStamer.com or the Stamer│Chadwick │Soefje PLLC or contact Ms. Stamer via email here or via telephone to (469) 767-8872.

About Solutions Law Press, Inc.™

Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at http://www.solutionslawpress.com such as:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here.

©2016 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved.


Health Plans, Sponsoring Employers & Others Urged To Act Immediately In Response To Premera, Anthem Blue Cross Breaches

March 17, 2015

Today’s report by Premera Blue Cross of a massive data breach affecting as many as 11 million customers’ personal health and financial information on the heels of the large-scale data breach announcement by fellow Blue Cross Association, Anthem, is another reminder that employers and other health plan sponsors, fiduciaries, insurers specifically, and U.S. businesses generally should immediately assess and tighten up their privacy, data security and data breach compliance and risk management to fulfill applicable legal mandates and to strengthen defenses against resulting liabilities and member backlash likely to arise from these or future breaches.

Notice of the Premera and Anthem breaches are likely to trigger obligations for health plans and their sponsoring employers or unions, administrators, insurers, and other vendors and service providers to take immediate steps to conduct documented investigations, take corrective action and provide breach notifications the  Privacy, Security and Breach Notification rules of the Health Insurance Portability & Accountability Act require health plans and their business associates to provide in response to notice of a breach. Depending on the scope and nature of data affected and their involvement with the affected plans, employer or other plan sponsors, fiduciaries, administrators and service providers also may be subject additional responsibilities under applicable contracts and policies, the fiduciary responsibility requirements of the Employee Retirement Income Security Act of 1974 (ERISA), the Internal Revenue Code, and a host of other laws.  Insurance industry or other vendors providing services to these plans also may face specific responsibilities under applicable insurance, health care, federal or state identity theft, privacy or data security, or other federal or state laws.  See, e.g., Restated HIPAA Regulations Require Health Plans To Tighten Privacy Policies And Practices; Cybercrime and Identity Theft: Health Information Security Beyond; HIPAA Compliance & Breach Data Shares Helpful Lessons For Health Plans, Providers and Business Associates.

The need for prompt assessment and action is not necessarily limited to health plans and organizations sponsoring, administering or doing business with the plans involved in the Premera or Anthem breaches.  The occurrence of these breaches arguably raises the questions about the adequacy of the safeguards, practices and policies of other health plans and insurers, their sponsors and fiduciaries, insurers, administrators and other vendors.  places other health plans.  Health plans, their sponsors, fiduciaries, administrators, insurers and other vendors generally will want to make prudent documented inquiries about the adequacy of their health plan’s data security and privacy safeguards in anticipation of potential future breaches, audits or other scrutiny.

Beyond the specific health plan related concerns, most businesses also will want to consider the adequacy and defensibility of the data collection, use, disclosure, security and other practices affecting sensitive data within or on behalf of their organization.  The report of these and other health plan breaches, as well recent reports of identity theft and other fraud impacting federal tax returns and other large data breach reports involving retailers and other prominent businesses are spurring recognition of the large risks and need for greater scrutiny and accountability to business collection, use, and protection of sensitive personal and other data.

Of course, as in the case of health plans, the risk is exploding largely in response to the continued evolution of electronic payment and other business operating systems coupled with the emergence of data harvesting and other capabilities.  These new technologies and practices are fueling a host of new mandates, opportunities and risks for virtually every U.S. business.  Cyber criminals seem to always be one step ahead of business and government in leveraging these emerging opportunities for their criminal purposes.

With everyone from the Internal Revenue Service and other federal and state government agencies to private business partners pushing to leverage the efficiencies and other opportunity of electronic transactions and data, businesses in the US and around the world increasing are encouraged if not required to conduct more and more transactions containing sensitive business and individual tax information, personal financial information, personal health information, trade secrets and other confidential business and personal information electronically.  Meanwhile big data and other business and marketing gurus also encourage business to leverage their own opportunities to use data collected for these business mandates and expanding technology also to collect, use and repurpose customer,  prospect or other business information collected in the course of business to benefit their business’ marketing, transactional and other opportunities.

As these practices take hold and expand, data breaches and other cyber crime events, the legal requirements and risks of collection and use of data also are growing.  Privacy, identity theft and other cyber crime and other concerns have led federal and state lawmakers to enact an ever-growing list of notice, consent, disclosure, security and other laws and regulations including but not limited to the Fair & Accurate Credit Transaction Act (FACTA),the Gramm-Leach-Bliley Act, the HIPAA Privacy & Security Rules, state identity theft, data security and data breach and other electronic privacy and security laws and an ever-growing plethora of others.

As the cyber crime epidemic continues to grow and notorious breeches and schemes involving the Internal Revenue Service, Veterans Administration, retail giants like Target, Home Depot, and others, insurance giants like Anthem and Premera and others, government and private enforcement is rising and the judgments, penalties and other costs soaring even as federal and state regulators are looking at the need for expanded rules and penalties.   See Cybercrime Enforcement Statistics; DOJ Enforcement Priorities & Statistics. In addition, widening data privacy and security concerns from these massive data breach reports also are prompting  Congress and State regulatorsto consider the need for added reforms, see, McCaul to Hold Hearing on President’s Cybersecurity.  In deed, even before news of the Premera breach broke, he Federal Trade Commission today announced plans to host a workshop on Nov. 16, 2015, to look at the privacy issues around the tracking of consumers’ activities across their different devices for advertising and marketing purposes.

While these and other legal and enforcement developments promise new liabilities and expenses, the business losses and customer and business partner implications experienced by Target, Anthem and other businesses already affected illustrate the severe business consequences that inevitably result if a business appears to have failed to take customer privacy or other data security concerns seriously.

The now notorious Target hacking data breach event is illustrative. Target reported in late 2013 that credit and debit card thieves stole the name, address, email address and phone number from the credit and debit card records of around 70 million Target shoppers between November 27 and December 15, 2013. After announcing the breach, Target reported a 46% drop in profits in the fourth quarter of 2013, compared with the year before despite having announced plans to invest $100 million upgrading their payment terminals to support Chip-and-PIN enabled cards and millions of dollars more in rectification efforts. See The Target Breach, By the Numbers. Subsequently, Target’s losses have continued to mount even as it now faces lawsuits and other enforcement actions as a result of the breach. See Banks’ Lawsuits Against Target for Losses Related to Hacking Can ContinueMeanwhile, the enforcement and other fallout continues to evolve.

While businesses generally need to tighten their defenses and compliance, health plans, their sponsors, fiduciaries, administrators and vendors have specific obligations that require immediate, well-documented action when an actual or potential breach happens.  The Privacy, Security and Breach Notification requirements of HIPAA require that health plans adopt specific policies and maintain and administer specific safeguards to prevent and respond to breaches of protected health information.  In the event of a breach, these rules require that the health plan, usually acting through its fiduciaries, and affected service providers that qualify as business associates both investigate and redress the breach, as well as provide specific notification as soon as possible and usually no later than 30 days after the health plan knows or has reason to know of the breach.  Significant civil and even criminal penalties can apply if a health plan, health insurer or its business associate fails to fulfill these obligations.

Beyond the specific requirements of HIPAA, employers and other plan sponsors and others involved in the maintenance and administration of the health plan or the selection and oversight of its vendors often may have other less-realized responsibilities.  As health plan data often includes payroll and other tax data, employers, the health plans and other parties involved also may have specific responsibilities under the Internal Revenue Code or other laws.   To the extent that the plan sponsor or another party is named as the plan administrator or otherwise exercises discretion and control over the selection of the insurer or other plan vendor or other plan operations, the fiduciary obligations of ERISA also may require a prudent investigation and other action to meet fiduciary obligations of ERISA.  Brokers, insurers, third party administrators, preferred provider organizations or other managed care providers and others doing business with the health plan also may have specific responsibilities under state insurance, health care, data breach and identity theft or other laws.  Under the provisions of most of these laws, leaving it to the insurer or other vendor involved in the breach generally will not suffice to fulfill applicable legal responsibilities, much less allay the fears of plan members, employees, health care providers and others involved with the health plan.

In the face of these developments, health plans and their sponsors, fiduciaries and others working with them must take immediate action in response to the breaches reported.  Along with these specific health plan related responses,  businesses also should the adequacy and defensibility of their current overall data collection, use and security practices while remaining ever vigilant for new requirements, as well as weaknesses in their own practices.  Health plans specifically and businesses generally need to build their defenses in anticipation of these events both to withstand government and private litigation and enforcement, and to survive the harsh judgment of public opinion.

 For Help With Risk Management, Compliance & Other Management Concerns

If you need assistance in responding to a health plan breach concern or with auditing or assessing, updating or defending your organization’s compliance, risk management or other  internal controls practices or actions, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469) 767-8872.

Scribe for the ABA JCEB Annual Agency Meeting with the Office of Civil Rights, a faculty and steering committee for the Southern California ISSA-HIMSS Health Care Privacy Program, Board Certified in Labor & Employment Law, a Fellow in the American College of Employee Benefits Counsel  recognized as a “Top 100” lawyer in labor and employment, employee benefits and health care law, Ms. Stamer is nationally recognized for her work, publications, public speaking and education and other leadership on privacy and data security and other risk management and compliance.

A management attorney who works with businesses and government to manage and redress people, process and risk, Ms. Stamer has worked extensively on data and other privacy risk management and compliance,  Throughout her career, she has conducted investigations and advised, and assisted health care, insurance, retail and a broad range of other public and private organizations with privacy and data security audit and risk management, contracting, investigation, defense and remediation throughout her more than 25 year career.

Past Chair and of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits,  past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, current Co-Chair of the RPTE Welfare Benefit Committee and Vice Chair of the ABA TIPS Employee Benefits Committee, Ms. Stamer works, publishes and speaks extensively on cyber crime and other privacy, management, reengineering, investigations, human resources and workforce, employee benefits, compensation, internal controls and risk management, federal sentencing guideline and other enforcement resolution actions, and related matters.  She also is recognized for her publications, industry leadership, workshops and presentations on these and other  concerns and regularly speaks and conducts training on these matters.Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the ABA, Insurance Thought Leadership, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications.

As part of her extensive involvements in privacy and data security concerns, Ms. Stamer will be among the panelists discussing “Fiduciary Obligations In the Context of a Data Breach” conference call to be hosted on April 2, 2015 by Fiduciary Responsibility Committee of the American Bar Association (ABA) Real Property Probate and Estate Section Employee Benefits & Other Compensation Group.  During the program, Ms. Stamer and other panelists will discuss the quagmire of fiduciary legal and operational challenges that data breach announcements by health plan vendors and insurers present for employer and union-sponsored health plan fiduciaries and health plans.  She also will serves as the scribe for the upcoming ABA Joint Committee On Employee Benefits Annual Agency Meeting with the Federal agency that enforces HIPAA, the Office of Civil Rights, and 2014 Conference Chair and  steering committee and faculty member of the Southern California ISSA/HIMSS Healthcare Privacy & Security Summit scheduled for June 4, 2015 in Los Angeles.

For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.  For information about participation in the April 2 Conference Call or joining the Committee, see here.

About Solutions Law Press

Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com.

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.

©2015 Cynthia Marcotte Stamer.  Non-exclusive right to republish granted to Solutions Law Press.  All other rights reserved.


Consider Fiduciary & Other Risk Management When Planning For ACA Transitional Reinsurance Costs, Other Plan Design Changes

July 7, 2014

Employer and other plan sponsors should start working now with their insurers, administrators and advisors to understand the implications of and their options for addressing the “Transitional Reinsurance Program” and other new Patient Protection & Affordable Care Act (ACA)-associated cost and plan design changes  so that they are prepared to finalize and implement their health plan design, contracts and arrangements in time to meet the accelerated deadlines for notifying participants of plan changes and otherwise implement their plan changes for the upcoming plan year.

The impending imposition of  Transitional Reinsurance Program assessments are only one of a myriad of new and pre-existing federal health plan rules and associated market changes impacting the design of employer and union-sponsored health plans.  Since ACA now also requires 60 days advance written notice of material health plan changes, .  When making these decisions, employer and other health plan sponsors and their advisors, administrators and insurers  should not only focus on the technically new mandates but also the allocation of fiduciary and other responsibilities, liabilities and other plan and services agreements terms.  Plan sponsors and their fiduciaries historically have underappreciated the significance of these allocations or presumed that their vendor contracts allocate responsibility to the service providers and vendors to match the sales pitch.  Always rarely the case, the changes in the marketplace and the law make it even more likely that sponsoring employers and their leaders of even plans that carefully reviewed and negotiated these responsibilities in their past contracts need to carefully look at these plan and contractual terms carefully.

The Transitional Reinsurance Program is one of a series of new ACA-imposed assessments that can impact the plan design and costs.    Proper understanding of these rules is critical for plan sponsors and their fiduciaries to ensure that they don’t unintentionally assume significantly greater liability for their self-insured health plans in an attempt to design around a relatively small by comparison ACA assessment.

Section 1341 of the Patient Protection & Affordable Care Act (ACA) requires the establishment of the reinsurance program to provide for stabilization of funding for exchanges.  Funding for the costs of the program is accomplished through amounts assessed upon insurers and self-insured plan third party administrators.  ACA § 1341 accomplishes this by providing for:

  • The establishment for each State of a transitional reinsurance program stabilize premiums for coverage in the individual market from 2014 through 2016;
  • Requiring all health insurance issuers and third party administrators on behalf of self-insured group health plans, to pay contributions to support reinsurance payments that cover high-cost individuals in non-grandfathered plans in the individual market.

Registration is now open for a series of webinars that the Department of Health & Human Services will host on “The Transitional Reinsurance Program: Contributing Entities and Counting Methods” on July 14, July 18 and July 23, 2014 from 2:00 p.m. – 3:30 p.m. EST.  The upcoming HHS webinars will cover the same information.  They will focus on reinsurance contributions including who is a contributing entity and how a contributing entity can calculate its annual enrollment count to determine reinsurance contribution amounts. The intended audience for this webinar is health insurance issuers, self-insured group health plans, third party administrators (TPAs) and administrative services-only (ASO) contractors.  To register for the HHS webinar and to obtain additional information see here.

Understanding how the Transitional Reinsurance Program assessments will be calculated is one of many critical steps in making plan design changes.  When considering whether to take advantage of options for minimizing these assessments, however, employer, union and other plan sponsors need to consider whether the liability and other consequences of meeting requirements for avoidance of the assessments is warranted by the anticipated savings.  With superficially it might seem desirable to avoid the payment of a few dollars per covered lives associated with the assessment, employers and other sponsoring organizations and the officers or other leadership employees involved in plan design or administration should critically review the effect of meeting these requirements specifically, as well as their proposed vendor contracts and associated plan documents and communications on their personal and organizations’ fiduciary and other liabilities.  To the extent that existing or expanded fiduciary liability cannot be avoided, it will be critical that the sponsor and its leadership ensure that proper steps are taken to select, credential, bond, and appoint the persons who will be or help carry out fiduciary or other plan-related responsibilities.  Additionally, most plan sponsors will want to consider exploring the availability of fiduciary liability insurance coverage to help mitigate the potential liability risks associated with plan sponsorship.

For Advice, Training & Other Resources

If you need assistance monitoring these and other regulatory policy, enforcement, litigation or other developments, or to review or respond to these or other workforce, benefits and compensation, performance and risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.

Board Certified in Labor & Employment Law, Past Chair of the ABA RPTE Employee Benefit & Other Compensation Arrangements Group, Co-Chair and Past Chair of the ABA RPTE Welfare Plan Committee, Vice Chair of the ABA TIPS Employee Benefit Plans Committee, Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 24 years experience advising health plan and employee benefit, insurance, financial services, employer and health industry clients about these and other matters. Ms. Stamer has extensive experience advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical privacy and other compliance and risk management policies, to health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. The author of the “Managed Care Contracting Guide” and a multitude of other highly-regarded publications on health plan and other fiduciary liability risk management, Ms. Stamer has advised plan sponsors, administrators, insurers and others about these and other health plan liabilities and their risk management throughout her more than 25 year career. You can get more information about her HIPAA and other experience here.

If you need assistance with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.

You can review other recent publications and resources and additional information about the other experience of Ms. Stamer here. Examples of some recent publications that may be of interest include:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here. For important information about this communication click here.

©2014 Cynthia Marcotte Stamer.  Non-exclusive right to republish granted to Solutions Law Press, Inc.   All rights reserved.


Review & Update Health Plan Notices, Language & Process For New Guidance On COBRA, Other Key Health Plan Rules

June 2, 2014

Add reviewing and updating your plan language, notices and processes for administering the coverage continuation requirements to the ever-growing list of items that employers and other group health plan sponsors, insurers, administrators and fiduciaries need to handle this year.

The most recently emerging guidance published by federal regulators to implement the Patient Protection & Affordability Act (ACA) and other health care reforms is a package of new guidance on COBRA and its interface with COBRA published in early May.  This guidance includes a new HHS Bulletin Allowing COBRA Qualified Beneficiaries to Enroll in the Health Insurance Marketplace,  as well as a series of updated model COBRA and CHIP Notices and related documents.

The HHS Bulletin on COBRA allows individuals who previously elected COBRA rather than enrolling in coverage through one of the new health insurance exchanges created under ACA a special extended enrollment opportunity to enroll in coverage under these exchanges.  Many employers and health plans may want to communicate this new option to help minimize their COBRA exposures.

Beyond  the extended exchange enrollment period for COBRA enrolled or eligible persons, the new guidance also may merit updates and changes to group health plan’s existing COBRA plan language, notices and election forms and procedures.  Labor Department guidance several years ago significantly expanded the number of notifications required under COBRA as well as the required content.  In connection with that guidance, the Labor Department published various model notices and other materials.  As part of new guidance published in May, 2014, the Labor Department has revised and published updated versions of many of these model documents.  The updated materials include:

In addition to the updated COBRA guidance, employers, health plans and their insurers, administrators and fiduciaries also will want to review and update their plan language, processes, budgets, notices and other materials in response to updated guidance in Affordable Care Act Implementation FAQs Part XIX on Department of Labor model notices, limitations on cost-sharing, coverage of preventive services, health flexible spending account (FSA) carryover and excepted benefits, and the Summary of Benefits and Coverage requirements of PHS Act §2715.  Employers and others involved in the design or administration of group health plans  also will want to review this new guidance as part of their continuing health plan compliance, cost forecasting and planning efforts.

Catch Up On Latest, Get Practical Health Plan Insights At June 17  Texas CEO Briefing

Texas CEO Magazine invites Solutions Law Press Readers to catch up on new developments and strategies to help employers prepare for and cope with the ever-evolving stream of health plan developments enacted under the Patient Protection & Affordable Care Act by participating in a practical briefing on:

Tuesday, June 17

7:30 – 9:00 a.m.

Park City Club

5956 Sherry Lane, Dallas

Register: https://texasceomagazine.com/events

Two of Texas CEO’s  “Top 10 Most Read” articles in 2013 were authored by Dallas attorney and benefit specialist Cynthia Stamer who will anchor a panel of benefit experts that will explore new developments and their practical implications on:

  • Benefit Plan Design
  • Workforce Classification
  • Data Collection
  • Cost Projections
  • Private Exchanges
  • New Reporting Requirements (IRC 6055 & 6056)
  • Noncompliance Penalties
  • Avoiding the Tax
  • The New Care Delivery Dynamic

Featured Speakers include Cynthia Stamer, Managing Partner, Solutions Lawyer Publisher and Author, Eric Bassett, Senior Partner & Central Market Leader, Mercer Health & Benefits Consulting, Scott Gibbs, Senior Vice President, McGriff, Seibels & Williams, Inc., and Becky Parker, Health Reform Director, MHBT Inc.

Cynthia is a Dallas-based attorney who has spent more than 25 years helping private and public employers and health and employee benefit planners develop, implement, administer and defend creative, legally compliant and operationally effective health plans and policies.

Cynthia’s Texas CEO Magazine article, “Benefit Plan Triage: 12 STEPS EVERY EMPLOYER WITH A HEALTH PLAN SHOULD DO NOW,” was one of the Top 10 most-read articles of 2012. And in 2013, “Getting Ready for ACA Reform: 13 Steps to Take Now,” and “Affordable Care Act Update,” were both Top 10 most read articles.

Cynthia, among other things,  is:

  • Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group
  • Immediate Past Chair of the ABA’s RPTE Employee Benefit & Compensation Committee
  • Marketing Committee Chair of the ABA Joint Committee on Employee Benefits
  • Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee
  • Current Vice-Chair of the Gulf States TEGE Council – Exempt Organizations Group

Eric works with clients in all areas of health care and group benefits with particular emphasis on health care strategies, delivery system capabilities, defined contribution, and consumerism. Eric began his 28-year health care career working for health care vendors. He has led cross-functional teams involved in the development of rural managed care strategies, integration of legacy networks and systems, physician profiling and implementation of open access networks and systems. Eric’s consulting experience includes:

  • Developing and managing health improvement, disease and demand management programs.
  • Chronic PCMH program design and development.
  • Working with management and labor during collective bargaining.
  • Integrating and consolidating benefit plans for mergers and acquisitions.
  • Working closely with corporate committees to facilitate decision-making.
  • Active and retiree exchange strategy and design.

Scott Gibbs works with large employers on long term strategies to make corporate benefit plans consistent with the company’s goals and budgets, working with both fully-insured and self-funded plans.

Scott is a member of:

  • Society for Human Resource Management (SHRM)
  • Texas Public Risk Management Association
  • International Foundation of Employee Benefit Plans
  • State and Local Government Benefit Association
  • Scott has an undergraduate degree from Baylor University and a Master’s in Health Care Administration from Trinity University.

Becky directs all corporate strategy and communication on the Affordable Care Act for MHBT and its clients. She has worked as an employee benefits advisor since 1992 and was one of the first employee benefits professionals to have earned a Certification in Health Care Reform Studies from The American College.

Becky is an active member of the Austin Association of Health Underwriters where she was president in 2003 and also served on the Texas Association of Health Underwriters board as their liaison to the Texas Department of Insurance and was honored nationally for her work.

Becky is an advocate for employee benefits in the legislative arena regularly testifying at the Texas State Capitol and engaging our federal elected officials on insurance related matters. Becky has even advised Texas Congressmen on the employer aspects of the Affordable Care Act.

Becky holds a Bachelor of Arts degree from The University of Texas at Austin.

For Representation, Training & Other Resources

If you need assistance monitoring these and other regulatory policy, enforcement, litigation or other developments, or to review or respond to these or other workforce, benefits and compensation, performance and risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.

Board Certified in Labor & Employment Law, Past Chair of the ABA RPTE Employee Benefit & Other Compensation Arrangements Group, Co-Chair and Past Chair of the ABA RPTE Welfare Plan Committee, Vice Chair of the ABA TIPS Employee Benefit Plans Committee, Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 24 years experience advising health plan and employee benefit, insurance, financial services, employer and health industry clients about these and other matters. Ms. Stamer has extensive experience advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical privacy and other compliance and risk management policies, to health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.

For the past two years, Ms. Stamer has served as the  scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR.   Ms. Stamer also regularly works with OCR, FTC, USSS, FBI and state and local law enforcement on privacy, data security, health care, benefits and insurance and other matters, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the second year will serve as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance frequently appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.  You can get more information about her HIPAA and other experience here.

If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.

You can review other recent publications and resources and additional information about the other experience of Ms. Stamer here. Examples of some recent publications that may be of interest include:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here. For important information about this communication click here.

©2014 Cynthia Marcotte Stamer.  Non-exclusive right to republish granted to Solutions Law Press, Inc.   All rights reserved.


6/17 Workshop Helps Businesses Get Ready for Latest Affordable Care Act Rollout

May 31, 2014

Texas CEO Magazine invites Solutions Law Press Readers to catch up on new developments and strategies to help employers prepare for and cope with the ever-evolving stream of health plan developments enacted under the Patient Protection & Affordable Care Act by participating in a practical workshop

Tuesday, June 17

7:30 – 9:00 a.m.

Park City Club

5956 Sherry Lane, Dallas

Register: https://texasceomagazine.com/events

The Affordable Care Act continues to hit the business world with successive waves of reform. To make sure your company is ready, we’ve assembled a panel of experts to update you about the current and impending legal terrain and share their benefit plan design and compliance tips to help your business cope with these changes.

Two of Texas CEO’s  “Top 10 Most Read” articles in 2013 were authored by Dallas attorney and benefit specialist Cynthia Stamer who will anchor our panel of benefit experts as we take you through:

  • Benefit Plan Design
  • Workforce Classification
  • Data Collection
  • Cost Projections
  • Private Exchanges
  • New Reporting Requirements (IRC 6055 & 6056)
  • Noncompliance Penalties
  • Avoiding the Tax
  • The New Care Delivery Dynamic

Featured Speakers Include:

Cynthia Stamer, Managing Partner, Solutions Lawyer

Cynthia is a Dallas-based attorney who has spent more than 25 years helping private and public employers and health and employee benefit planners develop, implement, administer and defend creative, legally compliant and operationally effective health plans and policies.

Cynthia’s Texas CEO Magazine article, “Benefit Plan Triage: 12 STEPS EVERY EMPLOYER WITH A HEALTH PLAN SHOULD DO NOW,” was one of the Top 10 most-read articles of 2012. And in 2013, “Getting Ready for ACA Reform: 13 Steps to Take Now,” and “Affordable Care Act Update,” were both Top 10 most read articles.

Ms. Stamer is:

  • Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group
  • Immediate Past Chair of the ABA’s RPTE Employee Benefit & Compensation Committee
  • Marketing Committee Chair of the ABA Joint Committee on Employee Benefits
  • Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee
  • Current Vice-Chair of the Gulf States TEGE Council – Exempt Organizations Group

Eric Bassett, Senior Partner & Central Market Leader, Mercer Health & Benefits Consulting

Eric works with clients in all areas of health care and group benefits with particular emphasis on health care strategies, delivery system capabilities, defined contribution, and consumerism. Eric began his 28-year health care career working for health care vendors. He has led cross-functional teams involved in the development of rural managed care strategies, integration of legacy networks and systems, physician profiling and implementation of open access networks and systems. Eric’s consulting experience includes:

  • Developing and managing health improvement, disease and demand management programs.
  • Chronic PCMH program design and development.
  • Working with management and labor during collective bargaining.
  • Integrating and consolidating benefit plans for mergers and acquisitions.
  • Working closely with corporate committees to facilitate decision-making.
  • Active and retiree exchange strategy and design.

Scott Gibbs, Senior Vice President, McGriff, Seibels & Williams, Inc.

Scott Gibbs works with large employers on long term strategies to make corporate benefit plans consistent with the company’s goals and budgets, working with both fully-insured and self-funded plans.

Scott is a member of:

  • Society for Human Resource Management (SHRM)
  • Texas Public Risk Management Association
  • International Foundation of Employee Benefit Plans
  • State and Local Government Benefit Association
  • Scott has an undergraduate degree from Baylor University and a Master’s in Health Care Administration from Trinity University.

Becky Parker, Health Reform Director, MHBT Inc.

Becky directs all corporate strategy and communication pertaining to the Affordable Care Act for MHBT and its clients. She has worked as an employee benefits advisor since 1992 and was one of the first employee benefits professionals to have earned a Certification in Health Care Reform Studies from The American College.

Becky is an active member of the Austin Association of Health Underwriters where she was president in 2003 and also served on the Texas Association of Health Underwriters board as their liaison to the Texas Department of Insurance and was honored nationally for her work.

Becky is an advocate for employee benefits in the legislative arena regularly testifying at the Texas State Capitol and engaging our federal elected officials on insurance related matters. Becky has even advised Texas Congressmen on the employer aspects of the Affordable Care Act.

Becky holds a Bachelor of Arts degree from The University of Texas at Austin.

For Representation, Training & Other Resources

If you need assistance monitoring these and other regulatory policy, enforcement, litigation or other developments, or to review or respond to these or other workforce, benefits and compensation, performance and risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.

Board Certified in Labor & Employment Law, Past Chair of the ABA RPTE Employee Benefit & Other Compensation Arrangements Group, Co-Chair and Past Chair of the ABA RPTE Welfare Plan Committee, Vice Chair of the ABA TIPS Employee Benefit Plans Committee, Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 24 years experience advising health plan and employee benefit, insurance, financial services, employer and health industry clients about these and other matters. Ms. Stamer has extensive experience advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical privacy and other compliance and risk management policies, to health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.

For the past two years, Ms. Stamer has served as the  scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR.   Ms. Stamer also regularly works with OCR, FTC, USSS, FBI and state and local law enforcement on privacy, data security, health care, benefits and insurance and other matters, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the second year will serve as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance frequently appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.  You can get more information about her HIPAA and other experience here.

If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.

You can review other recent publications and resources and additional information about the other experience of Ms. Stamer here. Examples of some recent publications that may be of interest include:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here. For important information about this communication click here.

©2014 Cynthia Marcotte Stamer.  Non-exclusive right to republish granted to Solutions Law Press, Inc.   All rights reserved.


HHS Share Model HIPAA Notices 1 Week Before Deadline For Updating Business Associate Agreements

September 16, 2013

A week before the September 23, 2013 deadline for all health care providers, health plans, health care clearinghouses (Covered Entities) and their business associates to have updated their business associate agreements to comply with the Final Omnibus HIPAA Rule, the Department of Health & Human Services Office of the National Coordinator for Health Information Technology (ONC) and the Office for Civil Rights (OCR) today (September 16, 2013) released Model Notices of Privacy Practices (Notices) for health care providers and health plans to use to communicate with their patients and plan members. With penalties and enforcement continuing to rise, Covered Entities and their business associates should take appropriate steps to review and update their privacy and breach notification policies and procedures, privacy officer appointments, notices of privacy practices, business associate agreements and other HIPAA compliance and risk management documentation, practices, procedures and coverage, breach notification and other HIPAA compliance and risk management practice.

Model HIPAA Notices

Developed collaboratively by ONC and OCR the Notices available here designed in the following three different styles are designed for users to customize to fit their specific needs and practices:

  • A notice in the form of a booklet;
  • A layered notice with a summary of the information on the first page and full content on the following pages; and
  • A notice with the design elements of the booklet, but that is formatted for full-page presentation.

Use of these model Notices is optional.  While the agencies designed the Notices to let Covered Entities to use these models by entering some of their own information into the model, such as contact information, and then printing for distribution and posting on their websites, Covered Entities should consult with legal counsel to determine the suitability of the Notices generally for their entity’s use and any customization, if any, that may be recommended or required to a Notice if the Covered Entity decides rely upon a model Notice to prepare its Notice of Privacy Practices.  To facilitate any tailoring, the agencies provided a text-only version for Covered Entities wishing only wish to use the content with or without tailoring.

September 23 Business Associate Agreement Update Deadline

September 23, 2013 also is the final deadline established in the Final Omnibus HIPAA Rule for Covered Entities and their business associations to update the business associate agreements required by HIPAA to reflect application of the breach notification, business associate, and many of HIPAA’s requirements to directly cover business associates and other aspects of the Health Information Technology for Economic and Clinical Health (HITECH) Act enacted as part of the American Recovery and Reinvestment Act of 2009.  While HHS published a Sample Business Associate Agreement last June to aid Covered Entities and their business associates with understanding the business associate agreement requirements as impacted by the Omnibus Final HIPAA Rule, it also made clear that Covered Entities and their business associates should tailor their business associate agreements to fit their specific circumstances and relationships.  OCR National Office and regional officials speaking about their findings about past business associate agreement compliance have indicated that their audit and enforcement activities show widespread compliance issues among Covered Entities and business associates with the original business associate agreements.  OCR clearly expects Covered Entities and their business associates to address and resolve these compliance issues going forward.

Covered Entities and their business associates are increasingly at peril if caught violating HIPAA’s Privacy, Security or Breach Notification rules.  With the HITECH Act Breach Notification rules now requiring Covered Entities to self-disclose breaches, OCR becomes aware of breaches much more easily.  Coupled with the HITECH Act’s increase in sanctions for HIPAA violations, Covered Entities and, beginning September 23, 2013, their business associates face rising risks for violating HIPAA.  See, e.g. HHS Settles with Health Plan in Photocopier Breach Case; WellPoint Settles HIPAA Security Case for $1,700,000; Shasta Regional Medical Center Settles HIPAA Security Case for $275,000; Idaho State University Settles HIPAA Security Case for $400,000; and HHS announces first HIPAA breach settlement involving less than 500 patients.

In response to the updated Final Regulations and these expanding HIPAA enforcement and exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable.   In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.

For Help or More Information

If you need assistance responding to HIPAA or other health industry regulatory, enforcement or other developments, reviewing or tightening your policies and procedures, conducting training or audits, responding to or defending an investigation or other enforcement actions; with 2014 health plan decision-making, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer for help.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer is widely recognized for her extensive work, publications, and thought leadership on HIPAA and other privacy and data security issues.  Scribe for the ABA JCEB annual Technical Sessions meeting with OCR for the past three years, Ms. Stamer’s experience includes extensive work advising, representing and training health plan, health insurance, health IT, health care and other clients on HIPAA and other privacy, data protection and breach and other related matters and represents and advises these and other clients in responding to OCR Privacy and Civil Rights and other HHS agencies, Labor Department, IRS regulations, investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns.  She also is recognized for her extensive publications and programs including numerous highly regarding publications and programs on HIPAA and other privacy and data security concerns as well as a wide range of other workshops, programs and publications.

Beyond her HIPAA involvement, Ms. Stamer also continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, HR.com, Insurance Thought Leadership, Solutions Law Press, Inc. and other publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication see here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer, P.C. 

Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved.


[*] On January 24, 2013, the Department of Labor (the Department) issued guidance stating the Department’s conclusion that the notice requirement under FLSA section 18B will not take effect on March 1, 2013 for several reasons until further guidance setting the extended deadline was published.


CMS Hosts Webinar Celebrating National Health IT Week 9/16-20

September 13, 2013

In celebration of the third annual National Health IT Week is September 16-20, the Centers for Medicare & Medicaid Services (CMS) will host several webinars and launching new eHealth tools and resources that it intends to help providers participate in eHealth programs.  These programs may be of interest to providers as well as payers who are interested in what providers are doing to use eHealth tools.

The eHealth Provider Webinar will be held on Thursday, September 19th from 12:00 p.m. to 1:30 p.m. ET.  CMS plans to present an overview of the eHealth programs and its eHealth initiative—an initiative that aligns health IT and electronic standards programs on:

  • Administrative Simplification
  • eRx Incentive Program
  • ICD-10
  • Quality Measurement

A portion of the webinar will also be dedicated to Q&A.

Registration Information

Space is limited.  Register now to secure your spot for the eHealth Provider WebinarOnce registration is complete, you will receive a follow-up email with step-by-step instructions on how to log-in to the webinar.  Listserv messages are sent prior to each webinar session with registration information.

If you’d like to view past webinars, the PowerPoint presentations and recordings can now be accessed on the Resources page of the eHealth website.  For more information about CMS’ eHealth Initiatives, visit the CMS eHealth website for the latest news and updates on CMS’ eHealth initiatives.

For Help or More Information

If you need help understanding or dealing with these eHealth or other health and health benefit programs, or with other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, HR.com, Insurance Thought Leadership, Solutions Law Press, Inc. and other publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this of interest, you may also be interested in the following recent publications by Ms. Stamer published by Solutions Law Press, Inc. including:

For important information about this communication see here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer. Non-exclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved.


IRS Publishes Final Health Reform Individual Shared Responsibility Rules

September 1, 2013

Starting in 2014, the Individual Shared Responsibility mandate of the Patient Protection & Affordable Care Act (ACA) dictates that each individual American either have minimum essential coverage for each month, qualify for an exemption, or make a payment when filing his or her federal income tax return.  In anticipation of the implementation of this Individual Shared Responsibility mandate, the Department of the Treasury and the Internal Revenue Service (IRS) published final regulations implementing the Individual Shared Responsibility mandate in the Internal Revenue Code. The guidance contained in these final regulations provide each American with critical information about their families’ potential exposure to liability for the individual shared responsibility tax in 2014 as well as key insights for employers.  Solutions Law Press, Inc.  authors are finalizing various articles on certain key aspects of these new regulations for publication over the next few days. Stay tuned for more details!

For each month beginning after December 31, 2013, Internal Revenue Code Section 5000A’s Individual Shared Responsibility mandate requires that individual Americans either qualify as exempt, maintain minimum essential coverage for themselves and any nonexempt family members, or pay an individual shared responsibility payment when paying their Federal income tax return.  A taxpayer will be obligated to pay the individual shared responsibility tax under Internal Revenue Code Section 5000A for any non-exempt individual the taxpayer claims on his or her individual tax return as a dependent who is not exempt or enrolled in minimum essential coverage.

Under § 5000A(f)(2), minimum essential coverage includes coverage under an eligible employer-sponsored plan.

The final regulations set the rules that the IRS will use to decide when an individual American will become liable for paying the tax imposed by ACA for failing to maintain the minimum required health insurance coverage mandated by ACA beginning January 1, 2013 and other related rules.  While specifically addressing the obligations of individual Americans to pay the Individual Shared Responsibility payment, the final rules coupled with the availability of the new option for individual Americans to buy coverage through an ACA-qualified federal health care exchange and, depending on the adjusted household income of the individual, potentially also to receive tax credits for enrolling in coverage through an exchange is likely to impact the enrollment choices that employed individuals make about enrolling in coverage offered by their employer versus in coverage through a federally qualified health insurance exchange.  Accordingly, both individual Americans and the businesses that employ them should act quickly to understand the key aspects of the final regulations and their implications.

When considering the effect of these final regulations, employers and individual Americans should keep in mind that Notice 2013-42, issued on June 26, 2013, provides limited transition relief from the Individual Shared Responsibility mandate for employees and their families who are eligible to enroll in certain employer-sponsored health plans with a plan year other than a calendar year if the plan year begins in 2013 and ends in 2014. For additional information on the Individual Shared Responsibility provision, the final regulations and Notice 2013-42, see the IRS questions and answers.

Coming slightly less than a month before the October 1, 2013 scheduled opening of the first enrollment period for individual Americans to enroll in health care coverage through a federally qualified health insurance exchange created pursuant to ACA and the deadline for employers to deliver the notice of the availability of this option dictated by Fair Labor Standards Act 18B,  the final regulations and Obama Administration’s announced plans to enforce its provisions has drawn criticism from a number of groups.  While the Obama Administration has indicated that it still plans to enforce the Individual Shared Responsibility mandate against individual Americans, it announced in July, 2013 that it would delay enforcement of the Employer Shared Responsibility Mandate rules of Internal Revenue Code Section 4980H until 2015.  Many consumer rights groups and others are arguing that the Administration should also delay its enforcement of the Individual Shared Responsibility Mandate in light of its delay of enforcement of Internal Revenue Code Section 4980H against businesses.   Pending a reversal of its position or Congressional relief, the final regulation signal to individual Americans and their employers to prepare to deal with the new Individual Shared Responsibility Mandate beginning in January, 2014.

While the delay in enforcement of the Section 4980H employer shared responsibility payment until 2015 means that employers will not incur liability for failing to provide coverage meeting the minimum essential coverage, minimum value and affordability standards of Internal Revenue Code Section 4980H, the impending implementation of the Individual Shared Responsibility mandate of Internal Revenue Code Section 5000A and the impending availability of tax credits for certain individuals with Household Adjusted Gross Incomes of less than 400 percent of the poverty level almost certainly will influence enrollment decisions that employees make concerning coverage offered by their employer, if any.  Employers  can expect that employee choices about enrolling in employer-sponsored group health coverage will be influenced by the impending obligation to enroll in coverage or pay the individual shared responsibility tax in 2014 governed by the final regulations.  Employers can expect that employee concern about these exposures will prompt many employees to carefully scrutinize and in some cases question the information and implications of information provided by the employer or its plan such as the Section 18B notice that employers must provide by October 1, 2013, the summary of benefits and coverage (SBC) that the Affordable Care Act obligations the employer or plan to provide as the employees work to sort out their choices.  As these and other plan communications are likely to face significant scrutiny, employers and their employee benefit plan fiduciaries and administrators should use extra care to ensure that these and other plan documents and communications are carefully and precisely tailored to accurately convey all material plan terms.

For Help or More Information

If you need help understanding or dealing with these impending notification requirements, with other 2014 health plan decision-making or preparation, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, HR.com, Insurance Thought Leadership, Solutions Law Press, Inc. and other publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication see here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer, P.C. 

Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved.


[*] On January 24, 2013, the Department of Labor (the Department) issued guidance stating the Department’s conclusion that the notice requirement under FLSA section 18B will not take effect on March 1, 2013 for several reasons until further guidance setting the extended deadline was published.


Impending 10/1 Exchange Notice & Other New Notice Deadlines Cut Time Short For Employers To Finalize 2014 Health Plan Terms & Contracts

August 21, 2013

Employer and union group health plan sponsors and insurers of group and individual health plans (Health Plans) agonizing over 2014 plan design decisions are running out of time. Impending deadlines to update and deliver the initial Exchange Notice by October 1, 2013, the Summary of Benefits and Communications (SBC) disclosure before their next enrollment period begins, and 60-day prior notice of material reductions in benefits or services under the plan mandated by the Patient Protection and Affordable Care Act (ACA) require employers or other sponsors to finalize design decisions and amendments well in advance of January 1, 2014.  These new notification obligations create added urgency and pressure for Health Plans and their employer and other sponsors to finalize and implement their decisions on their Health Plans 2014 plan designs and coverages and make the necessary determinations to prepare and timely deliver the required notifications in accordance with these new notification mandates well before the start of the 2014 plan year or its enrollment period. Employers who in the past have put off these decisions until the last month of the plan year no longer can legally do so.

ACA Exchange Notices Due By October 1

One of the biggest time constraints for finalizing 2014 plan designs, contracts and terms is the impending October 1, 2014 deadline for employers to provide the notice required by Fair Labor Standards Act Section 18B.

Regardless of if the employer sponsors a health plan or when the next plan enrollment period begins, all employers covered by the FLSA generally are required deliver a notice to employees about the new option beginning January 1, 2014 to get health care coverage through a health care exchange (now rebranded by the Obama Administration as a “Marketplace”)(Marketplace) created by ACA that meets the requirements of new FLSA Section 18B enacted Section 1512 of ACA.

Absent a delay or other reprieve from the Obama Administration or Congress,  Open enrollment for health insurance coverage through the Marketplace begins October 1, 2013.  Individuals and employees of small businesses beginning October 1, 2013 can apply for and, beginning January 1, 2014 to buy health care coverage offered through the Marketplace established under ACA for their state (including the Federal Marketplace for states that did not elect to establish their own Marketplace). Some individuals who earn less than 400% of the federal poverty level and meet certain other conditions also are slated to qualify to receive federal subsidies that will pay all or part of the cost of buying coverage through a Marketplace.

To promote awareness among employees of the Marketplace as an option for getting health coverage, creates a new FLSA Section 18B requiring a notice (Exchange Notice) to employees of coverage options available through the Marketplace.  Originally required by March 1, 2013,[*] the Department of Labor (DOL) extended the deadline for providing the Exchange Notice to October 1, 2013.  Employers must provide a notice of coverage options to each employee, regardless of plan enrollment status (if applicable) or of part-time or full-time status. Employers are not required to provide a separate notice to dependents or other individuals who are or may become eligible for coverage under the plan but who are not employees.

All FLSA-Covered Employers Must Provide Exchange Notices Beginning October 1, 2013

Under FLSA Section 18B of the FLSA, each applicable employer must provide each employee at the time of hiring (or with respect to current employees, by October 1, 2013), a written notice that fulfills the applicable Exchange Notice requirements as set forth in the DOL Regulations.

The FLSA section 18B requirement to provide a notice to employees of coverage options applies to all   employers subject to the FLSA. In general, the FLSA applies to employers that employ one or more employees who are engaged in, or produce goods for, interstate commerce. For most firms, a test of not less than $500,000 in annual dollar volume of business applies. The FLSA also specifically covers the following entities: hospitals; institutions primarily engaged in the care of the sick, the aged, mentally ill, or disabled who reside on the premises; schools for children who are mentally or physically disabled or gifted; preschools, elementary and secondary schools, and institutions of higher education; and federal, state and local government agencies.  Employers questioning whether their business is subject to the FLSA should seek the assistance of legal counsel experienced with the FLSA.

Timing and Delivery of Notice

Employers are required to provide the Exchange Notice to each new employee at the time of hiring beginning October 1, 2013. For 2014, the Department will consider a notice to be provided at the time of hiring if the notice is provided within 14 days of an employee’s start date.

For employees who are current employees before October 1, 2013, employers must provide the Exchange Notice no later than October 1, 2013.

The Exchange Notice must be provided in writing in a manner calculated to be understood by the average employee. Employers may deliver the Exchange Notice by first-class mail or, if the electronic notification requirements of the Department of Labor’s electronic disclosure safe harbor at 29 CFR 2520.104b-1(c) are met, electronically.

Required Content of Exchange Notice

The Exchange Notice content mandated by FLSA Section 18B is fairly limited.  Section 18B requires that the Exchange Notice only dictates three required elements:

  • Inform employees of coverage options, including information about the existence of the new Marketplace as well as contact information and description of the services provided by a Marketplace;
  • Inform the employee that the employee may be eligible for a premium tax credit under Section 36B of the Code if the employee purchases a qualified health plan through the Marketplace; and
  • Include a statement informing the employee that if the employee purchases a qualified health plan through the Marketplace, the employee may lose the employer contribution (if any) to any health benefits plan offered by the employer and that all or a portion of such contribution may be excludable from income for Federal income tax purposes.  At minimum, this generally requires that the Exchange Notice distributed by an employer must inform the employee.

Interim DOL guidance implementing these requirements construes the content requirements as requiring that the Exchange Notice tell the employee:

  • Of the existence of the Marketplace (referred to in the statute as the Exchange) including a description of the services provided by the Marketplace, and the way the employee may contact the Marketplace to request assistance;
  • That the employee may be eligible for a premium tax credit or subsidy under Section 36B of the Internal Revenue Code (the Code) if the employee purchases a qualified health plan through the Marketplace and the employer does not offer coverage to the employee under a group health plan that is considered to provide “Minimum Value” for purposes of ACA; and
  • That if the employee purchases a qualified health plan through the Marketplace, the employee may lose the employer contribution (if any) to any health benefits plan offered by the employer and that all or a portion of such contribution may be excludable from income for Federal income tax purposes.

Allow Adequate Time To Do Analysis, Complete Other Steps To Prepare Exchange Notices

Employers should resist the urge to allow the shortness of the list of information required that FLSA Section 18B requires in the Exchange Notice lure them into underestimating the time and effort required to prepare the Exchange Notification.  For many employers, determining if the Health Plan provides Minimum Value can be time-consuming and complex.

For this, the SBC notice discussed later in this update and other purposes, Code Section 36B(c)(2)(C)(ii) provides that an employer-sponsored Health Plan provides Minimum Value if the ratio of the share of total costs paid by the Health Plan relative to the total costs of covered services is no less than 60% of the anticipated covered medical spending for covered benefits paid by a group health plan for a standard population, computed in accordance with the plan’s cost-sharing, and divided by the total anticipated allowed charges for covered benefits provided to a standard population is no less than 60%.  See Patient Protection and ACA: Standards Related to Essential Health Benefits, Actuarial Value, and Accreditation Regulation.

Existing regulations require the employers to get an actuarial certification to determine if its Health Plan provides Minimum Value unless the employer can show that the Health Plan fits the criteria to use and satisfies this test using either the Minimum Value Calculator or an applicable safe harbor design approved by HHS, Treasury and DOL.  These determinations often are time consuming and complex requiring careful review and analysis of the group health plan coverage and benefits.  Many self-insured or other group health plans have plan designs that prevent the employer from relying on the Minimum Value Calculator or design safe harbors.  If the employer cannot rely upon the Minimum Value Calculator or one of the design safe harbors, an actuarial certification will be needed.  Employers need to allow sufficient time to make these determinations in time to complete and deliver the Exchange Notices.

Employers should particularly expect to need to obtain an actuarial certification to determine if the Health Plan provides Minimum Value determination if the Health Plan is taking advantage of temporary relief from the cost sharing limitations of ACA for 2014 announced by the Obama Administration in February and reconfirmed in July, that for 2014 allows Health Plans to apply a separate ACA-compliant out-of-pocket maximum to prescription drug benefits from the ACA-compliant out-of-pocket maximum applied to all other benefits subject to ACA’s cost sharing restrictions.   Since the Minimum Value Calculator cannot take into account this option, however, employers planning to apply a separate out-of-pocket maximum for prescription drug coverage versus other plan benefits should be prepared to get an actuarial certification of whether the plan provides Minimum Value.

DOL Model Exchange Notices Not Panacea

Employers may want to use some or all of the language that the DOL included in Model Notices that DOL published in conjunction with its publication of interim guidance on FLSA Section 18B in Technical Release No. 2013-02 on May 8, 2013 here. Because employers must tailor the content of the Exchange Notice for their group health plan based on specific information about their group health plan, employers are cautioned not to underestimate the time or effort that will be required to properly prepare the Exchange Notice for their group health plan, whether or not the employer makes use of the Model Notices in whole or part.

DOL published three model exchange notices (Model Notices) to assist employers in preparing the Exchange Notice for their Health Plan for 2014. One Model Notice is intended for employers who do not offer a Health Plan.  The second Model Notice is designed for employers who offer a health plan to some or all employees. The third Model Notice is designed for employers to use to notify individuals who are enrolled or eligible to enroll in continuation coverage  under the Health Plan under the Consolidated Omnibus Budget Reconciliation Act of 1985 (COBRA).   Technical Release No. 2013-02 says employers may use the applicable of these models or a modified version, provided the Exchange Notice meets the content requirements described above.

Despite the availability of these Model Notices, preparing and providing the required Exchange Notices required by Section 18B typically requires significant evaluation and presents a variety of challenges for most employers.  While intended to facilitate the ability of employers to prepare and provide the required Exchange Notices, preparing the Model Notices generally is challenging for many employers.

First, even using the Model Notices, the employer must decide if the Health Plan provides Minimum Value.

Another challenge with wholesale use of the Model Notices involves deciding how much of the optional language contained in the Model Notices to include in the Exchange Notice and what optional information, if any, to provide as part of that Notice.

For one thing, the Model Notices propose that the Exchange Notice include statements that many critics view as inappropriately promoting enrollment in coverage through the Marketplace rather than employer sponsored group health plans.  Critics complain, for instance that the Model Notice’s statement that the Marketplaces offer “one-stop shopping” that allows the employee to get coverage that the Model Notice states is more “affordable” are inaccurate or misleading. Many critics view the assertion that coverage obtained through the exchange is more “affordable” to be inaccurate as it does not take into account a comparison of the actual benefits and costs of the respective plan options and whether the employee can afford the typically richer (and therefore often more expensive) benefit packages ACA’s essential health benefits mandates require be included in coverage offered for sale through the Marketplaces and presumes that these higher costs will be defrayed by tax credits or subsidies that are only available if the employee earns less than 400% of the federal poverty level and is not offered the option to enroll in an employer sponsored group health plan coverage that provides “minimum essential coverage” (MEC) and Minimum Value and is “affordable” within the meaning of ACA.

Employers considering using the Model Notices also need to decide if their Exchange Notices will include the optional factual disclosures about their group health plan suggested in the Model Notices, but not required to fulfill the requirements of FLSA Section 18B.

The Model Notices propose that an employer also voluntarily provide a significant amount of other information about its group health plan that FLSA Section permits, but does not require that the Exchange Notice include.  The DOL says it designed the Model Notices to help employers to identify and disclose information that the DOL expects employees interested in the tax credit to subsidize the employee’s cost of enrolling in coverage through the Marketplace will need to get from employers to show eligibility.  DOL assumes that many employers might want to voluntarily provide this information in the Exchange Notice to avoid receiving a multitude of anticipated inquiries from employees interested seeking tax credits to subsidize their enrollment in coverage through the Marketplace.  Since collection the data necessary to make these optional disclosures can add significant complexity and time to the preparation of the Exchange Notice, employers should carefully weigh the pros and cons of making the optional disclosures.  The anticipated demand for this information has declined since the Obama Administration announced it plans to use an “honor system” approach to determine if individuals can claim eligibility for tax credit subsidies for buying coverage through the Marketplaces in 2014.  Meanwhile, the interim nature of the existing guidance on the Exchange Notice and other key aspects of ACA make it reasonable to expect further changes in the expected content of the Exchange Notice, ACA requirements that it is intended to communicate or both which could impact the need for or accuracy of these disclosures.  For this reason, employers should carefully consider whether and what optional disclosures to include in their Exchange Notices.

Don’t Forget To Notify COBRA Qualified Beneficiaries

Technical Release No. 2013-02 indicates that in addition to sending an Exchange Notice to employees, employers or their group health plan administrators also must notify COBRA eligible or enrolled individuals.

In general, under COBRA, an individual who was covered by a group health plan on the day before a qualifying event occurred may be able to elect COBRA continuation coverage upon a qualifying event (such as termination of employment or reduction in hours that causes loss of coverage under the plan). Individuals with such a right are called qualified beneficiaries. A group health plan must provide qualified beneficiaries with an election notice, which describes their rights to continuation coverage and how to make an election. The election notice must be provided to the qualified beneficiaries within 14 days after the plan administrator receives the notice of a qualifying event.

Technical Release No. 2013-02 says that the DOL considers the required disclosures for the Exchange Notice information to be disclosed to qualified beneficiaries and that the DOL is revising previously published model COBRA notices to incorporate this information.

DOL says in Technical Release No. 2013-02 that the group health plans can use the revised model COBRA election notice to satisfy the requirement to provide the election notice under COBRA including the disclosure of information required by FLSA Section 18B. The DOL cautions that as with the earlier model COBRA notices, in order to use this model election notice properly, the plan administrator must complete it by filling in the blanks with the appropriate plan information. Technical Release 2013-02 states that use of the model election notice, appropriately completed, will be considered by the Department of Labor to be good faith compliance with the election notice content requirements of COBRA.

ACA SBC Mandate Overview

In addition to the Exchange Notice requirement, the need to prepare and timely delivery the “Summary of Benefits and Coverage or “SBC”) required by ACA also pressures employers to finalize their health plan terms and contracts for 2014 as soon as possible.

ACA amended the Public Health Services Act (PHS) Section 2715, Employee Retirement Income Security Act (ERISA) Section 715 and the Internal Revenue Code (Code) Section 9815 to require that Health Plans and health insurance issuers provide a SBC and a “Uniform Glossary” that “accurately describes the benefits and coverage under the applicable plan or coverage” in a way that meets the format, content and other detailed SBC standards set for ACA as implemented by the Departments regulatory guidance. Like the Exchange Notice, proper preparation of the SBC requires determination of whether the Health Plan provides Minimum Value, as well as other detailed analysis of the plan terms and coverages to complete the other disclosures required in the SBC.

The Summary of Benefits and Coverage and Uniform Glossary Final Regulation  (Final Regulation) implementing this requirement published February 14, 2012 generally requires Health Plans at specified times including before the first offer of coverage under the Plan as well as following certain material changes to the Plan. For Health Plans providing group health plan coverage, FAQs About ACA Implementation (Part VII)[*] set the deadline for Health Plan to deliver a SBC as follows, while at the same time indicating that the Departments would not impose penalties on plans and issuers “working diligently and in good faith” to provide the required SBC content in an appearance consistent with the Final Regulations:

  • To covered persons enrolling or re-enrolling in an open enrollment period (including late enrollees and re-enrollees) as the first day of the first open enrollment period that begins on or after September 23, 2012; and
  • For individuals enrolling in coverage other than through an open enrollment period (including individuals who are newly eligible for coverage and special enrollees) as the first day of the first plan year that begins on or after September 23, 2012. See FAQs About ACA Implementation (Part VIII).

While the SBC doesn’t prohibit an employer from amending its Health Plan terms after the enrollment period begins, employers that change Health Plan terms or designs after distributing a SBC must incur the expense and effort to prepare and redistribute an updated SBC.  Accordingly, most Health Plans and their sponsors or insurers will want to finalize Health Plan terms before the enrollment period begins to avoid the need to and expense of sending updated SBCs as a result of a later change in Health Plan terms.

The Final Regulation and other existing guidance generally dictates that Health Plans follow a required template for providing the SBC and accompanying glossary. When publishing the Final Regulation, the Departments also published the required SBC template form (2013 SBC Template) and instructions for Health Plans to use to prepare and provide the required SBC for coverage beginning before January 1, 2014 and promised updated guidance and templates for use in providing SBCs for post-2013 coverage. While the Agencies clarified certain other details about the SBC rules, they did not materially change the required content or form of the 2013 SBC Template until their April 23, 2013 release of FAQs About ACA Implementation (Part XIV). See e.g. FAQs About ACA Implementation Part IX and Part X.

FAQ Part XIV Requires MEC and Minimum Value Disclosures In SBC

FAQs About ACA Implementation (Part XIV) published April 23, 2013 announces the updated required 2014 SBC Template that the Agencies are requiring to SBCs for periods of health coverage from January 1, 2014 to December 31, 2014.  Along with the 2014 SBC Template, the Agencies also published 2014 Sample Completed SBC, which provides an example of a SBC completed for a hypothetical health plan prepared by the Agencies.

The 2014 SBC Template updates the 2013 SBC Template and Sample Completed Template to add information the Agencies believe individuals eligible for Health Plan coverage should know in light of the impending implementation of the individual shared responsibility requirements of Internal Revenue Code (Code) Section 5000A and the employer shared responsibility rules of Code Section 4980H commonly called ACA’s “pay-or-play” rules.   These were the “penalty” provisions that the Supreme Court ruled are taxes in 2013.

The April 23, 2013 FAQ expressly requires that SBCs for periods of coverage after December 31, 2013 disclose if the Health Plans provide MEC and Minimum Value to enable participants and beneficiaries to understand if enrollment in the Health Plan will suffice to allow the employee to avoid paying the individual penalty under Code Section 5000(a)’s individual “shared responsibility” rules, to compare the coverage and costs to enroll in the employer’s Health Plan versus to enroll in health care coverage through a Marketplace and to predict how their eligibility for enrollment in the employer’s Health Plan will impact their eligibility to qualify to claim tax credits under Code Section 32G to help subsidize the cost to purchase coverage through a Marketplace.

Code Section 5000A generally imposes a penalty tax on individuals that fail to maintain enrollment in MEC within the meaning of Code Section 5000A(f) and not otherwise exempt under Code Section 5000A(d).  As of the publication of this update, the Obama Administration has not announced any delay in the enforcement of this penalty against individuals, but legislation is pending in Congress that would delay its applicability, along with approving the delay of enforcement of the Code Section 4980H penalties previously announced by the Obama Administration.

Although the Obama Administration announced in early July, 2013 that it will not enforce collection of the Code Section 4980H provisions against employers until 2015, Code Section 4980H generally requires employers of 50 or more full-time employees to pay a penalty if the employer fails to offer a group health plan providing MEC and Minimum Value   Minimum Value is determined for this purpose in the same manner that it is determined for purposes of making the required disclosure in the Exchange Notice.

60-Day Advance Notice of Material Changes Requirement

In addition to providing the required Exchange Notice and SBCs, employers, group health plans and their plan administrators also must ensure that participants and beneficiaries are given at least 60 days prior notice before the effective date of any “material reduction in covered services or benefits.” See 29

CFR Section 2520.104b-3(d)(3); also see 29 CFR Section 2520.104b-3(d)(2) regarding a 90-day alternative rule.

Section 102 of ERISA has been amended to require 60-day advance notice of material plan changes for plan years beginning on or after September 23, 2012 before the change can be effective.  The 60-day advance notification requirement is a modification to the summary plan description/summary of material modification requirements generally applicable to employee benefit plans under ERISA.

The rule’s definition of “material modification” is the same as the definition in the summary of material modifications rule generally applicable to employee benefit plans under ERISA Section 102.

DOL guidance indicates that group health plans can meet the 60-day advance notice requirement by providing an updated Summary of Benefits and Coverage if the change is reflected on the summary or by sending a separate written notice describing the material modification.

Group health plan issuers or sponsors that willfully (intentionally) fail to provide the notice of material modification can face a fine of up to $1,000 for each failure. Each covered individual equates to a separate offense for purposes of these penalties.

Employer and other group health sponsors, issuers, fiduciaries and administrators also should keep in mind that courts historically refuse to enforce reductions in benefits or services provided under the plan until participants and beneficiaries are notified of the change.  For purposes of the ERISA notification rules, group health plans, their sponsors, insurers, administrators and fiduciaries are cautioned to take into account whether health care providers or other parties who have assignments of benefits should be provided with notification under these or other ERISA rules in addition to the employees and dependents who are enrolled in coverage under the group health plan.

Notice Deadlines Mean Time Short To Adopt & Communicate 2014 Plan Terms

Employer and other health plan sponsors, insurers, administrators and others involved in 2014 group health plan decisions and preparations must take into account these notification deadlines and allow adequate lead time to properly finalize, adopt and communicate their 2014 health plan terms.

Since group health plan design decisions must be finalized to properly prepare the Minimum Value disclosures required in the Exchange Notice and the SBC and any material reductions required by the 60-day advance notice requirement, time running short to finalize 2014 plan designs.

Employer and other plan sponsors, fiduciaries, administrators, and insurers are cautioned that their preparations should ensure both the necessary disclosures are made and that all disclosures are carefully prepared so that the notifications and the plan terms are consistent.

These preparations should include the critical review and coordination of the language of health plan documents and summary plan descriptions in light of these other notifications to identify and address potential differences between the government-mandated terms and language in the Glossary and SBC, the Exchange Notice and 60-day notice and the plan terms and summary plan description.

Arrangements also must include proper structuring and formatting of all of these documents and timely distribution in accordance with applicable regulations to participants and beneficiaries entitled to receive these documents in a manner that positions the employer, the group health plan and its fiduciaries and insurers to show compliance. In regard to distributions, parties planning to distribute notifications electronically need to ensure that any electronic or other methods of distribution meet applicable requirements and that the Health Plans timely send copies to all entitled parties – employees and dependents – in accordance with the applicable rules.

When planning these activities, group health plans, their sponsors, insurers and administrators also generally will want to minimize distribution costs by coordinating distribution of these ACA mandated notices with other notifications required for group health plans about privacy, coverage for newborns and mothers, mental health coverage, post-mastectomy reconstructive surgery and the like.

For Help or More Information

If you need help understanding or dealing with these impending notification requirements, with other 2014 health plan decision-making or preparation, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, HR.com, Insurance Thought Leadership, Solutions Law Press, Inc. and other publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication see here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer, P.C. 

Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved.


[*] On January 24, 2013, the Department of Labor (the Department) issued guidance stating the Department’s conclusion that the notice requirement under FLSA section 18B will not take effect on March 1, 2013 for several reasons until further guidance setting the extended deadline was published.


Health Plan Pays $1.2M+ HIPAA Settlement For Not Protecting PHI On Copiers

August 15, 2013

Affinity Health Plan, Inc. (Affinity) will pay $1,215,780 and take other corrective actions to settle alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules under the Affinity Resolution Agreement and CAP (Affinity Settlement) with the U.S. Department of Health and Human Services (HHS) Office of Civil Rights (OCR).  The settlement comes as the September 24, 2013 deadline for health plans, health care providers, health care clearinghouses (Covered Entities) and their business associates to update the written business associate agreements that HIPAA requires exist before business associates can be allowed to create, use, access or disclose personally identifiable health care information protected by HIPAA (PHI) to carry out HIPAA-covered functions on behalf of a Covered Entity to comply with changes to HIPAA’s implementing regulations adopted by OCR earlier this year.  Health plans and other Covered Entities should take timely action to confirm that their existing procedures appropriate safeguards to protect PHI when using or disposing of copiers or other equipment or media as well as to implement business associate or other policy, procedures or training updates required to comply with the updated HIPAA rules.

HIPAA Updates Require Breach Notification, Tightened Other HIPAA Requirements

HIPAA generally requires that Covered Entities (and after September 24, 2013, their business associates) safeguard and restrict the use, access or disclosure of PHI as required by HIPAA.  The HITECH Act amended these requirements to tighten certain of these requirements and restrictions, to expand the sanctions for violation of these requirements, to require Covered Entities and their business associates to provide notification of breaches of unsecured PHI to individuals whose information was breached, OCR and in some cases, the media, and made certain other changes to the original requirements of HIPAA.  Earlier this year, OCR amended and restated its original Privacy and Security Rules here (2013 Final Rule) to comply with changes in the regulations resulting from these HITECH Act amendments beginning last March, but set the deadline for updating business associate agreements to meet these updated requirements at September 23, 2013.

The 2013 Final Rule and other OCR guidance makes clear that OCR expects Covered Entities and their business associates appropriately to safeguard PHI stored in computers, hard drives, and other digital media until it is properly disposed in accordance with the updated standards required by HIPAA as implemented under the 2013 Final Rule. HITECH Breach Notification Rule requires HIPAA-covered entities to tell HHS of a breach of unsecured protected health information, including breaches resulting from failure to properly secure PHI stored in digital format until it has been destroyed in accordance with the standards established by the 2013 Final Rule.   OCR previously has sanctioned other Covered Entities for failed to properly destroy or safeguard PHI stored in digital format on computer or other equipment before abandoning or disposing of that equipment.  The Affinity Settlement reaffirms OCR’s concern that Covered Entities meet these disposal requirements when replacing or abandoning equipment containing electronic PHI.

Affinity Settlement Highlights

According to the August 14, 2013 OCR announcement of the settlement, the settlement resulted from an investigation initiated after Affinity filed a breach report with OCR on April 15, 2010, as required by the Health Information Technology for Economic and Clinical Health Act (HITECH Act.)

In its breach report, Affinity indicated that a representative of CBS Evening News told Affinity that, as part of an investigatory report, CBS had purchased a photocopier previously leased by Affinity.  CBS informed Affinity that the copier that Affinity had used contained confidential medical information on the hard drive.

Affinity estimated in its breach report that up to 344,579 individuals may have been affected by this breach. OCR’s investigation indicated that Affinity impermissibly disclosed the protected health information of these affected individuals when it returned multiple photocopiers to leasing agents without erasing the data contained on the copier hard drives.  In addition, OCR reports its investigation revealed that Affinity failed to incorporate the electronic protected health information (ePHI) stored on photocopier hard drives in its analysis of risks and vulnerabilities as required by the Security Rule, and failed to implement policies and procedures when returning the photocopiers to its leasing agents.

In addition to the $1,215,780 payment, the Affinity Settlement includes a corrective action plan requiring Affinity to use its best efforts to retrieve all hard drives that were contained on photocopiers previously leased by the plan that remain in the possession of the leasing agent, and to take certain measures to safeguard all ePHI.

Learn From Affinity Lesson On Proper Disposal Procedures

Like prior OCR settlements stemming from inadequate security for PHI when transitioning equipment, media or facilities, the Affinity Settlement sends another reminder to Covered Entities and their business associates again of the importance of using appropriate procedures to protect or dispose of PHI when replacing or redeploying equipment or media that may contain PHI.

“This settlement illustrates an important reminder about equipment designed to retain electronic information: Make sure that all personal information is wiped from hardware before it’s recycled, thrown away or sent back to a leasing agent,” said OCR Director Leon Rodriguez.  “HIPAA covered entities are required to undertake a careful risk analysis to understand the threats and vulnerabilities to individuals’ data, and have appropriate safeguards in place to protect this information.”

OCR has published guidance concerning HIPAA’s requirements for the proper safeguarding and disposal of media and equipment in the 2013 Final Rule and other guidance.  Concerning the proper disposition of copiers that may have PHI stored on their hard drives or in other digital formal, OCR in the Affinity Settlement recommended that Covered Entities and their associates also review the Federal Trade Commission’s Guidance On Safeguarding Sensitive Data Stored In The Hard Drives Of Digital Copiers and the National Institute of Standards and Technology has issued Guidance On Assessing The Security Of Multipurpose Office Machines.  Covered Entities and their business associates should use this and other guidance to ensure that they can demonstrate that appropriate practices and procedures have been used to when disposing of or repurposing copies or other equipment that may contain electronic PHI.

HIPAA Regulation Updates Require Other Updates Beyond Disposal Procedures

In addition to addressing the concerns that lead to the Affinity Settlement, Covered Entities and their business associates also should verify that their practices, policies, privacy notices, business associate agreements, and training also are updated to comply with updates to the updated 2013 Final Rule adopted by OCR earlier this year here.

Since passage of the HITECH Act, OCR officials have warned Covered Entities to expect an omnibus restatement of its original regulations.  While OCR had issued certain regulations implementing some of the HITECH Act changes, it waited to publish certain regulations necessary to implement other HITECH Act changes until it could complete a more comprehensive restatement of its previously published HIPAA regulations to reflect both the HITECH Act amendments and other refinements to  its HIPAA Rules. The 2013 Regulations published today fulfill  that promise by restating OCR’s HIPAA Regulations to reflect the HITECH Act Amendments and other changes and clarifications to OCR’s interpretation and enforcement of HIPAA.

In response to the updated Final Regulations and these expanding HIPAA enforcement and exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable.   In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.

For Help or More Information

If you need help monitoring or providing input on this legislation or to understand and respond to these or other legislation, laws and regulations, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.  Author of numerous prominent publications on HIPAA and other data security and privacy concerns impacting health plans, health care providers, employers, financial services providers and others, Ms. Stamer also serves as the scribe for the ABA JCEB annual Technical Sessions meeting with OCR and has represented numerous health plans, employers, health care providers and others in investigating, redressing, reporting data breach, identity theft and other compliance concerns.

She advises clients on, publishes, and speaks on HIPAA and other health plan, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer, P.C.  Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved


Legislation Proposes To Change Obama Care Full-Time Employee Definition

August 5, 2013

Businesses and workers concerned that the definition of “full-time” employment as 30 hours per week in the “pay-or-play” penalties of the Patient Protection and Affordable Care Act (commonly referred to by the public  as “Obamacare”) is hurting American workers may want to share their input on recently introduced legislation that would raise the number of hours an employee must work to qualify as “full-time”  for purposes of the pay-or-pay penalty from 30 to 40 hours per week with members of the key Congressional Committees that will decide whether this legislation advances when Congress returns from its Summer vacation.

Growing concern about the costs and other implications of Obamacare are fueling renewed debate in Congress about the pay-or-play and other provisions of Obamacare.  Only 57 days before enrollment in coverage slated to be available as an alternative to employer coverage beginning January 1, 2014 through new federally mandated health insurance exchanges is prompting renewed debate in Congress about the full-time employee, pay-or play and other provisions of Obamacare.  As Congress takes its summer break, both sides are talking and listening to voters about health care reform. Concerned parties should share their input on Congress during this break to help shape the decisions Congress makes when it returns to work in September.

“Full-Time Employee” Definition Key Element Of  Employer’s “Pay-Or Play” Liability

Originally scheduled to take effect on January 1, 2014 until the Administration on July 2, 2013 announced it would not enforce its provisions until 2015, the employer “shared responsibility” or “pay-or-play” rules of Internal Revenue Code (Code) Section 4980H enacted as part of Obamacare have been widely criticized as killing jobs and reducing employment.

When effective, Code Section 4980H will require that businesses employing 50 or more “full-time” employees (Large Employers”) pay a tax penalty calculated in accordance with Code Section 4980H unless the Large Employer offers each “full-time employee” the opportunity to enroll himself and each of his dependent children in coverage under a qualifying health plan that meets the minimum essential coverage, minimum value and affordability standards of Obamacare.

Under the current provisions of Code Section 4980H, the amount of the penalty that a Large Employer must pay is:

  • $168 per employee per month for any month that the employer doesn’t offer minimum essential coverage to each full-time employee and has at least one full-time employee who receives a subsidy or tax credit for enrolling in coverage under one of the health insurance exchanges created by Obamacare (Subsidized Employee);
  • $250 per employee month multiplied by the number of full-time employees of the business that are Subsidized Employees if the employer offers coverage under the health plan that provides minimum essential coverage but the health plan fails to meet the minimum value or affordability standards of Code Section 4980H; or
  • $0 if the employer either offers health plan coverage that meets the minimum essential coverage, minimum value and affordability requirements of Code Section 4980H or doesn’t have any full-time employees who are Subsidized Employees.

30-Hour Full-Time Definition Reducing Full-Time Employment Opportunities

As the original January 1, 2014 implementation date of Code Section 4980H has approached, original largely Republican concern about its unintended adverse impact on employment increasingly has grown amid widespread reports that businesses are avoiding hiring and reducing employee hours to minimize exposures to Code Section 4980H-driven costs. See, e.g. Obamacare’s Employer Penalty And Its Impact On Temporary Workers;  States Cutting Employee Hours To Avoid Obama Care Costs; Americans Who Voted For Obama Now Seeing Weekly Job Hours Slashed Below 30 As Obamacare Kicks In.  Particularly embarrassing among these reports include the recent report that even a call center hired by the Administration to help promote enrollment coverage offered through the Obamacare-created  exchanges is limiting the hours its employees can work to under 30 hours per week.  ObamaCare Call Center To Keep Employees Under 30 Hours/Week.

As businesses already struggling to deal with a tough economy moved to minimize the number of their full-time employees, even labor unions that originally supported Obamacare joined the cry for reform of its provisions to mitigate employment losses resulting from employer efforts to minimize Code Section 4980H exposures.  See Companies Cut Hours Of Full-Time Employees To Avoid Providing Health Care Under New Rules.

S. 1188/H.R. 2575 Would Make Full-Time Mean 40 Hours Per Week

Prompted by growing concern about the apparent adverse impact of Obamacare on job opportunities for hourly workers, legislation now is pending in both the House and Senate to amend the Obamacare’s definition of “full-time.” In June, Senators Susan Collins (R-ME) and Joe Donnelly (D-IN) Collins introduced a bill to amend  Code Section 4980H to change the definition of full-time employee for purpose of the shared responsibility provisions of Obamacare,  S. 1188: Forty Hours Is Full Time Act to change the definition of “full-time” from 30 to 40 hours per week and the number of hours counted toward a “full-time equivalent” employee to 174 hours per month.  Representative Todd Young (R-IN) then introduced a similar provision in the House on June 28, 2013, H.R. 2575, Save American Workers Act of 2013

H.R. 2575 has garnered the support of 144 Cosponsors.  H.R. 2575.  Following its introduction, the House assigned H.R. 2575 to the House Ways and Means Committee, whose members now must decide when and if the bill will advance in the House.  Key members of the House Ways and Means Committee who will make this decision on include the following Committee Members:  Dave Camp; Sander Levin; Charles Boustany Jr.; Kevin Brady (Chair, Subcommittee on Health); Sam Johnson; Devin Nunes; David Reichert (Chair, Subcommittee on Human Resources);  Patrick “Pat” Tiberi; Xavier Becerra; Diane Black Earl Blumenauer; Vern Buchanan; Joseph Crowley; Danny Davis; Lloyd Doggett;  Jim Gerlach; Tim Griffin; Lynn Jenkins; Mike Kelly; Ron Kind; John Larson; John Lewis; Kenny Marchant; Jim McDermott; Richard Neal; Bill Pascrell Jr.;  Erik Paulsen; Tom Price; Charles Rangel; Tom Reed II, James Renacci; Peter Roskam; Paul Ryan; Aaron Schock; Allyson Schwartz; Adrian Smith; Linda Sánchez; Mike Thompson; and the Bill’s sponsor, Todd Young.

Although introduced before H.R. 2575, S. 1188 to date has drawn less interest among members of the Senate.  The Senate referred S. 1188 to the Senate Finance Committee, where to date, that Committee has not taken any further action. It presently has 8 cosponsors, 7 of which are Republicans.  See S. 1181 Cosponsors.  With Democrats the Majority Party in the Senate, many expect the bill to require significant public pressure and support for the Committee to report the bill out from the Committee, which presently is Chaired by Democrat Max Baucus.  Other Senate Finance Committee members include Orrin Hatch; Michael Bennet; Sherrod Brown; Robert “Bob” Casey Jr.; John “Jay” Rockefeller IV; Debbie Stabenow; Ron Wyden; Richard Burr; Maria Cantwell; Benjamin Cardin; John Cornyn; Michael Crapo;  Michael Enzi; Charles “Chuck” Grassley;  John “Johnny” Isakson; Robert “Bob” Menéndez; Bill Nelson; Robert “Rob” Portman; Pat Roberts; Charles Schumer; John Thune; and Patrick “Pat” Toomey.

This past weekend, S. 1188’s sponsor, Maine Senator Susan Collins sought to beef up support for the bill.  In urging support for her bill, Senator Collins said the health care law’s 30-hour per week definition kills jobs. “Obamacare is actually discouraging small businesses from creating jobs and hiring new employees,” she said. “The law also has perverse incentives for employers to reduce the number of hours that their employees can work.”

How To Contact Key Committees To Show Support or Share Other Feedback

Individuals wishing to share their support or other input about S. 1181 with the Senate Finance Committee can call (202) 224-4515 or  send their written input to the Senate Committee on Finance members via fax to (202) 228-0554.

Support or other input on H.R. 2575 should be sent via fax to House Ways & Means Committee members via fax to (202) 225-2610 or by calling the Committee office at (202) 225-3625.

Committee members and other members of Congress also generally can be contacted via e-mail through the link provided on each member’s webpage.  Because security precautions generally delay delivery of mail to members of Congress for 7-10 days, concerned individuals generally are encouraged to contact the Committee or other members of Congress via fax or e-mail.

Stay In Touch & Join The Discussion On Health Care Reform

Want to stay in touch with the latest developments on health care reform and get involved with helping to share  meaningful improvements in U.S. health care and workforce policy and our health care and health care insurance system?   The Coalition For Responsible Health Care Policy provides a resource that concerned Americans can use to share, monitor and discuss the Health Care Reform law and other health care, insurance and related laws, regulations, policies and practices and options for promoting access to quality, affordable healthcare through the design, administration and enforcement of these regulations.  We also encourage you to participate in our Project COPE: Coalition for Patient Empowerment initiative here to share ideas, discuss issues, and access and share tools and other resources.

For Help or More Information

If you need help monitoring or providing input on this legislation or to understand and respond to these or other legislation, laws and regulations, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

 

©2013 Cynthia Marcotte Stamer, P.C.  Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved


Employers & Insurers Reminded Of July 31 Deadline To Pay New ACA-Required PCORI Fees

July 26, 2013

Employers sponsoring self-insured group health plans and insurers are reminded that the deadline to report and pay the fee new fees required by the Patient Protection and Affordable Care Act (ACA) to help fund the Patient-Centered Outcomes Research Institute (PCORI) is July 31, 2013.

The PCORI fee, required to be reported annually on the second quarter Form 720 and paid by its due date, July 31, is based on the average number of lives covered under the policy or plan.  The annually required PCORI fee applies to policy or plan years ending on or after October 1, 2012, and before October. 1, 2019.

The PCORI fee is just one of a number of new fees and costs that ACA imposes upon employers and individuals as part of the health care reforms enacted under ACA.

Employers of more than 50 full-time employees recently received a temporary retrieve from another of these looming potential fees, the employer “shared responsibility” payment that ACA added to the Internal Revenue Code (Code) under new Code Section 4980H.

Earlier this month, the Internal Revenue Service (IRS) announced that it will delay until 2015 enforcement of the employer shared responsibility or “pay-or-play” rules of Code Section 4980H.  See July 2 Blog and Notice 2013-45.   Slated prior to the delayed enforcement announcement to take effect January 1, 2014, the employer shared responsibility rules generally will require employers which individually or collectively with other commonly controlled or affiliated employers employee 50 or more full-time employees that do not offer group health coverage that meets the minimum essential coverage, minimum value and affordability standards of the Affordable Care Act to pay an “assessment” that the Supreme Court ruled last year to be a tax, as well as to comply with certain reporting requirements.

While Notice 2013-45 gives large more time to prepare to comply with Code Section 4980H, it provides no relief from the obligation to pay the PCORI fee or from other group health plan mandates imposed by ACA or other applicable federal laws.  Consequently, as businesses continue to prepare for the delayed implementation of Code Section 4980H in 2015, they also need to ensure that they timely pay any required PCORI fees and meet other applicable federal group health plan mandates as they continue to diligently prepare to deal with Code Section 4980H.

While businesses work to meet current and impending federal health plan responsibilities, most business leaders also will want to continue to closely monitor and provide regular input to members of Congress and regulators on proposed regulatory and enforcement guidance and potential Congressional amendments to the Affordable Care Act or other health care or tax policy reforms.

For Help or More Information

If you need help with preparing these or other ACA compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer, P.C.  Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved


“Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines

July 11, 2013

The Internal Revenue Service (IRS) yesterday (July 10, 2013) shared its first “formal” guidance officially implementing the Obama Administration’s decision to delay until 2015 enforcement of certain of the employer shared responsibility or “pay-or-play” rules of new Internal Revenue Code (Code) Section 4980H first informally announced by Department of Treasury Assistant Secretary for Tax Policy Mark Mazar in this July 2 Blog.

Notice 2013-45 outlines the specific “transition relief” rules under which the IRS says it will forego during 2014 enforcement of the employer shared responsibility penalty tax rules and associated and information reporting requirements that are slated to take effect for single employers or groups of commonly controlled or affiliated employers that employ 50 or more full-time employees (Large Employers) beginning January 1, 2014 as part of the sweeping health care reforms enacted under the Patient Protection and Affordable Care Act (Affordable Care Act).  Even with the extension of time allowed by Notice 2013-45 to prepare to comply with Code Section 4980H, however, employers and insurers have much to do to prepare.

The first priority for employers wishing to take advantage of added time to comply with Affordable Care Act’s pay or play penalty to maximize their planning opportunities and to minimize their potential Code Section 4980H consequences should be to clean up worker classifications, to track all hours worked for all employees and collect all other relevant employee data.

Notice 2013-45 Confirms IRS Won’t Enforce Code Section 4980H In 2014

The transitional relief in Notice 2013-45 comes as businesses have struggled to understand and come to grips with the requirements of new Internal Revenue Code Section 4980H that beginning January 1, 2014, a Large Employer  calculate and pay the applicable “assessable payment” tax  under Section 4980H for each month that it fails to offer each full-time employee group health plan coverage meeting Code Section 4980H’s “minimum essential coverage,” “minimum  value” and “affordability standards” if any full-time employee receives a subsidy for enrolling in coverage through a health insurance exchange.

Specifically, Notice 2013-45 waives IRS enforcement only for 2014 and only of:

  • The information reporting requirements applicable to insurers, self-insuring employers, and certain other providers of minimum essential coverage (MEC) under Code Section 6055 (6055 Reporting);
  • The information reporting requirements applicable to applicable large employers under Code Section 6056 (6056 Reporting);  and
  • The obligation to pay tax penalties under the employer shared responsibility provisions under Code Section 4980H (4980H Tax).

This relief is limited in both scope and duration.  Notably, Notice 2013-58 states:

  • Its provisions have no effect on the effective date or application of the multitude of other new mandates that have or will kick in coming months in connection with the impending 2014 Affordable Care Act reforms; and
  • The IRS plans that the tax penalty provisions of Code Section 4980H and the information reporting requirements of Code Sections 6055 and 6056 “will be fully effective for 2015.”

While the IRS is promising in Notice 2013-45 that the IRS will not require any payments by any employer under Code Section 4980H for 2014, it also urges Large Employers other affected entities to prepare for 2015 by voluntarily complying with the information reporting provisions (once the information reporting rules have been issued) in 2014 including conducting “real-world testing of reporting systems and plan designs” and continuing employer-provided coverage.

Relief Leaves Large Employers & Other Employers With Much Work To Do

While Notice 2013-45 gives Large Employers more time to prepare to comply as well as to communicate with the IRS about the need and options for simplification, employers should continue to aggressively prepare for compliance. The IRS says it intends to fully enforce the rules against Large Employers beginning in 2015 and to implement other Affordable Care Act provisions.  Consequently, employers that know or question if they may be Large Employers, their insurers, service providers and advisors should continue to diligently prepare to deal with Code Section 4980H, as well as other federal health plan rules.  Accordingly, Large Employers, their insurers and advisors could continue to diligently prepare to prepare to manage their impending Code Section 4980H responsibilities and liabilities.

1.  Start With Worker Classification, Time & Income Data Collection & Recordkeeping

Employers wishing to use this reprieve to their best advantage should start by ensuring that they clean up and tighten their worker classification and time tracking practices.  This should start with auditing the classification of all workers providing services as employees, contractors or otherwise  to be sure that they are properly classified.  Code Section 4980H takes into account all workers who are under they facts and circumstances test applied by the Code “common law employees” for purposes of deciding what employers are covered by Code Section 4980H and calculating the penalties, if any owning.  Many businesses mistakenly fail to recognize a wide range of workers considered by the business to work as contractors, leased employees or in other capacities are likely to be considered by the IRS to be common law employees for purposes of these rules.  Ensuring that the business has properly accounted for all workers that the IRS is likely to view as common law employees is essential to any reliable planning or cost projection.

Beyond having an appropriate understanding of what individuals are considered common law employees, businesses also should seek to track accurately all hours worked, regardless of whether the employees are non-exempt workers that the Fair Labor Standards Act (FLSA) requires the employer pay hourly, or exempt employees under the FLSA that the employer pays on a salaried, commission or other non-hourly basis.  Under existing Code Section 4980H rules, employers that don’t have accurate time records for employees must rely upon safe-harbor rules for identifying workers that are considered full-time.  These safe harbor rules credit hours in such a way that tends to overstate the number of full-time employees and full-time equivalent employees.

In workforces where many employees many receive significant additional family income from the earnings of a spouse, another job or other sources, employers also may want to add processes to verify actual household adjusted gross income  (HAGI) for purposes of identifying which of its full-time employees, whose HAGI actually is below the 400 percent of the poverty level required to qualify to receive subsidies when enrolling in coverage through a Health Insurance Exchange.

2. Other To Dos

Other helpful preparations also generally will include:

  • Seeking and monitoring developing guidance about the meaning of minimum essential coverage and other associated rules;
  • Providing meaningful input to the IRS, the Department of Health & Human Services, Congress and others on the need for and options to simplify time and other data and reporting requirements,  employer interactions and data requests for verification of exchange subsidy eligibility and other purposes;
  • Evaluating and adjusting workforce and benefit practices, time and other record keeping systems, and plan designs;
  • Evaluating workflow and staffing practices to determine the potential advantages of using certain measurement, stability or administrative periods, safe harbors and other options for purposes of applying Code Section 4980H, making changes in workforce or staffing practices, redesigning benefits or other adjustments; and
  • Working with management, vendors and others to identify and change plan designs; and
  • Completing other preparations to cope with the rules.

While continuing these preparations to comply with Code Section 4980H in 2015, Large Employers as well as other businesses also need to get busy finalizing preparations for the upcoming 2014 plan year, particularly in the face of fast approaching notice deadlines. Employers are under the gun to finalize and implement plan design, vendor and other decisions and complete other preparations to prepare and deliver these and other materials on time, updated in time to meet new or revised federal health plan requirements under the Affordable Care Act and other laws.  The impending Affordable Care Act-imposed deadlines to deliver newly mandated exchange notices by October 1 and updated “Summaries of Benefits and Coverage” or “SBCs” by the beginning of their next enrollment period significantly shortens the time for employers to finalize their plan designs.  Under existing SBC rules, employers that amend their plans after the beginning of an annual enrollment period must update and resend SBCs to plan members.  Furthermore, Federal rules also now generally require health plan administrators provide 60 days advance notice to plan members of plan amendments that materially reduce coverage or benefits.  Therefore all employers regardless of size will want to ensure that their plans and associated contracts are finalized quickly to adequately meet these requirements without incurring the added expense of updating and redistributing their SBCs.

As part of these efforts, all businesses generally should act quickly and diligently to:

  • Carefully credential and contract with insurers, administrators, consultants and other plan service providers and advisors to document expectations and commitments about compliance, quality assurance, fiduciary and other responsibility and status, indemnification and other accountability and other matters including updated business associate commitments where required to comply with recently changes in the privacy rules of the Health Insurance Portability & Accountability Act generally required no later than September 24, 2013 for all existing plan business associates);
  • Audit within the scope of attorney-client privilege all existing employee and alternative workforce arrangements and patterns to confirm that all common law employees properly are identified and classified and that appropriate arrangements are in place to track and document time and other relevant information to position the business reliably its responsibilities and defend its action for Code Section 4980H and other federal health plan, Fair Labor Standards Act and other compliance purposes;
  • Consult with legal counsel within the scope of attorney-client privilege about any legally required or otherwise desired adjustments to worker classification or other workforce practices to minimize Affordable Care Act or other liabilities;
  • Finalize decisions about what health benefits, if any that their business will offer to what employees in the upcoming plan years and carefully contract with vendors, update plan documents, the SBCs, summary plan descriptions and other materials for the upcoming plan year before the first day of the next enrollment period;
  • Carefully amend and update plan documents, summary plan descriptions, SBCs, privacy practices notices and other required notices, communications and forms to the extent possible, before the upcoming enrollment period to minimize inconsistencies, and to be able to package required notices, summary plan descriptions and other communication and enrollment materials to take advantage of the opportunity to minimize distribution expenses;
  • Complete the necessary decisions and arrangements to prepare and send the exchange notice that the Affordable Care Act requires be delivered for the first time by October 1, 2013; and
  • Finalize other preparations for the upcoming plan year.

Monitor & Provide Input On Proposed Tax & Health Care Reform

While businesses work to meet current and impending federal health plan responsibilities, most business leaders also will want to continue to closely monitor and provide regular input to members of Congress and regulators on proposed amendments to the Affordable Care Act or other health care or tax policy reforms.

Despite a projected $ 5 billion reduction in federal budget revenue from non-enforcement of Code Section 4980H in 2014, the Administration is moving ahead aggressively to implement other Affordable Care Act reforms as scheduled.   Notice 2013-45 states that the Administration plans to continue to provide subsidies pursuant to the Affordable Care Act for individuals earning less than 400% of the Federal poverty level who enroll in health coverage through a Health Insurance Exchange, which the Administration has rebranded and now refers to as “Marketplaces.”  Furthermore, the Administration separately announced on July 5, 2013 that individuals will be allowed to apply for and claim these subsidies based on an “honor system” in 2014; the Administration will not require verification of eligibility.

Even before the IRS announced the relief now formalized by Notice 2013-45, the rising federal budget costs of the Affordable Care Act was fueling concern.  In March, the General Accounting Office (GAO) reported that after having already spent more than $394 million on exchange efforts, the Obama administration needs Congress to approve an extra $1.5 billion added to the budget to cover the  additional $2 billion that the GAO projects the Administration will need over the next fiscal year to create and run the federal exchanges. See GAO Report and  GAO Report.  Foregoing enforcement of Code Section 4980H, verification of subsidy eligibility and other unexpected costs resulting from glitches in the preparation and rollout of the Affordable Care Act reforms for 2014 are adding to the growing costs and projected budgetary impact of the Affordable Care Acts on the federal budget.  With existing budget shortfalls already fueling pressure for increased tax revenues, businesses and individuals concerned about tax liability will want to carefully monitor and provide input to Congressional leaders on health care and tax reform.

For Help or More Information

If you need help with preparing these or other ACA compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer, P.C.  Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved


HHS Continues Preparations For New Health Insurance Marketplace By Awarding Grants To Promote Kids Enrollment

July 2, 2013

As part of its continuing efforts to promote enrollment in the Health Insurance Marketplace slated to take effect January 1, 2014, the Department of Health and Human Services (HHS) today (July 2, 2013) announced the award of nearly $32 million in grants for efforts to identify and enroll children eligible for Medicaid and the Children’s Health Insurance Program (CHIP). The Connecting Kids to Coverage Outreach and Enrollment Grants were awarded to 41 state agencies, community health centers, school-based organizations and non-profit groups in 22 states; two grantees are multistate organizations.  The announcement comes as employers and others continue to express concern about the sufficiency of preparations and HHS’ recent rollout of online tools to aid consumers enroll in the new Health Care Marketplace scheduled to launch January 1, 2014 as part of the continuing implementation of reforms enacted as part of the Patient Protection & Affordable Care Act (Affordable Care Act).

Announced Grants Target Increased CHIP & Medicaid Enrollment In Preparation For Health Care Marketplace

In amounts ranging from $190,000 to $1 million out of the $140 million included in the Affordable Care Act and the Children’s Health Insurance Program Reauthorization Act (CHIPRA) of 2009 for enrollment and renewal outreach,  HHS Reports the grants awarded to the grantees listed here focus on 5 areas:

  • Engaging schools in outreach, enrollment and retention activities (9 awards);
  • Reducing health coverage disparities by reaching out to subgroups of children that are less likely to have health coverage (8 awards);
  • Streamlining enrollment for individuals participating in other public benefit programs such as nutritional or other assistance programs (3 awards);
  • Improving application assistance resources to provide high quality, reliable Medicaid and CHIP enrollment and renewal services in local communities (13 awards); and
  • Training communities to help families understand the new application and enrollment system and to deliver effective assistance to families with children eligible for Medicaid or CHIP (8 awards).

According to HHS, the grants will build on the Secretary’s Connecting Kids to Coverage Challenge to find and enroll all eligible children and support outreach strategies that have been shown to be successful.

According to HHS, Connecting Kids to Coverage Outreach and Enrollment Grant Awards (Cycle III) Efforts to streamline Medicaid and CHIP enrollment and renewal practices, combined with robust outreach activities, have helped reduce the number of uninsured children.  Since 2008,  HHS claims 1.7 million children have gained coverage and the rate of uninsured children has dropped to 6.6 percent in 2012

“Today’s grants will ensure that more children across the nation have access to the quality health care they need,” said Secretary Sebelius. “We are drawing from successful children’s health coverage outreach and enrollment efforts to help promote enrollment this fall in Medicaid and the new Health Insurance Marketplace.”

Continuing Preparations For New Health Care Marketplace

 The grant awards are part of a much broader effort by HHS to prepare Americans to enroll in the newly reformed Health Insurance Marketplace that the Obama Administration is working to implement as part of the sweeping reforms enacted by the Affordable Care Act.

Enrollment is the Health Insurance Exchanges also to be included in the new federal health care marketplace is scheduled to begin October 1, 2013.  In anticipation of this deadline, HHS recently also announced its rollout of new consumer health care education and decision-making tools on its newly designed www.healthcare.gov  website.

In announcing its launch of its Health Insurance Marketplace educational tools here on June 24, 2013, the Department of Health & Human Services (HHS) repeated recent claims that HHS and the states are on target to begin enrollment on October 1, 2013 in the federal and state health care exchanges now retitled “Health Insurance Marketplace” by the Administration, to meet other key milestones and to the beginning coverage under the newly created Health Insurance Marketplaces beginning January 1, 2014.

As part of these preparations, HHS kicked off an aggressive Health Insurance Marketplace education effort by announcing the deploying of with newly designed “consumer-focused” HealthCare.gov website and the 24-hours-a-day consumer call center that HHS claims provide all the necessary tools to prepare Americans for open enrollment and ultimately sign up for private health insurance.

While HHS says its tools and other preparations will get the Health Care Marketplaces and Americans ready for the conversion of the U.S. health care system slated to begin January 1, 2014, others are less confident.  For instance, GAO officials recently found that major work that federal and state officials  must complete to timely begin enrollment by October 1 remains unfinished, making it unclear if they will meet the impending October 1, 2013 enrollment kickoff deadline.  See GAO Report and  GAO Report.

Meanwhile, employers of 50 or more full-time employees and others also have complained that delayed and incomplete guidance has prevented them from understanding their obligations and moving to complete preparations to comply with the new employer mandates by delaying private market reforms and employer preparations.  These problems have been further complicated by recent media coverage and public debate about the access to sensitive personal health care, financial information and the role of the Internal Revenue Service and other government agencies under the Affordable Care Act following recent charges that certain Internal Revenue Service officials improperly targeted certain charitable organization and their organizers as part of application approval and audits.

Despite these concerns, HHS is marching ahead on its efforts to implement the law by launching these and other enrollment and educational outreach.

For Help or More Information

If you need help with preparing these or other Affordable Care Act compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer, P.C.  Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved


HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns

June 26, 2013

Despite growing concerns expressed by the General Accounting Office (GAO) and others about arrangements and the need for added funding to prepare for the massive conversion in the U.S. health care system slated to take effect January 1, 2014 under the Patient Protection & Affordable Care Act (“ACA), Obama Administration officials are continuing to claim readiness to begin enrollment of Americans In federal health care marketplace on schedule on October 1, 2013 and to meet other crucial deadlines necessary to effectively implement the next wave of ACA’s health care reforms in the Department of Health & Human Service’s rollout of new consumer health care education and decision-making tools on its newly designed healthcare.gov website.

In announcing its launch of its Health Insurance Marketplace educational tools here on June 24, 2013, the Department of Health & Human Services (HHS) repeated recent claims that HHS and the states are on target to begin enrollment on October 1, 2013 in the federal and state health care exchanges now retitled “Health Insurance Marketplace” by the Administration, to meet other key milestones and to the beginning coverage under the newly created Health Insurance Marketplaces beginning January 1, 2014.

As part of these preparations, HHS kicked off an aggressive Health Insurance Marketplace education effort by announcing the deploying of with newly designed “consumer-focused” HealthCare.gov website and the 24-hours-a-day consumer call center that HHS claims provide all the necessary tools to prepare Americans for open enrollment and ultimately sign up for private health insurance.

According to HHS, “The new tools will help Americans understand their choices and select the coverage that best suits their needs when open enrollment in the new Health Insurance Marketplace begins October 1.”

According to Centers for Medicare & Medicaid Services Administrator Marilyn Tavenner, “In October, HealthCare.gov will be the online destination for consumers to compare and enroll in affordable, qualified health plans.”

Between now and the start of open enrollment, HHS says the Marketplace call center will provide educational information and, beginning Oct. 1, 2013, will help consumers with application completion and plan choice.  In addition to English and Spanish, the call center provides assistance in more than 150 languages through an interpretation and translation service.  Customer service representatives are available for assistance via a toll-free number at 1-800-318-2596 and hearing impaired callers using TTY/TDD technology can dial 1-855-889-4325 for assistance.

While HHS says its tools and other preparations will get the Health Care Marketplaces and Americans ready for the conversion of the U.S. health care system slated to begin January 1, 2014, others are less confident.  For instance, GAO officials recently found that major work that federal and state officials  must complete to timely begin enrollment by October 1 remains unfinished, making it unclear if they will meet the impending October 1, 2013 enrollment kickoff deadline.  See GAO Report and  GAO Report such as::

  • 17 states committed to run their own exchanges have missed March 2013 deadlines on 44% of key activities;
  • Officials creating the small business exchanges still must review plans and train and certify the “navigators” that are supposed to help companies and individuals enroll in plans and complete other key arrangements;
  • A federal  the “data hub” designed to help individuals determine their eligibility and enroll in plans offered through the exchanges has only  undergone initial testing; and
  • The current planned process for coordination of data between employer and insurer plans and the health care exchanges to evaluate eligibility of the millions of Americans expected to apply for subsidies for enrolling in coverage through the exchange presently is for HHS to contact employers by telephone employers to ask if that employer asked that employee enrollee minimum essential coverage providing minimum essential value at an affordable cost that would disqualify the applicant for the subsidy.

Meanwhile, the GAO Reports also provide a glimpse at what the federal government has spent so far on preparing the federal exchanges and the data hub. They indicate that hat the Obama Administration had approximately $394 million on exchange efforts as of March 2013 including:

  • $84 million to CGI Federal, which is building the federal exchange computer infrastructure;
  • $55 million to Quality Software Services, which is building the data hub; and
  • $38 million to Booz Allen Hamilton to provide technical assistance for enrollment and eligibility.

Contractor Booz Allen Hamilton recently has drawn attention as the National Security Association contractor through which the notorious fugitive Edward Snowden allegedly accessed information he disclosed to the public about NSA surveillance of “big data” on Americans and others through the internet.

The GAO also estimated the Obama administration needs Congress to approve an extra $1.5 billion from the budget to provide the Administration with the additional $2 billion that the GAO projects the Administration will need over the next fiscal year to create and operate the federal exchanges.  Existing budget concerns make it unlikely that Congress will approve these extra funds.

 

For Help or More Information

If you need help with preparing these or other ACA compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer, P.C.  Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved


Final Regulations Update HIPAA Health Plan Wellness Program Rules

May 30, 2013

Register Now For 6/4 Solutions Law Press, Inc. Virtual Briefing

Employer, union and sponsors of employment-based group health plans that include health risk assessment (HRA) or other wellness plan features that reward participants for engaging in certain assessments or other activities designed to promote wellness or disease management, and fiduciaries insurers, and administrators  of these health plans should review and update their programs in light of final wellness program rules jointly published by the Department of Health and Human Services (HHS), Department of Labor Employee Benefit Security Administration (EBSA) and the Department of Treasury (collectively the “Agencies”) today (May 29, 2013) here (Wellness Regulations).

While these final Wellness Regulations implementation of changes to the “bona fide wellness program exception” to nondiscrimination rules contained in the Portability Rules of the Health Insurance Portability & Accountability Act (HIPAA) as amended by the Patient Protection and Affordable Care Act (ACA) allow group health plans to provide bigger rewards to members for cooperating in wellness activities required under a “bona wellness program” within the meaning of the Wellness Regulations, the Wellness Regulations and other federal rules still need care to design and administer these health plan features meet all applicable Wellness Regulations for qualification as a “bona fide wellness program while also safeguarding the use of “personal health information” and “genetic health information in accordance with the privacy rules of HIPAA as amended by the Genetic Information Nondiscrimination Act (GINA) managing potential employment disability discrimination exposures under the Equal Employment Opportunity Commission’s (EEOC’s) current interpretation of the employment discrimination rules of Americans With Disabilities Act (ADA) and GINA.

Wellness Rules Implement ACA Changes To HIPAA “Bona Fide Wellness Program Rules

The nondiscrimination prohibitions of the Health Insurance Portability & Accountability Act (HIPAA), as amended by the Genetic Information Nondiscrimination Act (GINA) and the Patient Protection and Affordable Care Act (ACA) generally prohibit health plans from discriminating against an individual based on eligibility or premium based on a health factor.  Wellness or disease management programs that vary premiums or contributions, cost-sharing or other benefit mechanisms, or provide other rewards or inducements can run afoul of this HIPAA nondiscrimination prohibition if not properly designed and administered to fall within the “bona fide wellness program” exception.

The Wellness Regulations as finalized continue to interpret HIPAA’s general prohibition against group health plan provisions that discriminate based on a health factor to prohibit group health plans to vary benefits (including cost-sharing mechanisms) or the premium or contribution for similarly situated individuals when wellness program that satisfies the requirements of the Wellness Regulations for a “bona fide wellness program

The Affordable Care Act generally increased the maximum permissible reward under a health-contingent wellness program from 20 percent to 30 percent of the cost of health coverage for qualifying bona fide wellness programs and to as much as 50 percent of the cost of health coverage for bona fide wellness programs designed to prevent or reduce tobacco use.  In keeping with these ACA amendments to HIPAA, the Wellness Regulations allow group health plans and insurers to offer these greater rewards as long as the wellness program otherwise meets the conditions that the Wellness Regulations set for qualification as a bona fide wellness program.

In order to offer these incentives, however, the Wellness Regulations make clear that group health plans, their insurers and fiduciaries still need to tread carefully to properly design and administer these arrangements to ensure that their wellness program meet the applicable conditions of the Wellness Regulations for qualification as a bona fide wellness program.

In keeping with the approach announced in proposed regulations the Agencies previously published here last Fall, the Wellness Regulations have different requirements for “participatory wellness programs” versus “health contingent wellness programs.”

  • “Participatory wellness programs” generally are programs that reward plan members for participating in wellness activities based on participation in specified activities without regard to an individual’s health status. These include programs that reimburse for the cost of membership in a fitness center; that provide a reward to employees for attending a monthly, no-cost health education seminar; or that reward employees who complete a health risk assessment, without requiring them to take further action
  • “Health-contingent wellness programs” generally are programs where individuals must meet a specific standard related to their health to qualify for the specified reward or avoid a specified penalty. Examples of health-contingent wellness programs include programs that provide a reward to those who do not use, or decrease their use of, tobacco, or programs that reward those who achieve a specified health-related goal, such as a specified cholesterol level, weight, or body mass index, as well as those who fail to meet such goals but take certain other healthy actions.

Group health plan sponsors, fiduciaries, insurers and administrators should use care to properly understand which type of program or programs their group health plans contain and ensure that their programs are properly designed and administered to meet these conditions.  While fulfillment of these requirements can allow the arrangement to avoid violation of HIPAA’s nondiscrimination rules, however, it is important also to ensure that other applicable federal requirements for the use of these arrangements also are fulfilled along with these HIPAA nondiscrimination requirements.

Meeting Other Federal Rules For Wellness Programs Also Important

In addition to fulfilling the Wellness Regulations, health plans, their sponsors, fiduciaries, insurers and administrators also need to ensure that any wellness program included in a group health plan also meets other federal rules about the protection of sensitive personal health information and genetic health information and do not violate the employment discrimination rules of the ADA and GINA

  • Update Privacy Compliance

.Since wellness programs generally inherently involve some collection, use, access or disclosure of “protected health information” within the meaning of the Privacy Rules of HIPAA, it is particularly important to review and tighten plan provisions and other documentation, processes, procedures, and training to reduce the risk of violating HIPAA. A review of the adequacy of these arrangements is made particularly important in light of recent changes to in the implementing regulations of these HIPAA Privacy Rules adopted earlier this year to implement changes enacted by the HITECH Act.  Among other things, these changes may require updates to the health plan’s definition of personal health care information to clarify that it includes family health information and other “genetic information” that wellness programs often collect. Other updates to plan provisions, privacy policies, vendor agreements or other practices also may be needed to comply with modifications to the HIPAA Privacy Rules on business associates, marketing, breach notification, training or other rules.

  • Manage Disability Discrimination Risks

In addition to ensuring compliance with current requirements about privacy, group health plans, their sponsors, fiduciaries, insurers and vendors also should take steps to minimize potential employment discrimination challenges under the ADA and GINA.

Despite ACA’ amendments to HIPAA’s bona fide wellness program rules and the 11th Circuit’s rejection of an EEOC challenge in Broward County v. Seff, EEOC officials continue to take the position that testing and inquiries about medical conditions made in connection with wellness programs presumptively violate the Americans With Disabilities Act physical testing and other disability discrimination rules as raising concerns about wellness and disease management programs..   See, e.g.EBSA Issues Guidance on Health Plan Wellness & Disease Management Programs Subject to HIPAA Nondiscrimination RulesADAAA Amendment Broader “Disability Definition Not Retroactive, Employer Action Needed To Manage Post 1/1/2009 RisksBusinesses Face Rising Disability Discrimination Enforcement Risks; EEOC Finalizes Updates To Disability Regulations In Response to ADA Amendments Act.

The ADA is not the only employment discrimination risk to manage, however.  In addition to the amendments to the group health plan nondiscrimination and Privacy Rules of HIPAA, GINA’s employment discrimination rules generally prohibit employment discrimination based on “genetic health information.” For instance, GINA’s genetic information nondiscrimination rules:

  • Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
  • Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
  • Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
  • Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
  • Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
  • Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
  • Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and

EEOC officials have stated publicly on certain occasions and reportedly have challenged health risk assessments or other wellness program features that request or collect family medical history or other genetic information as violating GINA’s employment discrimination rules.

Learn More At 6/4 Solutions Law Briefing

Solutions Law Press, Inc. invites employer and other employment-based group health plan sponsors, fiduciaries insurers, administrators, brokers, consultants and others to learn the key details of new Final Wellness Program regulations jointly published May 29, 2013 by the Departments of Health and Human Services, Labor and Treasury (collectively the “Agencies”) by participating in an informative and timely virtual briefing on “Making Wellness Programs Work Under New Final Tri-Agency Regulations” on June 4, 2013 beginning at Noon Central Time.  To register or for additional details, see here.

For Help or More Information

If you need help with preparing these or other ACA compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2013 Cynthia Marcotte Stamer, P.C.  Nonexclusive license to republish granted to Solutions Law Press, Inc.  All other rights reserved


OCR Gives HIPAA Guidance On Safety Disclosures

January 17, 2013

Tbe Office of Civil Rights (OCR) has issued a letter to health care providers to ensure that they are aware of their ability under the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to take action, consistent with their ethical standards or other legal obligations, to disclose necessary information about a patient to law enforcement, family members of the patient, or other persons, when they believe the patient presents a serious danger to himself or other people.  For more information, see: http://www.hhs.gov/ocr/office/lettertonationhcp.pdf.  The Guidance is released on the same day that OCR released its long-awaited omnibus restatement of its HIPAA regulations.

HIPAAFor Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs

If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.

Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.

A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.  Her publications and insights  on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications.   For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR.  Her insights on HIPAA risk management and compliance frequently appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.  You can get more information about her HIPAA and other experience here.

In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns. 

Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit  and management policies and practices.   Ms. Stamer often has worked, extensively on these and other workforce and performance related matters.  In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally.  A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad.  She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. 

For help  with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here

About Solutions Law Press, Inc.

Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:

©2013 Cynthia Marcotte Stamer, P.C.  Non-exclusive license to republish granted to Solutions Law Press, Inc.™  All other rights reserved.


New OCR HIPAA De-Identification Guidance Among Developments Covered In 12/12 HIPAA Update Web Workshop

November 27, 2012

Get Up To Date On Details of New De-Identification Guidance & Other HIPAA Developments By Participating In 12/12 HIPAA Update Web Workshop

Health care providers, health plans, health care clearinghouses (covered entities) and their business associates and leadership should check and update their policies and practices for the de-identification of protected health information (PHI) in light of newly-released Guidance Regarding Methods for De-identification of Protected Health Information in Accordance With the Health Insurance Portability and Accountablity Act (HIPAA) Privacy Rule (Guidance) released by the Department of Health & Human Services (HHS) Office of Civil Rights yesterday (November 26, 2012). 

Solutions Law Press, Inc. will host a one-hour, online HIPAA Update Workshop on the Guidance and other recent regulatory and enforcement developments under HIPAA for covered entities and their business associates on Wednesday, December 12 beginning at Noon Central Time. To register, see here.

PHI collected by health care providers, health plans, their management, sponsors, and vendors often includes a wealth of information valuable for use for functions unrelated to the HIPAA-covered functions and activities that leads covered entities or their business associates to collect or keep this data.  While it might be tempting to repurpose this information for business planning and marketing purposes, covered entities and their business partners or associates frequently assume that covered entities and others that they deal with must take proper steps to that no PHI is used, accessed, disclosed or shared unless that action is allowed under the Privacy Rules, properly de-identified, or both.

When planning to rely upon the de-identification of PHI to engage in these activities,  parties planning to rely upon HIPAA’s exception for de-identified PHI will want to consult new guidance just released by OCR about the de-identification requirements before moving forward. Existing Privacy Rules and the Guidance recognize two alternative methods that covered entities and their business can use to properly de-identify PHI for purposes of the HIPAA Privacy Rule.

OCR published the Guidance to help covered entities to understand what qualifies as de-identification, the general process by which de-identified information is created, and the options available for performing de-identification for purposes of the HIPAA Privacy Rule.  The publication of this guidance was mandated as part of amendments to HIPAA enacted by Health Information Technology for Economic and Clinical Health (HITECH) Act included in the American Recovery and Reinvestment Act of 2009 (ARRA).  Section 13424(c) of the HITECH Act requires the HHS to issue guidance on how best to implement the requirements for the de-identification of health information contained in the Privacy Rule.  

De-identification & Its Rationale Under Privacy Rule

The Privacy Rule was designed to protect individually identifiable health information through permitting only certain uses and disclosures of PHI provided by the Rule, or as authorized by the individual subject of the information.  However, in recognition of the potential utility of health information even when it is not individually identifiable, §164.502(d) of the Privacy Rule permits a covered entity or its business associate to create information that is not individually identifiable by following the de-identification standard and implementation specifications in Privacy Rule §164.514(a)-(b).  These provisions allow the entity to use and disclose information that neither identifies nor provides a reasonable basis to identify an individual provided the Covered Entity can show that the PHI has been de-identified in accordance with either the Expert Determination Method or the Safe Harbor Method of the de-identification standard of the Privacy Rule and is not re-identified.  Regardless of the method used to de-identify PHI, the Privacy Rule does not restrict the use or disclosure of de-identified health information, as it is no longer considered PHI and is not re-identified.

Privacy Rule De-Identification Implementation Standards Permit Alternative Methods of De-identification

Section 164.514(a) of the HIPAA Privacy Rule provides the standard for de-identification of protected health information.  Under this standard, health information is not individually identifiable if it does not identify an individual and if the covered entity has no reasonable basis to believe it can be used to identify an individual. See Privacy Rule § 164.514.

Sections 164.514(b) and (c) of the Privacy Rule contain the implementation specifications that a covered entity must follow to meet the de-identification standard. As summarized in Figure 1, the Privacy Rule provides two methods by which health information can be designated as de-identified:

  • The formal determination by a qualified expert in accordance with the Privacy Rule (Expert Determination Method); or
  • The removal of specified individual identifiers as well as absence of actual knowledge by the covered entity that the remaining information could be used alone or in combination with other information to identify the individual (Safe Harbor Method).

In order for PHI to qualify as de-identified under the “Expert Determination Method, Privacy Rule § 164.514(b)(1) requires that a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable:

  • Applying such principles and methods, determines that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual who is a subject of the information; and
  • Documents the methods and results of the analysis that justify such determination.

Alternatively, Privacy Rule § 164.514(b)(2) provides that PHI will qualify as de-identified under the Safe Harbor Method if:

  • All of an extensive list of identifiers of the individual or of relatives, employers, or household members of the individual, are removed from the data; and
  • The covered entity does not have actual knowledge that the information could be used alone or in combination with other information to identify an individual who is a subject of the information.

As long as the data is not re-identified, the Guidance indicates that a covered entity may prove fulfillment of the de-identification standard of Privacy Rule §164.514(a) by showing satisfaction of all applicable requirements of either method.  Under the Privacy Rule, de-identified health information created following these methods is no longer protected by the Privacy Rule because it does not fall within the definition of PHI.  Of course, de-identification leads to information loss which may limit the usefulness of the resulting health information in certain circumstances. Consequently, covered entities may wish to select de-identification strategies that minimize such loss.

Both alternatives for de-identification under the Privacy Rule require that covered entities and their business associates decide whether and how to keep the option for re-identification of PHI slated for de-identification and where applicable, appropriately manage the re-identification opportunity and data to avoid violation of the Privacy Rule.

According to the Privacy Rule, if a covered entity or business associate successfully undertook an effort to identify the subject of de-identified information it maintained, the health information now related to a specific individual would again be protected by the Privacy Rule, as it would meet the definition of PHI.  Disclosure of a code or other means of record identification designed to enable coded or otherwise de-identified information to be re-identified is also considered a disclosure of PHI.  In this regard, Privacy Rule §164.514(c) specifies that if the covered entity assigns a code or other means of  record identification to allow information de-identified under this section to be re-identified by the covered entity, themeans of record identification is not derived from or related to information about the individual and is not otherwise capable of being translated so as to identify the individual; it can’t use elements of the protected PHI as the re-identification key,must safeguard the key, and can’t use or disclose the key or other re-identification tool for any other purpose.

Preparing For, Guiding & Documenting The De-identification Process For Defensibility

The Guidance stresses that importance of documentation for which values in health data correspond to PHI, as well as the systems that manage PHI and its risk of identification or re-identification in the de-identification process cannot be overstated. 

The Guidance provides guidance to help guide covered entities and their business associates through the steps and analysis of using the Expert Determination versus Safe Harbor Method.  A review of this Guidance makes clear that the design and administration of the de-identification process under either method requires careful and well-documented planning, analysis and implementation to fulfill and to keep the documentation that a covered entity or business associate might need to defend its decision to treat and use PHI as de-identified under the Privacy Rule against a potential audit or enforcement inquiry.  The Guidance also seeks to further illuminate the requirements for effective de-identification  through a series of questions and answers, supplemented by work flow and other charts, examples and other illustrations and tips on the proper use of each alternative Method and managing risks and the process associated with that Method. A Glossary of Terms also is shared.  The discussion in the Guidance makes clear that covered entities and their businesses associates using either Method to de-identify PHI should be prepared to make a number of judgments about which Method to use, whether and how to make arrangements for re-identification, and how to properly manage the process to meet the requirements of the implementation standard and manage re-identification or other risks.

Register For 12/12 HIPAA Update Web Workshop To Catch Up On De-Identification Guidance & Other HIPAA & Texas HIPAA Regulatory & Enforcement Developments

Training and compliance mandates applicable to covered entities and their business associates under the newly strengthened Texas HIPAA law and HIPAA’s Privacy and Breach Notification Rules make it more  important than ever that covered entities and their business associates get the timely training and other assistance needed  to properly comply with requirements for the protection of PHI under the new Guidance and other HIPAA and Texas  HIPAA mandates. 

To aid in this process,  Solutions Law Press, Inc. will host a  2012 HIPAA Update Web Workshop covering the new Guidance on de-identification and other regulatory and enforcement developments under HIPAA and the newly amended Texas HIPAA law on December 12, 2012 from 1:00 P.M.-2:00 P.M. Eastern | Noon – 1:00 P.M. Central | 11:00 A.M-Noon Mountain | 10:00A.M-11:00 A.M. Pacific Time.

Expanded health care privacy mandates of the Texas Medical Records Privacy Act that take effect September 1, 2012 and HIPAA regulations require covered entities and their business associates conduct training and take other steps to protect the privacy and security of PHI.

Complete HIPAA Training While You Catch Up On The Latest On HIPAA & Texas Medical Records Privacy Rules & Get Helpful Compliance And Risk Management Tips!

Health care providers, health plans, health care clearinghouses face new imperatives to strengthen their HIPAA and other procedures for handling protected health information and other sensitive information to manage expanding risks and responsibilities arising from evolving rules, expanding enforcement and oversight, and rising penalties and other liabilities. 

Expanded health care privacy mandates of the Texas Medical Records Privacy Act that take effect September 1, 2012 and HIPAA regulations require covered entities and their business associates conduct training and take other steps to protect the privacy and security of personal health information (PHI) and certain other information.

The $4.3 million HIPAA Civil Monetary Penalty and growing list of $1 million plus resolution payments announced by the Office of Civil Rights coupled with its commitment to investigate all large breaches reported under the HITECH Act Breach Notification Rule and other stepped up enforcement and newly initiated audit activities send a clear signal that HIPAA-covered entities and their business associates face significant exposures for failing to appropriately manage their HIPAA and other responsibilities when handling protected health information.  Meanwhile, Texas House Bill 300 has raised maximum state civil penalties for unlawful disclosures of Protected Health Information under the Texas Medical Records Privacy Act to from $5,000 to $1.5 million per year.  Meanwhile HITECH Act amendments to HIPAA require covered entities provide notification of certain breaches while Texas House Bill 300 adds its own specific requirements to provide notice of certain breaches of computerized data containing sensitive personal information.

With Texas House Bill 300 expanding covered entities responsibilities and liabilities and OCR issuing new regulations and other guidance to implement amendments to the HIPAA Privacy & Security Standards and implement and enforce the HITECH Act Breach Notification Rule, health care providers, health plans and insurers, their brokers, third-party administrators, and other covered entities, as well as their business associates and employer and union clients must review and tighten their policies, practices, business associate and other contracts, and enforcement to manage HIPAA and other compliance and manage risks arising from the access, collection, use, protection and disclosure of PHI to meet expanding mandates and to guard against growing liability exposures under HIPAA and other federal and state laws. 

Solutions Law Press, Inc. invites you to catch up on the latest on these and other key HIPAA requirements and enforcement and learn tips for managing risks and liabilities by participating in the “HIPAA Update Workshop” on Wednesday, December 12, 2012 via WebEx for a registration fee of $125.00. 

Pre-approved for various types of continuing and professional education credit, the December 12, 2012 HIPAA Update Workshop will brief participants on the De-Identification Guidance as well as the latest on other regulatory and enforcement guidance under the HIPAA Privacy, Security and Breach Notification rules and guidance and share compliance and risk management lessons emerging from recent OCR enforcement and audit activities and other selected federal and state litigation and enforcement actions impacting the handling of protected health information.  Among other things, the workshop will cover:

  • The De-Identification Guidance just released by OCR on November 26, 2012;
  • The latest HIPAA Privacy, Security & Breach Notification Guidance, Audits & Enforcement
  • Highlights Texas House Bill’s Amendments To Texas Medical Records Privacy Law That Took Effect September 1, 2012
  • Post HITECH Act Heightened Liability Risks:  Audits, Civil Penalties, Criminal Penalties & State Lawsuits
  • Expansion of HIPAA Responsibilities & Liabilities To Business Associates & What Covered Entities & Business Associates Should Do In Response
  • HIPAA Data Breach Notification Requirements
  • Practical Challenges & Strategies For Managing These Responsibilities
  • Tips For Coordinating HIPAA & Other Federal & State Medical Privacy, Financial Information, Identity Theft & Date Security Compliance and Risk Management
  • Practical Strategies For Monitoring & Responding To New Requirements & Changing Rules
  • Participant Questions

About The Speaker

The workshop will be conducted by attorney Cynthia Marcotte Stamer.  A Fellow in the American College of Employee Benefits Counsel, recognized in International Who’s Who, North Texas Health Care Compliance Professionals Association Vice-President and Board Certified in Labor & Employment Law, attorney  Cynthia Marcotte Stamer has 25 years experience advising and representing private and public health care providers, employers, employer and union plan sponsors, employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental leaders and others on privacy and data security, health care, health and other employee benefit. employment, insurance and related matters. A well-known and prolific author and popular speaker, Ms. Stamer has worked extensively with heath care providers, health plans and other payers, health and insurance IT and data systems, and others on HIPAA and other privacy and data security concerns.  She served as the scrivener for the ABA JCEB Agency Meetings with the Office of Civil Rights on HIPAA Privacy for the past two years.  She presently serves as Co-Chair of the ABA RPTE Section Welfare Plan Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Representative, an Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com) and Employee Benefit News, and various other publications.  A primary drafter of the Bolivian Social Security privatization law with extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on public policy and regulatory advocacy on HIPAA and other privacy and data security risks and requirements as well as a broad range of other health,  employee benefits, human resources, insurance, tax, compliance and other matters and representing clients in dealings with OCR and other HHS agencies, as well as the Departments of Labor, Treasury, Federal Trade Commission, HUD and Justice, Congress and state legislatures, and various state attorneys general, insurance, labor, worker’s compensation, medical licensure and disciplinary and other agencies and regulators. A prolific author and popular speaker, Ms. Stamer regularly authors materials and conducts workshops and professional, management and other training on HIPAA and other privacy, health care, employee benefits, human resources, insurance and related topics for the ABA, Aspen Publishers, the Bureau of National Affairs (BNA), SHRM, World At Work, Government Institutes, Inc., the Society of Professional Benefits Administrators and many other organizations. Her insights on privacy and other matters are quoted in Modern Healthcare, HealthLeaders, Benefits, Caring for the Elderly, The Wall Street Journal and many other publications.  She also regularly serves on the faculty and planning committees of a multitude of symposium and other educational programs.  For more details about Ms. Stamer’s services, experience, presentations, publications, and other credentials or to ask about arranging counseling, training or presentations or other services by Ms. Stamer, see www.CynthiaStamer.com.

Registration

The Registration Fee is $125.00 per person.  Registration Fee Discounts available for groups of three or more. Pre-payment required via website registration required via website PayPal.  No checks or cash accepted.  Persons not registered at least 48 hours in advance will only participate subject to system and space availability.

 Continuing Education Credit

The HIPAA Update Workshop is approved to be offered for general certification credit by the State Bar of  Texas, Texas Department of Insurance, HRCI and WorldAtWork education credit  for the time period offered subject to fulfillment all applicable accrediting agency requirements, completion of required procedures.  Note that the applicable credentialing agency retain the final authority to determine whether an individual qualifies to receive requested continuing education credit.  Neither Solutions Law Press, Inc., the speaker or any of their related parties guarantees the approval of credit for any individual or has any liability for any denial of credit.  Special fees or other conditions may apply.  CANCELLATION   & REFUND POLICY:  In order to receive credit, cancellation (either fax or mail) must be received at least 48 hours in advance of the meeting and are subject to a $10.00 refund processing fee.  Refunds will be made within 60 days of receipt of written cancellation notice.

About Solutions Law Press, Inc.™

Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives.  Solutions Law Press, Inc.™ also conducts and assist businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs.  For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com   These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship,  to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com.  If you would prefer not to receive communications from Solutions Law Press, Inc. send an e-mail with “Solutions Law Press Unsubscribe” in the Subject to support@solutionslawyer.net.  CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN. If you are an individual with a disability who requires accommodation to participate, please let us know at the time of your registration so that we may consider your request.

©2012 Solutions Law Press, Inc. All Rights Reserved.


Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness

October 1, 2012

President Obama’s declaration today (October 1, 2012) of October as National Disability Employment Awareness Month reminds business that U.S. businesses and their leaders need to tighten their disability discrimination risk management and compliance in light of the Obama Administration’s emphasis on aggressively interpreting and enforcing disability discrimination laws, rising private plaintiff lawsuits and other recent regulatory and judicial changes.  With the Administration expected to step up further its already substantial educational outreach to the disabled and their advocates, U.S. employers should brace for this month’s celebration to fuel even more disability discrimination claims and other activity by the disabled and their activists.

Since taking office, President Obama has make enforcing and expanding the rights of the disabled in employment and other areas a leading priority. 

In his proclamation today, President Obama reaffirmed his often stated commitment to the aggressive enforcement of disability laws and other efforts to promote opportunities for disabled individuals, stating:

“[My Administration remains committed to helping our businesses, schools, and communities support our entire workforce. To meet this challenge,… we are striving to make it easier to get and keep those jobs by improving compliance with Section 508 of the Rehabilitation Act.”

As the administration marks the month, U.S. employers and other business leaders can expect the Obama Administration will be stepping up its already aggressive outreach to disabled Americans to promote awareness of their disability law rights and tools for asserting and enforcing these rights.  See, e.g. October Is National Disability Employment Awareness Month (NDEAM).

Business Faces Growing Employment Disability Exposures

As part of his administration’s commitment, the Obama Administration has moved to aggressively enforce the disability and accommodations of the Americans With Disabilities Act (ADA), Section 508 of the Rehabilitation Act, and other federal disability discrimination laws.  The reach and effectiveness of these efforts has been enhanced by statutory and regulatory changes that require employers to exercise greater efforts to meet their compliance obligations and manage their disability and other discrimination risks.

ADA Exposures Heightened

The ADA, for instance, generally prohibits disability discrimination and requires employers to make reasonable accommodations to employees’ and applicants’ disabilities as long as this does not pose an undue hardship.  Violations of the ADA can expose businesses to substantial liability. Violations of the ADA may be prosecuted by the EEOC or by private lawsuits.  Employees or applicants that can prove they experienced prohibited disability discrimination under the ADA generally can recover actual damages, attorneys’ fees, and up to $300,000 of exemplary damages (depending on the size of the employer).   

In recent years, amendments to the original provisions of the ADA have made it easier for plaintiffs and the EEOC to prove disabled status of an individual.  Businesses should exercise caution to carefully document legitimate business justification for their hiring, promotion and other employment related decisions about these and other individuals who might qualify as disabled.  Provisions of the ADA Amendments Act (ADAAA) that expand the definition of “disability” under the ADA,  As signed into law on September 25, 2008, the ADAAA amended the definition of “disability” for purposes of the disability discrimination prohibitions of the ADA to make it easier for an individual seeking protection under the ADA to establish that that has a disability within the meaning of the ADA.  The ADAAA retains the ADA’s basic definition of “disability” as an impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment. However, provisions of the ADAAA that took effect January 1, 2009 change the way that these statutory terms should be interpreted in several ways. Most significantly, the Act:

  • Directs EEOC to revise that part of its regulations defining the term “substantially limits;”
  • Expands the definition of “major life activities” by including two non-exhaustive lists: (1) The first list includes many activities that the EEOC has recognized (e.g., walking) as well as activities that EEOC has not specifically recognized (e.g., reading, bending, and communicating); and (2) The second list includes major bodily functions (e.g., “functions of the immune system, normal cell growth, digestive, bowel, bladder, neurological, brain, respiratory, circulatory, endocrine, and reproductive functions”);
  • States that mitigating measures other than “ordinary eyeglasses or contact lenses” shall not be considered in assessing whether an individual has a disability;
  • Clarifies that an impairment that is episodic or in remission is a disability if it would substantially limit a major life activity when active;
  • Changes the definition of “regarded as” so that it no longer requires a showing that the employer perceived the individual to be substantially limited in a major life activity, and instead says that an applicant or employee is “regarded as” disabled if he or she is subject to an action prohibited by the ADA (e.g., failure to hire or termination) based on an impairment that is not transitory and minor; and
  • Provides that individuals covered only under the “regarded as” prong are not entitled to reasonable accommodation.

The ADAAA also emphasizes that the definition of disability should be construed in favor of broad coverage of individuals to the maximum extent permitted by the terms of the ADA and generally shall not require extensive analysis.In adopting these changes, Congress expressly sought to overrule existing employer-friendly judicial precedent construing the current provisions of the ADA and to require the EEOC to update its existing guidance to confirm with the ADAAA Amendments.  Under the leadership of the Obama Administration, the EEOC and other federal agencies have embraced this charge and have significantly stepped up enforcement of the ADA and other federal discrimination laws.

Recent enforcement, regulatory and other activities by the EEOC show that the EEOC is enthusiastically moving forward to exercise its regulatory and enforcement powers under these enhanced ADA provisions to tighten requirements for employers and to enforce its rules. See e.g.,  Leprino Foods To Pay $550K To Settle OFCCP Charge Pre-Hire Screening Test Illegally Discriminated « As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released; Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries; Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s.

Rising Rehabilitation Act Risks For Government Contractors

Beyond the generally applicable risks applicable to all employers of more than 15 employees under the ADA, federal and state government contractors face more responsibilities and risks. 

Subject to limited exceptions, government contractors providing services or supplies on ARRA or other government-funded contracts or projects must comply both with generally applicable employment discrimination requirements and special statutory and contractual nondiscrimination, affirmative action, and recordkeeping requirements applicable government contractors. For instance, federal law generally requires government contractors to comply with the special equal employment opportunity requirements of  Executive Order 11246 (EO 11246); Section 503 of the Rehabilitation Act of 1973 (Section 503); and the Vietnam Veterans’ Readjustment Assistance Act of 1974 (VEVRAA).   Pursuant to these laws, business with the federal government, both contractors and subcontractors, generally must follow a number of statutory and contractual requirements to follow the fair and reasonable standard that they not discriminate in employment on the basis of sex, race, color, religion, national origin, disability or status as a protected veteran. OFCCP generally audits and enforces these requirements. Memo to Funding Recipients: Compliance with Applicable Nondiscrimination and Equal Opportunity Statutes, Regulations, and Executive Orders.  

OFCCP has made clear that it will conduct compliance evaluations and host compliance assistance events to ensure that federal contractors comply and are aware of their responsibilities under EO 11246, Section 503 and VEVRAA. 

While many government contractors may be tempted to become complacent about OFCCP exposures based on reports of the OFCCP’s relatively low enforcement in the past, see Report Says OFCCP Enforcement Data Show Infrequent Veteran, Disability Bias Findings | Bloomberg BNA recent enforcement data documents OFCCP is getting much more serious and aggressive about auditing and enforcing compliance with its affirmative action and other requirements against government contractors under the Obama Administration.  See, OFCCP Enforcement Data is Available on a New DOL Website. See also, Affirmative Action Update: OFCCP Enforcement Statistics Show Increase in Violations.  The readiness of OFCCP to enforce its rules is illustrated by the settlement of an OFCCP action filed against federal contractor Nash Finch Co. (Nash Finch) announceed last week.  Under the settlement, Nash Finch to pay $188,500 in back wages and interest and offer jobs to certain women applicants who OFCCP charged Nash rejected for the entry-level position of order selector at the company’s distribution facility in Lumberton, Minnesota.  See Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks.

These government contractor disability discrimination risks are particularly acute where the government contractor works on or provides supplies on contacts or projects funded in whole or in part by monies provided under ARRA.    When the contract or project in question receives any funding out of the $787 billion of stimulus funding provided by ARRA, special OFCCP rules applicable to ARRA funded projects necessitates that federal contractors exercise special care to understand and meet their responsibilities and manage associated exposures.   See, e.g. Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks

GINA & Other Medical Information Nondiscrimination & Privacy Risks

Employers also need to use care to ensure that their hiring and other employment practices, as well as their employee benefits, workers’ compensation and wellness practices are up to date and properly managed to mitigate exposures under laws like the Genetic Information and Nondiscrimination Act (GINA),  the ADA’s medical information privacy requirements,  as well as the privacy and nondiscrimination rules of the Health Insurance Portability & Accountability Act and other relevant federal and state laws.

Signed into law by President Bush on May 21, 2008 and in effect since November 21, 2009, for instance, Title VII of GINA amended the Civil Rights Act to prohibit employment discrimination based on genetic information and to restrict the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like now available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws.  For instance, GINA’s employment related provisions include rules that:

  • Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
  • Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
  • Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
  • Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
  • Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
  • Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
  • Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
  • Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.

These employment provisions of GINA are in addition to amendments to HIPAA, the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009.  Under these HIPAA and GINA rules, health plans generally may not make certain medical inquiries or discriminate against employees or their family members based on family or individual medical history or genetic information.  In addition, health plans and others are required to safeguard personal medical information and may only share that information only under very limited circumstances requiring specific documentation be in place and that the parties can prove that the access and use of that information is appropriately restricted.  Violation of these and other rules can have significant civil and in some cases even criminal liabilities for companies, plans, plan fiduciaries and company officials that take part in violations of these rules.

Businesses Should Act To Manage Risks

The ADAAA amendments, the Rehabilitation Act’s expanded reach, and the Obama Administration’s emphasis on enforcement make it likely that businesses generally will face more disability claims from a broader range of employees and will have fewer legal shields to defend themselves against these claims. These changes will make it easier for certain employees to qualify and claim protection as disabled under the ADA, the Rehabilitation Act, and other disability discrimination laws. 

All U.S. businesses should review and tighten the adequacy of their existing compliance and risk management practices to promote and document compliance.  These efforts should focus on all relevant hiring, recruitment, promotion, compensation, recordkeeping and reporting policies and practices internally, as well as those of any recruiting agencies, subcontractors or other business partners whose actions might impact on compliance.

In light of these and other developments and risks, businesses generally should act cautiously when dealing with applicants or employees with actual, perceived, or claimed physical or mental impairments to minimize exposures under the ADA, the Rehabilitation Act and other laws.  Management should exercise caution to carefully and appropriately assess and identify the potential legal significance of physical or mental impairments or conditions that might be less significant in severity or scope, correctable through the use of eyeglasses, hearing aids, daily medications or other adaptive devices, or that management might be tempted to assume fall outside the ADA’s scope.  

Likewise, businesses should be ready for the EEOC, OFCCP and the courts to treat a broader range of disabilities, including those much more limited in severity and life activity restriction, to qualify as disabling for purposes of the Act. Businesses should assume that a greater number of employees with such conditions are likely to seek to use the ADA as a basis for challenging hiring, promotion and other employment decisions.  For this reason, businesses generally should tighten job performance and other employment recordkeeping to enhance their ability to demonstrate nondiscriminatory business justifications for the employment decisions made by the businesses.

Businesses also should consider tightening their documentation regarding their procedures and processes governing the  collection and handling records and communications that may contain information regarding an applicant’s physical or mental impairment, such as medical absences, worker’s compensation claims, emergency information, or other records containing health status or condition related information.  The ADA generally requires that these records be maintained in separate confidential files and disclosed only to individuals with a need to know under circumstances allowed by the ADA. 

As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under  the genetic information nondiscrimination and privacy rules enacted as part of GINA, the health care privacy rules of the HIPAA, and the medical record privacy rules of the ADA.  Particular care should be used when planning wellness, health risk assessment, work-related injury, family or other medical leave or related programs, all of which raise particular risks and concerns.

In the face of the rising emphasis of OFCCP, the EEOC and other federal and state agencies on these audit and enforcement activities, government contractors should exercise additional compliance and risk management efforts beyond these generally recommended steps.   Among other things, these steps should include the following:

  • Government contractors and subcontractors should specifically review their existing or proposed contracts and involvements to identify projects or contracts which may involve federal or state contracts or funding that could trigger responsibility.  In this respect, businesses should conduct well-documented inquiries when proposing and accepting contracts to ensure that potential obligations as a government contractor are not overlooked because of inadequate intake procedures. Businesses also should keep in mind that ARRA and other federal program funds often may be filtered through a complex maze of federal grants or program funding to states or other organizations, which may pass along government contractor status and liability when subcontracting for services as part of the implementation of broader programs.  Since the existence of these obligations often is signaled by contractual representations in the contracts with these parties, careful review of contractual or bid specifications and commitments is essential.  However, it also generally is advisable also to inquire about whether the requested products or services are provided pursuant to programs or contracts subject to these requirements early in the process. 
  • In addition to working to identify contracts and arrangements that are covered by OFCCP or other requirements, government contractors and other businesses also should reconfirm and continuously monitor the specific reporting, affirmative action, and other requirements that apply to any programs that may be subject to OFCCP requirements to ensure that they fully understand and implement appropriate procedures to comply with these conditions as well as pass along  the obligation to make similarly necessary arrangements to any subcontractors or suppliers that the government contractor involves as a subcontractor. 
  • Throughout the course of the contract, the government contractor also should take steps to maintain and file all required reports and monitor and audit operational compliance with these and other requirements.  
  • The organization should develop and administer appropriate procedures for monitoring and investigating potential compliance concerns and maintaining documentation of that activity.  Any known potential deficiencies or complaints should be promptly investigated and redressed with the assistance of qualified counsel in a prompt manner to mitigate potential risks.
  • Documentation should be carefully retained and organized on a real time and continuous basis to faciliate efficiency and effectiveness in completing required reports, monitoring compliance indicators and responding to OFCCP, EEOC or private plaintiff charges as well as other compliance inquiries.
  • Any audit inquiries or charges should be promptly referred to qualified legal counsel for timely evaluation and response.
  • When available and affordable, management should consider securing appropriate employment practices liability coverage, indemnification from business partners and other liability protection and assurance to help mitigate investigagtion and defense costs.
  • Board members or other senior management should include periodic review of compliance in their agenda.

If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the Rehabilitation Act, ADA, GINA or other applicable laws, or if we may be of help with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Board Certified Labor and Employment Attorney and Management Consultant Cynthia Marcotte Stamer at 469.767.8872.

About The Author

Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to meet their business and operational goals and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 25 years human resource, employee benefits and management experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters.  Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail here.

Other Helpful Resources & Other Information

If you found these updates of interest, you also be interested in one or more of the following other recent articles published in this electronic Solutions Law publication available for review here including:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@solutionslawyer.net.

©2012 Cynthia Marcotte Stamer.  Non-exclusive right to republish granted to Solutions Law Press, Inc.  All other  rights reserved. 


12 Steps Every Employer With A Health Plan Should Do Now To Manage 2012-14 Health Plan Risks & Liabilities

August 1, 2012

August 1 marked the effective date of yet another Affordable Care Act mandate:  the controversial contraceptive coverage and other women’s health preventive coverage benefits mandates.  Although many mandates have taken effect over the past two years, few employer plans are adequately updated.  Here’s some suggestions about what employers and fiduciaries responsible for group health plan sponsorship or administration and their vendors should do now to manage exposures arising from current Affordable Care Act and other federal health plan rules.  Following the Supreme Court’s June 28, 2012 National Federation of Independent Business v. Sebelius ruling, most employers and insurers of employment based group health plans now are bracing to cope with radical changes in their health plan related responsibilities scheduled to take effect in 2014. 

While anticipating and preparing to cope with these future changes health plan sponsors, fiduciaries, administrators and advisors need to manage the substantial and growing health plan related costs and liabilities that the sponsorship or administration of an employee health plan between now and 2014 is likely to create for their company and its management.  Consequently, while planning for 2014, employers sponsoring health plans and their management, insurers, administrators and vendors must act now to update and administer their group health plans timely to comply with the requirements of the Affordable Care Act and other federal rules that have, or in coming months will, take effect pending the law’s full rollout in 2014. 

For most health plans, these steps should include the following:

  1. Know The Cast Of Characters & What Hat(s) (Including You) They Wear & Prudently Select, Contract With & Monitor Them To Manage Risks

Employers and their management rely upon many vendors and advisors and assumptions when making plan design and risk management decisions.  Many times, employer and members of their management unknowingly assume significant risk because of misperceptions about these allocations of duties and operational and legal accountability.   An correct understanding of these roles and responsibilities is the foundation for knowing where the risks come from, who and to what extent a business or its management can rely upon a vendor or advisor to properly design and administer a health plan or carry out related obligations, what risks cannot be delegated, and how to manage these risks.

Under the Employee Retirement Income Security Act (ERISA), party or parties that exercise discretion or control over health plan administration, funds or certain other matters are generally called “fiduciaries.” Fiduciaries generally are personally liable for prudently and appropriately administering their health plan related responsibilities prudently in accordance with ERISA and other applicable laws and the plan terms.  Knowing who is acting as a fiduciary and understanding those duties and liabilities and how to manage these risks significantly affects the exposure that an employer or member of its management risks as a result of an employer’s sponsorship in a group health plan or other employee benefit program.  Also, knowing what duties come first and how to prove that the fiduciary did the right thing is critical to managing risks when an individual who has fiduciary responsibilities under ERISA also has other responsibilities in the management of the sponsoring employer, a vendor or elsewhere that carries duties or interests that conflict with his health plan related fiduciary duties.

The plan sponsor or members of its leadership, a service provider or members of their staff generally may be a fiduciary for purposes of ERISA if it either is named as the fiduciary, it functionally exercises the discretion to be considered a fiduciary, or it otherwise has discretionary power over plan administration or other fiduciary matters.  Many plan sponsors and their management unwittingly take on liability that they assume rests with an insurer or service provider because the company or members of its management are named as the plan administrator or named fiduciary with regard to duties that the company has hired an insurer or service provider to provide or allowed that service provider to disclaim fiduciary or discretionary status with regard to those responsibilities.  Also, by not knowing who the fiduciaries are, plans and their fiduciaries often fail to confirm the eligibility of all parties serving as fiduciaries, to arrange for bonding of service providers or fiduciaries as required to comply with Title I of ERISA.   Failing to properly understand when the plan sponsor, member of its management or another party is or could be a fiduciary can create unnecessary and unexpected risks and lead to reliance upon vendors who provide advice but leave the employer holding the bag for resulting liability.

In addition to fiduciary status, employer and other plan sponsors also need to understand the additional responsibilities and exposures that the employer bears as a plan sponsor.  Beyond contractual and fiduciary liabilities, federal law increasingly imposes excise tax or other liability for failing to maintain legally compliant plans, file required reports, provide required notifications or fulfill other requirements.   The Affordable Care Act, the Internal Revenue Code, the Social Security Act, the Privacy, Security, and Administrative Simplification For instance, the Health Insurance Portability & Accountability Act (HIPAA) and various other federal laws also impose certain health plan related obligations and liabilities on employer or other health plan sponsors and other parties.  The Internal Revenue Service interprets Internal Revenue Code § 6039D as obligating employers sponsoring health plans that violate these and certain other federal health plan rules to self-identify, self-report, and self-assess and pay excise and other taxes due under the Internal Revenue Code as a result of this non-compliance.   Knowing what everyone’s roles and responsibilities are is a critical first step to properly understanding and managing health plan responsibilities and related risks.

An accurate understanding of the risks and who bears them is critical to understand the risks, opportunities to mitigate risk through effective contracting or other outsourcing, when outsourcing does not effectively transfer risks, where to invest resources for contract, plan or process review and changes or other risk management, and where to expect costs and risks and implement processes and procedures to deal with risks that cannot be outsourced or managed.

  1. Know What Rules Apply To Your Plan, The Sponsoring Employer, The Plan Its Fiduciaries & Plan Related  Vendors & How This Impacts You & Your Group Health Plan

The requirements and rules impacting health plans and their liabilities have undergone continuous changes.  Amid these changing requirements, health plans, their sponsors, fiduciaries, insurers, and service providers often may not have kept their knowledge, much less their plan documents, summary plan descriptions and other communications, administrative forms and procedures and other materials and practices up to date. These requirements and their compliance and risk management significance may vary depending upon whether the reviewing or regulated party is the plan, its sponsor, fiduciary, insurer or services in some other rules; how the plans are arranged and documented, the risk and indemnification allocations negotiated among the parties, the risk tolerance of the party, and other factors.  Proper understanding of these rules and their implications is critical to understand and manage the applicable risks and exposures.

  1. Review & Update Health Plan Documents, SPDs & Other Communications, Administrative Forms & Procedures, Contracts & Processes To Meet Requirements & Manage Exposures

Timely updating written plan documents, communications and administration forms, administrative practices, contracts and other health plan related materials processes and procedures has never been more critical. 

Federal law generally requires that health plan be established, maintained and administered in accordance with legally complaint, written plan documents and impose a growing list of standards and requirements governing the design and administration of these programs. In addition, ERISA, the Internal Revenue Code, the Social Security Act, federal eligibility and coverage continuation mandates of laws like the Consolidated Omnibus Budget Reconciliation Act (COBRA), the Health Insurance Portability & Accountability Act, the Family & Medical Leave Act, Michelle’s Law and others require that health plan administrators or sponsors communicate plan terms and other relevant information to participants and beneficiaries.

Failing to update documents, communications, administrative forms and processes and other materials and practices can unleash a host of exposures. Among other things, noncompliant plans, communications and practices can trigger unanticipated costs and liabilities by undermining the ability to administer plan terms and conditions.  They also may expose the plan, plan fiduciaries and others to lawsuits, administrative enforcement and sanctions and other enforcement liabilities. 

Beyond these exposures, employers who sponsor group health plans that violate certain federal group health plan mandates have a duty to self-report certain regulatory plan failures and pay excise taxes where such failures are not corrected in a timely fashion once discovered, or are due to willful neglect. Internal Revenue Code Section 6039D imposes excise taxes for failure to comply with health care continuation (COBRA) , health plan portability (HIPAA), genetic nondiscrimination (GINA), mental health parity (MHPAEA) , minimum hospital stays for newborns and mothers (Newborns’ and Mothers’ Health Protection Act), coverage of dependent students on medically necessary leaves of absence (Michelle’s Law), health savings account (HSA) and Archer medical savings account (Archer MSA) contribution comparability and various other federal requirements incorporated into the Internal Revenue Code.   Since 2010, Internal Revenue Service regulations have required employers sponsoring group health plans not complying with mandates covered by Internal Revenue Code Section 6039D to self-report violations and pay related excise taxes.  Under these regulations, the sponsoring employer (or in some cases, the insurer, HMO or third-party administrator) must report health plan compliance failures annually on IRS Form 8928 (“Return of Certain Excise Taxes Under Chapter 43 of the Internal Revenue Code”) and self-assess and pay resulting excise taxes.  The potential excise tax liability that can result under these provisions can be significant.  For example, COBRA, HIPAA, and GINA violations typically carry excise tax liability of $100 per day per individual affected. Compliance with applicable federal group health plan mandates is critical to avoid these excise taxes as well as other federal group health plan liabilities.

For this purpose of deciding what and how much to do, it is critical to keep in mind the devil is in the details.  Not only must the documentation meet all technical mandates, the language, its clarity and specificity, and getting the plan document to match the actual processes that will be used to administer the plan and ensuring that the plan documents and processes match the summary plan description, summary of benefits and coverage, administrative forms and documentation and other plan communications and documentation in a legally compliant way significantly impacts the defensibility of the plan terms and the cost that the plan, its sponsor and fiduciaries can expect to incur to defend it.

  1. Update & Tighten Claims and Appeals Plan & SPD Language, EOBs & Other Notifications, Processes, Contracts & Other Practices For Changing Compliance Requirements & Enhanced Defensibility

Proper health plan claims and appeals plan and summary plan description language, procedures, processing, notification and documentation is critical to maintain defensible claims and appeals decisions required to enforce plan terms and manage claims denial related liabilities and defense costs.  Noncompliance with these requirements may prevent health plans from defending their claims or appeals denials, expose the plan administrator and plan fiduciaries involved or responsible for these activities to penalties, prompt unnecessary lawsuits, Labor Department enforcement or both; and drive up plan administration costs.

Unfortunately, most group health plans, their insurers and administrators need to substantially strengthen their plan documentation; handling; timeliness; notifications and other claims denials; and other claims and other appeals processes and documentation to meet existing regulations and otherwise strengthen their defensibility.  Among other things, existing court decisions document that many plans existing plan documents, summary plan descriptions and explanations of benefits, claims and appeals investigations and documentation and notifications often need improvement to meet the basic plan document, summary plan description and reasonable claims rules of the plan document, summary plan description, fiduciary responsibility, reasonable claims and appeals procedures of ERISA and its implementing regulations.  Court precedent shows that inadequate drafting of these provisions, as well as specific provisions coverage and benefit provisions frequently undermines the defensibility of claims and appeals determinations. In addition to requiring that claims be processed and paid prudently in accordance with the terms of written plan documents, ERISA also requirements that plan fiduciaries decide and administer claims and appeals in accordance with reasonable claims procedures.  Although the Labor Department updated its regulations implementing this reasonable claims and appeals procedure requirement more than 10 years ago, the Department of Labor updated its ERISA claims and appeals regulations to include detailed health plan claims and appeals requirements, many group health plans, their administrators and insurers still have not updated their health plans, summary plan descriptions, claims and appeals notification, and claims and appeals procedures to comply with these requirements.   The external review and other detailed additional requirements that the Affordable  Care Act dictates that group health plans not grandfathered from its provisions and its provisions holding these non-grandfathered plans strictly liable for deficiencies in their claims and appeals procedures makes the need to address inadequacies even more imperative for those non-grandfathered group health plans.  Inadequate attention to these concerns can force a plan to pay benefits for claims otherwise not covered as well as other defense costs and penalties.

  1. Consistency Matters:  Build Good Plan Design, Documentation & Processes, Then Follow Them.

Defensible health plan administration starts with the building and adopting strong, legally compliant plan terms and processes that are carefully documented and communicated in a prudent, legally compliant way.  The next key is to actually use this investment by conducting plan administration and related operations consistent with the terms and allocated responsibilities to administer the plan in a documented, legally compliant and prudent manner.  Good documentation and design on the front end should minimize ambiguities in the meaning of the plan and who is responsible for doing what when.  With these tools in place, delays and other hiccups that result from confusion about plan terms, how they apply to a particular circumstance or who is responsible for doing what, when should be minimized and much more easily resolved by timely, appropriate action by the proper responsible party.  This facilitation of administration and its consistency can do much to enhance the defensibility of the plan and minimize other plan related risks and costs.

  1. Ensure Correct Party Carefully Communicates About Coverage and Claims in Compliant, Timely, Prudent, Provable Manner

Having the proper party respond to claims and inquiries in a compliant, timely, prudent manner is another key element to managing health plan risk and promoting enforceability.   Ideally, the party appointed to act as the named fiduciary for purposes of carrying out a particular function also should conduct all plan communications regarding that function in terms that makes clear its role and negates responsibility or authority of others.  When an employer or other plan sponsor goes to the trouble to appoint a committee, service provider or other party to serve as the named fiduciary then chooses to communicate about the plan anyway, the Supreme Court in FMC v. Halliday made clear it runs the risk that the plan related communications may be considered discretionary fiduciary conduct for which it may be liable as a functional fiduciary.  Meanwhile, these communications by non-fiduciaries also may create binding obligations upon the plan and its named fiduciaries to the extent made by a plan sponsor or conducted by a staff member or service provider performing responsibilities delegated by the plan fiduciary. Beyond expanding the scope of potential fiduciaries, communications conducted by nonfiduciaries also tend to create defensibility for many other reasons.  For instance, allowing unauthorized parties to perform plan functions may not comport with the plan terms, and are less likely to create and preserve required documentation and follow procedures necessary to promote enforceability.  Also, the communications, decisions and other actions by these non-fiduciary actors also are unlikely to qualify for discretionary review by the courts because grants of discretionary authority, if any in the written plan document to qualify the decisions of the named fiduciary for deferential review by courts typically will not extend to actions by these non-fiduciary parties.  Furthermore, the likelihood that the communication or other activity conducted will not comply with the fiduciary responsibility or other requirements governing the performance of the plan related functions is significantly increased when a plan sponsor, service provider, member of management, or other party not who has not been appointed or accepted the appointment  act as a named fiduciary undertakes to speak or act because that party very likely does not accept or fully appreciate the potential nature of its actions, the fiduciary and other legal rules applicable to the conduct, and the potential implications for the non-fiduciary actor, the plan and its fiduciaries.

  1. Design and Implement Updated, Properly Secured Payroll, Enrollment, Eligibility and Other Data Collection Features To Meet New Requirements and Prepare For Added Affordable Care Act Data Gathering and Reporting Requirements.

Existing and impending Affordable Care Act mandates require that group health plans, their sponsors collect, maintain and administer is exploding. Existing eligibility mandates, for example, already require that plans have access to a broad range of personal indentifying, personal health and a broad range of other sensitive information about employees and dependents who are or may be eligible for coverage under the plan. While employers and their health plans historically have collected and retained the names, place of residence, family relationships, social security number, and other similar information about employees and their dependents, these data collection, retention and reporting requirements have and will continued to expand dramatically in response to evolving legal requirements.  Already, health plans also from time to time need employee earnings, company ownership, employment status, family income, family, medical, military, and school leave information, divorce and child custody, enrollment in Medicare, Medicaid and other coverage and a broad range of other additional information.  Under the Affordable Care Act, these data needs will explode to include a whole new range of information about total family income, availability and enrollment in other coverage, cultural and language affiliations, and many other items.   Collecting, retaining and deploying this information will be critical to meeting existing and new plan administration and reporting requirements.  How this data collection is conducted, shared, safeguarded against misuse or other legally sensitive contact by the employer, service providers, the plan and others will be essential to mitigate exposures to federal employment and other nondiscrimination, HIPAA and other privacy, fiduciary responsibility and other legal risks and obligations.  To the extent that payroll providers, third party administrators or other outside service providers will participate in the collection, retention, or use of this data, time also should be set aside both to conduct due diligence about their suitability, as well as to negotiate the necessary contractual arrangements and safeguards to make their involvement appropriate.  Finally, given the highly sensitive nature of this data, employers, health plans and others that will collect and use this data will need to implement appropriate safeguards to prevent and monitor for improper use, access or disclosure and to conduct the necessary training to suitably protect this data.

  1. Monitor, Assess Implications & Provide Relevant Input to Regulators About Emerging Requirements & Interpretive Guidance Implementing 2014 Affordable Care Act & Other Mandates.

While the Supreme Court’s decision upholds the constitutionality of the Affordable Care Act’s individual mandates, many opportunities to impact its mandates remain. Beyond the highly visible, continuing and often heated debates ranging in Congress and the court of public opinion concerning whether Congress should modify or repeal its provisions, a plethora of regulatory interpretations issued or impending release by the implementing agencies, the Internal Revenue Service, Department of Health & Human Services, Department of Labor and state insurance regulators will significantly impact what requirements and costs employers, insurers, individuals and governments will bear when the law takes effect.  Businesses sponsoring health plans should carefully scrutinize this regulatory guidance and provide meaningful, timely input to Congress, the regulators or both as appropriate to help influence the direction of regulatory or Congressional actions that would materially impact these burdens.

  1. Help Employees & Their Families Build Their Health Care Coping Skills With Training & Supportive Tools

Whether or not your company plans to continue to sponsor employee health coverage after 2014, providing training and tools to help employees and their families strengthen their ability to understand and manage their health, health care needs and benefits can pay big dividends.  Beyond the financial costs to employees and employers of paying to care for a serious illness or injury, productivity also suffers while employees dealing with their own or a family member’s chronic or serious health care condition.  Wellness programs that encourage and support the efforts of employees and their families to stay healthy may be one valuable part of these efforts.  Beyond trying to prevent the need to cope with illness behind wellness programs, however, opportunities to realize big financial, productivity and benefit value recognition rewards also exist in the too often overlooked opportunity to provide training, education and tools that employees and their families need to better understand and self-manage care, benefits, finances and life challenges that commonly arise when dealing with their own or a family member’s illness. Providing education, tools and other resources that can help employees access, organize and effectively use health care and benefit information to manage care and the consequences of illness, their benefits and how to use them, to take part more effectively in care and care decisions, to recognize and self-manage financial, lost-time and other challenges associated with the illness not addressable or covered by health benefit programs, and other practical skills can help reduce lost time and other productivity impacts while helping employees and their families get the most out of the health care dollars spent.

  1. Pack Your Parachute & Locate The Nearest Exit Doors

With the parade of expenses and liabilities associated with health plans, businesses sponsoring health plans and the management, service providers and others involved in their establishment, continuation, maintenance or administration are well advised to pack their survival kit and develop their exit strategies to position to soften the landing in case their health plan experiences a legal or operational disaster. 

Employers and other health plan sponsors and fiduciaries typically hire and rely upon a host of vendors and advisors to design and administer their health plans.  When selecting and hiring these service providers, health plan sponsors and fiduciaries are well-advised to investigate carefully their credentials as well as require the vendors to provide written commitments to stand behind their advice and services.  Too often, while these service providers and advisors encourage plan sponsors and fiduciaries to allow the vendor to lead them or even handle on an ongoing basis plan administration services by touting their services, experience, expert systems and process and commitment to stand behind the customer when making the sale or encouraging reliance upon their advice when tough decisions are made, they rush to stand behind exculpatory and on-sided indemnification provisions in their service contracts to limit or avoid liability,   demand indemnification from their customer or both when things go wrong.  While ERISA may offer some relief from certain of these exculpatory provisions under some circumstances, plan sponsors and fiduciaries should work to credential service providers and require service providers to commit to being accountable for their services by requiring contracts acknowledge all promised services and standards of quality, require vendors to commit to provide legally compliant and prudently designed and administered services that meet or exceed applicable legal requirements, to provide liability-backed indemnification or other protection for damages and costs resulting from vendor imprudence or malfeasance, to allow for contract termination if the vendor becomes unsuitable for continued use due to changing law or other circumstances and requiring the vendor to return data and other documentation critical to defend past decisions and provide for ongoing administration.  Keep documentation about advice, assurances and other relevant evidence received from vendors which could be useful in showing your company’s or plan’s efforts to make prudent efforts to provide for the proper administration of the plan.  When concerns arise, use care to investigate and redress concerns in a timely, measured fashion which both shows the prudent response to the concern and reflects sensitivity to the fiduciary and other roles and responsibilities of the employer sponsor and other parties involved.

  1. Get Moving Now On Your Compliance & Risk Management Issues. 

Since many compliance deadlines already have past and the impending deadlines allow plan sponsors and fiduciaries limited time to finish arrangements, businesses, fiduciaries and their service providers need to get moving immediately to update their health plans to meet existing  and impending compliance and risk management risks under the Affordable Care Act and other federal laws, decisions and regulations.

  1. Monitor, Assess Implications & Provide Relevant Input to Regulators About Emerging Requirements & Interpretive Guidance Implementing 2014 Affordable Care Act & Other Mandates.

While the Supreme Court upheld the individual mandate, employer and other health plan sponsors, Congress continues to debate changes to the Affordable Care Act and other federal health plan rules.  Meanwhile, significant opportunity still exists to provide input to federal and state regulators on many key aspects of the Affordable Care Act and its relationship to other applicable laws even as court challenges to contraceptive coverage and other specific requirements are emerging.  Businesses and other health plan sponsors, plan fiduciaries, insurers and administrators, and other vendors must stay involved and alert.  Zealously monitor new developments and share timely input with Congress and regulators about existing and emerging rules that present concerns and other opportunities for improvement even as you position to respond to these rules before they become fully implemented.

For Help or More Information

If you need help reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health  or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.

A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters. 

A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals.  A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns. 

Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations.   She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications.   You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and registerto receive future updates about developments on these and other concerns from Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

For important information concerning this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

 

©2012 Cynthia Marcotte Stamer.  Non-Exclusive License To Republish Granted To Solutions Law Press, Inc.  All Other Rights Reserved.

 


OCR 1st HIPAA Privacy, Security & Breach Notification Compliance Audits Begin

November 9, 2011

The kickoff of a new compliance audit pilot program provides another reason for health care providers, health plans, healthcare clearinghouses and their business associates to get serious about compliance with the privacy, security and data breach requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA). 

OCR Pilot Audit Program Begins

On November 8, 2011, the Office of Civil Rights (OCR) of the Department of Health & Human Services (HHS) announced that it will begin auditing HIPAA compliance this month under a new pilot program.

As amended by the American Recovery and Reinvestment Act of 2009 in Section 13411 of the HITECH Act, requires HHS to provide for periodic audits to make sure covered entities and business associates are complying with the HIPAA Privacy and Security Rules and Breach Notification standards.  To carry out this mandate, OCR is piloting a program to perform up to 150 audits of covered entities to assess privacy and security compliance between November 2011 and December 2012.

The commencement of OCR HIPAA compliance audits is yet another sign that covered entities and their business associates should get serious about HIPAA compliance. The audit program serves as a new part of OCR’s health information privacy and security compliance program.  While OCR says that it presently views the pilot audits as primarily a compliance improvement tool, this does not mean violators should expect a free walk.

Even before the impending audits, HIPAA Privacy exposures of covered entities for failing to comply with HIPAA already had risen significantly.  Earlier this year, OCR imposed a $4.3 Million Civil Money Penalty (CMP) against Cignet Health of Prince George’s County (Cignet) for violating HIPAA.  Meanwhile, the Department of Justice has secured several criminal convictions or pleas under HIPAA’s criminal provisions. Under amendments made by the HITECH Act, state attorneys general also now are empowered to bring civil lawsuits against covered entities and business associates that commit HIPAA violations that injure citizens in their state under certain circumstances. Eventually, individuals injured by HIPAA violations also will get the right to share in a portion of certain HIPAA recoveries.

These and other audit and enforcement activities send a strong message that covered entities and their business associates need to get serious about HIPAA compliance. As stated by OCR Director Georgina Verdugo when announcing the Mass General Resolution Agreement, “To avoid enforcement penalties, covered entities must ensure they are always in compliance with the HIPAA Privacy and Security Rules,” Verdugo added, “A robust compliance program includes employee training, vigilant implementation of policies and procedures, regular internal audits, and a prompt action plan to respond to incidents.” Learn more here.

For Help With Monitoring Developments, Compliance, Investigations Or Other Needs

If you need assistance monitoring federal health reform, policy or enforcement developments, or to review or respond to these or other health care or health IT related risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer, can help.

Vice President of the North Texas Health Care Compliance Professionals Association, a member of the American College of Employee Benefit Counsel, Past Chair of the ABA RPTE Employee Benefits & Other Compensation Arrangements Group, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has extensive experience advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical privacy and other compliance and risk management policies.  Ms. Stamer also regularly helps clients deal with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.  Her publications and insights appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications.  Her insights on the required “culture of compliance” with HIPAA are frequently included in medical privacy related publications of the Atlantic Information Service, Modern Health Care, HealthLeaders and many others. Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, employee benefit and other clients, trade and professional associations and others.  You can get more information about her HIPAA and other experience here or may contact her at (469) 767-8872 or via e-mail here.

You can review other selected publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here.

Other Resources

If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:

About Solutions Law Press

Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available at www.solutionslawpress.com

THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2011 Cynthia Marcotte Stamer, P.C.  Non-exclusive license to republish granted to Solutions Law Press.  All other rights reserved.

 


Spectrum Healthcare NLRB Charge Settlement Highlights Need To Defend Against Possible Unfair Labor Practices & Other Union Exposures

May 20, 2011

The National Labor Regulations Board (NLRB)’s announcement of a settlement against a Connecticut nursing home operator this week in conjunction with a series of other enforcement actions highlight the need for businesses to tighten defenses and exercise other caution to minimize their organization’s exposure to potential NLRB charges or investigation.    As reflected by many of these enforcement acts, the exposures arise both from active efforts by businesses to suppress union organizing or contracting activities, as well as the failure to identify and manage hidden labor law exposures in the design and administration of more ordinary human resources, compliance, business operations and other policies and practices.

On May 17, 2011, the NLRB announced here  that Connecticut nursing home operator Spectrum Healthcare has agreed to settle a NLRB case involving multiple allegations of unlawful suspensions, discharges and unilateral changes in violation of the National Labor Relations Act and other federal labor laws by offering reinstatement and back pay to all discharged and striking workers and signing a new three-year collective bargaining agreement with its employees’ union, New England Health Care Employees Union District 1199, SEIU.

Along with the contract and reinstatement of all employees, the company agreed to pay $545,000 in back pay and pension benefits to employees who were harmed by the unfair labor practices, and to expunge any disciplinary records related to the case. As a result, all NLRB charges against the company have been withdrawn. Spectrum admits to no wrongdoing in the settlement.

The settlement, reached midway through a hearing before an NLRB administrative law judge in Connecticut and approved by the judge yesterday, ends a long-running dispute which grew into a strike by almost 400 employees at four nursing homes in Connecticut operated by Spectrum Healthcare, LLC.  Complaints issued by the NLRB Regional Office in Hartford alleged that, beginning in the fall of 2009, several months after the prior collective bargaining agreement expired, Spectrum discharged seven employees and suspended three others to retaliate against their union activities and to discourage other employees from supporting the union. In addition, one employee was discharged and seven others were suspended after the employer unilaterally changed its tardiness discipline policy without first bargaining with the union.

The complaints further alleged that in April 2010, employees at the four nursing homes — in Derby, Ansonia, Winsted, and Hartford — went on strike to protest the unfair labor practices. When the strikers offered unconditionally to return to work in late August, the employer refused to take them back. Under federal labor law, if a strike is called because of an unfair labor practice, employees are entitled to reinstatement after an unconditional offer to return to work.

The reinstated employees are due to return to the facilities this week.

The Spectrum Healthcare settlement is reflective of the growing number of NLRB enforcement orders against employers generally and health care providers specifically under the Obama Administration. The Obama Administration has close ties and has expressed its strong and open support for union and union organizing activities.  The adoption of a series of union friendly labor law reforms was one of the key campaign promises of President Obama during his election campaign.  While other legislative priorities and the change in the leadership of the House of Representatives appears to have slowed efforts to push through this agenda, it has not slowed the Administration’s efforts to support unions with strong enforcement activities.  Empowered by a difficult economic and job situation and an awareness of the Obama Administration’s strong support for union organizing and other activities, unions are stepping up organizing efforts and more aggressively challenging employers actions.

Over the past few months, public awareness of the Obama Administration’s aggressive enforcement agenda on behalf of unions has drawn new attention as a result of the widespread media coverage of NLRB actions challenging Boeings planned relocation of certain manufacturing jobs intervention in a planned relocation of certain manufacturing operations.  See, e.g., Acting General Counsel Lafe Solomon releases statement on Boeing complaint; National Labor Relations Board issues complaint against Boeing Company for unlawfully transferring work to a non-union facilityHowever, the Boeing and Spectrum Healthcare actions represent only the tip of the iceberg of the rising number of NLRB enforcement activities, most of which take place with little media or public attention.

Along side the Spectrum Healthcare and Boeing actions, in recent weeks, the NLRB also has been busy with several other enforcement activities.  For instance:

  • On May 9 2011, the NLRB issued a complaint against Hispanics United of Buffalo (HUB), a nonprofit that provides social services to low-income clients, that alleges that HUB unlawfully discharged five employees after they took to Facebook to criticize working conditions, including work load and staffing issues. The case involves an employee who, in advance of a meeting with management about working conditions, posted to her Facebook ; and
  • On May 17, the NLRB secured a temporary injunction from a U.S. District Court in San Jose California against San Jose area waste hauling company OS Transport LLC,   charged with engaging in unfair labor practices including the termination of a lead organizer and another Union supporter, retaliation against Union efforts in the form of unfavorable assignments, threats to Union supporters, and promises of improved treatment of employees who disavow the Union for the alleged purpose of defeating a union. o offer reinstatement to two drivers and restore full assignments to other drivers who had expressed support for a union during an organizing campaign. More Details here.,

In addition, in recent weeks, the NLRB also has:

 Amid this difficult enforcement environment, business leaders should exercise special care to prepare to defend their actions against both potential organizing efforts, to understand the types of actions and activities that may help fuel charges, and take steps to manage these and other union organization and other labor risks.  

For Help With Labor & Employment, Employee Benefits Or Other Risk Management and Defense

If you need assistance in auditing or assessing, updating or defending your labor and employment, employee benefits, compliance, risk manage or other  internal controls practices or actions, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469)767-8872.

Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 23 years of work helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit  and management policies and practices. Her experience includes extensive work helping employers implement, audit, manage and defend wage and hour and other workforce and internal controls policies, procedures and actions.  The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer works, publishes and speaks extensively on wage and hour, worker classification and other human resources and workforce, employee benefits, compensation, internal controls and related matters.  She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.

About Solutions Law Press

Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources including:

 

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here .

 ©2011 Cynthia Marcotte Stamer.  Non-exclusive right to republish granted to Solutions Law Press.  All other rights reserved.


OCR’s McAndrew Speaks At 5/16 JCEB HIPAA Teleconference; OCR/NIST To Share Other HIPAA Training On Line

May 10, 2011

The National Institute of Standards and Technology (NIST) and the Department of Health and Human Services (HHS), Office for Civil Rights (OCR) are making presentations from the 4th annual conference on “Safeguarding Health Information: Building Assurance through HIPAA Security” co-hosted in Washington, D.C. on May 10 & 11, 2011 available on line for review.  The training is part of a series of continuing efforts by the agencies to outreach to various parties on the Privacy and Security Rules of the Health Insurance Portability & Accountability Act of 1996, as amended (HIPAA).  Meanwhile, OCR’s Susan McAndrew is scheduled to share insights on OCR’s HIPAA regulatory and enforcement agenda at a teleconference to be hosted by the American Bar Association Joint Committee on Employee Benefits at Noon Central on May 16, 2011. 

 The Security Rule sets federal standards to protect the confidentiality, integrity and availability of electronic protected health information by requiring HIPAA covered entities and their business associates to implement and maintain administrative, physical and technical safeguards. Presentations cover a variety of current topics including updates on HHS health information privacy and security initiatives, OCR’s enforcement of health information privacy and security activities, integrating security safeguards into health IT and security automation, insider threat trends and safeguards, and more.

The conference is designed to explore the current health information technology security landscape and the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, the agencies share their practical strategies, tips and techniques for implementing the HIPAA Security Rule. 

For details about reviewing the May 10-11 presentations, see the 2011 HIPAA Conference website here.  For details about the May 16 teleconference, see here.

For Help With Monitoring Developments, Compliance, Investigations Or Other Needs

If you need assistance monitoring federal health reform, policy or enforcement developments, or to review or respond to these or other health care or health IT related risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer, can help.  Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 23 years experience advising health industry clients about these and other matters. Ms. Stamer has extensive experience advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical privacy and other compliance and risk management policies, to health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.   

Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.  Her publications and insights appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications.   For instance, On May 3, 2011, Ms. Stamer served as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR and will moderate a teleconference featuring comments by OCR’s Susan McAndrew for the Joint Committee on Employee Benefits scheduled for May 16.  Her insights on the required “culture of compliance” with HIPAA also recently were quoted in medical privacy related publications of the Atlantic Information Service.  Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, employee benefit and other clients, trade and professional associations and others.

You can get more information about her HIPAA and other experience here.

If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.

About Solutions Law Press

Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources including:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here. For important information concerning this communication click here. 

THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS.  ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.

©2011 Cynthia Marcotte Stamer, P.C.  Non-exclusive license to republish granted to Solutions Law Press.  All other rights reserved.


Rite Aid Pays $1 Million HIPAA Privacy Settlement As OCR Tightens HIPAA Regulations

August 3, 2010

Drug store chain Rite Aid Corporation and its 40 affiliated entities (Rite Aid) will pay $1 million to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule.  Although targeting a health care provider, employers, health plan sponsors, administrators, and service providers should recognise the the Rite Aid settlement as a strong reminder of the importance of reviewing and tightening their own human resources, employee benefits, adn other policies and processes to better safeguard protected health information, personal financial information and other sensitve data.   

The U.S. Department of Health and Human Services (HHS) Office of Civil Rights announcement of the HIPAA resolution agreement with Rite Aid and the concurrent negotiation of a separate consent order of potential FTC Act violations between Rite Aid and the Federal Trade Commission (FTC) follows HHS’ announcement of proposed changes to its HIPAA Privacy Rules and associated penalties in response to changes enacted under the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act).  The Rite Aid settlement and the proposed Privacy Rule changes illustrate the growing penalty risks that health plans, health care providers, healthcare clearinghouses and their business associates (Covered Entities) face for violating the Privacy Rules.  Read more details.

Additionally, the Rite Aid decision also serves as a reminder to employers, health plans and their administrators, insurers and finance and finance departments to tighten their controls over the use, access and disposal of sensitive information.  A walk through of almost most employee benefit, human resources and finance department typically reveals that at any given time a wide range of personal health and other sensitve information is handled and disposed of in a manner that leaves it open to improper or unnecessary use or disclosure.  Additionally, while situations like those in Rite Aid and CVS draw big press, Secret Service, FBI, DOL and other statistics show that most wrongful access and damage comes from the improper use of access of information gained through credentials as an employee, contractor or customer.  Rite Aid, CVS, and other HIPAA, FTC and personal identity breach statistics, settlements and judgments are a reminder to all of the advisability of cleaning up their policies and controls to better protect this data. 

For Assistance or More Information

If your organization needs assistance updating or defending your privacy, data security or other health plan design, documentation policies or procedures in response to these or other requirements or with other employee benefit, insurance or human resources matters, please contact the author of this update, Board Certified Labor & Employment attorney Cynthia Marcotte Stamer at (469) 767-8872 or via e-mail here.

Current Chair of the American Bar Association (ABA) RPTE Employee Benefit & Other Compensation Group, a Council Member of the ABA Joint Committee on Employee Benefits and Past Chair of the ABA Health Law Section Managed Care & Insurance  Interest Group, Stamer continuously advises employers, health and other employee benefit plans, plan sponsors, fiduciaries, plan administrators, plan vendors, insurers and others about health program related legal, operational, documentation, public policy, enforcement, privacy, technology, litigation and risk management and other concerns. Ms. Stamer also publishes, conducts client and other training, speaks and consults extensively on these and other health and managed care program concerns and practices. She regularly speaks and conducts training for the ABA, American Health Lawyers Association, Institute of Internal Auditors, Society for Professional Benefits Administrators, Southwest Benefits Association and many other organizations.  Her extensive publications include numerous highly regarding works on HIPAA and other health plan matters published by the Bureau of National Affairs, the ABA, and others.  Her insights on these and related topics have appeared in Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, Managed Healthcare, Health Leaders, various ABA publications and a many other national and local publications.  To contact Ms. Stamer or for additional information about Ms. Stamer, her experience, involvements, programs or Publishers of her many highly regarded writings on health industry and human resources matters include the Bureau of National Affairs, Aspen Publishers, ABA, AHLA, Aspen Publishers, Schneider Publications, Spencer Publications, World At Work, SHRM, HCCA, State Bar of Texas, Business Insurance, James Publishing and many others.  You can review other highlights of Ms. Stamer’s experience here

Other Resources

If you found this information of interest, you also may be interested in reviewing other recent Solutions Law Press updates including:

About Solutions Law Press

Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available for review here. If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. For important information concerning this communication click here.

©2010 Solutions Law Press. All rights reserved.


CMS & ONC To Co-Host 7/22 ONC Certification & Medicare/Medicaid EHR Incentive Program Audio Training

July 19, 2010

The Centers for Medicare & Medicaid Services (CMS) and the Office of the National Coordinator for Health Information Technology (ONC) will co-host an Audio Training on the Final Rules for ONC Certification and Medicare and Medicaid EHR Incentive Programs on July 22, 2010 from 2:00-3:30 pm EST. 

During the training, the Agencies plan to discuss:

  • Benefits of HIT
  • Summary of the final rules
  • ONC temporary certification process
  • ONC initial set of standards and implementation specifications
  • Medicare and Medicaid EHR Incentives Programs including the initial definition of meaningful Use

To join the audio training, dial 1-877-251-0301 and enter the Conference ID pass code: 87841621

Materials will be made available prior to the training at the following web address here

For more information about CMS EMR incentives, see here. 

About The Author

Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 23 years of work helping employer and other plan sponsors, insurers, administrators, fiduciaries, governments and others design, administer and defend innovative health and other employee benefit programs and other human resources and health care IT, human resources, compensation and management policies and practices.

The author of numerous highly regarding publications on HIPAA and other health care IT related matters, Ms. Stamer works extensively with employer and other health plan sponsors, fiduciaries, administrative and other service providers, insurers, and other clients on health benefit program and product design, documentation, administration, compliance, risk management, and public policy matters.  The publisher of Solutions Law Press, Ms. Stamer also publishes, conducts training and speaks extensively on these and related concerns for the ABA, the Bureau of National Affairs and many other organizations.

The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, and the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, Ms. Stamer also is recognized for her publications, industry leadership, workshops and presentations on these and other HIPAA, EMR and other health technology, health industry and human resources concerns. She regularly speaks and conducts training for the ABA, Institute of Internal Auditors, Society for Professional Benefits Administrators, Southwest Benefits Association and many other organizations.  Publishers of her many highly regarded writings on health industry and human resources matters include the Bureau of National Affairs, Aspen Publishers, ABA, AHLA, Aspen Publishers, Schneider Publications, Spencer Publications, World At Work, SHRM, HCCA, State Bar of Texas, Business Insurance, James Publishing and many others.  You can review other highlights of Ms. Stamer’s experience hereHer insights on these and other matters appear in Managed Care Executive, Modern Health Care, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, MDNews, Kentucky Physician, and many other national and local publications. 

If you need help with human resources or other management, concerns, wish to ask about compliance, risk management or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer here or (469)767-8872. 

Other Resources

If you found this information of interest, you also may be interested in reviewing other recent Solutions Law Press updates including:

If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to receive our Solutions Law Press distributions here. For important information about this communication click here.


Privacy Rule Changes & Posting of Breach Notices On OCR Website Signal New Enforcement Risks For Health Plans, Their Sponsors & Business Associates

February 23, 2010

 By Cynthia Marcotte Stamer

The Department of Health and Human Services Office of Civil Rights (OCR) has begun disclosing on its website the employer and other health plans, health care providers, health care clearinghouses and their business associates (Covered Entities) that report breaches of unsecured protected health information (UPIC) affecting more than 500 individuals as required by new rules enacted as part of the Health Information Technology for Economic and Clinical Health Act (HITECH Act). This posting of Covered Entities reporting breaches comes just days after these and other Covered Entities became subject on February 17, 2010 to a host of other tighter federal requirements for the use, access, protection and disclosure of protected health information under Privacy & Security Standards of the Health Insurance Portability & Accountability Act (HIPAA) also enacted as part of the HITECH Act. As failing to comply with the amended rules effective February 17, 2010 can trigger obligations under the Breach Regulations and other exposures, prompt action to manage risk under both the Breach Regulations and the revised HIPAA rules is critical to minimize Covered Entity and business associate exposures under both these rules. With criminal, administrative and civil prosecutions of such violations increasing and likely to expand, timely action to manage compliance and other risks is warranted. Health plans and their business associates also should prepare for increased awareness and oversight of the adequacy of their medical information safeguards as these disclosures and other enforcement actions heighten interest and awareness of employees and others in these rules.

Covered Entity Breach Notification Requirements

OCR posted the initial list of Covered Entities disclosing these breaches on its website for the first time yesterday (February 22, 2010) to comply with breach notification requirements imposed by Section 164.408 of the interim “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) published here

The Breach Regulation requires Covered Entities subject to the Health Insurance Portability & Accountability Act (HIPAA) to notify affected individuals, OCR and certain other parties following a “breach” of “unsecured” protected health information occurring on or after September 23, 2009.  The Breach Regulation implements new breach notification requirements added to HIPAA by Section 13402(e)(3) of the Health Information Technology for Economic and Clinical Health Act (HITECH Act). It and the posting of Covered Entities reporting breaches of protected health information are part of the ongoing implementation and enforcement of new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under provisions of the HITECH Act and expanded remedies for violations signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).

You can review the list of Covered Entities that have reported breaches on the OCR website here.  Learn more about the Breach Regulation requirements here.

Broader & Stricter Medical Privacy Mandates Effective 2/17/210

Just last Wednesday (February 17, 2010) Covered Entities and their business associates also became subject to tighter federal requirements for the use, access, protection and disclosure of protected health information under amendments to HIPAA’s Privacy & Security Standards enacted by the HITECH Act. The changes that became effective on February 17, 2010 generally require that Covered Entities and their business associates make specific changes to update their written policies, operational procedures, privacy notices, business associate agreements, training, and other management procedures in several respects. For more details, see here.

While the HITECH Act gave Covered Entities and business associates a year to complete the necessary arrangements to comply with these HITECH Act changes, many Covered Entities and business associates have remain unnecessarily exposed under these new requirements by not completing or otherwise failing to adequately implement the necessary arrangements despite expanding liability exposures that can result from noncompliance. To mitigate these exposures, Covered Entities and their business associates should act quickly to review and update their policies, procedures, training, business associate and other services agreements, and other practices and procedures, as well as to implement the training, oversight, and other management necessary to comply with the HITECH Act changes and to mitigate other HIPAA risks.

Exposures Significant & Growing

Covered Entities and business associates failing to devote adequate attention and resources to  managing HIPAA compliance and associated risks risk increasing peril.  Aside from the potential implications that disclosures of violations may have on patients and others impacting their business, the legal risks of noncompliance for Covered Entities, business associates and others mishandling protected health information are real and growing.   

Timely action to comply with the amended HIPAA requirements and Breach Regulations is important both to preserve critical trust in the business, to avoid triggering breach notifications that can undermine this trust and fuel legal complaints, and to avoid exposure to an expanding range of sanctions that can result when a violation occurs. 

Amendments made under the HITECH Act have expanded the size and availability of remedies that can be imposed for HIPAA violations as well as the parties empowered to pursue these remedies.  Wrongful use, access or disclosure of protected health information in violation of HIPAA subjects participating health plans, health care providers, health care clearinghouses, their business associates and other workforce members and others to civil penalties,  criminal prosecution and, since February 17, 2009, civil lawsuits brought by state attorneys general on behalf of citizens of their states whose HIPAA rights were violated.  Since September 23, 2009, health plans and other HIPAA Covered Entities as well as their  business associates also became obligated to provide breach notification under new mandates imposed by the HITECH Act.  Coupled with increased enforcement emphasis by regulators, these expansions to HIPAA’s remedy provisions increase the risk that Covered Entities or business associates violating HIPAA face investigation and sanction.  Furthermore, the wrongful use, access or disclosure of protected health information or other confidential information also increasingly is the basis of civil or criminal actions brought under a variety of other federal and state laws.

Expanded HIPAA & Other Federal Prosecutions & Remedies

The expanded requirements imposed under the Breach Regulation and the other HITECH Act changes that took effect on February 17, 2010 follow the implementation changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, when President Obama signed the HITECH Act into law. The HITECH Act amendments to HIPAA’s remedies significantly increase the risk that health plans and other Covered Entities and their business associates will face civil lawsuits, civil or criminal penalties or other consequences for violating HIPAA. Noncompliance with these and other HIPAA requirements subjects Covered Entities and business associates to civil penalties, criminal prosecution, civil damage awards under lawsuits brought by state attorneys general, and other legal remedies.  In addition, timely update written policies, procedures, business associate agreements, training and documentation is imperative in order for Covered Entities and their business associates to fulfill their breach notification obligations under new rules enacted as part of the HITECH Act. 

HITECH Amendments Expand Liability Exposures

The expanded risks stem in part from the HITECH Act’s amendments to HIPAA’s remedy provisions.  Among other things, the HITECH Act amended HIPAA to:

  • Allow a State Attorney General to sue health plans or other Covered Entities, business associates or both that harm state citizens by committing HIPAA violations after February 16, 2009;
  • Expand the mandate by OCR to investigate violations and audit compliance with HIPAA;
  • Require Office of Civil Rights to impose civil sanctions against Covered Entities and business associates involved in violations of HIPAA in accordance with tightened standards added to HIPAA by the HITECH Act;
  • Revise the criminal sanctions that the Department of Justice can seek against Covered Entities, their business associates and others for violations of HIPAA; and
  • Amend HIPAA to make clear that HIPAA’s criminal sanctions also can imposed on business associates, workforce members and other persons that improperly use, access and disclose protected health information in violation of HIPAA.

State Attorney General Lawsuit Exposures

Covered Entities and their business associates now also need to be concerned about the potential that a state Attorney General may bring civil suit to remedy damages caused to state citizens by a breach of HIPAA. 

The HITECH Act empowers a state attorney general to sue Covered Entities or business associates engaging in HIPAA violations that harms citizens of the state for statutory damages equal to the sum of the number of violations multiplied by 100 up to a maximum of $25,000 per calendar year plus attorneys fees and costs

A HIPAA civil lawsuit filed on January 13, 2010 demonstrates the willingness of at least some states to exercise the new authority created by the HITECH Act on February 17, 2009 to sue Covered Entities and business associates that violate HIPAA for civil damages.

On January 13, 2010 Connecticut Attorney General Richard Blumenthal sued Health Net of Connecticut, Inc. (Health Net) for failing to secure private patient medical records and financial information involving 446,000 Connecticut enrollees and promptly notify consumers endangered by the security breach.   The suit also names UnitedHealth Group Inc. and Oxford Health Plans LLC, who have acquired Health Net.  The first attorney general enforcement action brought based on amendments made to HIPAA under the HITECH Act, Connecticut charges that Health Net violated HIPAA by failing to safeguard protected medical records and financial information on almost a half million Health Net enrollees in Connecticut then allowing this information to remain exposed for at least six months before notifying authorities and consumers.

Stepped Up Federal Enforcement

Even before the HITECH Act amendments, however, OCR and Department of Justice already were stepping up HIPAA investigation and enforcement.  The Department of Justice has obtained a variety of criminal convictions against violators of HIPAA.  See, e.g., 2 New HIPAA Criminal Actions Highlight Risks From Wrongful Use/Access of Health InformationMeanwhile, OCR also is emphasizing HIPAA enforcement.  In February, 2009, for instance, OCR announced that CVS Pharmacies, Inc. would pay $2.25 million to resolve HIPAA charges.  This announcement followed OCR’s announcement in July, 2008 that Providence Health Care would pay $100,000 to resolve HIPAA violation charges.  OCR also has taken HIPAA enforcement actions against a broad range of other Covered Entities to redress HIPAA violations or other compliance concerns.  To review examples of these other actions, see hereWhile not resulting in the significant payments involved in CVS or Providence, all Covered Entities involved in these and other enforcement actions or investigations have incurred significant legal and other defense costs, loss of community trust, or both.

In addition to these HIPAA-specific exposures, wrongful use, access or disclosure of medical information also can give rise to liability for health plans and other Covered Entities, business associates, employees and other members of their workforce and others improperly using, accessing or disclosing protected health information.  Federal and state prosecutions may and increasingly do criminally prosecute individuals for improperly accessing or using medical or other personal information under a variety of other federal or state laws .  See e.g., Cybercrime & Identity Theft: Health Information Security Beyond HIPAA; NY AG Cuomo Announcement of 1st Settlement For Violation of NY Security Breach Notification Law; Woman Who Revealed AIDs Info Gets A YearAdditionally, State courts also increasingly are permitting individuals harmed by HIPAA violations to use HIPAA as the foundation of state law duties used to maintain state negligence, invasion of privacy, retaliation or other claims for damages. Read more here

State Civil Lawsuits

Along side these governmental actions, state courts also increasingly are willing to allow individual plaintiffs to rely on violations of HIPAA as the basis for bringing state privacy, retaliation or other actions.  While prior to the recent HITECH Act amendments, federal courts had ruled that private plaintiffs could not sue under HIPAA for damages they incurred from a Covered Entity’s violation of HIPAA, state courts have allowed private plaintiffs to use the obligations imposed by HIPAA as the basis of a Covered Entity’s duty for purposes of certain state law lawsuits.  In  Sorensen v. Barbuto, 143 P.3d 295 (Utah Ct. App. 2006), for example, a Utah appeals court ruled a private plaintiff could use HIPAA standards to establish that a physician owed a duty of confidentiality to his patients for purposes of maintaining a state law damages claim.  Similarly, the Court in Acosta v. Byrum, 638 S.E. 2d 246 (N.C. Ct. App. 2006) ruled that a plaintiff could use HIPAA to establish the “standard of care” in a negligence lawsuit.

Meanwhile, disgruntled employees or other business partners also increasingly raise alleged HIPAA misconduct as a basis of their legal complaints.  For instance, private plaintiffs employed by Covered Entities also are increasingly pointing to HIPAA as the basis for their retaliation or wrongful discharge claims. See, e.g.,  Retaliation For Filing HIPAA Complaint Recognized As Basis For State Retaliatory Discharge Claim.  Coupled with the HITECH Act changes, these and other enforcement actions signal growing potential hazards for Covered Entities and their business associates that  fail to properly manage their HIPAA compliance obligations and risks.

Given these and other developments, Covered Entities and their business associates generally should resist the temptation to underestimate their potential HIPAA exposure for a variety of reasons.  In fact, a number of factors demonstrate that the risks are significant and growing for Covered Entities, business associates and others that breach HIPAA’s mandates or otherwise inappropriately access protected health information. 

Covered Entities & Business Associates Urged To Act Promptly To Manage Expanded HIPAA Risks & Obligations

As a consequence of these collective HITECH Act changes and growing HIPAA-related and other exposures, Covered Entities, their business associates and business associates generally will find it necessary or advisable among other things to:

  • Conduct well-documented due diligence within the scope of attorney-client privilege on their own practices and procedures;
  • Review the adequacy of the practices, policies and procedures of the Covered Entities, business associates, and others that may come into contact with protected health information;;
  • Renegotiate their service provider agreements to detail the specific compliance obligations of each party relating to for auditing compliance, investigating potential breaches; providing required breach notifications; specify leadership and required cooperation in the event of a breach, charge, or other concern; indemnification and other liability allocations; and other related matters;
  • Update policies, privacy and other notices, practices, procedures, training and other practices as needed to promote compliance and defensibility;
  • Conduct well-documented training as necessary to ensure that business associates and other members of the Covered Entity’s workforce understand and are prepared to comply with the expanded requirements of HIPAA, can detect potential breaches or other compliance concerns, and understand and are prepared to follow appropriate procedures for reported suspected violations; and
  • Pursue appropriate liability and other protection as appropriate to improve their ability to demonstrate both their commitment to compliance and their realistic efforts to ensure that these commitments are both appropriately documented on paper and operationalized in performance.

As part of these compliance and risk management efforts, most Covered Entities and their business associates will find it advisable to devote significant attention to the business associate relationship and its associated business associate agreements. Proper management of the expanded compliance obligations and liability exposures created by the HITECH Act generally will necessitate that Covered Entities and their business associates focus significant attention on the reworking of their operating and contractual relationships including the definition of detailed procedures for monitoring, reporting, investigating, and resolving potential breaches or other compliance concerns.

Even before the impending HIPAA changes scheduled to take effect on February 17, 2010, a strong need for more detailed contracting and planning of these relationships already existed. Since the enactment of HIPAA, the practice of many Covered Entities and their business associates of appending generic “business associate” representations onto existing services contracts without specific tailoring and planning has created undesirable ambiguities in these agreements. Further updating and tailoring of these and other provisions of services agreements has become even more important over the past year in light of the new breach notification mandates that took effect under the HITECH Act in September, 2009, changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, and the impending extension by the HITECH Act to business associates of direct liability for compliance with HIPAA scheduled to occur on February 17, 2010.

These and other stepped up oversight and enforcement activities make it critical that all Covered Entities and their business associates update their policies and practices, conduct training, tighten their compliance and data breach monitoring processes, strengthen their internal controls and documentation, and take other steps to prepare to defend their actions under the newly strengthened Privacy Rules.  Covered Entities and their business associates more than ever must ensure their ability to demonstrate to federal regulators the effectiveness of their HIPAA compliance efforts by both adopting the written policies and procedures required by HIPAA and continuously monitoring and administering these safeguards.  Covered Entities should consider reviewing the adequacy of their current HIPAA Privacy and Security compliance practices taking into consideration the Corrective Action Plan, published OCR noncompliance and enforcement statistics, their own and reports of other security and privacy breaches and near misses, and other developments to determine if additional steps are necessary or advisable.

For Assistance With Compliance Or Other Concerns

If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting the author of this article, Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer at (214) 270-2402 or via e-mail  here

Ms. Stamer is nationally known for her work, training and presentations, and publications on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts. 

Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 22 years experience advising clients about health and other privacy and security matters.  A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters.  Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.  

Other Recent Developments

If you found this information of interest, you also may be interested in information about upcoming programs to be presented by Ms. Stamer, acquiring a copy of a recording or materials from previous programs she has presented, or arranging training for your organization.  For more information about these opportunities, contact Ms. Stamer directly.

If you found this information of interest, you also may be interested in reviewing some of the following recent Updates available online by clicking on the article title:

Curran Tomko Tarski LLP Can Help

If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.

A widely published author and speaker on HIPAA and other employee benefit and human resources related matters, Ms. Stamer has extensive experience advising health plans, their employer and other sponsors, health insurers, TPAs and other business associates and others about HIPAA and other health plan and privacy matters. Currently serving as both Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and as an ABA Joint Committee on Employee Benefits Council representative and Former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer has more than 23 years experience assisting employers, insurers, plan administrators and fiduciaries and others to design, implement, draft and administer health and other employee benefit plans and to defend audits, litigation or other disputes by private parties, the IRS, Department of Labor, Office of Civil Rights, Medicare, state insurance regulators and other federal and state regulators. A nationally recognized author and lecturer, Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.   For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.

Other Information & Resources

We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here.  Examples of other recent updates that may be of interest include:

For important information concerning this communication click here.   If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.

 

©2010 Cynthia Marcotte Stamer. All rights reserved.


SouthWest Benefits e-Connections Highlights Stamer Article About Importance For Health Plans, Their Sponsors & Business Associates To Update HIPAA Policies, Practices & Agreements

February 22, 2010

Cynthia Marcotte Stamer’s article Health Plans & Business Associates Face 2/17 Deadline To Comply With HIPAA Privacy Rule Changes is featured in the Winter, 2010 edition of the SouthWest Benefits Association e-Connection.  The article originally published in the Solutions Law Press HR & Benefit Update highlights the need for health plans, employer and other plan sponsors, administrators, and health insurers as well as the brokers, advisors, and other service providers performing functions on behalf of these entities to update their plans, policies, vendor agreements, practices, privacy notices and other communications and other materials, conduct training and take other steps in response to tighter federal requirements for the use, access, protection and disclosure of protected health information under Privacy & Security Standards of HIPAA, as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH Act).

Founded in 1975, SouthWest Benefits is a regional, non-profit association designed to foster relationships and support the educational growth of professionals in employee benefits through an annual schedule of professional educational conferences and workshops. As part of these activities, the SWBA is scheduled to host its 35th Annual Conference on May 12th-14th at the Westin Riverwalk in San Antonio.  For information about these and other SWBA, see here.

A former Southwest Benefits Association board member who remains active in the organization, Ms. Stamer is a board certified labor and employment attorney recognized, internationally, nationally and locally for her more than 22 years of work, advocacy, education and publications on employee benefit and related matters.  As a core focus of her role as the Chair of the Curran Tomko Tarski Labor, Employment & Employee Benefits Practice, Ms. Stamer continuously advises and assists employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources programs and practices. Chair of the American Bar Association (ABA) RPTE Employee Benefits & Compensation Committee, an ABA Joint Committee on Employee Benefits Council member, Ms. Stamer also is a widely published author and highly regarded speaker on these and other employee benefit and human resources matters who is active in many other employee benefits, human resources and other management focused organizations  For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.   For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.

If you need assistance with these or other compliance concerns, wish to inquire about federal or state regulatory compliance audits, risk management or training, assistance investigating or responding to a known or suspected compliance or risk management concern, or need legal representation on other matters please contact the author of this update, Cynthia Marcotte Stamer, CTT Labor & Employment Practice Chair at cstamer@cttlegal.com, 214.270.2402; or your other preferred Curran Tomko Tarski LLP attorney.

You can review other recent human resources, employee benefits and internal controls publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here and learn more about other Curran Tomko Tarski LLP attorneys here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information to Cstamer@CTTLegal.com or registering to participate in the distribution of these and other updates on our Solutions Law Press distributions here. For important information concerning this communication click here.    If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to here.

©2010 Cynthia Marcotte Stamer. All rights reserved.


Health Plan Liability Heats Up As Plans & Businesses Face New Obligations, Costs & Exposures under New HIPAA Privacy Rules Effective 2/17 & Other Expanding Federal Health Plan Mandates

February 17, 2010

Today (February 17, 2010), employer and other health plans and health insurers (“covered entities”) and service providers performing functions on behalf of these entities (“business associates”) must begin complying with tighter federal requirements for the use, access, protection and disclosure of protected health information under Privacy & Security Standards of the Health Insurance Portability & Accountability Act (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH Act). Coming as U.S. employers continue to struggle to provide health benefits in the face of skyrocketing health benefit costs, these and other new federal regulations impacting employment-based health plans and their sponsoring businesses, fiduciaries and administrators are forcing U.S. business leaders to make appropriate health plan cost and compliance management a key management priority.

2/17/10 & Other HIPAA Privacy Rule Changes Require Prompt Attention

The HIPAA Privacy Rule changes scheduled to take effect February 17, 2010 are likely to require that health plans and their business associates update their written policies, operational procedures, privacy notices and business associate agreements in several respects.

While the HITECH Act gave covered entities and business associates a year to complete the necessary arrangements to comply with these impending HITECH Act changes, many health plans and business associates have not completed the necessary arrangements despite expanding liability exposures that can result from noncompliance. To mitigate these exposures, covered entities and their business associates should act quickly both to update their services agreements, plans and policies, practices, and procedures, and to implement the training, oversight, and other management procedures necessary to comply with the HITECH Act changes and to mitigate other HIPAA risks.

The risks of noncompliance for health plans, business associates and others mishandling protected health information are real and growing. Wrongful use, access or disclosure of protected health information in violation of HIPAA subjects participating health plans, health care providers, health care clearinghouses, their business associates and other workforce members and others to civil penalties,  criminal prosecution and, since February 17, 2009, civil lawsuits brought by state attorneys general on behalf of citizens of their states whose HIPAA rights were violated.  Since September 23, 2009, health plans and other HIPAA covered entities as well as their  business associates also became obligated to provide breach notification under new mandates imposed by the HITECH Act. 

In addition to these HIPAA-specific exposures, wrongful use, access or disclosure of medical information also can give rise to liability for health plans and other covered entities, business associates, employees and other members of their workforce and others improperly using, accessing or disclosing protected health information.  Federal and state prosecutions may and increasingly do criminally prosecute individuals for improperly accessing or using medical or other personal information under a variety of other federal or state laws .  See e.g., Cybercrime & Identity Theft:Health Information Security Beyond HIPAA; NY AG Cuomo Annoucment of 1st Settlement For Violation of NY Security Breach Notification Law; Woman Who Revealed AIDs Info Gets A Year.  Additionally, State courts also increasingly are permitting individuals harmed by HIPAA violations to use HIPAA as the foundation of state law duties used to maintain state negligence, invasion of privacy, retaliation or other claims for damages. Read more here

To manage these and other HIPAA-related risks, sponsoring employers, fiduciaries, administrators, insurers and their vendors should begin with carefully and timely reviewing and updating existing plan documents, vendor agreements, privacy notices and other communications and associated practices and policies.  The focus of these efforts definitely should seek both to adopt the specific technical changes necessary to make the health plans and their contracts technically comply on paper with these and other HIPAA mandates, and to tailor these documents, communications and practices promote operational compliance and minimize exposure to associated risks.  In relation to these efforts, sponsoring employers, insurers, fiduciaries and administrators also should ensure that required certifications from employers and other plan sponsors, representations from business associates, training and other compliance conditions are properly in place.  In this respect, employers sponsoring health plans should not overlook the potential need to adopt appropriate policies and implement needed training and safeguards to enable the health plan and the employer demonstrate, if necessary that HIPAA’s requirements for sharing protected health information with members of the employer’s workforce for plan administration, underwriting or certain other purposes have been satisfied.

Other Health Plan Updates Also Required

The HIPAA Privacy Rule changes effective today are only part of the ever-growing list of federal mandates that group health plan sponsors, fiduciaries, insurers, administrators and service providers need to be concerned about.  In addition to the new HIPAA Privacy Rule requirements taking effect today, health plans, their sponsors, administrators, fiduciaries, insurers, business associates and other service providers face a host of other new federal health plan and privacy mandates that have taken effect over the past year, and will become subject to additional mandates in upcoming months.  Consequently, while focusing on HIPAA compliance, health plans, their employer or other sponsors, insurers, fiduciaries, administrators and service providers also should not overlook the need to review and update their health plans in response to a host of other changes in federal health plan mandates.

In addition to otherwise applicable civil damage awards and civil penalty exposures that can result from violations of these requirements, new Internal Revenue Service regulations that took effect January 1, 2010 also require that employers, health plans or others self-report violations of certain of these requirements and self assess and pay resulting excise taxes arising under the Internal Revenue Code.  See, e.g., COBRA, HIPAA, GINA, Mental Health Parity or Other Group Health Plan Rule Violations Trigger New Excise Tax Self-Assessment & Reporting Obligations

The highly volatile health plan regulatory environment makes it likely that many health plans are not appropriately updated to comply with these and other federal requirements. In recent months, health plans, their employer or other sponsors, administrators and others also have become obligated to comply with a host of other expanded federal health plan rules and requirements. See e.g., New Mental Health Parity Regulations Require Health Plan Review & Updates; New Labor Department Rule Allows Employers 7 Days To Deliver Employee Contributions To Employee Benefit Plans; Newly Extended COBRA Subsidy Rules Require Employers, Administrators Send Required Notices & Update Health Plan Documents & Procedures Quickly;  Employer & Other Health Plans & Other HIPAA-Covered Entities & Their Business Associates Must Comply With New HHS Health Information Data Breach Rules By September 23.

These and other developments make it imperative that health plans, their employer or other  sponsors, administrators, insurers, fiduciaries and service providers get serious about complying with these and other federal health plan mandates and managing health plan related liabilities and costs. Sponsors, insurers, fiduciaries and administrators should ensure that health plan documents, insurance and other vendor contracts, policies, procedures and communications are timely updated to comply with these and other emerging mandates.  When implementing these updates, parties concerned about costs or liabilities also should exercise care to ensure that plan documents, communications, contracts, administrative forms and procedures are optimally designed and drafted not only to be technically compliant, but also to support the enforceability of plan design and cost expectations, minimize administrative and other avoidable costs, and minimize liability exposures.  In furtherance of these efforts, employer and other plan sponsors also should consider tightening their practices and requirements for credentialing, selection, oversight and contracting with administrators and vendors, and take other prudent steps to manage health plan related risks.

Curran Tomko Tarski LLP Can Help

If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.

A widely published author and speaker on HIPAA and other employee benefit and human resources related matters, Ms. Stamer has extensive experience advising health plans, their employer and other sponsors, health insurers, TPAs and other business associates and others about HIPAA and other health plan and privacy matters. Currently serving as both Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and as an ABA Joint Committee on Employee Benefits Council representative and Former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer has more than 23 years experience assisting employers, insurers, plan administrators and fiduciaries and others to design, implement, draft and administer health and other employee benefit plans and to defend audits, litigation or other disputes by private parties, the IRS, Department of Labor, Office of Civil Rights, Medicare, state insurance regulators and other federal and state regulators. A nationally recognized author and lecturer, Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.   For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.

Other Information & Resources

We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here.  Examples of other recent updates that may be of interest include:

For important information concerning this communication click here.   

 ©2010 Cynthia Marcotte Stamer. All rights reserved.


Stamer Speaks To CPAs About “Privacy & Information Security: Managing Your Accounting Practice’s Liabilities & Counseling Your Clients” January 12, 2010

December 28, 2009

Accountants and their clients face increasing regulatory and business pressures to protect the sensitive business and personal information collected and maintained in the course of their operation to minimize their exposure to personal identity theft and other cybercrime scams by employees, business partners and others. Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer will speak about “Privacy & Information Security: Managing Your Accounting Practice’s Liabilities & Counseling Your Clients” to members of the Dallas CPA Society on January 12, 2010 beginning at 2:00 p.m.

Part of the Dallas CPA Society Member Appreciation CPE Series Meeting, Ms. Stamer’s presentation will be part of four hours of free CPE training to be provided at a program open to members only at the Hilton Lincoln Centre Hotel located at 5410 LBJ Freeway, Dallas TX  75240 from 1 p.m. to 4:50 p.m. Central Time.  (Parking at the facility costs $5.00).  To register or for additional information, see here.

If you need help responding to these developments or other legislative, regulatory or enforcement concerns, Curran Tomko Tarski LLP can help.  Curran Tomko and Tarski LLP and its attorneys have significant experience assisting businesses and business leaders to manage and defend privacy, data security, tax employee benefit, employment, health care, environmental, safety, securities and other compliance and risk management concerns.

Curran Tomko Tarksi LLP Partner Cynthia Marcotte Stamer has more than 22 years experience helping businesses to use the law, process and technology to manage people and processes, and to manage technology, privacy and data security, employment and other legal and operational risks affecting their businesses.  Author of “Privacy & Securities Standards-A Brief Nutshell,” “Privacy Invasions of Medical Care-An Emerging Perspective,” and “E-Health Business and Transactional Law Other Liability-Tort and Regulatory;” published by The Bureau of National Affairs, Inc., and many other publications, Ms. Stamer has extensive experience advising a accounting firms, law firms, banks and financial services organizations, insurers, consultants, health plans, health care providers and others about HIPAA, FACTA, and other privacy, trade secret and other information security and data breach risk management and compliance concerns.  Ms Stamer also speaks, publishes and provides public policy input extensively on data security, technology and other internal controls and risk management matters.   Chair of the American Bar Association RPTE Employee Benefits & Compensation Committee, an ABA Joint Committee on Employee Benefits  Council member, and Chair of the Curran Tomko Tarski Labor, Employment & Employee Benefits Practice, Ms. Stamer also is Board Certified in Labor & Employment law.  For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.   For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.

If you need assistance with these or other compliance concerns, wish to inquire about federal or state regulatory compliance audits, risk management or training, assistance investigating or responding to a known or suspected compliance or risk management concern, or need legal representation on other matters please contact the author of this update, Cynthia Marcotte Stamer, CTT Labor & Employment Practice Chair at cstamer@cttlegal.com, 214.270.2402; or your other preferred Curran Tomko Tarski LLP attorney.

You can review other recent human resources, employee benefits and internal controls publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here /the Curran Tomko Tarski LLP attorneys here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information to Cstamer@CTTLegal.com or registering to participate in the distribution of these and other updates on our Solutions Law Press HR & Benefits Update distributions here. For important information concerning this communication click here.    If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to here.

©2009 Cynthia Marcotte Stamer. All rights reserved.


Rising Enforcement and Changing Rules Require Prompt Review & Update of Health Plan Privacy & Data Security Policies & Procedures

December 25, 2009

Health plans and their business associates should review and update their practices and policies concerning the use access and disclosure of protected health information in response to changing requirements and expanding enforcement exposures under the Health Insurance Portability & Accountability Act of 1996 (HIPAA) Privacy and Security Rules.

A series of Office of Civil Rights (OCR) enforcement action against health plans highlights the need for group health plans and insurers to exercise care to comply with HIPAA’s Privacy & Security Rules.  For example, OCR recently required a HMO to take a series of corrective actions based on findings from its investigation of a complaint that the HMO impermissibly disclosed a member’s protected health information by sending her entire medical record to a disability insurance company without her authorization.  Based on its investigation, OCR found the HMO violated HIPAA by relying on a form to make the disclosure that failed to meet the Privacy Rule requirements to qualify as a valid authorization under the Privacy Rule.  Based on these findings, OCR required the HMO among other things:

  • To create a new HIPAA-compliant authorization form that specifies what records and/or portions of the files will be disclosed, that the respective authorization will be kept in the patient’s record, together with the disclosed information and otherwise to meet the content requirements of the Privacy Rule for an authorization; and
  • To implement a new policy that directs staff to obtain patient signatures on these forms before responding to any disclosure requests, even if patients bring in their own “authorization” form.

Another action resulted after a national health maintenance organization sent explanation of benefits (EOB) by mail to a complainant’s unauthorized family member. OCR’s investigation determined that a flaw in the health plan’s computer system put the protected health information of approximately 2,000 families at risk of disclosure in violation of the Privacy Rule.  To resolve this case, OCR required among other things that the insurer to correct the flaw in its computer system, review all transactions for a six month period and correct all corrupted patient information.

In yet another case, OCR found an employee of a major health insurer impermissibly disclosed the PHI of one of its members without following the insurer’s authorization and verification procedures. Among other corrective actions to resolve the specific issues in the case, OCR required the health insurer to train its staff on the applicable policies and procedures, to take action to mitigate the harm to the individual and to counsel and give a written warning to an employee who made the disclosure.

While OCR declined to impose any civil penalties in any of these three instances, violations of the Privacy Rules have resulted in both criminal prosecutions by the Department of Justice and the payment of large civil settlements to OCR.  See, e.g., 2 New HIPAA Criminal Actions Highlight Risks From Wrongful Use/Access of Health Information  HIPAA Risks Soar As CVS Agrees to Pay $2.25 Million To Resolve HIPAA Charges & Stimulus Bill Amends HIPAA.  Furthermore, recent amendments to the Privacy Rules increase the likelihood that health plans and other covered entities violating the Privacy Rules will incur civil penalties.  The American Recovery and Reinvestment Act of 2009 (ARRA) amended the Privacy Rules effective October, 2009 to increase the civil penalties for Privacy Rule violations and to include new breach notification requirements for covered entities.  Additional ARRA amendments to HIPAA scheduled to take effect February 17, 2010 will further tighten the conditions under which covered entities may use, access or disclose PHI under the Privacy Rules, will expand the circumstances under which health plans and other covered entities will be required to account for dealings with PHI under HIPAA, and will extend the duty to comply with and liability for violations of the Privacy Rules to business associates.  In the meanwhile, employees increasingly are alleging Privacy Rule violations as part of their whistleblower or other wrongful discharge claims.  See, e.g. Retaliation For Filing HIPAA Complaint Recognized As Basis For State Retaliatory Discharge Claim.

In light of these changing rules and expanding liabilities, health plans and their business associates need to review and update their Privacy and Security practices, business associate agreements and privacy notices for compliance in light of the expanding enforcement activities of OCR and these evolving Privacy and Security Rules.  These and other developments make it imperative that health plans and other covered entities and their business associates immediately review and update their HIPAA and other data security and privacy practices to guard against growing liability exposures under HIPAA and other federal and state laws.

If your organization needs assistance reviewing, updating, administering or defending privacy and data security practices under HIPAA, state data breach or other laws, Curran Tomko Tarski LLP can help.  The author of this update, Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer has extensive experience advising and assisting health plans, health insurers, and other covered entities and business associates to review, update, document, enforce and defend their HIPAA and other privacy and data security policies and practices.  The author of numerous publications on HIPAA and other privacy and data security rules, she also speaks and conducts training extensively on these concerns. 

Ms. Stamer is experienced with assisting employers, insurers, administrators, and others to design and administer group health plans cost-effectively in accordance with HIPAA and other applicable federal regulations as well as well as advising and defending employers, health plans, insurers and others against privacy, tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the OCR, DOJ,IRS, Department of Labor and other federal and state regulators.. Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group, a representative to the ABA Joint Committee on Employee Benefits Council, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, Ms. Stamer has advised and represented employers on these and other labor and employment, compensation, employee benefit and other personnel and staffing matters for more than 22 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.   For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.

Other Information & Resources

We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here.  Some other recent updates that may be of interested include the following, which you can access by clicking on the article title:

 

For important information concerning this communication click here.   If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.

©2009 Cynthia Marcotte Stamer. All rights reserved. 


Senate Finance Chairman Baucus Introduces New Health Care Reform Bill

November 19, 2009

S.1796, America’s Healthy Future Act of 2009 Reflects Chairman’s Response To House’s Passage of HR 3962 & Other Feedback

Senate Finance Committee Chairman Max Baucus (D-MT) today (November 19, 2009) introduced his latest health care reform proposal, the America’s Healthy Future Act of 2009 (S.1796).  Chairman Baucus’ introduction of S. 1796 follows the November 7, 2009 passage by the U.S. House of Representatives of the massive health care reform proposal sponsored by Representative John Dingell (D-MI) and supported by Speaker Nancy Pelosi, the Affordable Health Care for America Act (HR. 3962).

Totaling 1504 pages in length, S.1796 proposes a lengthy and complex array of reforms to the U.S. health care coverage and delivery system, which would affect virtually each U.S. employer, health care provider, payer, and resident. As with the provisions of HR. 3962 and other versions of health care reform, the reforms outlined in the provisions of S.1796 include complexities and nuances which may not be apparent in partisan or non-partisan discussions or summaries of its goals or purposes. Consequently, individuals or businesses concerned about the proposed reforms are encouraged to begin and base their review and analysis on the actual text of S.1796, a copy of which as introduced is available for review here.  

The continuing emphasis of President Obama and other members of the Democratic Party Leadership in Congress on the passage of health care reform means that Senator Baucus and other Democratic Leaders in Congress are likely to continue to make passage of health care reform a priority.  U.S. businesses and individuals concerned about the proposed reforms should carefully review both the Senate and House bills and act quickly to provide their input on any matters of special interest and concern.

Selected Health Coverage Reform Highlights

Among other things, S.1796, as introduced, would enact sweeping health insurance coverage reforms that would create new obligations for employers, insurers, and individual workers.  In this respect, S.1796, among other things would:

  • Amend the Social Security Act (SSA) to add a new title XXII (Health Insurance Coverage) to ensure that all Americans have access to affordable and essential health benefits coverage.
  • Require all health benefits plans offered to individuals and employers in the individual and small group market to be qualified health benefits plans (QHBPs).
  • Amend the Internal Revenue Code to: (1) allow tax credits related to the purchase of health insurance through the state exchanges; and (2) impose an excise tax on individuals without essential health benefits coverage and on employers who fail to meet health insurance coverage requirements with respect to their full-time employees.
  • Prohibit QHBP from excluding coverage for preexisting conditions, or otherwise limiting or conditioning coverage based on any health status-related factors.
  • Require QHBPs to offer coverage in the individual and small group markets on a guaranteed issue and guaranteed renewal basis.
  • Amend the cafeteria plan rules of Internal Revenue Code § 125 to, among other things, require that in order for a health flexible spending arrangement (HFSA) to qualify as a qualified benefit eligible to be offered under a cafeteria plan, the cafeteria plan must limit the maximum salary reduction contribution per employee per taxable year to $2,500 beginning in 2011.
  • Increase the threshold for the itemized income tax deduction for medical expenses.
  • Require states to: (1) establish rating areas; (2) adopt a specified risk adjustment model; and (3) establish transitional reinsurance programs for individual markets.
  • Require QHBP offerors in the individual and small group markets to consider all enrollees in a plan to be members of a single risk pool.
  • Require the Secretary of Health and Human Services (HHS) to establish: (1) risk corridors for certain plan years; (2) high risk pools for individuals with preexisting conditions; (3) a temporary reinsurance program for retirees covered by employer-based plans; and (4) a program under which a state establishes one or more QHBPs to provide at least an essential benefits package to eligible individuals in lieu of offering coverage through an exchange.
  • Entitle a qualified individual to the choice to enroll or not to enroll in a QHBP offered through an exchange covering the individual’s state as well as QHBPs in the individual market while at the same time requiring that such individuals to be U.S. citizens or lawful residents.
  • Require each state to establish: (1) an exchange designed to facilitate enrollment in QHBPs in the individual market; and (2) a Small Business Health Options Program (SHOP) exchange designed to assist qualified small employers in facilitating the enrollment of their employees in QHBPs in either the individual or the small group market.
  • Direct the Secretary to: (1) establish a system allowing state residents to participate in state health subsidy programs; and (2) study methods exchange QHBPs can employ to encourage health care providers to make increased meaningful use of electronic health records.
  • Dictate the mandated contents of an essential health benefit benefits package, including little or no cost-sharing, no annual or lifetime limits on coverage, and preventive services.
  • Amend the Internal Revenue Code to codify and revise the Health Insurance Portability and Accountability Act of 1996 (HIPAA) wellness program regulations.
  • Amend the Internal Revenue Code to codify and revise the Health Insurance Portability and Accountability Act of 1996 (HIPAA) wellness program regulations.
  • With regard to abortions: (1) declare that the Act does not require health care benefits plans to provide coverage for abortions; prohibit QHBPs from discriminating against any individual health care provider or health care facility because of its willingness or unwillingness to provide, pay for, provide coverage of, or refer for abortions; (3) continues application of state and federal laws regarding abortion; (4) prohibit the use of premium credits and cost-sharing subsidies for QHBPs covering abortion services for which federal funding is prohibited; (5) require the plan offeror to determine whether or not the plan provides coverage of abortion services for which federal funding is prohibited or is allowed; and  (6) require the Secretary to assure that at least one QHBP covers abortion services for which federal funding is prohibited or allowed; and at least one QHBP that does not cover abortion services for which federal funding is allowed.

Other Selected Health Care System, Reimbursement & Other Reform Highlights

S.1796 also would expand and modify existing Medicare, Medicaid, CHIP and other federal health care programs and enact a host of other new rules and requirements affecting health care providers, drug companies and other participants in the U.S. health care system.  Other proposed reforms include provisions that would:

  • Require the President to: (1) certify annually in the President’s Budget whether or not the provisions in this Act will increase the budget deficit in the coming fiscal year; and (2) instruct the HHS Secretary and the Secretary of the Treasury to make required reductions in exchange credits and subsidies.
  • Establish a new mandatory eligibility category under SSA title XIX (Medicaid) for all non-elderly, nonpregnant individuals who are otherwise ineligible for Medicaid.
  • Revise Medicaid benefits.
  • Rescind funds available in the Medicaid Improvement Fund for FY2014-2018.
  • Make appropriations for Aging and Disability Resource Center initiatives.
  • Increase the federal medical assistance percentage (FMAP) for states to offer home and community-based services as a long-term care (LTC) alternative to nursing homes.
  • Create a Community First Choice Option.
  • Add a new optional categorically needy eligibility group to Medicaid for individuals: (1) with income that exceeds 133% of the poverty line; and (2) certain other individuals, but only for benefits limited to family planning services and supplies.
  • Direct the Secretary to establish a grants program to support school-based health centers.
  • Remove smoking cessation drugs, barbiturates, and benzodiazepines from Medicaid’s excluded drug list.
  • Revise requirements for Medicaid disproportionate share hospital (DSH) payments.
  • Direct the Secretary to establish a Federal Coordinated Health Care Office within the Centers for Medicare & Medicaid Services (CMMS).
  • Direct the Secretary to establish a Medicaid Quality Measurement Program.
  • Revise requirements for the Medicaid and CHIP Payment and Access Commission (MACPAC) under SSA title XXI, Children’s Health Insurance Program.
  • Set forth special rules relating to American Indians and Alaska Indians.
  • Require the Secretary to establish procedures for sharing data collected under a federal health care program on race, ethnicity, sex, primary language, type of disability, and related measures and data analyses.
  • Amend SSA title V with respect to the Maternal and Child Health (MCH) block grant program.
  • Provide funding for abstinence education.
  • Incorporate reforms originally proposed under the Elder Justice Act of 2009 pursuant to which amendments would be made to the provisions of SSA title XX relating to Block Grants to States for Social Services with respect to elder abuse, neglect, and exploitation and their prevention.
  • Establish within the Office of the Secretary an Elder Justice Coordinating Council.
  • Direct the Secretary to establish a hospital value-based purchasing program under Medicare.
  • Extend the Medicare Physician Quality Reporting Initiative program (PQRI) incentive payments beyond 2010.
  • Modify the Physician Feedback Program.
  • Require the Secretary to develop a plan to implement a Medicare value-based purchasing program for home health agencies and skilled nursing facilities (SNFs).
  • Amend SSA title XVIII (Medicare) to direct the Secretary to establish a national strategy to improve the delivery of health care services, patient health outcomes, and population health.
  • Direct the President to convene an Interagency Working Group on Health Care Quality.
  • Amend the General Provisions of SSA title XI to provide for the establishment of a Center for Medicare and Medicaid Innovation within CMMS.
  • Amend SSA title XVIII to direct the Secretary to establish a shared savings program that promotes accountability for a patient population and coordinates items and services under Medicare parts A (Hospital Insurance) and B (Supplementary Medical Insurance).
  • Create a Hospital Readmissions Reduction Program.
  • Direct the Secretary to establish a Community-Based Care Transitions Program.
  • Revise requirements with respect to residents in teaching hospitals.
  • Increase the Medicare physician payment update.
  • Direct the Secretary to establish a Working Group on Access to Emergency Medical Care.
  • Extend the Medicare-Dependent Hospital Program.
  • Amend the Tax Relief and Health Care Act of 2006 with respect to the hospital wage index.
  • Establish a Medicare prescription drug discount program for brand-name drugs for beneficiaries who enroll in Medicare part D (Voluntary Prescription Drug Benefit Program) and have drug spending that falls into the coverage gap.
  • Establish an independent Medicare Commission to reduce the per capita rate of growth in Medicare spending.
  • Amend SSA title XI to add a new part D, Comparative Effectiveness Research, under which would be established a Patient-Centered Outcomes Research Institute.
  • Establish in the Department of Treasury the Patient-Centered Outcomes Research Trust Fund.
  • Establish a nationwide program for national and state background checks on direct patient access employees of long term care facilities and providers.
  • Direct the Secretary to establish new procedures for screening providers of medical or other items or services and suppliers under the Medicare, Medicaid, and CHIP programs.
  • Direct the Secretary to establish a self-referral disclosure protocol to enable health care service providers and suppliers to disclose violations.
  • Requires the Secretary to expand the number of areas included in Round Two of the durable medical equipment (DME) competitive bidding program.
  • Extend the period for collection of overpayments due to fraud.
  • Amend the Internal Revenue Code with respect to: (1) an excise tax on the excess benefit of high cost employer-sponsored health coverage; (2) distributions from health savings accounts for drugs and insulin that are prescribed drugs and insulin only; (3) a limitation on salary reduction contributions by employers to a health flexible spending arrangement; (4) expanded information reporting requirements; (5) additional qualifying requirements for charitable hospital organizations; and (6) a qualifying therapeutic discovery project tax credit.
  • Impose annual fees on: (1) manufacturers and importers of branded prescription pharmaceuticals or of medical devices; and (2) health insurance providers.
  • Prescribe a special rule to limit excessive remuneration by certain health insurance providers.
  • Exclude from an individual’s gross income the value of any qualified Indian health care benefit.

Monitoring & Responding To Health Care Reform Proposals

As was the case with HR. 3962, members of the Senate are likely to debate and weigh a variety of amendments and refinements to the provisions of S.1796 as it deliberates its enactment.  If you or someone else you know would like to receive updates about health care reform proposals and other related legislative, regulatory, and enforcement developments, please:

  • Register for this resource at the link above;
  • Join the Coalition for Responsible Health Policy group at linkedin.com to share information and input and join in other dialogue with others concerned about health care reform;
  • Share your input by communicating with key members of Congress on committees responsible for this legislation and your elected officials directly and by actively participating in and contributing to other like-minded groups; and
  • Be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here

If you have questions about or need assistance evaluating, commenting on or responding to health care or other legislative or regulatory reforms, or any other employment, compensation, employee benefit, workplace health and safety, corporate ethics and compliance practices, concerns or claims, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment/Employee Benefits  Practice Chair Cynthia Marcotte Stamer. 

Ms. Stamer has more than 22 years of experience advising and assisting business, government and other clients to evaluate and respond to health care, pension reform, workforce and other proposed or adopted changes in federal or state health care, employee benefit, employment, tax and other federal and state laws.  A member of the leadership council of the American Bar Association Joint Committee on Employee Benefits, Chair of the ABA Real Property, Probate & Trust Section and Employee Benefits & Compensation Group and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group Ms. Stamer is highly regarded legal advisor, policy advocate, author and speaker recognized both nationally and internationally for her more than 20 years of work assisting U.S. public and private employers, health care providers, health insurers, and a broad range of other clients to respond to these and other health care, employee benefit and workforce public policy, regulatory and compliance and risk management concerns within the U.S. as well as internationally.  Her work includes extensive involvement providing input and assistance about health care, workforce, pensions and social security and other reforms domestically and internationally.  In addition to her continuous involvement in U.S. health care, pensions and savings, and workforce policy matters, Ms. Stamer has served as an advisor on these matters internationally.  As part of this work, she served as a lead advisor to the Government of Bolivia on its social security reform as well as has provided input on ethics, medical tourism, workforce and other reforms internationally.

In addition to her extensive work on health and other employee benefit matters, Ms. Stamer also is Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization and has continuously has advised and represented employers and others on labor and employment, compensation, employee benefit and other personnel and staffing matters throughout her career. Ms. Stamer is experienced with assisting employers and others about compliance with federal and state equal employment opportunity, compensation and employee benefit, workplace safety, and other labor and employment, as well as advising and defending employers and others against tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the IRS, Department of Labor and other federal and state regulators. Ms. Stamer is a widely published author and popular speaker on health plan and other human resources, employee benefits and internal controls issues.   Her work has been featured and published by the American Bar Association, BNA, SHRM, World At Work, Employee Benefit News and the American Health Lawyers Association.  Her insights on human resources risk management matters have been quoted in The Wall Street Journal, the Dallas Business Journal, Managed Care Executive, HealthLeaders, Business Insurance, Employee Benefit News and the Dallas Morning News.

If your organization needs assistance with monitoring, assessing, or responding to these or other health care, employee benefit or human resources reforms,  please contact Ms. Stamer via e-mail here, or by calling (214) 270-2402.  For additional information about the experience, services, publications and involvements of Ms. Stamer specifically or to access some of her many publications, see here. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.

Other Information & Resources

We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here.  Some other recent updates that may be of interested include the following, which you can access by clicking on the article title:

Proposed Chemical Facility Anti-Terrorism Bill Would Obligate Chemical Facilities To New Background Check, HR & Other Safety & Security Safeguards

IRS Rules For Employer Reporting Of Wages Paid to Nonresident Alien Employees Performing Services In U.S. Change

House Passes Affordable Health Care For America, Health Care Reform Debate Focus Now Moves To The Senate

SHRM Tells Members Say “NO!” To Pelosi-Backed Health Care Reform

IRS Updates Procedures Qualifying Small Employers Can Use To Qualify To Report Employment Taxes Annually Rather Than Quarterly

OSHA Proposes To Change Hazard Communication Standard

IRS Proposes Changes In Actuarial Enrollment Standards For Performance of Actuarial Services Under the Employee Retirement

EEOC Prepares To Broaden “Disability” Definition Under ADA Regulations

IRS Proposes To Update Regulations On Exclusion of Damages Received on Account of Personal Physical Injuries or Physical Sickness To Eliminate Tort Test

OSHA Final Rule Updates OSHA Personal Protective Equipment Standards

DOL Proposes Changes To H-2A Temporary & Seasonal Agricultural Nonimmigrant Worker Certification Procedures & Related Rules

ADAAA Amendment Broader ADA “Disability” Definition Not Retroactive, Employer Action Needed To Manage Post 1/1/2009 Risks

New Study Shares Data On Migrant Health Care Challenges Along The Border

Employer & Other Health Plans & Other HIPAA-Covered Entities & Their Business Associates Must Comply With New HHS Health Information Data Breach Rules By September 23

HHS Reassignment Of HIPAA Enforcement Duties Signals Rising Seriousness of Enforcement Commitment

Speak Up America: Where & How To Read & Share Your Feedback About The Health Care Reform Legislation

For important information concerning this communication click here.   If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.

©2009 Cynthia Marcotte Stamer. All rights reserved. 


Register Now For HITECH Act Health Data Security & Breach Update: Learn What You Must Do This Month To Comply With New Health Data Breach Regulations

September 2, 2009

September 10, 2009 – Noon to 1:30 P.M. Central Time       Participate In Person or Via Remote!

Health care providers, health plans, health clearinghouses and their business associates (Covered Entities) must comply with the new “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) by September 23, 2009. 

Catch up on what the Breach Rule means for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Thursday, September 10, 2009 from Noon to 1:30 P.M. Central Time for a registration fee of $45.00. Registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201.  For information about registering for this program or other questions here,

The Breach Rule requires Covered Entities to notify affected individuals following a “breach” of “unsecured” protected health information. Just published August 24th, the Breach Regulation is part of a series of guidance that HHS is issuing to implement new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).  The briefing will cover:

  • Who must comply, health plans, employers, others?
  • What your organization must do
  • How to qualify protected health information as exempt from the breach regulations as “secure” protected health information
  • What is considered a breach of unsecured protected health information
  • What steps must a covered entity take if a breach of unsecured protected information happens
  • What liabilities do covered entities face for non-compliance
  • What new contractual requirements, policies and procedures Covered Entities and Business Associates will need
  • How the Breach Regulation, the Privacy Regulation, impending FTC red flag rules and state data breach and privacy rules interrelate
  • Other recent developments
  • Practical tips for assessing, planning, moving to and defending compliance
  • Participant questions
  • More

About The Presenter

The program will be presented by Curran Tomko and Tarski LLP Health Care & Employee Benefits Practice Leader and Partner Cynthia Marcotte Stamer.  Ms. Stamer is nationally known for her work, publications and presentations on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts.  Chair of the ABA RPTE Employee Benefits & Other Compensation Committee, a ABA Joint Committee on Employee Benefits Council Representative, Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 20 years experience advising clients about health and other privacy and security matters.  A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters.  Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here

We hope that this information is useful to you.  If you need assistance monitoring, evaluating or responding to these or other compliance, risk management, transaction or operation concerns, please contact the author of this update, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or another Curran Tomko Tarski LLP Partner of your choice.

Other Helpful Resources & Other Information 

If you find this of interest, you also be interested in one or more of the following other recent articles published on our electronic Curran Tomko Tarski LLP publications available for review here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@cttlegal.net.

©2009 Solutions Law Press.   All rights reserved.


Employer & Other Health Plans & Other HIPAA-Covered Entities & Their Business Associates Must Comply With New HHS Health Information Data Breach Rules By September 23

August 24, 2009

Employer and other health plans, health care providers, health clearinghouses and their business associates must start complying with new federal data breach notification rules on September 23, 2009.   

The new “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) published here  in today’s Federal Register requires health plans, health care providers, health care clearinghouses and their business associates (Covered Entities) covered under the personal health information privacy and security rules of the Health Insurance Portability & Accountability Act (HIPAA) to notify affected individuals following a “breach” of “unsecured” protected health information.The Breach Regulation is part of a series of guidance that HHS is issuing to implement new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA). 

You are invited to catch up on what these new rules mean for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Wednesday, September 9 2009 from Noon to 1:30 P.M. Central Time.  

HITECH Act Data Breach and Unsecured PHI Rules 

Published in the August 24, 2009 Federal Register, the new Breach Regulation implements the HITECH Act requirement that Covered Entities and their business associates notify affected individuals, the Secretary of HHS, and in some cases, the media, when a breach of “unsecured protected health information” happens and the form, manner, and timing of that notification. Covered Entities must begin complying with the new Breach Regulation on September 23, 2009.

Part of a series of new HHS rules implementing recent changes to HIPAA enacted under the HITECH Act to strengthen existing federally mandates requiring Covered Entities to safeguard protected health information, the Breach Regulation will obligate Covered Entities and business associates to provide certain notifications following a breach of “protected health information” that not secured at the time of the breach through the use of a technology or methodology meeting minimum standards issued by HHS pursuant to other provisions of the HITECH Act.

Under the HITECH Act, the breach notification obligations contained in the Breach Notification only apply to a breach of “unsecured protected health information.” The Breach Regulation exempts breaches of protected health information that qualify as “secured” under separately issued HHS and Federal Trade Commission (FTC) standards for encryption and destruction of protected health information from its breach notification requirements.  

 For purposes of the HITECH Act, electronic protected health information is considered “unsecured” unless the Covered Entity has satisfied certain minimum standards for the protection of that data established pursuant to the HITECH Act.  Earlier this year, HHS and the FTC issued interim rules defining the minimum encryption and destruction technologies and methodologies that Covered Entities must use to render protected health information unusable, unreadable, or indecipherable to unauthorized individuals for purposes of determining when protected health information is “unsecured” for purposes of the HITECH Act.  Concurrent with its publication of the Breach Regulation, HHS also released guidance updating and clarifying this previously issued guidance. 

Read the Breach Regulation here .  To review the HITECH Act Breach Notification Guidance and Request for Information, see here .

Register For September 9, 2009  “HITECH Act Health Data Security & Breach Update”

Interested persons are invited to register here now  to learn what these new rules mean for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Wednesday, September 9, 2009 from Noon to 1:30 P.M. Central Time. For a registration fee of $45.00, registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201.  For questions or other information about this program, e-mail here.

Conducted by Curran Tomko and Tarski LLP Partner Cynthia Marcotte Stamer, the briefing will cover: 

  • Who must comply
  • What your organization must do
  • How to qualify protected health information as exempt from the breach regulations as “secure” protected health information
  • What is considered a breach of unsecured protected health information
  • What steps must a covered entity take if a breach of unsecured protected information happens
  • What liabilities do covered entities face for non-compliance
  • What new contractual requirements, policies and procedures Covered Entities and Business Associates will need
  • How the Breach Regulation, the Privacy Regulation, impending FTC red flag rules and state data breach and privacy rules interrelate
  •  Other recent developments
  • Practical tips for assessing, planning, moving to and defending compliance
  • Participant questions
  • More

About The Presenter

The program will be presented by Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.  Ms. Stamer is nationally known for her work, publications and presentations on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts. 

 Past Chair of the ABA Health Law Section Managed Care & Insurance Section and currently the Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Section and a Council Representative of the ABA Joint Committee On Employee Benefits, Ms. Stamer has more than 20 years experience advising clients about health and other privacy and security matters.  A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters.  Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.  

We hope that this information is useful to you.  If you need assistance monitoring, evaluating or responding to these or other compliance, risk management, transaction or operation concerns, please contact the author of this update, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or another Curran Tomko Tarski LLP Partner of your choice.

Other Helpful Resources & Other Information

If you found these updates of interest, you also be interested in one or more of the following other recent articles published on our electronic Curran Tomko Tarski LLP publications available for review here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@cttlegal.com.

©2009 Cynthia Marcotte Stamer.   All rights reserved.