April 8, 2026
Human resources and other business leaders, using or allowing workforce members to CHAT-GPT or other artificial intelligence (“AI”) tools to research, make decisions or to support other activities should ensure that their organizations and their teams understand and manage the resulting evidentiary consequences and responsibilities these activities create.
In today’s AI age, Human Resources directors and other business leaders in increasingly are encouraged to turn to AI tools for a quick understanding of the law, drafting of documents, and a host of other human relations and business functions traditionally performed with the assistance of legal counsel. Although AI tools can be valuable under the right situations and properly used, the use of AI tools, along side of or as a substitute for legal advice obtained within the scope of attorney client privilege can carry a number of inherent risks and challenges. Human Resources and other leaders and their organization should carefully evaluate and manage these consequences before using AI.
AI Searches May Be And Create Evidence
AI prompts, outputs, and related metadata often qualify as discoverable electronically stored information (“ESI”) in litigation, regulatory audits, and enforcement proceedings.
Under the Federal Rules of Civil Procedure, discoverable information includes electronically stored information (ESI”) relevant to claims or defenses. See Fed. R. Civ. P. 26(b)(1); 34(a)(1)(A). Once litigation is reasonably anticipated, organizations must preserve relevant ESI under Federal Rules of Civil Procedure. See e.g.,Hoffer v. Tellone, 128 F.4th 433 (2d Cir. 2025).
AI searches and other interactions and the information and other outputs they produce generally qualify as ESI for purposes of the Federal Rules of Civil Procedure, Federal Rules of Evidence, (hereafter collectively the “Federal Rules”) and comparable federal and state litigation procedural rules.
Likewise, federal and state regulatory and enforcement agencies tend to consider AI and other ESI evidence covered by document retention and discovery rules.
Where applicable, these Federal Rules and agency rules generally include AI and other ESI evidence organizations must preserve, identify, and subject to discovery or other production like traditional evidence in litigation and agency audits and investigations.
ESI evidence generally includes any data stored in electronic form—such as emails, texts, spreadsheets, social media, and Internet of Things (“IoT”) data. As broadly construed by the courts, courts already long have admitted:
- Internet search histories;
- Internal chats and Slack messages;
- Draft documents; and
- Deleted files.
AI searches are simply the next evolution of this evidence category. AI records and information considered ESI can include;
- AI prompt histories;
- Generated outputs;
- Embedded AI-assisted drafts;
- Platform logs (if accessible); and
- Other records.
Organizations that fail to fulfill requirements for AI or other ESI early identification, data authentication and other requirements of Federal Rule of Evidence 902, the requirements of Federal Rule of Civil Procedure 37(e) regarding lost evidence, or other applicable requirements to preserve and produce ESI may result in sanctions, adverse inferences, and penalties under the Federal Rules. Similarly, organizations may incur evidentiary sanctions, regulator penalties, and other adverse consequences for failing to identify, retain and produce ESI from AI or other sources in government audits and investigations. Common sanctions include:
- Monetary sanctions;
- Evidence preclusion;
- Adverse inference jury instructions; and
- Other authorized sanctions.
See, e.g., Jones v. Riot Hosp. Grp. LLC, 95 F.4th 730 (9th Cir. 2024) (affirming dismissal as sanction for intentional destruction of ESI); Maziar v. City of Atlanta, No. 1:21-cv-02172, 2024 WL 197561 (N.D. Ga. June 10, 2024) (denying summary judgment and awarding fees based on loss of text messages); McBride v. Moore, No. 2:23-cv-02904, 2024 WL 1136429 (C.D. Cal. Feb. 23, 2024) (denying sanctions where ESI not shown lost or duty not triggered). Gregory v. State of Montana, No. 22-____ (9th Cir. 2024) (reversing sanctions imposed outside Rule 37(e); emphasizing Rule 37(e) as exclusive remedy for ESI spoliation); DR Distribs., LLC v. 21 Century Smoking, Inc., 513 F. Supp. 3d 839 (N.D. Ill. 2021) (recognizing financial prejudice from spoliation and awarding fees); Bistrian v. Levi, 448 F. Supp. 3d 454 (E.D. Pa. 2020) (Rule 37(e) provides exclusive framework for ESI spoliation); Fast v. GoDaddy.com LLC, 340 F.R.D. 326 (D. Ariz. 2022) (failure to preserve mobile device data warranted sanctions).
These and other related cases alert organizations that AI and other modern data sources are squarely within ESI. Courts treat AI, texts, mobile data, and app-based communications as discoverable ESI.
The precedent reflects that the best opportunity to position your organization to show the reasonability of the actions taken is through the existence and enforcement of policies before and during the use of the AI tool.ESI preservation obligations depend on foreseeability, control, and access to data. When deciding the consequences of the unavailability or failure to produce ESI, the determination regarding failure to take “reasonable steps” is fact-intensive. Of course, the failure to retain the documentation will be particularly likely to be found unreasonable where the party was under a statutory, regulatory, ethical, contractual, or other pre-existing obligation to preserve the evidence.
Also, courts require proof of intent to deprive before imposing the most severe adverse inference or dismissal sanctions, a lack of proof of intent to deprive the request requesting party of evidence does not mean there will not be consequences for the non-producing party. Negligent failure to retain and produce ESI and other evidence still carries consequences. Even without bad faith, courts may impose curative measures, fees, or evidentiary limitations.
Similarly, the U.S. Department of Justice Securities and Exchange CommissionDepartment of Health and Human Services Office for Civil Rights Equal Employment Opportunity Commission and other federal and state government agencies are increasingly sophisticated in digital evidence collection.
Among other things, organizations should be prepared to routine and produce documentation and data obtained, utilized, or otherwise interacting with AI tools and it’s associated meta-data and other components to respond to litigation and regulatory request for a broad range of data and information. Optimally the data captured and retained should include, but it’s not necessarily limited to:
- AI usage policies;
- Employee and other agent AI interaction records;
- Evidence of AI and other relevant governance and training; and
- Data protection controls.
Consequently, failure to govern, identify, preserve and produce AI-generated and AI-assisted records appropriately can expose organizations to spoliation sanctions, adverse inference instructions, regulatory penalties, loss of privilege protections, and expanded liability exposure.
In recognition of the possibility that AI tool interactions may give rise to obligations to retain and produce ESI evidence created as a consequence of that interaction, or organization should work with legal counsel to develop an administer appropriate practices to monitor, identify, retain, manage, and where necessary produce this ESI evidence.
AI Tools Create Evidence
Beyond considering and meeting documentation and other evidently protection, preservation, and production responsibilities, organizations and their human resources and other leaders need to recognize that the use of the tool itself and its outputs creates evidence that may give rise to legal opportunities, risks, and obligations for the organization.
Organizations should keep in mind that the use of AI tools creates legal evidently risks because AI tools typically generate synthesized responses (not just links) that often incorporate user inputs into outputs that may reflect user intent, knowledge, biases and opinions, and decision-making. This often makes AI interactions particularly valuable evidence for:
- Intent (e.g., “how to terminate employee without legal risk”) Knowledge (awareness of compliance obligations) State of mind (deliberate vs. negligent conduct);
- Knowledge (awareness of compliance obligations);
- State of mind (intentional, willful, or deliberate vs. negligent conduct)
The potential risks of this and other evidence is heightened by the fact that the evidence created may arise not only from the actions taken by the user of the AI tool, but also may be inherently built into the design of the AI tool itself or the databases or other reference materials that it accesses, not all of which may be transparent to the user or the organization that employs the user. These risks are further heightened when the AI tool use is not conducted internally within the organization by its employee, but rather is a tool utilized by a consultant or other third-party provider conducting activities of a sensitive nature on behalf of the organization, such as a recruiting company, investigation, company, or other service provider.
These unique characteristics of AI make it advisable that organizations recognize and manage potentially heightened exposures that employee or other agent use AI tools can produce for the organization in a wide range of sensitive areas.
Examples of queries that can become “smoking gun” evidence include but are not limited to:
- In employment or other workforce administration searches, AI queries such as “How to terminate employee with medical condition,” ‘How to avoid claims when, terminating older, disabled, complaining, injured or other employee with protected status, or the like can be evidence of discriminatory or other adverse intent;” or “How to beat a union organizing campaign;”
- Compliance & Regulatory searches such as “How to structure payments to avoid reporting requirements,” “HIPAA penalties for disclosure; searches about compliance or looking for compliance loophole; searches where company researched sanctions for noncompliance in areas involved in litigation or enforcement; or searches on risk management that could be evidence the organization saw but chose not to follow rules or standards or otherwise looked for or acted to circumvent compliance or disregarded interpretations less favorable to chosen challenged course of action;
- Litigation or Other Defense Strategy searches or tools such as “How to defeat a whistleblower claim,” “Ways to minimize damages in lawsuit” “Protecting your assets from IRS or in bankruptcy,” “How to conceal” or How to hide” orthe like can harm the organization’s interest by showing adverse intent, willfulness, or other motive or state of mind;
- Litigation case law, enforcement, argument drafting, or other actions that could reveal or provide insight on sensitive litigation strategies or their strengths or weaknesses;
- Financial & Tax searches such as “Aggressive tax strategies unlikely to be audited,” or “contract terms to reclassify employee to contractor,” “Structure transaction to avoid disclosure” or the like; and
- Other searches or tool uses that could reflect improper, intent, or document improper activities, such as how to hide evidence, how to create a bomb, how to poison somebody or that creates a record of conduct such as edits to revise data or documentation in reports or records, where the changes are tracked and retained.
Given these other risks, organizations should carefully consider and manage these and other risks when deciding whether, when, how and what AI tools their organizations allow their people to use, who gets to use what tools, designate and train those authorized to use these tools appropriately, and design and implement appropriate tools to track, capture, retain and manage these records of AI use and their implications. Optimally, the planning should identify and work to manage the creation and preservation of evidence and related AI ESI required or otherwise helpful to meet, applicable, regulatory, contractual, statutory, or other requirements in a manner that minimizes the creation of evidence that could call into question the compliance or other appropriateness of the organizations actors.
Privilege and Confidentiality Risks
Asking AI tools to answer legal questions or provide guidance in legal advice obtained within the scope of attorney. Client privilege also can enhance the exposure for the organization and it’s actors because of the implications of that Youts on the availability of attorney-client privilege for the activities and information obtained. Using AI tools and output also can have implications on the ability of an organization to protect legal advice and work product developed and shared within the scope of attorney privileges from discovery in judicial or regulatory actions. Organizations need to recognize risk to the confidentiality of legal advice or work product that entering sensitive legal questions or information into public AI tools not specifically designed and used outside the scope of the attorney-client relationship to avoid creating problematic evidence, disclosing discussions or work product that otherwise might qualify for protect against discovery in litigation or agency proceedings under the attorney-client privilege or attorney work product rules, or both.
Searches conducted by organization employees, consultants, or other agents or representatives about the law, strategies, or legal risks and consequences without or outside the scope of an attorney-client relationship generally can be discovered and used as evidence. Consequently, organizations should regulate the use by officers, directors, compliance officers, human resources directors, consultants, non-legal investigators and auditors and others of AI tools, internet or other searches to investigate the law or legal strategies independent of or outside the scope of attorney-client privilege.
Particularly risky scenarios include:
- In-house counsel, Human Resources, risk management or compliance staff using public AI tools;
- Employees seeking legal guidance outside approved channels;
- Consultants, contractors, and other vendors use of AI in performing tasks or tools;
- Embedded AI in software or other tools; or
- Uploading contracts, PHI, or proprietary data into AI systems.
Additionally, organizations and others communicating or working with legal counsel on behalf of the organization within the scope of attorney-client privilege to design strategies or investigate or defend actions generally should not use AI tools to conduct their own legal research or analysis without authorization and direction of the legal counsel to avoid forfeiting attorney-client privilege and work product protections.
If the required confidentiality is preserved, the attorney-client privilege and work product privileges rules can protect confidential communications between a client and its attorney and work product prepared for risk management, defense or other purposes of the legal engagement against disclosure in litigation or other proceedings in many circumstances. However these protections are lost if the communication or work product is disclosed to or discussed with third parties outside the attorney-client relationship. Entering factual information, conducting legal searches, or using AI tools outside the attorney-client relationship, not specifically designed to preserve confidentiality, or both to draft or evaluate legal documents, research, drafts, or strategies generally is considered a third party disclosure that can waiver or undermine the privilege for the specific information input to the AI tool as well as potentially related communications or work product.
For these and other reasons, organizations and individuals generally should resist the temptation to use AI tools to evaluate legal strategies, advice or work product.
Trade Secret, HIPAA and Other Data Privacy and Use Exposures
Human Resources and other leaders also must keep in mind their organization’s responsibilities to respect other organizations, intellectual property, to safeguard the confidentiality and security of data, and their organization’s need to protect its own intellectual property.
AI tool enthusiasts promote AI tools as substitutes for legal advice and other paid services. While asking AI to write a “free” policy or contract may seem a great way to save legal or other consulting, licensing or other costs, human resources and other leaders and their organizations must keep in mind that not all data, information and resources obtained through a ChatGPT or other AI search is shareware. Most nongovernmental data bases, contractual firms, tools, templates and other materials accessed through AI searches are or incorporate materials owned or subject to copyrights or other intellectual property protections of third parties. Unlicensed use of these resources can expose their organizations to copyright and other intellectual property infringement liability.
Furthermore, human resources and other executives choosing to use materials drafted using AI tools or otherwise acquired off of the Internet or other sources without legal advice to recognize that acquired materials and resources may not be currently compliant, appropriately tailored to their use, or contain other deficiencies for utilization in their organizations. These deficiencies can arise from a number of sources. For one thing, the queries input by the user may not be sufficiently tailored to adequately represent all of the material considerations necessary to tailor he organizations, questions, and the AI response to the needs of the organization. Also, because AI databases often times include a broad range of historical data, AI responses may rely upon outdated, legal or operational presumptions incorporated into these historical policies when they no longer are appropriate for use in your organization. Additionally, the response of AI may draw from a wide range of sources, including many of which may be sample policies not drafted by qualified individuals with adequate expertise to fully understand the legal and operational implications of the policy and properly draft a policy appropriate for use in the organization, acquiring the form or materials off of the Internet.
Beyond suitability of the information where tool obtained through the AI search itself, unlicensed use of the response, may expose your organization to liability for violating other organizations or authors, intellectual property rights. AI searches can and often do access and incorporate data and other resources protected by third party copyright,trade secrets, HIPAA or other confidentiality, or other safeguards. Accordingly, accessing or using data bases, sample language or forms, or other materials without proper licensing or attribution may trigger liability to individuals and organizations for breaches of these intellectual property rights.
A separate concern arising from the use of AI tools in HR and other business operations to evaluate, formate or otherwise process sensitive data also creates potentially serious risks when theof these tools involves allowing the AI tool to access or uploading the confidential or other sensitive information into the tool. Human resources and other leaders must exercise care not to share inappropriately and to help their organizations use policies and processes to prevent their people’s use of AI tools to avoid violating statutory, regulatory or contractual confidentiality requirements, compromising confidential information, their own or business partner’s trade secrets, proprietary information and other intellectual property, or both.
Furthermore, uploading or sharing trade secrets, Health Insurance Portability and Accountability (“HIPAA”) protected health information, confidential employee, tax or other regulated information, trade secrets or other confidential or sensitive data into AI tools or searches without proper controls may itself breach of HIPAA, trade secret, federal or state privacy laws (e.g., biometric, consumer data laws) or other statutory, regulatory, ethical or contractual data privacy or confidentiality obligations. Additionally, allowing AI tools to access and interact with electronic data or systems frequently triggers data and systems security obligations under HIPAA, the Fair and Accurate Credit Transactions Act, Equal Employment Opportunity and other Human Resources and benefits data, electronic crimes, federal and state government contract, and a broad range of international, federal and state cybersecurity laws and regulations, and other government and private contractual and program participation, statutes, and regulations.
Given these concerns, organizations should avoid using AI tools that require uploading customer, financial, sales, or other data or information that the organization considers its own trade secrets or proprietary information into AI data bases or tools that do not adequately safeguard the ownership and confidentiality of that information.
AI Tool Hallucinations and Other Output Deficiency Risks
AI tools and the output they produce are not always reliable. Among other things, certain AI tools are known to:
- Lack the ability to distinguish between more and less credible information sources;
- Create plausible-sounding but entirely fabricated facts, news articles, legal authorities, or academic citations;
- Create biased, false, incomplete, or inaccurate responses when models lack complete training data, are subjected to biased data, have limited context, ir under other circumstances;
- Create false positives such as I dentifying a threat (e.g., in fraud detection) that is not actually present.
- Fail to detect a real threat (e.g., in medical imagery) or report other false positives;
- Fabricate non-existent, fake information or other incorrect or inaccurate information; and
- Engage in hallucinations or other errors
The quality of the response, at best, often varies based on the quality and precision of the question asked. Lack of experience and careful structuring of the questions and inquiries made, lack of specialized knowledge necessary to structure the inquiry to be tailored to the specific needs at hand, and other limitations and concerns about the searches can undermine the accuracy, completeness and relevance of the AI tools output. Accordingly, response obtained by AI tools, often are unreliable and must be validated by a person experienced and skilled. The validation process should be conducted in such a matter that it preserves evidence that changes and responses are made based on thoughtful and reasonable determinations that the evidence obtained was not applicable or reliable, to minimize susceptibility to claims that decisions and actions were cherry picking based on improper intent rather than appropriate quality assurance processes. Organizations allowing the use of the tools and the individuals utilizing them need to understand and appropriately manage the very operational, legal in other risks of these deficiencies and error errors when utilizing AI tools.
Adopt And Enforce AI Policies To Manage AI Tool Use Responsibilities and Risks
Considering these and other responsibilities, human resources and other leaders and their organizations should use care to decide when, how, why, and by whom it allows AI tools to be used in or on behalf of its organization and provide appropriate steps to manage those uses in the resulting ESI to fill its legal obligations and manage its legal and operational risks. Because this process of itself could be evidence impacting, the organizations, legal exposures, organizations generally should work with qualified legal counsel within the scope of attorney-client privilege to work define and enforce policies and practices, to promote the organization’s legal and operational interests and manage the resulting legal obligations.
The author of this update, Cynthia Marcotte Stamer has decades of experience advising and representing governmental and private entities, AI and other technology, workforce and other legal and operational compliance, risk management and other operational and enforcement matters. If you have questions or need advice or help evaluating or addressing these or other compliance, risk management, or other concerns, contact her.
For More Information
We hope this update is helpful. For more information about these or other legal, contractual or operational compliance or risk management, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452-8297.
Solutions Law Press, Inc. invites you receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for her more than 35 years of health industry and other management work, public policy leadership and advocacy, coaching, teachings, and publications including leading edge work on workforce and other risk management and compliance.
Ms. Stamer’s work throughout her career has focused heavily on working with businesses domestically and internationally on employment, benefits, technology, data confidentiality, privacy, and security, and other Federal Sentencing Guidelines and other workforce management, regulatory and public policy and other legal and operational concerns.
Author of many highly regarded compliance, training and other resources on these and other operations, risk management, compliance and government affairs concerns, Ms. Stamer is widely recognized for her thought leadership and advocacy on these matters.
In addition, Ms. Stamer currently or previously served as the American Bar Association (“ABA”) Joint Committee on Employee Benefits OCR annual agency scribe and a Council Representative, International Section International Employment Law Committee Chair and International Life Sciences and Health Committee Chair, ABA TIPS Medicine and Law Committee Chair, ABA Health Law Section Managed Care & Insurance Interest Group Chair, former Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, and a host of other professional and civic leadership roles. She is a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her extensive publications and thought leadership as well as leadership involvement in a broad range of other professional and civic organizations.
For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press™
Solutions Law Press™ provides health care, human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on health care, leadership, governance, human resources, employee benefits, data security and privacy, insurance, and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press™ resources.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general information and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation considering the specific facts and circumstances presented in their unique circumstance at the particular time. No comment or statement in this publication is to be construed as legal advice or admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law constantly and often evolves, subsequent developments that could impact the currency and completeness of this discussion are likely. The author and Solutions Law Press, Inc. disclaim and have no responsibility to provide any update or otherwise notify anyone of any fact or law specific nuance, change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2026 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on Managing Evidentiary Consequences Of AI Use |
Accommodation, ADA, adea, Age Discrimination, Antitrust, Attorney-Client Privilege, board of directors, Brokers, Civil Monetary Penalties, Civil Rights, Claims, Claims Administration, compliance, conflict of interest, Corporate Compliance, corporate governance, Cybercrime, Cybersecurity, Data Breach, Data breach, Data Security, defined benefit plan, defined contribution plan, Department of Defense, DFAR, directors, Disability, Disability Discrimination, Disability Plans, Discovery, Discrimination, Diversity, Drug Testing, EBSA, Education, EEOC, Electronic Medical Record, Employee Benefits, Employee Handbook, Employer, Employers, Employment, Employment Agreement, Employment Discrimination, Employment Policies, ERISA, Evidence, Executive Compensation, Fair Credit Reporting Act, Fair Labor Standards Act, Federal Sentencing Guidelines, FICA, Fiduciary Responsibility, FLSA, FMLA, GINA, Government Contractors, government employer, government plan, group health plan, health benefit, health Care, health insurance, HIPAA, HIPAA, Hiring, Human Resources, I-9, Identity Theft, Internal Controls, Internal Investigations, Labor Management Relations, Leave, Licensing, Management, OFCCP, OFCCP, OSHA, Protected Health Information, Provider, provider contracting, Public Accommodation, Public Policy, Rehabilitation Act, Reporting & Disclosure, Retaliation, Risk Management, Safety, tpa, Union, Union certification, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
April 14, 2025
The $350,000 paid by Northeast Radiology, P.C. (“NERAD”) provides the latest warning to health plans, health care providers, healthcare clearinghouses (“Covered Entities”) and their business associates (collectively “Regulated Entities”) they risk costly fines and other costs for failing to maintain the up-to-date risk assessments required by the Health Insurance Portability & Accountability Act (“HIPAA”).
Following up on the five other previous Risk Analysis Initiative enforcement actions and settlements recently announced by the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) and OCR’s publication of proposed rules to significantly tighten HIPAA’s Risk Analysis and other requirements, the settlement with medical imaging center NERAD sends a strong warning to health plans and other Regulated Entities to clean up and strengthen their Risk Analysis and other HIPAA Security Rule compliance.
$350,000 NERAD Risk Analysis Settlement Latest Product Of New Enforcement Initiative
The sixth Risk Analysis Initiative enforcement action announced by OCR in recent months, the NERAD settlement resolves an OCR Risk Analysis Initiative enforcement action arising from OCR’s investigation of a breach of ePHI stored on NERAD’s Picture Archiving and Communication System (“PACS”) server for storing, retrieving, managing, and accessing radiology images.
OCR initiated its investigation of NERAD after receiving a NERAD breach report about a breach of unsecured ePHI in March 2020. NERAD reported that between April 2019 and January 2020, unauthorized individuals accessed radiology images stored on NERAD’s PACS server. NERAD notified the 298,532 patients whose information was potentially accessible on the PACS server of this breach. OCR’s investigation found that NERAD had failed to conduct an accurate and thorough Risk Analysis to determine the potential risks and vulnerabilities to the ePHI in NERAD’s information systems.
To avoid potentially much greater HIPAA civil monetary penalties under the terms of the resolution agreement, NERAD paid OCR $350,000 and agreed to implement a corrective action plan that OCR will monitor for two years. Under the corrective action plan, NERAD will take steps to improve its compliance with the HIPAA Security Rule and protect the security of ePHI, including:
- Conducting an accurate and thorough Risk Analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI;
- Developing and implementing a risk management plan to address and mitigate security risks and vulnerabilities identified in its Risk Analysis;
- Developing and implementing a written process to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports;
- Developing, maintaining, and revising, as necessary, its written policies and procedures to comply with the HIPAA Rules; and
- Augmenting its existing HIPAA and security training program to all of its workforce members who have access to PHI.
OCR Turns Up Heat On HIPAA Risk Analysis Requirements & Enforcement
The HIPAA Privacy, Security, and Breach Notification Rules set forth the requirements that Regulated Entities must follow to protect the privacy and security of protected health information. Since the HIPAA Security Rule first took effect, risk analysis is one of the four required implementation specifications the Security Rule requires to fulfill its Security Management Process Standard’s requirement that regulated entities “[i]mplement policies and procedures to prevent, detect, contain, and correct security violations.”
Written Risk Analysis Longstanding Requirement
Although OCR only recently formally adopted a Risk Analysis Initiative, OCR’s regulatory guidance and enforcement actions have communicated clearly the necessity for each Regulated Entity to possess and maintain an adequate documented Risk Analysis. OCR guidance since has required Regulated Entities to conduct and document the required Risk Analysis to safeguard ePHI and avoid liability under the HIPAA Rule. The importance of fulfillment of the Risk Analysis requirement is driven home by OCR’s recent identification of Risk Analysis inadequacies as a basis for its assessment of civil monetary penalties or required resolution payments to settle HIPAA Security Rule violations following a breach of ePHI.
While the Security Rule does not currently dictate how frequently a regulated entity must perform Risk Analysis, a proposed rule published by OCR on December 27, 2024 seeks to amend the existing Security Rule to expand the requirement to require regulated entities to develop and revise a technology asset inventory and a network map that illustrates the movement of ePHI throughout the regulated entity’s electronic information system(s) on an ongoing basis, at least once every 12 months and in response to a change in the regulated entity’s environment or operations that may affect ePHI. Although OCR has not adopted this and other changes contained in the proposed rule, substantial evidence exists that it already regularly administers the Risk Analysis requirement with the expectation that regulated entities will perform Risk Analysis at least this frequently. For instance, current OCR resolution agreements require impacted organizations to conduct Risk Analysis to identify and address vulnerabilities at least annually, and more frequently as needed in response to signs of potential breach or susceptibility.
To fulfill the “Risk Analysis” implantation specification, the Security Management Process Standard requires Regulated Entities maintain appropriate administrative, physical, and technical safeguards for the confidentiality, integrity, and security of electronic protected health information (“ePHI”) based on an up-to-date conduct of an up-to-date accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by that organization (“Risk Analysis”).
The Security Rule requires Regulated Entities to document each Risk Analysis in writing, to maintain their Risk Analysis documentation for six years, and to make available Risk Analysis documentation to OCR upon request.
Among other things, the Risk Analysis implementation standard requires regulated entities adequately to:
- Identify where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems.
- Integrate Risk Analysis and risk management into the organization’s business processes.
- Ensure that audit controls are in place to record and examine information system activity.
- Implement regular reviews of information system activity.
- Utilize mechanisms to authenticate information to ensure only authorized users are accessing ePHI.
- Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate.
- Incorporate lessons learned from incidents into the organization’s overall security management process.
- Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.
OCR Heightens Risk Analysis Enforcement While Proposing Heightened Risk Analysis And Other Security Requirements
The proposed rule published by OCR on December 27, 2024 seeks to significantly broaden these original requirements of the Risk Assessment implementation standard. Under the proposed rule, a Regulated Entity’s Risk Analysis also would be required to include:
- Require the development and revision of a technology asset inventory and a network map that illustrates the movement of ePHI throughout the regulated entity’s electronic information system(s) on an ongoing basis, at least once every 12 months and in response to a change in the regulated entity’s environment or operations that may affect ePHI.
- Require greater specificity for conducting a risk analysis, including a written assessment that contains, among other things:
- A review of the technology asset inventory and network map;
- Identification of all reasonably anticipated threats to the confidentiality, integrity, and availability of ePHI;
- Identification of potential vulnerabilities and predisposing conditions to the regulated entity’s relevant electronic information systems;
- An assessment of the risk level for each identified threat and vulnerability, based on the likelihood that each identified threat will exploit the identified vulnerabilities; and
- A review of the technology asset inventory and network map.
Other changes included in the proposed rule would further heighten the Risk Analysis and other Security Standard requirements for Regulated Entities. For instance, the proposed rule would require Regulated Entities:
- To establish written procedures to restore the loss of certain relevant electronic information systems and data within 72 hours;
- To perform an analysis of the relative criticality of their relevant electronic information systems and technology assets to determine the priority for restoration;
- To establish written security incident response plans and procedures documenting how workforce members are to report suspected or known security incidents and how the regulated entity will respond to suspected or known security incidents;
- To implement written procedures for testing and revising written security incident response plans;
- To conduct a compliance audit at least once every 12 months to ensure their compliance with the Security Rule requirements;
- To require business associates to verify at least once every 12 months for covered entities (and that business associate contractors verify at least once every 12 months for business associates) that they have deployed technical safeguards required by the Security Rule to protect ePHI through a written analysis of the business associate’s relevant electronic information systems by a subject matter expert and a written certification that the analysis has been performed and is accurate;
- To encrypt ePHI at rest and in transit, with limited exceptions;
- To establish and deploy technical controls for configuring relevant electronic information systems, including workstations, in a consistent manner including deployment of anti-malware protection, removal of extraneous software, and disabling network ports in accordance with the regulated entity’s risk analysis;
- Use of multi-factor authentication, with limited exceptions;
- Vulnerability scanning at least every six months and penetration testing at least once every 12 months;
- Network segmentation;
- Separate technical controls for backup and recovery of ePHI and relevant electronic information systems;
- To review and test the effectiveness of certain security measures at least once every 12 months, in place of the current general requirement to maintain security measures;
- Business associates to notify covered entities (and subcontractors to notify business associates) upon activation of their contingency plans without unreasonable delay, but no later than 24 hours after activation;
- Group health plans to include in their plan documents requirements for their group health plan sponsors to: comply with the administrative, physical, and technical safeguards of the Security Rule; ensure that any agent to whom they provide ePHI agrees to implement the administrative, physical, and technical safeguards of the Security Rule; and notify their group health plans upon activation of their contingency plans without unreasonable delay, but no later than 24 hours after activation.
To help Regulated Entities understand and fulfill these responsibilities, OCR alone and in conjunction with the Office of the National Coordinator for Health Information Technology (“ONC”) also has published guidance like the HIPAA Security Risk Assessment (SRA) Tool. OCR guidance reflects that fulfillment of the Tool can help Regulated Entities may help defend but does not guarantee fulfillment of the Risk Assessment requirements, as the adequacy of the Risk Assessment always depends upon the unique facts and circumstances of the Regulated Entity at a particular time. This guidance confirms the importance of conducting timely and appropriate Risk Analysis in a manner that shows the Regulated Entity appropriately evaluated the risks to its e-PHI and acted reasonably in designing, administering, and updating that Risk Analysis to reasonably defend its e-PHI against breaches or other susceptibilities.
Recommended Actions For Health Plans & Other HIPAA-Regulated Entities
With the continued explosion in ransomware and other cyberthreats heightening the risk of experiencing a breach or other incident likely to draw the attention of OCR, each health plan or other Regulated Entity should take assess and confirm the adequacy of their current Risk Analysis, both to protect its ePHI and to promote its ability to defend its compliance with the HIPAA Security Rule’s Risk Analysis and other requirements in light of OCR’s heightened emphasis on Risk Analysis compliance and enforcement. For purposes of conducting this analysis, Regulated Entities generally will want to use a process like the following to structure their evaluation of their existing Risk Analysis to take advantage of the opportunity to use attorney-client privilege and other evidentiary rules to help protect discoverability of sensitive discussions about possible deficiencies in their existing Risk Analysis and discussions about potential tradeoffs considered in current or future Risk Analysis response:
- Engage legal counsel experienced with HIPAA and other cybersecurity-related risks and liabilities to advise and assist your organization in designing and administering your Risk Analysis processes and response within the scope of attorney-client privilege;
- Appoint and designate leadership and technical leadership for team responsible for design and administration of your organization’s initial and ongoing cybersecurity Risk Analysis and response (“Cyber-Risk Team”) and process for board and senior management reporting of the Cyber-Risk Team;
- Select and engage outside consulting service providers, cyber-liability insurers and other risk service providers expected to participate in the process; work with qualified legal counsel to contract with these business associates to include the business associate agreement and other reassurances required by the HIPAA Privacy, Security and Breach Notification Rule and other performances, cooperation to provide and back services in accordance with agreed-upon protocols in the contract;
- Train Cyber-Risk Team in the appropriate processes for working with internal teams, outside service providers, leadership, and designated legal counsel to conduct Risk Analysis, investigation and response using attorney-client privilege and other evidentiary tools and processes to maximize defensibility;
- Require the Cyber-Risk Team conduct an updated, document assessment of cyber-risk within scope of attorney-client privilege and work with legal counsel to develop a documented cyber-risk policy that captures analysis and determinations for your justification for the size, scope and timing of your periodic Risk Analysis and rules and processes for interim risk identification, reassessments and response in reaction to potential cyber-risk signs between periodic Risk Analysis for presentation and approval by the Board taking into account the insights from published final and proposed guidance, enforcement actions and industry standards;
- Require, oversee and enforce Cyber-Risk Team’s documented administration of the initial and subsequently required Risk Analysis and response pursuant to the adopted cyber-risk policy to identify vulnerabilities and work with legal counsel within the scope of privilege to document your analysis and justifications for addressing identified vulnerabilities and other required actions in response to identified susceptibilities or event;
- Review adequacy of incident detection and response arrangements, including reporting and response mechanisms, insurance and indemnification protection, and other critical elements for mitigation and recovery; and
- Other actions as warranted based on advice of counsel taking into account emerging threats, guidance, and risk susceptibility.
The author of this update, Cynthia Marcotte Stamer is an American College of Employee Benefits Counsel Fellow and attorney board certified in Labor and Employment Law by the Texas Board of Legal Specialization, nationally known and celebrated for her experience providing advice and representation on HIPAA and other risk management and compliance to employers and other health plan sponsors, health plans, health plan fiduciaries and administrators, health and other insurers, third party administrators, health care and other managed care providers and organizations, human resources and health plan technology, and other businesses about health plan design, administration, and other compliance, risk management and operational matters. If you have questions or need advice or help evaluating or addressing these or other compliance, risk management, or other concerns, contact her.
For More Information
We hope this update is helpful. For more information about these or other health or other employee benefits, human resources, or health care developments, please contact the author, Cynthia Marcotte Stamer, via e-mail or telephone at (214) 452-8297.
Solutions Law Press, Inc. invites you to receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.
About the Author
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation; Cynthia Marcotte Stamer is an attorney board certified in labor and employment law by the Texas Board of Legal Specialization, management consultant, author, public policy advocate and lecturer sought out by clients and industry and government leaders for her more than 35 years of health, insurance, employment and employee benefits and other industry management work, thought leadership, public policy and regulatory affairs advocacy, coaching, teaching, and publications on health and other employee benefits, health care, insurance, workforce and other risk management and compliance.
Along with her decades of legal and strategic consulting experience, Ms. Stamer also contributes her leadership and experience to many professional, civic and community organizations. Along with currently serving as Co-Chair of the ABA Real Property Trusts and Estates (“RPTE”) Section Welfare Plan Committee, Co-Chair of the ABA International Section International Employment Law Committee and its Annual Meeting Program Planning Committee, Chair Emeritus and Vice Chair of the ABA Tort Trial and Insurance (“TIPS”) Section Medicine and Law Committee, and Chair of the ABA Intellectual Property Section Law Practice Management Committee, her previous ABA leadership roles include more than a decade of service as a Scribe for the Joint Committee on Employee Benefits (“JCEB”) annual agency meetings with the Department of Health and Human Services and JCEB Council Representative, International Section Life Sciences Committee Chair, RPTE Section Employee Benefits Group Chair and a Substantive Groups Committee Member, Health Law Section Managed Care & Insurance Interest Group Chair, as TIPS Section Medicine and Law Committee Chair and Employee Benefits Committee and Workers Compensation Committee Vice Chair, Tax Section Fringe Benefit Committee Chair, and in various other ABA leadership capacities. Ms. Stamer also is a former Southwest Benefits Association Board Member and Continuing Education Chair, SHRM National Consultant Board Chair and Region IV Chair, Dallas Bar Association Employee Benefits Committee Chair, former Texas Association of Business State, Regional and Dallas Chapter Chair, a founding board member and Past President of the Alliance for Healthcare Excellence, as well as in the leadership of many other professional, civic and community organizations. She also is recognized for her contributions to strengthening health care policy and charitable and community service resolving health care challenges performed under PROJECT COPE Coalition For Patient Empowerment initiative and many other pro bono service involvements locally, nationally and internationally.
Ms. Stamer is the author of many highly regarded works published by leading professional and business publishers, the ABA, the American Health Lawyers Association, and others. Ms. Stamer also frequently speaks and serves on the faculty and steering committee for many ABA and other professional and industry conferences and conducts leadership and industry training for a wide range of organizations.
For more information about Ms. Stamer or her health industry and other experience and involvements, see http://www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press™
Solutions Law Press™ provides health care, insurance, human resources and employee benefit, data and technology, regulatory and operational performance, and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education. These include extensive resources on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press™ resources or training.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general information and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation considering the specific facts and circumstances presented in their unique circumstances at the particular time. No comment or statement in this publication is to be construed as legal advice or an admission. Solutions Law Press and its authors reserve the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law constantly and often rapidly evolves, subsequent developments that could impact the currency and completeness of this discussion are likely. Solutions Law Press and its authors disclaim and have no responsibility to provide any update or otherwise notify anyone of any fact or law-specific nuance, change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2025 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press.™ For information about licensing for republication, please contact the author directly. All other rights reserved.
Comments Off on 6th Risk Analysis Settlement & Other OCR Actions Warn Health Plans & Other HIPAA-Regulated Entities To Tighten Risk Analysis |
Association Health Plan, Attorney-Client Privilege, church plan, Civil Monetary Penalties, compliance, Corporate Compliance, Cybercrime, Cybersecurity, Data Breach, Data Security, Employee Benefits, Employers, ERISA, GINA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, Health IT, health plan, Health Plans, HIPAA, HIPAA, Identity Theft, Managed Care | Tagged: business, Cyber Security, Cybersecurity, Security, Technology |
Permalink
Posted by Cynthia Marcotte Stamer
November 3, 2022
The Centers for Disease Control released updated opiate prescription guidance today, loosening restrictions on prescription of the pain management narcotics under certain conditions.
Ironically the new guidance loosening opiate prescription guidelines comes on the heels of the announcement yesterday of sellements of opiate litigation against CVS and Walgreens brought by multiple states’ seeking to recover states’ costs arising from citizens ‘ addicted to opiates.
Guideline changes are likely to implicate prescribing practices as well as some prescription drug coverages, as well as electronic recordkeeping and prescribing systems.
Among other things, depending on the plan design, the revised restrictions may have implications for prescription drug coverage design and practices. Easing availability even under these new standards also likely will increase access, creating additional concerns for employers and plans about addiction and associated costs. The introduction of potential opportunities for addiction raises particular concerns for health plans and their sponsors because of federal healthcare parity mandates for mental health and substance abuse coverage as well as Biden Administration recently announced expanded expectations of employers to provide accommodation and other changes to welcome individuals impacted by substance-abuse into their workplaces.
Slay tuned for more details about the new guidelines and other health care and life sciences relevant developments.
More Information
We hope this update is helpful. For more information about the these or other health or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297.
Solutions Law Press, Inc. invites you receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years of health industry and other management work, public policy leadership and advocacy, coaching, teachings, and publications.
A Fellow in the American College of Employee Benefit Counsel, Vice Chair of the American Bar Association (“ABA”) International Section Life Sciences and Health Committee, Past Chair of the ABA Managed Care & Insurance Interest Group, Scribe for the ABA JCEB Annual Agency Meeting with HHS-OCR, past chair of the the ABA RPTE Employee Benefits & Other Compensation Group and current co-Chair of its Welfare Benefit Committee, Ms. Stamer is most widely recognized for her decades of pragmatic, leading edge work, scholarship and thought leadership on health and managed care industry legal, public policy and operational concerns.
Ms. Stamer’s work throughout her 30 plus year career has focused heavily on working with health care and managed care, health and other employee benefit plan, insurance and financial services and other public and private organizations and their technology, data, and other service providers and advisors domestically and internationally with legal and operational compliance and risk management, performance and workforce management, regulatory and public policy and other legal and operational concerns.
For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources available here.
IMPORTANT NOTICE ABOUT THIS COMMUNICATION
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author and Solutions Law Press, Inc.™ reserve the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The author and Solutions Law Press, Inc.™ disclaim, and have no responsibility to provide any update or otherwise notify anyone any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication. Readers acknowledge and agree to the conditions of this Notice as a condition of their access of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2022 Cynthia Marcotte Stamer. Limited non-exclusive right to republish granted to Solutions Law Press, Inc.™
Comments Off on Eased Opiate Prescription Guidelines Could Impact Employers & Health Plans |
Corporate Compliance, EEOC, GINA, health plan, Health Plans, Mental Health, Mental Health Parity, Prescription Drugs |
Permalink
Posted by Cynthia Marcotte Stamer
February 15, 2018
Health plans and insurers, their service providers that act as business associates within the meaning of the Health Insurance Portability & Accountability Act (HIPAA) and employer and other health plan sponsors, fiduciaries, and other management leaders should heed the warnings contained in the new Resolution Agreement (FileFax Resolution Agreement) with former HIPAA business associate FileFax, Inc. announced by the Department of Health & Human Services (HHS) Office of Civil Rights (OCR) about their own need to ensure that they and their business associates comply with HIPAA’s business associate and other Privacy, Security, Breach Notification rules as well as the advisability of tightening up their risk management and oversight of business associates that handle protected health information (PHI).
Significant for business associates as what appears to be the first announced resolution agreement with a business associate directly charged by OCR with violating HIPAA and the second resolution agreement pursued and reached with a HIPAA-regulated entity in bankruptcy, the FileFax, Inc. Resolution Agreement OCR announced February 13, 2018 also contains critical lessons for Covered Entities about their dealings with their own business associates when read in conjunction with the April, 2017 resolution agreement the Center for Children’s Digestive Health (CCDH) agreed to resolve OCR charges CCDC, as a Covered Entity, violated HIPAA by allowing FileFax, Inc. to act as its business associate without adequately complying with HIPAA’s business associate requirements.
With widespread media coverage over large scale breaches of health care and other sensitive information placing further pressure upon OCR and other governmental agencies to act to protect Americans’ privacy and data fueling even greater demands for OCR and other agencies to take meaningful action to enforce HIPAA and other privacy and data security requirements, health plans, health care providers, health care clearinghouses (Covered Entities) and their business associates can expect OCR and other agencies to continue to turn up the heat on investigation and enforcement of HIPAA compliance.
In the face of these developments, Covered Entities, their business associates and those responsible for their leadership and operations need to recognize and take the necessary steps both effectively to manage their own HIPAA compliance and risk management as well as to anticipate and make provision to deal with the likelihood that they may face HIPAA responsibilities, exposures and other fallout from their own or another business partner’s breach of PHI or other sensitive data or other HIPAA violations, bankruptcy or other business distress, or other compliance or business event.
HIPAA Privacy, Security & Breach Notification Rule Responsibilities & Risks
The Privacy Rule requires that health plans, health care providers, health care clearinghouses (Covered Entities) and their vendors that qualify as “business associates” under HIPAA comply with detailed requirements concerning the protection, use, access, destruction and disclosure of protected health information. As part of these requirements, Covered Entities and their business associates must adopt, administer and enforce detailed policies and practices, assess, monitor and maintain the security of electronic protected health information (ePHI) and other protected health information, provide notices of privacy practices and breaches of “unsecured” ePHI, afford individuals that are the subject of protected health information certain rights and comply with other requirements as specified by the Privacy, Security and Breach Notification Rules. In addition, Covered Entities and business associates also must enter into a written and signed business associate agreement that contains the elements specified in Privacy Rule § 164.504(e) before the business associate creates, uses, accesses or discloses PHI of the Covered Entity. Furthermore, the Privacy Rule includes extensive documentation and keeping requirements require that Covered Entities and BAs maintain copies of these BAAs for a minimum of six years and to provide that documentation to OCR upon demand.
Violations of the Privacy Rule can carry stiff civil monetary penalties or even criminal penalties. Pursuant to amendments to HIPAA enacted as part of the HITECH Act, civil penalties typically do not apply to violations punished under the criminal penalty rules of HIPAA set forth in Social Security Act , 42 U.S.C § 1320d-6 (Section 1177).
Resolution Agreements the just announced FileFax Resolution Agreement allow Covered Entities and business associates to resolve potentially substantially larger civil monetary penalty liabilities that OCR can impose under the civil enforcement provisions of HIPAA for HIPAA violations through a negotiated settlement process. As amended by the HITECH Act, the civil enforcement provisions of HIPAA empower OCR to impose Civil Monetary Penalties on both Covered Entities and BAs for violations of any of the requirements of the Privacy or Security Rules. The penalty ranges for civil violations depends upon the circumstances associated with the violations and are subject to upward adjustment for inflation. As most recently adjusted here effective September 6, 2016, the following currently are the progressively increasing Civil Monetary Penalty tiers:
- A minimum penalty of $100 and a maximum penalty of $50,000 per violation, for violations which the CE or BA “did not know, and by exercising reasonable diligence would not have known” about using “the business care and prudence expected from a person seeking to satisfy a legal requirement under similar circumstances;”
- A minimum penalty of $1,000 and a maximum penalty of $50,000 per violation, for violations for “reasonable cause” which do not rise to the level of “willful neglect” where “reasonable cause” means the “circumstances that would make it unreasonable for the Covered Entity, despite the exercise of ordinary business care and prudence, to comply with the violated Privacy Rule requirement;”
- A minimum penalty of $10,000 and a maximum penalty of $50,000 per violation, for violations attributed to “willful neglect,” defined as “the conscious, intentional failure or reckless indifference to the obligation to comply” with the requirement or prohibition; and
- A minimum penalty of $50,000 and a maximum penalty of $1.5 million per violation, for violations attributed to “willful neglect” not remedied within 30 days of the date that the Covered Entity or BA knew or should have known of the violation.
For continuing violations such as failing to implement a required BAA, OCR can treat each day of noncompliance as a separate violation. However, sanctions under each of these tiers generally are subject to a maximum penalty of $1,500,000 for violations of identical requirements or prohibitions during a calendar year. For violations such as the failure to implement and maintain a required BAA where more than one Covered Entity bears responsibility for the violation, OCR an impose Civil Monetary Penalties against each culpable party. OCR considers a variety of mitigating and aggravating facts and circumstances when arriving at the amount of the penalty within each of these applicable tiers to impose.
In addition to these potential civil liability exposures, Covered Entities, their business associates and other individuals or organizations that wrongfully use, access or disclose electronic or other protected health information also can face civil liability under various circumstances. The criminal enforcement provisions of HIPAA authorize the Justice Department to prosecute a person who knowingly in violation of the Privacy Rule (1) uses or causes to be used a unique health identifier; (2) obtains individually identifiable health information relating to an individual; or (3) discloses individually identifiable health information to another person, punishable by the following criminal sanctions and penalties:
- A fine of up to $50,000, imprisoned not more than 1 year, or both;
- If the offense is committed under false pretenses, a fine of up to $100,000, imprisonment of not more than 5 years, or both; and
- If the offense is committed with intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm, a fine of up to $250,000, imprisoned not more than 10 years, or both.
Because HIPAA Privacy Rule criminal violations are Class A Misdemeanors or felonies, Covered Entities and business associates should include HIPAA compliance in their Federal Sentencing Guideline Compliance Programs and practices and need to be concerned both about criminal exposure for their own direct violations, as well as imputed organizational liability for violations committed by their employees or agents under the Federal Sentencing Guidelines, particularly where their failure to implement or administer these required compliance policies and practices or failure to properly investigate or redress potential violations enables, perpetuates or covers up the criminal breach.
FileFax, Inc. Breach & Resolution Agreement
While Congress amended the Civil Monetary Penalty provisions of HIPAA enforced by OCR to make many of the requirements and Civil Monetary Penalty sanctions of HIPAA directly enforceable by OCR against business associates as part of the Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted as part of the American Recovery and Reinvestment Act of 2009, the FileFax Resolution Agreement appears to be the first HIPAA resolution agreement with a business associate announced by OCR.
Indeed, OCR’s enforcement action that resulted in the FileFax Resolution Agreement would never have occurred had FileFax, Inc. not become involved in handling medical records containing PHI in the capacity of a business associate for Covered Entities.
Before filing for bankruptcy in 2016, FileFax, Inc. advertised it provided HIPAA-compliant storage, maintenance, and delivery of medical records for HIPAA Covered Entities including Illinois based health care provider CCDC, which entered into a resolution agreement with OCR in April, 2017 to resolve OCR charges that it violated HIPAA by allowing FileFax, Inc. to handle PHI without fulfilling HIPAA’s business associate agreement requirements.
Like the CCDC Resolution Agreement, the FileFax, Inc. Resolution Agreement resulted from an investigation of FileFax, Inc. that OCR began in response to a February 10, 2015 anonymous complaint filed with OCR about FileFax, Inc. about deficiencies in its delivery of these HIPAA services in its capacity as a business associate to Covered Entities. The complaint to OCR alleged that FileFax, Inc. violated these requirements because an individual transported medical records obtained from FileFax, Inc. to a shredding and recycling facility to sell on February 6 and 9, 2015.
OCR’s investigation of the complaint against FileFax, Inc. confirmed that an individual had left medical records of approximately 2,150 patients at the shredding and recycling facility, and that these medical records contained patients’ PHI. OCR’s investigation additionally found that between January 28, 2015, and February 14, 2015, FileFax, Inc. impermissibly disclosed the PHI of 2,150 individuals by leaving the PHI in an unlocked truck in the FileFax, Inc. parking lot, or by granting permission to an unauthorized person to remove the PHI from FileFax, Inc. and leaving the PHI unsecured outside the FileFax, Inc. facility.
After OCR commenced its investigation of the complaint, FileFax, Inc. was placed into bankruptcy and a receiver was appointed to liquidate FileFax, Inc.’s assets for distribution to creditors and others in 2016. Despite the bankruptcy, OCR continued to pursue enforcement against FileFax, Inc. for the HIPAA violations it found through its investigation. On February 13, 2018, OCR announced that that the receiver on behalf of FileFax, Inc. had agreed in the FileFax Resolution Agreement to pay a $100,000 monetary settlement out of the bankruptcy estate and to arrange to properly store and dispose of remaining medical records found at FileFax, Inc.’s facility in compliance with HIPAA to resolve OCR’s HIPAA charges against FileFax, Inc.
OCR Previously Sanctioned Covered Entity For Involvement With FileFax, Inc.
Beyond affirming the exposure business associates to OCR civil monetary penalties or other enforcement for violating HIPAA, the FileFax Resolution Agreement in conjunction with OCR’s previously announced April 20, 2017 resolution agreement (CCDC Resolution Agreement) with CCDC also demonstrates the need for Covered Entities to recognize that their organizations are likely to face HIPAA investigations or enforcement from HIPAA violations by or OCR audits or investigations of the conduct of their business associates.
In fact, this is exactly what happened to CCDC. A small, Illinois based Covered Entity, CCDC used FileFax, Inc. to store and dispose of medical records. As a consequence of the FileFax, Inc. investigation, OCR conducted a compliance review of CCDC. OCR reports that its compliance review revealed that while CCDC had disclosed to and allowed FileFax, Inc. to store records containing PHI for CCDC since in 2003, neither party could produce a signed business associate agreement (BAA) prior to October 12, 2015. As a consequence, OCR charged CCDC with violating HIPAA by disclosing PHI to FileFax, Inc. in violation of HIPAA’s business associate requirements.
To resolve its exposure to potentially much greater civil monetary penalties associated with this charge, CCDC agreed under the CCDC Resolution Agreement to pay OCR a $31,000 resolution payment and take a variety of corrective actions. Beyond requiring CCDC to implement and maintain written business associate agreements before allowing business associates to possess or access PHI, the corrective action plan imposed as part of the CCDC Resolution Agreement also expressly requires CCDC to promptly investigate information of a possible violation of its HIPAA policies and procedures by a “workforce member,” which the Privacy Rule defines to include a business associate, and if the investigation reveals a violation, to report the violation and corrective action taken to OCR.
OCR Enforces HIPAA Against Covered Entities & Business Associates In Bankruptcy
OCR’s announcement of the FileFax Resolution Agreement also is significant in its reaffirmation of OCR to its commitment to HIPAA enforcement, even if the HIPAA-violating Covered Entity or business associate goes bankruptcy.
OCR’s enforcement action against FileFax, Inc. despite its bankruptcy and its successful negotiation of the FileFax Resolution Agreement within the bankruptcy should alert Covered Entities and business associates that OCR does not consider the bankruptcy of a Covered Entity or business associate as an obstacle to OCR enforcement against Covered Entities or business associates that violate HIPAA. The seriousness of OCR’s commitment to enforcement, even in the face of bankruptcy is driven home by its announcement of the FileFax Resolution Agreement on the heels of its December, 2017 announcement of its first OCR HIPAA resolution agreement secured with the formal approval of a bankruptcy court, a resolution agreement (21CO Resolution Agreement) against bankrupt health care provider, 21CO.
Secured with bankruptcy court approval, the 21CO Resolution Agreement resolved potentially much larger civil monetary penalties that the Fort Myers, Florida based provider of cancer care services and radiation oncology could have faced for alleged HIPAA breaches OCR charged it committed in connection with its failure to adequately act to prevent and respond to hacking and misappropriation of records containing sensitive electronic protected health information (ePHI) of up to 2,213597 individuals.
The OCR charges against 21CO arose from an OCR investigation commenced after the Federal Bureau of Investigation (FBI) notified 21CO on November 13, 2015 and a second time on December 13, 2015 than unauthorized third party illegally obtained 21CO sensitive patient information and produced 21CO patient files purchased by a FBI informant. As part of its internal investigation, 21CO hired a third party forensic auditing firm in November 2015. 21CO determined that the attacker may have accessed 21CO’s network SQL database as early as October 3, 2015, through Remote Desktop Protocol from an Exchange Server within 21CO’s network. 21CO determined that it is possible that 2,213,597 individuals may have been affected by the impermissible access to their names, social security numbers, physicians’ names, diagnoses, treatment and insurance information.
Although it knew of the breaches in November and December, 2015, 21CO waited more than three months after the FBI notified it of the breaches before it sent HIPAA or other breach notifications about the data breach to patients or notified investors in March, 2016. Its March 4, 2016 Securities and Exchange Commission 8-K on Data Security Incident (Breach 8-K) states 21CO delayed notification at the request of the FBI to avoid interfering in the criminal investigation of the breach.
When announcing the breach, 21CO provided all individuals affected by the breach with a free one-year subscription to the Experian ProtectMyID fraud protection service. At that time, 21CO said it had no evidence that any patient information actually had been misused. However some victims of the breach subsequently have claimed being victimized by a variety of scams since the breach in news reports and lawsuits about the breach.
At the time of the breach and its March 4, 2016 announcement of the breach, 21CO already was working to resolve other compliance issues. On December 16, 2015, 21CO announced that a 21CO subsidiary had agreed to pay $19.75 million to the United States and $528,000 in attorneys’ fees and costs and comply with a corporate integrity agreement related to a qui tam action in which it was accused of making false claims to Medicare and other federal health programs. See 21CO 8-K Re: Entry into a Material Definitive Agreement (December 22, 2015). Among other things, the corporate integrity agreement required by that settlement required 21CO to appoint a compliance officer and take other steps to maintain compliance with federal health care laws. In addition, five days after releasing the March 4, 2017 Breach 8-K, 21CO notified investors that its subsidiary, 21st Century Oncology, Inc. (“21C”), had agreed to pay $37.4 million to settle health care fraud law charges relating to billing and other protocols of certain staff in the utilization of state-of-the-art radiation dose calculation system used by radiation oncologists called GAMMA. See 21CO 8-K Re: GAMMA Settlement March 9, 2016 ; See also United States Settles False Claims Act Allegations Against 21st Century Oncology for $34.7 Million.
Based on OCR’s subsequent investigation into these breaches, OCR found:
- 21CO impermissibly disclosed certain PHI of 2,213,597 of its patients in violation of 45 C.F.R. § 164.502(a);
- 21CO failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information (ePHI) held by 21CO in violation of 45 C.F.R. § 164.308(a)(1)(ii)(A);
- 21CO failed to implement certain security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with 45 C.F.R. § 164.306(A) in violation of 45 C.F.R. § 164.308(a)(1)(ii)(B);
- 21CO failed to implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports as required by 45 C.F.R. §164.308(a)(1)(ii)(D);
- 21CO disclosed protected health information to a third party vendors, acting as its business associates, without obtaining satisfactory assurances in the form of a written business associate agreement in violation of HIPAA’s business associate rule requirements under 45 C.F.R. §§ 164.502(e) and 164.308(b)(3).
In return for OCR’s agreement not to further pursue charges or penalties relating to the breach investigation, the Resolution Agreement entered into with the approval of the Bankruptcy Court requires that 21CO pay OCR a $2.3 million Resolution Amount and implement to OCR’s satisfaction a corrective action plan that among other things requires that 21CO complete a detailed series of corrective actions to the satisfaction of OCR.
In addition to the OCR investigation that lead to the 21CO Resolution Agreement announced by OCR on December 28, 2017, 21CO experienced other fallout following its March 4, 2016 public disclosure of the breach. Not surprisingly, the breach notification led to a multitude of class-action civil lawsuits by breach victims and shareholders. See, e.g., 16 Data Breach Class Action Lawsuits Filed Against 21st Century Oncology Consolidated; 21st Century Oncology data breach prompts multiple lawsuits. Reports of spoofing and other misleading contacts made to 21CO patients following the breach prompted the Federal Trade Commission (FTC) to issue a specific notice alerting victims about potential false breach notifications and other misleading contacts. See April 4, 2016 FTC Announcement Re: 21st Century Oncology breach exposes patients’ info.
These and other developments also had significant consequences on 21CO’s financial status and leadership. By March 31, 2015, 21CO notified the SEC and investors that it needed added time to complete its financial statements. Subsequent SEC filings document its restatement of financial statements, the departure of board members and other leaders, default on credit terms, and ultimately its filing for Chapter 11 bankruptcy protection in the United States Bankruptcy Court for the Southern District of New York on May 25, 2017.
Because 21CO sought bankruptcy court protection from the fallout of its HIPAA breaches and other compliance and business issues, the 21CO Resolution Agreement required bankruptcy court approval. Funds for payment of the required $2.3 million resolution payment and other charges associated with the investigation apparently are being provided in part from breach liability insurance coverage provided under a policy issued by Beazley Insurance, as the Bankruptcy Court order directs Beazley Breach Response Policy No. W140E2150301 to make immediate payment to the OCR of the resolution amount and the payment of fees incurred by 21CO in connection with regulatory defense issues.
HIPAA & Data Breach Enforcement A Growing Health Plan Risk
Health plans and other Covered Entities, plan sponsors and plan fiduciaries, their business associates and other consultants and service providers and members of their workforce need to recognize that the FileFax, CCDC, 21CO and other resolution agreements are part of a growing trend, rather than isolated incidents of enforcement and that their exposure to investigation and enforcement is likely to continue to rise in the face of growing public and Congressional concern about privacy and data security.
While civil monetary penalty enforcement remains much more common than criminal prosecution, Covered Entities, their business associates and members of their workforce must understand that HIPAA enforcement and resulting liability is growing and that this trend is likely to continue if not increase.
While Department of Justice federal criminal prosecutions and convictions under HIPAA remain relatively rare, they occur and are growing. See e.g., Former Hospital Employee Sentenced for HIPAA Violations (Texas man sentenced to 18 months in federal prison for obtaining protected health information with the intent to use it for personal gain); Three Life Sentences Imposed On Man Following Convictions For Drug Trafficking, Kidnapping, Using Firearms and HIPAA Violations (drug king pin gets multiple 10 year consecutive prison terms for unauthorized access to private health information in violation of HIPAA; his health care worker friend sentenced for accessing electronic medical files and reporting information to him); Former Therapist Charged In HIPAA Case; Hefty Prison Sentence in ID Theft Case (former assisted living facility worker gets 37 months in prison after pleading guilty to wrongful disclosure of HIPAA protected information and other charges); Hefty Prison Sentence in ID Theft Case (former medical supply company owner sentenced to 12 years for HIPAA violations and fraud). While the harshest sentences tend to be associated with health care fraud or other criminal conduct, lighter criminal sentences are imposed against defendants in other cases as well. See e.g., Sentencing In S.C. Medicaid Breach Case (former South Carolina state employee sentenced to three years’ probation, plus community service, for sending personal information about more than 228,000 Medicaid recipients to his personal e-mail account.); HIPAA Violation Leads To Prison Term (former UCLA Healthcare System surgeon gets four months in prison after admitting he illegally read private electronic medical records of celebrities and others.)
While criminal enforcement of HIPAA remains relatively rare and OCR to date only actually has assessed HIPAA civil monetary penalties against certain Covered Entities for violating HIPAA in a couple isolated instances, the growing list of multi-million dollar resolution payments against Covered Entities and with the FileFax Resolution Agreement announcement, now also business associates for violating HIPAA make clear that HIPAA enforcement is both meaningful and growing. See e.g., Learn From Children’s New $3.2M+ HIPAA CMP For “Knowing” Violation of HIPAA Security Rules ($3.2 million Children’s Medical Center HIPAA Civil Monetary Penalty); 1st HIPAA Privacy Civil Penalty of $4.3 Million Signals CMS Serious About HIPAA Enforcement; $400K HIPAA Settlement Shows Need To Conduct Timely & Appropriate Risk Assessments; $5.5M Memorial HIPAA Resolution Agreement Shows Need To Audit. For more examples, also see here.
The experiences of FileFax, Inc., CCDC, 21CO and these other OCR HIPAA Resolution Agreements provide strong evidence that that health plans and other Covered Entities and their business associates can anticipate that OCR will continue to zealously investigate HIPAA breaches and other HIPAA violations. Aside from OCR’s recurrent affirmations of its commitment to HIPAA enforcement, Covered Entities, their business associates and their leaders must recognize that public and Congressional privacy and data security concerns fueled by the ever growing stream of massive data breaches at Alteryx, eBay, Paypal owner TIO Networks, Uber, Equifax and a long list of other previously trusted prominent businesses are creating additional pressure upon OCR and other agencies to pursue even stronger and more aggressive HIPAA oversight and enforcement. Amid this growing concern, OCR, the FTC and other federal and state agencies with regulatory or enforcement authority over HIPAA or other data security and privacy concerns face increasing scrutiny and pressure to take meaningful action to regulate and enforce HIPAA and other laws intended to protect sensitive data even as private litigants enjoy increasing success in obtaining civil judgments from damages resulting from breaches of their PHI or other sensitive personal information using an expanding arsenal of legal theories of recovery. In the face of these growing concerns about privacy and data security, OCR can be expected to continue, if not increase its HIPAA compliance enforcement and oversight by OCR.
Furthermore, the experiences of FileFax, Inc., 21CO, CCDC and other Covered Entities and business associates that already have become the subject of OCR investigation or enforcement also reflect that HIPAA resolution payments or penalties paid to OCR and other costs and expenses associated with the defense and resolution of OCR’s investigations and enforcement actions typically only a portion of the financial and other business consequences that Covered Entities or business associates might expect to incur as a consequence of a breach of PHI or other substantial HIPAA violation or charge.
Beyond their potential HIPAA enforcement exposures following a HIPAA covered data breach or other violation, health care or other Covered Entities and members of their workforce experiencing breaches of ePHI or other PHI often also face FTC or other government investigations and enforcement relating their data breaches under the Fair and Accurate Credit Transactions Act (FACTA) and other federal or state identity theft, data privacy and security, electronic crimes and other laws. They or members of their workforce may face licensing board, credentialing, accreditation, contractual or other investigations or sanctions. Victims, business partners, investors and others often bring civil litigation to address losses or other injures associated with the breach or other misconduct. In addition, losses and disruptions in patients, plan member, vendor, investor, employee, management and other business relationships, and other business disruptions also are common.
Where the breach of other HIPAA violation involves a health plan, health plans, their fiduciaries and sponsors also need to give due consideration to the implications and exposures that might arise under the fiduciary responsibility rules of the Employee Retirement Income Security Act (ERISA). Beyond the direct exposure of their health plan to HIPAA and other compliance liabilities, health plan fiduciaries generally will want to consider whether their fiduciary responsibility under ERISA requires that prudent or other steps be taken to safeguard health plan information and maintain and administer their health plan in accordance with HIPAA and other laws. As a consequence, fiduciaries generally will want to ensure that they take and document prudent steps to evaluate, monitor and address HIPAA and other privacy and data security safeguards to minimize not only the liability exposures of their health plans, but also to help mitigate their own potential personal liability exposures that could arise or be asserted in response to a HIPAA breach or other HIPAA violation involving their health plans.
In the face of these growing risks and liabilities, Covered Entities and their business leaders face a strong imperative to clean up and maintain their HIPAA compliance and other data security to minimize their exposure to similar consequences. In addition to reaffirming the need for Covered Entities and their business associates to take the necessary steps to maintain and effectively demonstrate the adequacy of their own HIPAA compliance, the CCDC and FileFax Resolution Agreements alert Covered Entities and business associates of the advisability of greater oversight and risk management of their dealings and relationships with the other Covered Entities and business associates with access to or involvement with their PHI or other critical functions.
In light of these rises, leaders, investors, insurers, lenders and others involved with Covered Entities and their business associates should take steps to verify that the Covered Entities and their business associates not only maintain compliance with HIPAA and its business associate and other privacy, data security and breach notification and response requirements, but also maintain appropriate practices, insurance and other safeguards to prevent, respond to and mitigate exposures in the event of a breach of protected health information or other sensitive data. The bankruptcies and other financial and business fallout of HIPAA or other data breaches experienced by FileFax, Inc. 21CO and other HIPAA-covered and non-HIPAA regulated entities also makes clear that Covered Entities and business associates should anticipate that their own fallout from a breach or other HIPAA event and resulting responsibilities and consequences could be impacted by their own or a business associate’s financial distress or bankruptcy. Beyond the risk that their own or another entity’s breach, compliance issues, or other financial or business issues could trigger breach investigation, notice or other responsibilities for their own organizations, Covered Entities, business associates and their leaders also should evaluate and revise their HIPAA risk assessments and security plans to address foreseeable threats to the availability, access, retention and security of PHI and associated records and systems.
The Bankruptcy Court’s order to 21CO’s cyber liability insurer to pay the resolution payment required under the 21CO Resolution Agreement and other costs of investigation and defense also strongly suggests that the purchase of insurance and other arrangements for funding costs of defense or settlement should be included in these evaluations.
In light of these rises, leaders, investors, insurers, lenders and others involved with Covered Entities and their business associates should take steps to verify that the Covered Entities and their business associates not only maintain compliance with HIPAA, but also comply with data security, privacy and other information protection requirements arising under other laws, regulations, and contracts, as well as the practical business risks that typically follow the announcement of a breach. Considering these risks, Covered Entities and their business associates should recognize the advisability of taking meaningful, documented action to verify their existing compliance and ongoing oversight to ensure their organizations can demonstrate appropriate action to maintain appropriate practices, insurance and other safeguards to prevent, respond to and mitigate exposures in the event of a breach of protected health information or other sensitive data.
As part of these efforts, Covered Entities and their business associates should ensure that they have conducted, and maintain and are ready to produce appropriate policies and procedures backed up by a well-documented, up-to-date industry wide risk assessment of their organization’s susceptibility to breaches or other misuse of electronic or other protected health information. The starting point of these efforts should be to adopt and enforce updated written policies, procedures, technical and physical safeguards, processes and training to prevent the improper use, access, destruction or disclosure of patient PHI. Processes also should create, retain and be designed to cost effectively track, capture, and retain both all protected health information, its use, access, protection, destruction and disclosure, and the requisite supportive documentation supporting the appropriateness of those action to position the organization cost-effectively and quickly to fulfill required accounting, reporting and other needs in the event of a data breach, audit, participant inquiry or other event.
As part of this process, Covered Entities and business associates should maintain strong and ongoing processes for assessing and monitoring the adequacy of their policies and practices. In addition to ensuring that their organization has a comprehensive risk management and compliance assessment, Covered Entities and business associates need to conduct documented periodic audits and spot HIPAA audits and assessments. In doing so, they must use care to look outside the four corners of their Privacy Policies and core operating systems to ensure that their policies, practices, oversight and training address all protected health information within their operations on an entity wide basis. This entity-wide assessment should include communications and requests for information normally addressed to the Privacy Officer as well as requests and communications that could arise in the course of media or other public relations, practice transition, workforce communication and other operations not typically under the direct oversight and management of the Privacy Officer.
In connection with these efforts, the enforcement actions make clear that Covered Entities and business associates should adopt, implement and monitor PHI privacy, and security on an entity wide basis. These efforts should include general policies, practices and procedures as well as specifically tailored policies, processes and training to protect PHI and preserve HIPAA compliance throughout their organization. Testing and analysis should be conducted on a regular basis. Documented reassessments and testing should be performed in response to software, hardware or other changes or events that could impact security or other operations. Beyond security, attention also should cover business or system interruption including losses that might occur from the bankruptcy, termination of business or other disruptions of business associates or other parties. Attention should be paid both to protecting access and use of PHI and ePHI in the course of business as well as the transmission, transport, storage and destruction of records or systems containing such information.
Careful attention should be devoted to ensuring that business associate agreements as well and other processes provide for HIPAA compliance with respect to all PHI created, used, accessed or disclosed to business associates or others not part of their direct workforce or operating outside the core boundaries of their facilities.
Covered entities and their business associates also must recognize and design their compliance efforts and documentation recognizing that HIPAA compliance is a living process, which require both constant diligence about changes in systems or other events that may require reevaluation or adjustments, whether from changes in software, systems or processes or external threats.
Because the cost of responding to and investigating breaches or other compliance concern can be quite burdensome, Covered Entities and their business associates also generally will want to pursue options to plan for and minimize potential expenses in the design and administration of their programs as well as to minimize and cover the potentially extraordinary costs of breach or other compliance investigation and results that commonly arise following a breach or other compliance event. As a part of this planning, Covered Entities and their business associates also generally will want to add consideration of changes to federal tax rules on the deductibility of compliance penalty and other related compliance expenditures.
While the Internal Revenue Code traditionally has prohibited businesses and individuals from deducting penalties, fines and other expenditures arising from violations of federal or state laws under Section 162(f) of the Internal Revenue Code, Section 13306 of the Tax Cuts and Jobs Creation Act creates a new exception for amounts (other than amounts paid or incurred any amount paid or incurred as reimbursement to the government or entity for the costs of any investigation or litigation) that a taxpayer establishes meet the following requirements:
- Constitute restitution (including remediation of property) for damage or harm which was or may be caused by the violation of any law or the potential violation of any law, or
- Are paid to come into compliance with any law which was violated or otherwise involved in the investigation or inquiry into a violation or potential violation of any law;
- Are identified as restitution or as an amount paid to come into compliance with such law, as the case may be, in the court order or settlement agreement, and
- In the case of any amount of restitution for failure to pay any tax imposed under this title in the same manner as if such amount were such tax, would have been allowed as a deduction under this chapter if it had been timely paid.
Because the true effect of these modifications will be impacted by implementing regulations and a number of other special conditions and rules may impact the deductibility of these payments and the reporting obligations attached to their payment, Covered Entities will want to consult with legal counsel about these rules and monitor their implementation to understand their potential implications on compliance expenditures and penalties.
About The Author
Repeatedly recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, a Fellow in the American College of Employee Benefit Council, the American Bar Foundation and the Texas Bar Foundation and board certified in labor and employment law by the Texas Board of Legal Specialization, Cynthia Marcotte Stamer is a practicing attorney, management consultant, author, public policy advocate and lecturer widely known for health and managed care, employee benefits, insurance and financial services, data and technology and other management work, public policy leadership and advocacy, coaching, teachings, and publications. Nationally recognized for her work, experience, leadership and publications on HIPAA and other medical privacy and data use and security, FACTA, GLB, trade secrets and other privacy and data security concerns, Ms. Stamer has worked extensively with clients and the government on cybersecurity, technology and processes and other issues involved in the use and management of medical, insurance and other financial, workforce, trade secrets and other sensitive data and information throughout her career. Scribe or co-scribe of the ABA Joint Committee on Employee Benefits Agency meeting with OCR since 2011 and author of a multitude of highly regarded publications on HIPAA and other health care, insurance, financial and other privacy and data security, Ms. Stamer is widely known for her extensive and leading edge experience, advising, representing, training and coaching health care providers, health plans, healthcare clearinghouses, business associates, their information technology and other solutions providers and vendors, and others on HIPAA and other privacy, data security and cybersecurity design, documentation, administration, audit and oversight, business associate and other data and technology contracting, breach investigation and response, and other related concerns including extensive involvement representing clients in dealings with OCR and other Health & Human Services, Federal Trade Commission, Department of Labor, Department of Treasury, state health, insurance and attorneys’ general, Congress and state legislators and other federal officials.
Ms. Stamer also has an extensive contributes her leadership and insights with other professionals, industry leaders and lawmakers. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here. For additional information about Ms. Stamer, see here, e-mail her here or telephone Ms. Stamer at (214) 452-8297.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2018 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on OCR HIPAA Resolution Agreement Against Bankrupt Business Associate Signals Growing Exposures, Need for Tighter HIPAA Compliance By Health Plans & Business Associates |
Association Health Plan, board of directors, Brokers, church plan, Civil Monetary Penalties, Civil Rights, Claims Administration, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, EBSA, employee, Employee Benefits, Employer, Employers, Employment, ERISA, FACTA, Fair Credit Reporting Act, fiduciary duty, Fiduciary Responsibility, GINA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Technology, third party administrators, Trade secret, Uncategorized | Tagged: Health Plans, HIPAA, Technology |
Permalink
Posted by Cynthia Marcotte Stamer
February 2, 2018
The $3.5 million payment that Fresenius Medical Care North America (FMCNA) is paying to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) to settle potential liability for potentially much higher Civil Monetary Penalties (CMPs) to OCR for Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules violation charges under a voluntary resolution agreement illustrates the need for group health plans and their employer and other sponsors, fiduciaries, and vendors to make HIPAA compliance a key priority for 2018.
Widespread publicity and fallout from data breaches involving Equifax, Blue Cross, the Internal Revenue Service and many other giant organizations have ramped up public awareness and government concern about health care and other data security. The resulting pressure is adding additional fuel to the already substantial concern of OCR and other agencies about compliance with HIPAA and other data security and breach laws. Like the $2.3 million HIPAA resolution agreement OCR announced with now bankrupt radiation oncology and cancer care provider 21st Century Oncology, Inc. (21CO) earlier this year, see, e.g., $23M Penalty Small Part of 21st Century’s Data Breach Fallout; Offers Data Breach Lessons For Other Businesses, the growing list of OCR resolution agreements and other enforcement actions against FMCNA, 21CO and other covered entities and other legal and market fallout that covered entities and other organizations experience following the announcement of breaches or other security deficiencies make the case for why HIPAA-covered health care providers, health plans, health care clearinghouses and their business associates (covered entities) must prioritize HIPAA compliance and other medical and other data security protection, privacy and risk management a top priority in 2018.
When weighing the importance of HIPAA compliance and risk management for their health plans, health plans, their employer or other sponsors, fiduciaries, insurers, administrators and their business associates should resist the temptation to underestimate the exposure because providers, rather than health plans, have been the most common target of the majority of the announced OCR enforcement actions resulting in substantial civil monetary penalties or resolution payments.
HIPAA Privacy, Security & Breach Notification Rule Responsibilities & Risks
The Privacy Rule requires that health plans, health care providers, health care clearinghouses (covered entities) and their vendors that qualify as “business associates” under HIPAA comply with detailed requirements concerning the protection, use, access, destruction and disclosure of protected health information. As part of these requirements, covered entities and their business associates must adopt, administer and enforce detailed policies and practices, assess, monitor and maintain the security of electronic protected health information (ePHI) and other protected health information, provide notices of privacy practices and breaches of “unsecured” ePHI, afford individuals that are the subject of protected health information certain rights and comply with other requirements as specified by the Privacy, Security and Breach Notification Rules. In addition, covered entities and business associates also must enter into a written and signed business associate agreement that contains the elements specified in Privacy Rule § 164.504(e) before the business associate creates, uses, accesses or discloses PHI of the covered entity. Furthermore, the Privacy Rule includes extensive documentation and keeping requirements require that covered entities and BAs maintain copies of these BAAs for a minimum of six years and to provide that documentation to OCR upon demand.
Violations of the Privacy Rule can carry stiff civil monetary penalties or even criminal penalties. Pursuant to amendments to HIPAA enacted as part of the HITECH Act, civil penalties typically do not apply to violations punished under the criminal penalty rules of HIPAA set forth in Social Security Act , 42 U.S.C § 1320d-6 (Section 1177).
Resolution Agreements like the $3.2 million FMCNA resolution agreement allow covered entities and business associates to resolve potentially substantially larger civil monetary penalty liabilities that OCR can impose under the civil enforcement provisions of HIPAA. As amended by the HITECH Act, the civil enforcement provisions of HIPAA empower OCR to impose Civil Monetary Penalties on both covered entities and BAs for violations of any of the requirements of the Privacy or Security Rules. The penalty ranges for civil violations depends upon the circumstances associated with the violations and are subject to upward adjustment for inflation. As most recently adjusted here effective September 6, 2016, the following currently are the progressively increasing Civil Monetary Penalty tiers:
- A minimum penalty of $100 and a maximum penalty of $50,000 per violation, for violations which the CE or BA “did not know, and by exercising reasonable diligence would not have known” about using “the business care and prudence expected from a person seeking to satisfy a legal requirement under similar circumstances;”
- A minimum penalty of $1,000 and a maximum penalty of $50,000 per violation, for violations for “reasonable cause” which do not rise to the level of “willful neglect” where “reasonable cause” means the “circumstances that would make it unreasonable for the covered entity, despite the exercise of ordinary business care and prudence, to comply with the violated Privacy Rule requirement;”
- A minimum penalty of $10,000 and a maximum penalty of $50,000 per violation, for violations attributed to “willful neglect,” defined as “the conscious, intentional failure or reckless indifference to the obligation to comply” with the requirement or prohibition; and
- A minimum penalty of $50,000 and a maximum penalty of $1.5 million per violation, for violations attributed to “willful neglect” not remedied within 30 days of the date that the covered entity or BA knew or should have known of the violation.
For continuing violations such as failing to implement a required BAA, OCR can treat each day of noncompliance as a separate violation. However, sanctions under each of these tiers generally are subject to a maximum penalty of $1,500,000 for violations of identical requirements or prohibitions during a calendar year. For violations such as the failure to implement and maintain a required BAA where more than one covered entity bears responsibility for the violation, OCR an impose Civil Monetary Penalties against each culpable party. OCR considers a variety of mitigating and aggravating facts and circumstances when arriving at the amount of the penalty within each of these applicable tiers to impose.
In addition to these potential civil liability exposures, covered entities, their business associates and other individuals or organizations that wrongfully use, access or disclose electronic or other protected health information also can face civil liability under various circumstances. The criminal enforcement provisions of HIPAA authorize the Justice Department to prosecute a person who knowingly in violation of the Privacy Rule (1) uses or causes to be used a unique health identifier; (2) obtains individually identifiable health information relating to an individual; or (3) discloses individually identifiable health information to another person, punishable by the following criminal sanctions and penalties:
- A fine of up to $50,000, imprisoned not more than 1 year, or both;
- If the offense is committed under false pretenses, a fine of up to $100,000, imprisonment of not more than 5 years, or both; and
- If the offense is committed with intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm, a fine of up to $250,000, imprisoned not more than 10 years, or both.
Because HIPAA Privacy Rule criminal violations are Class A Misdemeanors or felonies, Covered Entities and business associates should include HIPAA compliance in their Federal Sentencing Guideline Compliance Programs and practices and need to be concerned both about criminal exposure for their own direct violations, as well as imputed organizational liability for violations committed by their employees or agents under the Federal Sentencing Guidelines, particularly where their failure to implement or administer these required compliance policies and practices or failure to properly investigate or redress potential violations enables, perpetuates or covers up the criminal breach.
Fresenius Breach, Charges & Settlement Agreement Illustrate Civil Exposures
The FMCNA resolution agreement is another example of a growing list of resolution agreements various HIPAA covered entities have entered into to resolve their exposure to potentially greater liability should OCR assess civil monetary penalties under HIPAA’s civil sanction scheme.
The breach reports filed on January 21, 2017 reported five separate breach incidents occurring between February 23, 2012 and July 18, 2012 implicating the electronic protected health information (ePHI) of five separate FMCNA owned covered entities (FMCNA covered entities): Bio-Medical Applications of Florida, Inc. d/b/a Fresenius Medical Care Duval Facility in Jacksonville, Florida (FMC Duval Facility); Bio-Medical Applications of Alabama, Inc. d/b/a Fresenius Medical Care Magnolia Grove in Semmes, Alabama (FMC Magnolia Grove Facility); Renal Dimensions, LLC d/b/a Fresenius Medical Care Ak-Chin in Maricopa, Arizona (FMC Ak-Chin Facility); Fresenius Vascular Care Augusta, LLC (FVC Augusta); and WSKC Dialysis Services, Inc. d/b/a Fresenius Medical Care Blue Island Dialysis (FMC Blue Island Facility).
OCR concluded its investigation showed the breaches resulted because FMCNA failed to conduct an accurate and thorough risk analysis of potential risks and vulnerabilities to the confidentiality, integrity, and availability of all of its ePHI. OCR also concluded:
- The FMCNA covered entities impermissibly disclosed the ePHI of patients by providing unauthorized access for a purpose not permitted by the Privacy Rule.
- FMC Ak-Chin failed to implement policies and procedures to address security incidents.
- FMC Magnolia Grove failed to implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain ePHI into and out of a facility; and the movement of these items within the facility.
- FMC Duval and FMC Blue Island failed to implement policies and procedures to safeguard their facilities and equipment therein from unauthorized access, tampering, and theft, when it was reasonable and appropriate to do so under the circumstances.
- FMC Magnolia Grove and FVC Augusta failed to implement a mechanism to encrypt and decrypt ePHI, when it was reasonable and appropriate to do so under the circumstances.
In addition to a $3.5 million monetary settlement, a corrective action plan requires the FMCNA covered entities to complete a risk analysis and risk management plan, revise policies and procedures on device and media controls as well as facility access controls, develop an encryption report, and educate its workforce on policies and procedures.
HIPAA & Data Breach Enforcement A Growing Health Plan Risk
Health plans and other covered entities, plan sponsors and plan fiduciaries, their business associates and other consultants and service providers and members of their workforce need to recognize that the FMCNA and other resolution agreements are part of a growing trend, rather than isolated incidents of enforcement.
While civil monetary penalty enforcement remains much more common than criminal prosecution, covered entities, their business associates and members of their workforce must understand that HIPAA enforcement and resulting liability is growing.
While Department of Justice federal criminal prosecutions and convictions under HIPAA remain relatively rare, they occur and are growing. See e.g., Former Hospital Employee Sentenced for HIPAA Violations (Texas man sentenced to 18 months in federal prison for obtaining protected health information with the intent to use it for personal gain); Three Life Sentences Imposed On Man Following Convictions For Drug Trafficking, Kidnapping, Using Firearms and HIPAA Violations (drug king pin gets multiple 10 year consecutive prison terms for unauthorized access to private health information in violation of HIPAA; his health care worker friend sentenced for accessing electronic medical files and reporting information to him); Former Therapist Charged In HIPAA Case; Hefty Prison Sentence in ID Theft Case (former assisted living facility worker gets 37 months in prison after pleading guilty to wrongful disclosure of HIPAA protected information and other charges); Hefty Prison Sentence in ID Theft Case (former medical supply company owner sentenced to 12 years for HIPAA violations and fraud). While the harshest sentences tend to be associated with health care fraud or other criminal conduct, lighter criminal sentences are imposed against defendants in other cases as well. See e.g., Sentencing In S.C. Medicaid Breach Case (former South Carolina state employee sentenced to three years’ probation, plus community service, for sending personal information about more than 228,000 Medicaid recipients to his personal e-mail account.); HIPAA Violation Leads To Prison Term (former UCLA Healthcare System surgeon gets four months in prison after admitting he illegally read private electronic medical records of celebrities and others.)
While criminal enforcement of HIPAA remains relatively rare and OCR to date only actually has assessed HIPAA civil monetary penalties against certain Covered Entities for violating HIPAA in a couple isolated instances, the growing list of multi-million dollar resolution payments that FMCNA and other covered entities caught violating HIPAA make clear that HIPAA enforcement is both meaningful and growing. See e.g., Learn From Children’s New $3.2M+ HIPAA CMP For “Knowing” Violation of HIPAA Security Rules ($3.2 million Children’s Medical Center HIPAA Civil Monetary Penalty); 1st HIPAA Privacy Civil Penalty of $4.3 Million Signals CMS Serious About HIPAA Enforcement; $400K HIPAA Settlement Shows Need To Conduct Timely & Appropriate Risk Assessments; $5.5M Memorial HIPAA Resolution Agreement Shows Need To Audit. For more examples, also see here.
Beyond the direct exposure of their health plan to HIPAA and other compliance liabilities, health plan fiduciaries also should note that their fiduciary responsibility under the Employee Retirement Income Security Act (ERISA) likely includes taking prudent steps to safeguard health plan information and maintain and administer their health plan in accordance with HIPAA. As a consequence, fiduciaries generally will want to ensure that they take and document prudent steps to evaluate, monitor and address HIPAA and other privacy and data security safeguards to minimize not only the liability exposures of their health plans, but also to help mitigate their own potential personal liability exposures that could arise or be asserted in response to a HIPAA breach or other HIPAA violation involving their health plans.
Coming on the heels of an already lengthy and growing list of OCR high dollar HIPAA enforcement actions, the FMCNA and other resolution agreements and civil monetary penalties these and other announced enforcement actions clearly reflect that OCR takes HIPAA compliance seriously and stands ready to impose substantial penalties when it finds violations in connection with breach notice investigations. Viewed in the context of these and other enforcement actions, the FMCNA Resolution Agreement and others clearly reflect the time for complacency in HIPAA compliance and leniency in HIPAA HIPAA enforcement are passed. Rather, these and other enforcement actions make clear why health care providers, health plans, healthcare clearinghouses and their business associates must make HIPAA compliance a priority now.
Covered entities and business associates also should recognize their potential responsibilities and risks for breaches or other improper conduct concerning patient or other sensitive personal financial information, trade secrets or other data under a wide range of laws beyond HIPAA and its state law equivalents. As documented by the media coverage of the legal and business woes of Alteryx, eBay, Paypal owner TIO Networks, Uber, Equifax and a long list of other previously trusted prominent businesses have and continue to incur from data breaches within their organizations, health care or other covered entities experiencing breaches often also face FTC or other government investigations and enforcement under the Fair and Accurate Credit Transactions Act (FACTA) and other federal or state identity theft, data privacy and security, electronic crimes and other rules as well as business losses and disruptions; civil litigation from breach victims, shareholders and investors, and business partners as well as OCR, FTC, and state data security regulation enforcement. Amid this growing concern, OCR has indicated that it intends to continue to diligently both seek to support and encourage voluntary compliance by covered entities and their business associates and investigate and enforce HIPAA against HIPAA covered entities and their business associates that fail to adequately safeguard PHI and ePHI in accordance with HIPAA. In the face of these growing risks and liabilities, covered entities and their business leaders face a strong imperative to clean up and maintain their HIPAA compliance and other data security to minimize their exposure to similar consequences.
In light of these rises, leaders, investors, insurers, lenders and others involved with covered entities and their business associates should take steps to verify that the covered entities and their business associates not only maintain compliance with HIPAA, but also comply with data security, privacy and other information protection requirements arising under other laws, regulations, and contracts, as well as the practical business risks that typically follow the announcement of a breach. Considering these risks, covered entities and their business associates must recognize and take meaningful, documented action to verify their existing compliance and ongoing oversight to ensure their organizations can demonstrate appropriate action to maintain appropriate practices, insurance and other safeguards to prevent, respond to and mitigate exposures in the event of a breach of protected health information or other sensitive data.
In response to these growing risks and concerns, covered entities and their business associates should ensure that they have conducted, and maintain and are ready to produce appropriate policies and procedures backed up by a well documented, up-to-date industry wide risk assessment of their organization’s susceptibility to breaches or other misuse of electronic or other protected health information. The starting point of these efforts should be to adopt and enforce updated written policies, procedures, technical and physical safeguards, processes and training to prevent the improper use, access, destruction or disclosure of patient PHI. Processes also should create, retain and be designed to cost effectively track, capture, and retain both all protected health information, its use, access, protection, destruction and disclosure, and the requisite supportive documentation supporting the appropriateness of those action to position the organization cost-effectively and quickly to fulfill required accounting, reporting and other needs in the event of a data breach, audit, participant inquiry or other event.
As part of this process, covered entities and business associates should start by reviewing and updating their policies, HIPAA audits and assessments and other documentation and processes. In doing so, they must use care to look outside the four corners of their Privacy Policies and core operating systems to ensure that their policies, practices, oversight and training address all protected health information within their operations on an entity wide basis. This entity-wide assessment should include both communications and requests for information normally addressed to the Privacy Officer as well as requests and communications that could arise in the course of media or other public relations, practice transition, workforce communication and other operations not typically under the direct oversight and management of the Privacy Officer.
In connection with these efforts, the enforcement actions make clear that Covered Entities and business associates should adopt, implement and monitor PHI privacy, and security on an entity wide basis. These efforts should include both general policies, practices and procedures as well as specifically tailored policies, processes and training to protect PHI and preserve HIPAA compliance throughout their organization as well as the business associate agreements and other processes to provide for HIPAA compliance with respect to protected health information created, used, accessed or disclosed to business associates or others not part of their direct workforce or operating outside the core boundaries of their facilities.
Covered entities and their business associates also must recognize and design their compliance efforts and documentation recognizing that HIPAA compliance is a living process, which require both constant diligence about changes in systems or other events that may require reevaluation or adjustments, whether from changes in software, systems or processes or external threats.
Because the cost of responding to and investigating breaches or other compliance concern can be quite burdensome, covered entities and their business associates also generally will want to pursue options to plan for and minimize potential expenses in the design and administration of their programs as well as to minimize and cover the potentially extraordinary costs of breach or other compliance investigation and results that commonly arise following a breach or other compliance event. As a part of this planning, covered entities and their business associates also generally will want to add consideration of changes to federal tax rules on the deductibility of compliance penalty and other related compliance expenditures.
While the Internal Revenue Code traditionally has prohibited businesses and individuals from deducting penalties, fines and other expenditures arising from violations of federal or state laws under Section 162(f) of the Internal Revenue Code, Section 13306 of the Tax Cuts and Jobs Creation Act creates a new exception for amounts (other than amounts paid or incurred any amount paid or incurred as reimbursement to the government or entity for the costs of any investigation or litigation) that a taxpayer establishes meet the following requirements:
- Constitute restitution (including remediation of property) for damage or harm which was or may be caused by the violation of any law or the potential violation of any law, or
- Are paid to come into compliance with any law which was violated or otherwise involved in the investigation or inquiry into a violation or potential violation of any law;
- Are identified as restitution or as an amount paid to come into compliance with such law, as the case may be, in the court order or settlement agreement, and
- In the case of any amount of restitution for failure to pay any tax imposed under this title in the same manner as if such amount were such tax, would have been allowed as a deduction under this chapter if it had been timely paid.
Because the true effect of these modifications will be impacted by implementing regulations and a number of other special conditions and rules may impact the deductibility of these payments and the reporting obligations attached to their payment, covered entities will want to consult with legal counsel about these rules and monitor their implementation to understand their potential implications on compliance expenditures and penalties.
About The Author
Repeatedly recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, a Fellow in the American College of Employee Benefit Council, the American Bar Foundation and the Texas Bar Foundation and board certified in labor and employment law by the Texas Board of Legal Specialization, Cynthia Marcotte Stamer is a practicing attorney, management consultant, author, public policy advocate and lecturer widely known for health and managed care, employee benefits, insurance and financial services, data and technology and other management work, public policy leadership and advocacy, coaching, teachings, and publications. Nationally recognized for her work, experience, leadership and publications on HIPAA and other medical privacy and data use and security, FACTA, GLB, trade secrets and other privacy and data security concerns, Ms. Stamer has worked extensively with clients and the government on cybersecurity, technology and processes and other issues involved in the use and management of medical, insurance and other financial, workforce, trade secrets and other sensitive data and information throughout her career. Scribe or co-scribe of the ABA Joint Committee on Employee Benefits Agency meeting with OCR since 2011 and author of a multitude of highly regarded publications on HIPAA and other health care, insurance, financial and other privacy and data security, Ms. Stamer is widely known for her extensive and leading edge experience, advising, representing, training and coaching health care providers, health plans, healthcare clearinghouses, business associates, their information technology and other solutions providers and vendors, and others on HIPAA and other privacy, data security and cybersecurity design, documentation, administration, audit and oversight, business associate and other data and technology contracting, breach investigation and response, and other related concerns including extensive involvement representing clients in dealings with OCR and other Health & Human Services, Federal Trade Commission, Department of Labor, Department of Treasury, state health, insurance and attorneys’ general, Congress and state legislators and other federal officials.
Ms. Stamer also has an extensive contributes her leadership and insights with other professionals, industry leaders and lawmakers. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here. For additional information about Ms. Stamer, see here, e-mail her here or telephone Ms. Stamer at (214) 452-8297.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2018 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on $3.5M HIPAA Settlement Highlights Need To Prioritize Health Plan HIPAA Compliance in 2018 |
Association Health Plan, board of directors, Brokers, church plan, Civil Monetary Penalties, Civil Rights, Claims Administration, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, EBSA, employee, Employee Benefits, Employer, Employers, Employment, ERISA, FACTA, Fair Credit Reporting Act, fiduciary duty, Fiduciary Responsibility, GINA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Technology, third party administrators, Trade secret, Uncategorized | Tagged: Health Plans, HIPAA, Technology |
Permalink
Posted by Cynthia Marcotte Stamer
January 17, 2018
Health plans, their employer, union, insurer or other sponsors, fiduciaries, administrative or other service providers and their vendors and advisors should act immediately to investigate if any action is needed to protect electronic protected health information or other sensitive data and systems in response to the following cyber risk alert from the Department Of Health and Human Services Office of Civil Rights.

TLP: WHITE: ASPR/CIP HPH Cyber Notice: Meltdown and Spectre Vulnerability Guidance UPDATE #1
January 17, 2018
DISCLAIMER: This product is provided “as is” for informational purposes only. The Department of Health and Human Services (HHS) does not provide warranties of any kind regarding any information contained within. HHS does not endorse any commercial product or service referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header.
TLP: WHITE information may be distributed without restriction (subject to standard copyright rules).
Healthcare and Public Health Sector partners-
The attached report is a technical update to the previously distributed HPH Cyber Notice covering chip vulnerabilities named Meltdown and Spectre. Both Meltdown and Spectre are vulnerabilities in how computer chips handle data that have the potential to expose sensitive information, such as protected health information (PHI), being processed on the chip. As this information is protected from disclosure under HIPAA, Healthcare and Public Health (HPH) entities should employ risk management processes to address these vulnerabilities and ensure the security of medical records and other PHI.
Major concerns for the HPH sector include but are not limited to:
• Challenges identifying vulnerable medical devices and accessory medical equipment and ensuring patches are validated to prevent impacts to the intended use.
• Cloud Computing: Potential PHI or Personally Identifiable Information (PII) data leakage in shared computing environments
• Web browsers: Possible PHI/PII data leakage
• Patches: Potential for service degradation and/or interruption from patches
The detailed report can be found here: Technical Report on Widespread Processor Vulnerabilities
Comments Off on Check & Protect Health & Other Electronic Systems & Data Against New Security Threat |
4980D, ADA, Association Health Plan, board of directors, Brokers, Civil Rights, compliance, Corporate Compliance, Cybercrime, Data Breach, Data Security, directors, Disease Management, Electronic Medical Record, Employee Benefits, Employer, Employers, ERISA, exchange, Fiduciary Responsibility, GINA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, Uncategorized |
Permalink
Posted by Cynthia Marcotte Stamer
December 5, 2017
The Justice Department’s report Tuesday that the Justice Department spent $3.2 million on Special counsel Robert Mueller’s Russia probe its first four-and-a-half months highlights the importance for leaders accountable for their organizations’s Federal Sentencing Guideline, sexual harassment and other corporate compliance programs to appropriately plan and budget for potential investigation and defense costs as part of their compliance and risk management planning.
Conducting an internal investigation or defending a government or other allegation of wrongdoing often proves surprisingly expensive. While how much an internal investigation costs can vary widely depending on the issue, its potential civil and criminal liability and public relations implications on the organization and its management, it’s timing, the adequacy of the pre-event compliance management and record keeping relating to the issue, and a host of other concerns, investigation and defense costs often become largely irrelevant when an organization is required to investigate or defend against charges of legal or other business misconduct that expose the organization or its leadership to potentially devastating legal or business consequences. When these events happen, organizations and their leaders often see little option to spend whatever is necessary to defend their organization and its reputation.
Compared to the reported internal investigation and defense expenditures of private sector organizations that have faced these these make or break investigations, the Justice Department’s reported expenditures to date on the Russian probe look small.
For instance, Twenty-First Century Fox in March, 2017 Securities and Exchange Commission (SEC) filings disclosed spending $45 million tied to litigation related to harassment allegations in the 9 first three quarters of 2017 and $10 million “related to settlements of pending and potential litigations” during its fiscal third quarter as well as having received investigative inquiries and stockholder demands to inspect the books and records of the company which could lead to future litigation in the aftermath of sexual harassment allegations at Fox News.
In contrast, Avon Products spent nearly $500 million conducting its internal investigation before paying a $135m fine to the US government to settle charges it violated the Foreign Corrupt Practices Act by giving Chinese authorities $8 million in gifts and cash while it sought to obtain the first “direct sell” license in China.
These and other publicly disclosed expenditures make clear that corporate officers and directors need to reassess their investment in compliance both to strengthen the effectiveness of their efforts and to plan to deal with the financial, legal, operational and other costs of investigating and defending potential charges.
Aboaut The Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for management work, coaching, teachings, and publications.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, internal controls and regulatory compliance, change management and other performance and operations management and compliance. Her day-to-day work encompasses both labor and employment issues, as well as independent contractor, outsourcing, employee leasing, management services and other nontraditional service relationships. She supports her clients both on a real-time, “on demand” basis and with longer term basis to deal with all aspects for workforce and human resources management, including, recruitment, hiring, firing, compensation and benefits, promotion, discipline, compliance, trade secret and confidentiality, noncompetition, privacy and data security, safety, daily performance and operations management, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Well-known for her extensive work with health, insurance, financial services, technology, energy, manufacturing, retail, hospitality, governmental and other highly regulated employers, her nearly 30 years’ of experience encompasses domestic and international businesses of all types and sizes.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other concerns by her service as a management consultant, business coach and consultant and policy strategist as well through her leadership participation in professional and civic organizations such her involvement as the Vice Chair of the North Texas Healthcare Compliance Association; Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE: Coalition on Patient Empowerment; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Gulf Coast TEGE Council Exempt Organization Coordinator; a founding Board Member and past President of the Alliance for Healthcare Excellence; former board member and Vice President of the Managed Care Association; past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; a member and policy adviser to the National Physicians’ Council for Healthcare Policy; current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee; current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section; Past Chair of the ABA Health Law Section Managed Care & Insurance Section; ABA Real Property Probate and Trust (RPTE) Section former Employee Benefits Group Chair, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative, and Defined Contribution Committee Co-Chair, past Welfare Benefit Committee Chair and current Employee Benefits Group Fiduciary Responsibility Committee Co-Chair, Substantive and Group Committee member, Membership Committee member and RPTE Representative to the ABA Health Law Coordinating Council; past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a former member of the Board of Directors, Treasurer, Member and Continuing Education Chair of the Southwest Benefits Association and others.
Ms. Stamer also is a widely published author, highly popular lecturer, and serial symposia chair, who publishes and speaks extensively on human resources, labor and employment, employee benefits, compensation, occupational safety and health, and other leadership, performance, regulatory and operational risk management, public policy and community service concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clients on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications.
Want to know more? See here for details about the author of this update, attorney Cynthia Marcotte Stamer, e-mail her here or telephone Ms. Stamer at (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at SolutionsLawPress.com such as the following:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please provide your current contact information and preferences including your preferred e-mail by creating or updating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on Consider Internal Investigation & Defense Costs When Administering Compliance Programs |
ADA, Affirmative Action, board of directors, Brokers, Child Labor, Civil Monetary Penalties, Civil Rights, Claims Administration, compliance, conflict of interest, Corporate Compliance, corporate governance, Data Breach, Data Security, directors, E-Verify, EEOC, Employers, Employment, Employment Discrimination, Employment Policies, Employment Tax, English As A Second Language, ERISA, Executive Compensation, Fair Credit Reporting Act, Fair Labor Standards Act, FICA, fiduciary duty, Fiduciary Responsibility, Financial Security, FINRA, FLSA, GINA, Government Contractors, h-2A Visa, health benefit, health plan, HIPAA, Human Resources, I-9, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Labor Management Relations, Leadership, LEP, LGBT, Management, Managment, Military Leave, Non-Compete, Nonresident aliens, occupational safety, OFCCP, officers, OSHA, Overtime, Pay, Plan Admistrator, Privacy, Professional Liability, Rehabilitation Act, Retaliation, Safety, Uncategorized, USERRA, VEVRRA, visas, Wage & Hour, Whistleblower, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
October 6, 2017
As businesses continue to struggle to comply with the growing plethora of federal and state laws mandating data security, the identity theft and cyber security epidemic keeps growing.
As human resources and other business leaders work to guard their own data and respond to employee demands for assistance in responding to breaches of their personal financial and other data, this weeks’ announcement that embattled credit monitoring giant Equifax has been awarded the exclusive contract to provide taxpayer identification and fraud prevention services to the Internal Revenue Service has many questioning whether these investments are futile.
The IRS’ announcement comes despite the September 7, 2017 announcement by Equifax of a data breach of its records impacting sensitive personal information of millions of consumers including:
- The names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers of an estimated 143 million U.S. consumers;
- Credit card numbers for approximately 209,000 U.S. consumers,
- Certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers,and
- Personal information for certain U.K. and Canadian consumers.
The huge breach already was creating many headaches for many businesses and their human resources departments before the IRS announced the award of the contract to Equifax. Due to the massive size of the breach, mist companies have been required to respond to concerns of workers impacted directly by the breach as well as requests of employees and identity theft protection companies that the business consider offering cybersecurity protection for employees or customers.
Beyond helping their workforce understand and cope with the news, many businesses and employee benefit plans also face the added headache of needing to investigate and respond to concerns about their own potential responsibilities to provide breach notification or take other actions. This added headache arises due to their or their plans’ use of Equifax or vendors utilizing Equifax to run employee or vendor background checks or carry out internal employee or employee benefit plan, customer or other business activities. These involvements often give rise to duties to conduct investigations and potentially provide notification or other responses to employees, applicants, benefit plan members, contractors or customers whose data may have been impacted under the Fair and Accurate Credit Transactions Act (FACTA), the Health Insurance Portability and Accountability Act (HIPAA), the Employee Retirement Income Security Act (ERISA) Fiduciary Responsibility rules or various other federal and state laws and regulations, vendor contracts or their own data privacy or security policies.
When notification is recommended or required, human resources and other business leaders also have to consider if modifications should be considered to standard protocols recommended to data breach victims. Notification and registration as an identity theft victim with Equifax long has been a standard part of the federal and state government recommended protocol for recommended to consumers impacted by identity theft or other data breaches. See,e.g., IRS Taxpayer Guide To Identity Theft. Although government agencies as of yet have not changed this recommendation to remove Equifax reporting, many consumers and others view reporting to Equifax as akin to the fox watching the hen house. Consequently, employers and other parties helping consumers respond to the breach often receive push back or questions from consumers about the appropriateness and security reporting to Equifax in light of its breach.
Beyond evaluating and handling their own legal responsibilities to investigate and deal with any breach impacting their data, employers and other business leaders also likely are or should consider what claims against Equifax, other vendors and business partners involved with Equifax and their own liability insurers are available and warranted to help cover the costs and potential liabilities for the business arising from the breach and it’s fall out.
As employers and other businesses work through these issues, They should keep in mind that the fallout is likely to continue for years and be further complicated by past and subsequent breaches impacting other governmental and private organizations. Human resources, employee benefits and other businesses and their leaders can expect to experience challenges dealing with fraudulent uses of misappropriated information as well as demands that they tighten up their background check, data security and usage and other practices and documentation to mitigate risks from the compromised data.
Human resources, employee benefits and other business leaders need to secure the assistance of counsel experienced in guiding their organizations through these and other challenges.
About The Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for management work, coaching, teachings, and publications.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, internal controls and regulatory compliance, change management and other performance and operations management and compliance. Her day-to-day work encompasses both labor and employment issues, as well as independent contractor, outsourcing, employee leasing, management services and other nontraditional service relationships. She supports her clients both on a real-time, “on demand” basis and with longer term basis to deal with all aspects for workforce and human resources management, including, recruitment, hiring, firing, compensation and benefits, promotion, discipline, compliance, trade secret and confidentiality, noncompetition, privacy and data security, safety, daily performance and operations management, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Well-known for her extensive work with health, insurance, financial services, technology, energy, manufacturing, retail, hospitality, governmental and other highly regulated employers, her nearly 30 years’ of experience encompasses domestic and international businesses of all types and sizes. Author of numerous works on privacy and data security, Ms. Stamer‘s experience includes involvement in cyber security and other data privacy and security matters for more than 20 years.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other concerns by her service as a management consultant, business coach and consultant and policy strategist as well through her leadership participation in professional and civic organizations such her involvement as the Vice Chair of the North Texas Healthcare Compliance Association; Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE: Coalition on Patient Empowerment; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Gulf Coast TEGE Council Exempt Organization Coordinator; a founding Board Member and past President of the Alliance for Healthcare Excellence; former board member and Vice President of the Managed Care Association; past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; a member and policy adviser to the National Physicians’ Council for Healthcare Policy; current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee; current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section; Past Chair of the ABA Health Law Section Managed Care & Insurance Section; ABA Real Property Probate and Trust (RPTE) Section former Employee Benefits Group Chair, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative, and Defined Contribution Committee Co-Chair, past Welfare Benefit Committee Chair and current Employee Benefits Group Fiduciary Responsibility Committee Co-Chair, Substantive and Group Committee member, Membership Committee member and RPTE Representative to the ABA Health Law Coordinating Council; past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a former member of the Board of Directors, Treasurer, Member and Continuing Education Chair of the Southwest Benefits Association and others.
Ms. Stamer also is a widely published author, highly popular lecturer, and serial symposia chair, who publishes and speaks extensively on human resources, labor and employment, employee benefits, compensation, occupational safety and health, and other leadership, performance, regulatory and operational risk management, public policy and community service concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clients on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications.
Want to know more? See here for details about the author of this update, attorney Cynthia Marcotte Stamer, e-mail her here or telephone Ms. Stamer at (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at SolutionsLawPress.com such as the following:
▪RAISE Act Immigration Reforms Touted As “Giving Americans A Raise”
▪Health Clinic At Houston Convention Center, Other HHS Help For Hurricane Harvey Victims
▪IRS Updates Amounts Used To Calculate 2017 Obamacare Individual Individual Shares Responsibility Tax Penalties
▪DB Plan Sponsors Check Out New Bifurcated Distribution Model Amendmentsy
▪U.S. News Names 2017-2018 “Best” Hospitals; Patient Usefulness Starts With Metholodogy Understanding
▪Use Lessons Of Past Mistakes or Injustice To Build Better Future
▪Prepare For Turnover, Other Challenges From Rising Workforce Competition
▪Employers, Health Plans Should Brace For Tightened Federal Mental Health Coverage Mandate Disclosure And Enforcement
▪Withholding Calculator Tool Helps Workers Figure Withholding
▪Better Preparing U.S. Workers To Fill Your Jobs
▪SCOTUS Ruling Bars Many State Arbitration Agreement Restrictions
▪$2.4M HIPAA Settlement Message Warns Health Plans & Providers Against Sharing Medical Info With Media, Others
If you or someone else you know would like to receive future updates about developments on these and other concerns, please provide your current contact information and preferences including your preferred e-mail by creating or updating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on Dealing With HR, Benefits & Other Headaches From Equifax and Other Data Breach |
Banking, board of directors, Brokers, Civil Monetary Penalties, Claims, Claims Administration, compliance, conflict of interest, Consumer Protection, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, defined benefit plan, Defined Benefit Plans, defined contribution plan, Defined Contribution Plans, directors, E-Verify, EBSA, Educational Privacy, employee, Employee Benefits, Employer, Employers, Employment, Employment Policies, Employment Tax, ERISA, ESOP, Excise Tax, FACTA, Fair Credit Reporting Act, FICA, fiduciary duty, Fiduciary Responsibility, Financial Security, Form 5500, GINA, Government Contractors, health benefit, Health Benefits, health Care, health insurance, health plan, Health Plans, HIPAA, Hiring, HR, Human Resources, I-9, Identity Theft, Income Tax, Insurance, insurers, Internal Controls, Internal Investigations, Internal Revenue Code, Internet, IRC, Labor Management Relations, Leadership, Management, Managment, Patient Empowerment, Payroll Tax, pension plan, Physician, Plan Admistrator, Privacy, Professional Liability, Protected Health Information, Provider, Reporting & Disclosure, retirement plan, Retirement Plans, Retirements, Risk Management, Security, Tax, Tax Credit, Tax Qualification, Technology, third party administrators, visas, Workforce | Tagged: ADA, Corporate Compliance, Data Breach, Employee Benefits, Employer, Employers, employment law, Equifax, ERISA, Health Care, Health Insurance, HIPAA, Human Resources, Insurance, Insurer, Labor Department, Privacy, Retirement Plans, Risk Management, Tax, Technology, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
May 10, 2017
Healthcare providers, health plans, healthcare clearinghouses and their business associates (Covered Entities) can’t disclose the name or other protected health care information about a patient in press releases or other announcements without prior authorization from the patient. That’s the clear lesson Covered Entities should learn from the $2.4 million payment to the U.S. Department of Health and Human Services (HHS) that the largest not-for-profit health system in Southeast Texas, Memorial Hermann Health System (MHHS) is paying to settle charges it violated the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule by issuing a press release with the name and other protected health information (PHI) about a patient without the patient’s prior HIPAA-compliant authorization under a Resolution Agreement and Corrective Action Plan (Resolution Agreement) announced May 10, 2017 by HHS Office of Civil Rights (OCR).
The Resolution Agreement resolves OCR charges the operator of 13 hospitals, eight Cancer Centers, three Heart & Vascular Institutes, and 27 sports medicine and rehabilitation centers violated the Privacy Rule that resulted from an OCR compliance review of MHHS triggered by multiple media reports suggesting that MHHS improperly disclosed the name and other details about a patient arrested and charged with presenting an allegedly fraudulent identification card to office staff at an MHHS’s clinic after MHHS clinic staff alerted law enforcement of suspicions the patient was presenting false identification to the clinic. According to OCR, after law enforcement investigated and arrested the patient, MHHS published a press release concerning the incident in which MHHS senior management approved the impermissible disclosure of the patient’s PHI by adding the patient’s name in the title of the press release without securing prior authorization of the patient.
While OCR concluded the report to law enforcement allowable under the Privacy Rule, OCR found MHHS violated the Privacy Rule by issuing the press release disclosing the patient’s name and other PHI without authorization from the patient and also by failing to timely document the sanctioning of its workforce members for impermissibly disclosing the patient’s information.
To resolve and avoid the potential Civil Monetary Penalties that HIPAA could authorize OCR to impose for the alleged Privacy Rule violation, MHHS agrees in the Resolution Agreement to pay OCR a $2.4 million monetary settlement and implement a corrective action plan that obligates MHHS to update and train its workforce on its policies and procedures on safeguarding PHI from impermissible uses and disclosures including specific instructions and procedures to:
- Address (a) Uses and disclosures for which an authorization is required, including to the media, to public officials, and on the internet; (b) Disclosures for law enforcement purposes; and (c) Uses and disclosures for health oversight activities;
- Identify MHHS personnel or representatives whom workforce members, agents, or business associates may contact in the event of any inquiry or concern regarding compliance with HIPAA in relation to these activities;
- Internal reporting procedures requiring all workforce members to report to the designated person or office at the earliest possible time any potential violations of the Privacy, Security or Breach Notification Rules or of MHHS’ privacy and security policies and procedures and MHHS promptly to investigate and address all received reports in a timely manner; and
- Application and documentation of appropriate sanctions (which may include retraining or other instructive corrective action, depending on the circumstances) against members of MHHS’ workforce, including senior level management, who fail to comply with the Privacy, Security or Breach Notification Rules or MHHS’ privacy and security policies and procedures, including a description of the sanctions; a timeframe in which MHHS will apply and document sanctions for violations of the HIPAA Rules or of MHHS’ privacy, security or breach policies or procedures; the manner in which MHHS will document the sanctions; and where MHHS will store or retain such documentation (e.g., personnel file).
The corrective action plan in the Resolution Agreement also requires all MHHS facilities to attest to their understanding of permissible uses and disclosures of PHI, including disclosures to the media and others.
Covered entities should keep in mind the MHHS Resolution Agreement is the latest in a series of OCR enforcement actions and resolution agreements highlighting the need for Covered Entities to adopt and use appropriate policies and procedures to prevent wrongful disclosures of PHI to the media or public. For instance, in June, 2013, OCR required Shasta Regional Medical Center (SRMC) to pay a $275,000 settlement payment and implement a comprehensive corrective action plan to resolve OCR charges stemming from SRMC’s disclosure of PHI about a patient to members of the media and its workforce in an effort to respond to accusations the patient made that SRMC engaged in fraud and other misconduct. See HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce. In contrast, the $2.2 million resolution agreement that OCR required New York Presbyterian Hospital for improperly allowing a film crew to film hospital patients in violation of HIPAA was almost 10 times greater than the SRMC penalty and was accompanied by OCR’s publication OCR of specific additional guidance warning Covered Entities against improper disclosures to the media. See $2 Million+ HIPAA Settlement, FAQ Warn Providers Protect PHI From Media, Other Recording Or Use.
Following on the heels of this previous guidance and prior enforcement actions warning Covered Entities against wrongful disclosure to the media, the MHHS Resolution Agreement sends a strong message to Covered Entities that they should expect little sympathy if their organizations improperly share PHI with the media. OCR’s announcement of the MHHS Resolution Agreement, for instance quotes OCR Director Roger Severino with stating that “Senior management should have known that disclosing a patient’s name on the title of a press release was a clear HIPAA Privacy violation that would induce a swift OCR response.” The announcement goes on to quote Director Severino further as stating, “This case reminds us that organizations can readily cooperate with law enforcement without violating HIPAA, but that they must nevertheless continue to protect patient privacy when making statements to the public and elsewhere.”
Conduct Entity-Wide Risk Assessment & Review & Tighten Media Relations Policies, Processes & Training ASAP
Covered entities should heed the warning by conducting a risk assessment of their organization’s susceptibility to potential improper disclosures to media or others and reviewing and implementing necessary written policies, procedures and training to prevent the improper disclosure of patient PHI to media or others unless the Covered Entity either secures prior HIPAA-compliant authorization from the patient or can prove the disclosure falls squarely under an exception to the Privacy Rule’s prohibition against disclosure of PHI without authorization except as allowed by the Privacy Rule.
Taking these and other needed steps to evaluate, and strengthen and enforce as needed, risk assessments, policies, procedures, and training to prevent wrongful use, access or disclosure of PHI to the media or others is particularly critical in light of the ongoing tightening of expectations, and rising enforcement and sanctions for HIPAA violations since Congress amended HIPAA in 2009. See OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website.
Based on experiences reported in the MHHS and other similar resolution agreements, Covered Entities also generally will want to ensure that their policies, procedures and training extend to all potential sources of communications that could involve patient information and make clear that the Privacy Rule restrictions must be followed even if the circumstances involve allegations of misconduct, special performance by healthcare providers or others that it would benefit the organization or certain individuals to have known to the public, or other circumstances likely to be of interest to the media or other parties.
As part of this process, covered entities should ensure they look outside the four corners of their Privacy Policies to ensure that appropriate training and clarification is provided to address media, practice transition, workforce communication and other policies and practices that may be covered by pre-existing or other policies of other departments or operational elements not typically under the direct oversight and management of the Privacy Officer such as media relations. Media relations, physician and patients affairs, outside legal counsel, media relations, marketing and other internal and external departments and consultants dealing with the media, the public or other inquiries or disputes should carefully include and coordinate with the privacy officer both to ensure appropriate policies and procedures are followed and proper documentation created and retained to show authorization, account, or meet other requirements.
In conducting this analysis and risk assessment, it will be important that Covered Entities include, but also look beyond the four corners of their Privacy Policies to ensure that their review and risk assessment identifies and assesses and addresses compliance risks on an entity wide basis. This entity-wide assessment should include both communications and requests for information normally addressed to the Privacy Officer as well as requests and communications that could arise in the course of media or other public relations, practice transition, workforce communication and other operations not typically under the direct oversight and management of the Privacy Officer. For this reason, Covered Entities also generally will not only to adopt and implement specific policies, processes and training in these other departments to prohibit and prevent inappropriate disclosures of PHI in the course of those departments operations. It also may be advisable to pre-established processes for reviewing media or other communications for potential PHI content and require prior review of any proposed public relations and other internal or external communications containing patient PHI or other information by the privacy officer, legal counsel or another suitably qualified party.
Because of the high risk that the preparation or review of media or other public communications reports will involve the use and disclosure of PHI, Covered Entities also generally should verify that all outside media or public relations, legal, or other outside service providers participating in the investigation, response or preparation or review of communications to the media or others both are covered by signed business associate agreements that fulfill the Privacy Rule and other requirements of HIPAA as well as possess detailed knowledge and understanding of the Privacy and Security Rules suitable to participate in and help safeguard the Covered Entity against violations of these and other Privacy Rules. See e.g., Latest HIPAA Resolution Agreement Drives Home Importance Of Maintaining Current, Signed Business Associate Agreements.
About The Author
Recognized by LexisNexis® Martindale-Hubbell® as a “AV-Preeminent” (Top 1%/ the highest) and “Top Rated Lawyer,” with special recognition as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Health Care,” “Labor & Employment,” “Tax: Erisa & Employee Benefits” and “Business and Commercial Law” by D Magazine, the author of this update is widely known for her 29 plus years’ of work in health care, health benefit, health policy and regulatory affairs and other health industry concerns as a practicing attorney and management consultant, thought leader, author, public policy advocate and lecturer.
Throughout her adult life and nearly 30-year legal career, Ms. Stamer’s legal, management and governmental affairs work has focused on helping health industry, health benefit and other organizations and their management use the law, performance and risk management tools and process to manage people, performance, quality, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer supports these organizations and their leaders on both a real-time, “on demand” basis as well as outsourced operations or special counsel on an interim, special project, or ongoing basis with strategic planning and product and services development and innovation; workforce and operations management, crisis preparedness and response as well as to prevent, stabilize and cleanup legal and operational crises large and small that arise in the course of operations.
As a core component of her work, Ms. Stamer has worked extensively throughout her career with health care providers, health plans and insurers, managed care organizations, health care clearinghouses, their business associates, employers, banks and other financial institutions, management services organizations, professional associations, medical staffs, accreditation agencies, auditors, technology and other vendors and service providers, and others on legal and operational compliance, risk management and compliance, public policies and regulatory affairs, contracting, payer-provider, provider-provider, vendor, patient, governmental and community relations and matters including extensive involvement advising, representing and defending public and private hospitals and health care systems; physicians, physician organizations and medical staffs; specialty clinics and pharmacies; skilled nursing, home health, rehabilitation and other health care providers and facilities; medical staff, accreditation, peer review and quality committees and organizations; billing and management services organizations; consultants; investors; technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, insurers, self-insured health plans and other payers; and other health industry clients to manage and defend compliance, public policy, regulatory, staffing and other operations and risk management concerns. A core focus of this work includes work to establish and administer compliance and risk management policies; comply with requirements, investigate and respond to Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; dealings with JCHO and other accreditation and quality organizations; investigation and defense of private litigation and other federal and state health care industry investigations and enforcement; insurance or other liability management and allocation; process and product development; managed care, physician and other staffing, business associate and other contracting; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others.
Author of leading works on HIPAA and other privacy and data security works and the scribe leading the American Bar Association Joint Committee on Employee Benefits Annual Agency Meeting with OCR, her experience includes extensive compliance, risk management and data breach and other crisis event investigation, response and remediation under HIPAA and other data security, privacy and breach laws. Heavily involved in health care and health information technology, data and related process and systems development, policy and operations innovation and a Scribe for ABA JCEB annual agency meeting with OCR for many years who has authored numerous highly regarded works and training programs on trade secret, HIPAA and other medical, consumer, insurance, tax, and other privacy and data security, Ms. Stamer also is widely recognized for her extensive work and leadership on leading edge health care and benefit policy and operational issues including meaningful use and EMR, billing and reimbursement, quality measurement and reimbursement, HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and many other concerns.
In connection with this work, Ms. Stamer has worked extensively with health care providers, health plans, health care clearinghouses, their business associates, employers and other plan sponsors, banks and other financial institutions, and others on risk management and compliance with HIPAA, FACTA, trade secret and other information privacy and data security rules, including the establishment, documentation, implementation, audit and enforcement of policies, procedures, systems and safeguards, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns. Her clients include public and private health care providers, health insurers, health plans, technology and other vendors, and others.
Her work includes both regulatory and public policy advocacy and thought leadership, as well as advising and representing a broad range of health industry and other clients about policy design, drafting, administration, business associate and other contracting, risk assessments, audits and other risk prevention and mitigation, investigation, reporting, mitigation and resolution of known or suspected violations or other incidents and responding to and defending investigations or other actions by plaintiffs, DOJ, OCR, FTC, state attorneys’ general and other federal or state agencies, other business partners, patients and others.
In addition to representing and advising these organizations, she also has conducted training on Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, MGMA, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
A former lead consultant to the Government of Bolivia on its Pension Privatization Project with extensive domestic and international public policy concerns in Pensions, healthcare, workforce, immigration, tax, education and other areas.
The American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting, former Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Section, past ABA JCEB Council Representative, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has worked closely with a diverse range of physicians, hospitals and healthcare systems, DME, Pharma, clinics, health care providers, managed care, insurance and other health care payers, quality assurance, credentialing, technical, research, public and private social and community organizations, and other health industry organizations and their management deal with governance; credentialing, patient relations and care; staffing, peer review, human resources and workforce performance management; outsourcing; internal controls and regulatory compliance; billing and reimbursement; physician, employment, vendor, managed care, government and other contracting; business transactions; grants; tax-exemption and not-for-profit; licensure and accreditation; vendor selection and management; privacy and data security; training; risk and change management; regulatory affairs and public policy and other concerns.
Past Chair of the ABA Managed Care & Insurance Interest Group and, a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also has extensive health care reimbursement and insurance experience advising and defending health plans, health care providers, payers, and others about Medicare, Medicaid, Medicare and Medicaid Advantage, Tri-Care, self-insured group, association, individual and group and other health benefit programs and coverages including but not limited to advising public and private payers about coverage and program design and documentation, advising and defending providers, payers and systems and billing services entities about systems and process design, audits, and other processes; provider credentialing, and contracting; providers and payer billing, reimbursement, claims audits, denials and appeals, coverage coordination, reporting, direct contracting, False Claims Act, Medicare & Medicaid, ERISA, state Prompt Pay, out-of-network and other “nonpar,” insured, and other health care claims, prepayment, post-payment and other coverage, claims denials, appeals, billing and fraud investigations and actions and other reimbursement and payment related investigation, enforcement, litigation and actions.
A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, privacy and data security, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other related concerns by her service in the leadership of the Solutions Law Press, Inc. Coalition for Responsible Health Policy, its PROJECT COPE: Coalition on Patient Empowerment, and a broad range of other professional and civic organizations including North Texas Healthcare Compliance Association, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children (now Warren Center For Children); current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, past Representative and chair of various committees of ABA Joint Committee on Employee Benefits; an ABA Health Law Coordinating Council representative, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposium and chair, faculty member and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, Insurance Thought Leadership and many other prominent publications and speaks and conducts training for a broad range of professional organizations.
For more information about Ms. Stamer or her health industry and other experience and involvements, see here or contact Ms. Stamer via telephone at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved. For information about republication or other use, please contact Ms. Stamer here.
Comments Off on $2.4M HIPAA Settlement Message Warns Health Plans & Providers Against Sharing Medical Info With Media, Others |
ADA, board of directors, Brokers, Cafeteria Plans, Civil Monetary Penalties, Civil Rights, compliance, conflict of interest, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, directors, Disability Discrimination, Electronic Medical Record, employee, Employee Benefits, Employer, Employers, Employment, EMR, ERISA, Fair Credit Reporting Act, fiduciary duty, GINA, HIPAA, HIPAA, Hiring, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Internal Revenue Code, IRC, Leadership, LGBT, Management, Medicare Part D, Mental Health, Mental Health Parity, MEWA, Physician, Prescription Drugs, Privacy, Professional Liability, Protected Health Information, Provider, Risk Management, Technology, third party administrators, Uncategorized | Tagged: Health Care Provider, Health Plans, HIPAA, Medical Privacy, PHI, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
April 26, 2017
A new Department of Health and Human Services Office of Civil Rights (OCR) CardioNet Resolution Agreement and Corrective Action Plan (Resolution Agreement) settling OCR charges of violations of the Privacy and Security Rules of the Health Insurance Portability & Accountability Act against remote cardiac monitoring provider CardioNet provides important lessons for all health plans, health insurers, telemedicine and other healthcare providers, healthcare clearinghouses (Covered Entities) and their business associates about steps to take to reduce their risk of getting hit with big OCR penalty like the $2.5 million settlement payment CardioNet must pay under the Resolution Agreement.
OCR announced the first OCR HIPAA settlement involving a wireless health services provider Monday, April 24. Under the Resolution Agreement, CardioNet agrees to pay OCR $2.5 million and to implement a corrective action plan to settle potential OCR charges it violated the HIPAA Privacy and Security Rules based on the impermissible disclosure of unsecured electronic protected health information (ePHI).
CardioNet Charges & Settlement
As has become increasingly common in recent years, the CardioNet settlement arose from concerns initially brought to OCR’s attention in connection with a HIPAA breach notification report. On January 10, 2012, OCR received notification from the provider of remote mobile monitoring of and rapid response to patients at risk for cardiac arrhythmias that a workforce member’s laptop with the ePHI of 1,391 individuals was stolen from a parked vehicle outside of the employee’s home. CardioNet subsequently notified OCR of a second breach of ePHI 2,219 individuals, respectively.
Likewise, the HIPAA breaches uncovered by OCR in the course of investigating these CardioNet breaches occur in the operations of many other covered entities. According to the OCR’s investigation in response to these breach reports revealed a series of continuing compliance concerns, including:
- CardioNet failed to conduct an accurate and thorough risk analysis to assess the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI and failed to plan for and implement security measures sufficient to reduce those risks and vulnerabilities;
- CardioNet’s policies and procedures implementing the standards of the HIPAA Security Rule were in draft form and had not been implemented;
- CardioNet was unable to produce any final policies or procedures regarding the implementation of safeguards for ePHI, including those for mobile devices;
- CardioNet failed to implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of its facilities, the encryption of such media, and the movement of these items within its facilities until March 2015; and
- CardioNet failed to safeguard against the impermissible disclosure of protected health information by its employees, thereby permitting access to that information by an unauthorized individual, and failed to take sufficient steps to immediately correct the disclosure.
To resolve these OCR charges, CardioNet agrees in the Resolution Agreement to pay $2.5 million to OCR and implement a corrective action plan. Among other things, the corrective action plan requires CardioNet to complete the following actions to the satisfaction of OCR:
- Prepare a current, comprehensive and thorough Risk Analysis of security risks and vulnerabilities that incorporates its current facility or facilities and the electronic equipment, data systems, and applications controlled, currently administered or owned by CardioNet, that contain, store, transmit, or receive electronic protected health information (“ePHI”) and update that Risk Analysis annually or more frequently, if appropriate in response to environmental or operational changes affecting the security of ePHI.
- Assess whether its existing security measures are sufficient to protect its ePHI and revise its Risk Management Plan, Policies and Procedures, and training materials and implement additional security measures, as needed.
- Develop and implement an organization-wide Risk Management Plan to address and mitigate any security risks and vulnerabilities found in the Risk Analysis as required by the Risk Management Plan.
- Review and, to the extent necessary, revise, its current Security Rule Policies and Procedures (“Policies and Procedures”) based on the findings of the Risk Analysis and the implementation of the Risk Management Plan to comply with the HIPAA Security Rule.
- Provide certification to OCR that all laptops, flashdrives, SD cards, and other portable media devices are encrypted, together with a description of the encryption methods used (“Certification”).
- Review, revise its HIPAA Security training to include a focus on security, encryption, and handling of mobile devices and out-of-office transmissions and other policies and practices require to address the issues identified in the Risk Assessment and otherwise comply with the Risk Management Plan and HIPAA train its workforce on these policies and practices.
- Investigate all potential violations of its HIPAA policies and procedures and notify OCR in writing within 30 days of any violation.
- Submit annual reports to OCR, which must be signed by an owner or officer of CardioNet attesting that he or she has reviewed the annual report, has made a reasonable inquiry regarding its content and believes that, upon such inquiry, the information is accurate and truthful.
- Maintain for inspection and copying, and provide to OCR, upon request, all documents and records relating to compliance with the corrective action plan for six years.
Implications For Covered Entities & Business Associates
The latest in a rapidly-growing list of high dollar HIPAA enforcement actions by OCR, the CardioNet Resolution Agreement contains numerous lessons for other Covered entities and their business associates about the importance of appropriate HIPAA privacy and security compliance, including but not limited to the following:
- Like many previous resolution agreements announced by OCR, the Resolution Agreement reiterates the responsibility of covered entities and business associates to properly secure their ePHI and that as part of this process, OCR expects all laptop computers and other mobile devices containing or with access to ePHI be properly encrypted and secured.
- It also reminds covered entities and their business associates to be prepared for, and expect an audit from OCR when OCR receives a report that their organization experienced a large breach of unsecured ePHI.
- The Resolution Agreement’s highlighting of the draft status of CardioNet’s privacy and security policies also reflects OCR expects covered entities to actually final policies, procedures and training in place for maintaining compliance with HIPAA.
- The discussion and requirements in the Corrective Action Plan relating to requirements to conduct comprehensive risk assessments at least annually and in response to other events, and to update policies and procedures in response to findings of these risk assessments also drives home the importance of conducting timely, documented risk analyses of the security of their ePHI, taking prompt action to address known risks and periodically updating the risk assessment and the associated privacy and security policies and procedures in response to the findings of the risk assessment and other changing events.
- The requirement in the Resolution Agreement of leadership attestation and certification on the required annual report reflects OCR’s expectation that leadership within covered entities and business associates will make HIPAA compliance a priority and will take appropriate action to oversee compliance.
- Finally, the $2.5 million settlement payment required by the Resolution Agreement and its implementation against CardioNet makes clear that OCR remains serious about HIPAA enforcement.
Clearly, covered entities, business associates and their management should take steps to promptly review the adequacy of their organizations’ HIPAA compliance policies, practices and documentation in light of the deficiencies listed in the CardioNet and other HIPAA OCR settlements and civil monetary penalty assessments. See e.g., Latest HIPAA Resolution Agreement Drives Home Importance Of Maintaining Current, Signed Business Associate Agreements; $400K HIPAA Penalty Teaches Risk Assessment Importance; $3.2 Children’s HIPAA CMP Teaches Key Lessons.
Of course, covered entities and business associates need to keep in mind that acts, omissions and events that create HIPAA liability risks also carry many other potential legal and business risks. For instance, since PHI records and data involved in such breaches usually incorporates Social Security Numbers, credit card or other debt or payment records or other personal consumer information, and other legally sensitive data, covered entities and business associates generally also may face investigation, notification and other responsibilities and liabilities under confidentiality, privacy or data security rules of the Fair and Accurate Credit Transaction Act (FACTA), the Internal Revenue Code, the Social Security Act, state identity theft, data security, medical confidentiality, privacy and ethics, insurance, consumer privacy, common law or other state privacy claims and a host of other federal or state laws. Depending on the nature of the covered entity or its business associates, the breach or other privacy event also may trigger fiduciary liability exposures for health plan fiduciaries in the case of a health plan, professional ethics or licensing investigations or actions against health care providers, insurance companies, administrative service providers or brokers, shareholder or other investor actions, employment or vendor termination or disputes and a host of other indirect legal consequences.
Beyond, and regardless of if, a covered entity or business ultimately succeeds in defending its actions against a charge of violating any of these or other standards, however, covered entities, business associates and their leaders should keep in mind that the most material and often most intractable consequences of a HIPAA or other data or other privacy breach report or public accusation, investigation, admission also typically are the most inevitable:
- The intangible, but critical loss of trust and reputation covered entities and business associates inevitably incur among their patients, participants, business partners, investors and the community; and
- The substantial financial expenses and administrative and operational disruptions of investigating, defending the actions of the organization and implementation of post-event corrective actions following a data or other privacy breach, audit, investigation, or charge.
In light of these risks, covered entities business associates and their management should use the experiences of CardioNet and other covered entities or business associates caught violating HIPAA or other privacy and security standards to reduce their HIPAA and other privacy and data security exposures. Management of covered entities and their business associates should take steps to ensure that their organizations policies, practices and procedures currently are up-to-date, appropriately administered and monitored, and properly documented. Management should ensure that their organizations carefully evaluate and strengthen as necessary their current HIPAA risk assessments, policies, practices, record keeping and retention and training in light of these and other reports as they are announced in a well-documented manner. The focus of these activities should be both to maintain compliance and position their organizations efficiently and effectively to respond to and defend their actions against a data breach, investigation, audit or accusation of a HIPAA or other privacy or security rule violation with a minimum of liability, cost and reputational and operational damages.
As the conduct of these activities generally will involve the collection and analysis of legally sensitive matters, most covered entities and business associates will want to involve legal counsel experienced with these matters and utilize appropriate procedures to be able to use and assert attorney-client privilege and other evidentiary privileges to mitigate risks associated with these processes. To help plan for and mitigate foreseeable expenses of investigating, responding to or mitigating a known, suspected or asserted breech or other privacy event, most covered entities and business associates also will want to consider the advisability of tightening privacy and data security standards, notification, cooperation and indemnification protections in contracts between covered entities and business associates, acquiring or expanding data breach or other liability coverage, or other options for mitigating the financial costs of responding to a breach notification, investigation or enforcement action.
About The Author
Recognized by LexisNexis® Martindale-Hubbell® as a “AV-Preeminent” (Top 1%/ the highest) and “Top Rated Lawyer,” with special recognition as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Health Care,” “Labor & Employment,” “Tax: Erisa & Employee Benefits” and “Business and Commercial Law” by D Magazine, the author of this update is widely known for her 29 plus years’ of work in health care, health benefit, health policy and regulatory affairs and other health industry concerns as a practicing attorney and management consultant, thought leader, author, public policy advocate and lecturer.
Throughout her adult life and nearly 30-year legal career, Ms. Stamer’s legal, management and governmental affairs work has focused on helping health industry, health benefit and other organizations and their management use the law, performance and risk management tools and process to manage people, performance, quality, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer supports these organizations and their leaders on both a real-time, “on demand” basis as well as outsourced operations or special counsel on an interim, special project, or ongoing basis with strategic planning and product and services development and innovation; workforce and operations management, crisis preparedness and response as well as to prevent, stabilize and cleanup legal and operational crises large and small that arise in the course of operations.
As a core component of her work, Ms. Stamer has worked extensively throughout her career with health care providers, health plans and insurers, managed care organizations, health care clearinghouses, their business associates, employers, banks and other financial institutions, management services organizations, professional associations, medical staffs, accreditation agencies, auditors, technology and other vendors and service providers, and others on legal and operational compliance, risk management and compliance, public policies and regulatory affairs, contracting, payer-provider, provider-provider, vendor, patient, governmental and community relations and matters including extensive involvement advising, representing and defending public and private hospitals and health care systems; physicians, physician organizations and medical staffs; specialty clinics and pharmacies; skilled nursing, home health, rehabilitation and other health care providers and facilities; medical staff, accreditation, peer review and quality committees and organizations; billing and management services organizations; consultants; investors; technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, insurers, self-insured health plans and other payers; and other health industry clients to manage and defend compliance, public policy, regulatory, staffing and other operations and risk management concerns. A core focus of this work includes work to establish and administer compliance and risk management policies; comply with requirements, investigate and respond to Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; dealings with JCHO and other accreditation and quality organizations; investigation and defense of private litigation and other federal and state health care industry investigations and enforcement; insurance or other liability management and allocation; process and product development; managed care, physician and other staffing, business associate and other contracting; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others.
In the course of this work, Ms. Stamer has accumulated extensive experience helping health industry clients manage workforce, medical staff, vendors and suppliers, medical billing, reimbursement, claims and other provider-payer relations, business partners, and their recruitment, performance, discipline, compliance, safety, compensation, benefits, and training, board, medical staff and other governance; compliance and internal controls; strategic planning, process and quality improvement; change management; assess, deter, investigate and address staffing, quality, compliance and other performance; meaningful use, EMR, HIPAA and other data security and breach and other health IT and data; crisis preparedness and response; internal, government and third-party reporting, audits, investigations and enforcement; government affairs and public policy; and other compliance and risk management, government and regulatory affairs and operations concerns.
Author of leading works on HIPAA and other privacy and data security works and the scribe leading the American Bar Association Joint Committee on Employee Benefits Annual Agency Meeting with OCR, her experience includes extensive compliance, risk management and data breach and other crisis event investigation, response and remediation under HIPAA and other data security, privacy and breach laws. Heavily involved in health care and health information technology, data and related process and systems development, policy and operations innovation and a Scribe for ABA JCEB annual agency meeting with OCR for many years who has authored numerous highly regarded works and training programs on HIPAA and other data security, privacy and use, Ms. Stamer also is widely recognized for her extensive work and leadership on leading edge health care and benefit policy and operational issues including meaningful use and EMR, billing and reimbursement, quality measurement and reimbursement, HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and many other concerns.
In connection with this work, Ms. Stamer has worked extensively with health care providers, health plans, health care clearinghouses, their business associates, employers and other plan sponsors, banks and other financial institutions, and others on risk management and compliance with HIPAA, FACTA, trade secret and other information privacy and data security rules, including the establishment, documentation, implementation, audit and enforcement of policies, procedures, systems and safeguards, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns. Her clients include public and private health care providers, health insurers, health plans, technology and other vendors, and others.
Her work includes both regulatory and public policy advocacy and thought leadership, as well as advising and representing a broad range of health industry and other clients about policy design, drafting, administration, business associate and other contracting, risk assessments, audits and other risk prevention and mitigation, investigation, reporting, mitigation and resolution of known or suspected violations or other incidents and responding to and defending investigations or other actions by plaintiffs, DOJ, OCR, FTC, state attorneys’ general and other federal or state agencies, other business partners, patients and others.
In addition to representing and advising these organizations, she also has conducted training on Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, MGMA, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
A former lead consultant to the Government of Bolivia on its Pension Privatization Project with extensive domestic and international public policy concerns in Pensions, healthcare, workforce, immigration, tax, education and other areas.
The American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting, former Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Section, past ABA JCEB Council Representative, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has worked closely with a diverse range of physicians, hospitals and healthcare systems, DME, Pharma, clinics, health care providers, managed care, insurance and other health care payers, quality assurance, credentialing, technical, research, public and private social and community organizations, and other health industry organizations and their management deal with governance; credentialing, patient relations and care; staffing, peer review, human resources and workforce performance management; outsourcing; internal controls and regulatory compliance; billing and reimbursement; physician, employment, vendor, managed care, government and other contracting; business transactions; grants; tax-exemption and not-for-profit; licensure and accreditation; vendor selection and management; privacy and data security; training; risk and change management; regulatory affairs and public policy and other concerns.
Past Chair of the ABA Managed Care & Insurance Interest Group and, a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also has extensive health care reimbursement and insurance experience advising and defending health care providers, payers, and others about Medicare, Medicaid, Medicare and Medicaid Advantage, Tri-Care, self-insured group, association, individual and group and other health benefit programs and coverages including but not limited to advising public and private payers about coverage and program design and documentation, advising and defending providers, payers and systems and billing services entities about systems and process design, audits, and other processes; provider credentialing, and contracting; providers and payer billing, reimbursement, claims audits, denials and appeals, coverage coordination, reporting, direct contracting, False Claims Act, Medicare & Medicaid, ERISA, state Prompt Pay, out-of-network and other “nonpar,” insured, and other health care claims, prepayment, post-payment and other coverage, claims denials, appeals, billing and fraud investigations and actions and other reimbursement and payment related investigation, enforcement, litigation and actions.
A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, privacy and data security, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other related concerns by her service in the leadership of the Solutions Law Press, Inc. Coalition for Responsible Health Policy, its PROJECT COPE: Coalition on Patient Empowerment, and a broad range of other professional and civic organizations including North Texas Healthcare Compliance Association, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children (now Warren Center For Children); current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, past Representative and chair of various committees of ABA Joint Committee on Employee Benefits; an ABA Health Law Coordinating Council representative, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposium and chair, faculty member and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, Insurance Thought Leadership and many other prominent publications and speaks and conducts training for a broad range of professional organizations.
For more information about Ms. Stamer or her health industry and other experience and involvements, see here or contact Ms. Stamer via telephone at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved. For information about republication or other use, please contact Ms. Stamer here.
Comments Off on Latest $2.5M HIPAA Settlement Warning To Health Plans, Providers: Get HIPAA Compliant |
ARRA, Attorney-Client Privilege, board of directors, Brokers, Civil Monetary Penalties, Civil Rights, compliance, Consumer Protection, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, directors, Electronic Medical Record, Employee Benefits, Employer, fiduciary duty, Fiduciary Responsibility, FINRA, GINA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Physician, Plan Admistrator, Privacy, Professional Liability, Protected Health Information, Provider, Risk Management, Technology, Telecommuting, Uncategorized | Tagged: Breach, Breach Notification, Business Associate, Covered Entity, Health Insurance, Health Plan, HIPAA, HIPAA Privacy, HIPAA Security, Medical Privacy, OCR, Office of Civil Rights, REmote Care, Technology, Telemedicine |
Permalink
Posted by Cynthia Marcotte Stamer
October 28, 2016
Cyber and other bullying usually is discussed as a child protection concern. However bullying of adults in the workplace also can be a big employment issue.
Applying the term “harassment” to adult bullying in the workplace allows most businesses to rapidly recognize need to prevent bullying and harassment in the workplace.
The connection between bullying and harassment is rapidly apparent from the definition of bullying. The government website stopbullying.gov defines “bullying” as unwanted, aggressive behavior among school aged children that involves a real or perceived power imbalance. The behavior is repeated, or has the potential to be repeated, over time. Bullying includes actions such as making threats, spreading rumors, attacking someone physically or verbally, and excluding someone from a group on purpose.”
In employment or other adult environments, the word “harassment” typically is used instead of bullying to refer to aggressive unwarranted behavior against an adult. Regardless of which term is used, bullying and harassment in workplaces and other communities is disruptive for the victims, co-workers, the employment or other community and those who interact with them.
Of course by now, all businesses and their leaders are legally accountable to know that the law generally requires businesses to prevent and protect their employees against harassment by management or other employees, customers, vendors and others with whom they do business on account of sex, sexual preference, race, age, disability, National origin, religion, whistleblower status, worker’s compensation or certain other benefit claims and the exercise of a host of other protected types of conduct.
Beyond the substantial legal exposures that businesses risk from harassment in the workplace, harassment or other pulling in the work place also inevitably creates other substantial operation costs for businesses by undermining job performance of bullying victims and others, undermining morale, increasing employee turnover, creating distractions, increasing management demands, eroding trust and team work, and more.
To reduce their exposure to these legal and operational risks, most US businesses have policies, conduct training and investigations, and engage in a host of other anti-harassment activities. Even with these efforts, however, effective prevention, detection and management of bullying and other harassment behaviors in most workplaces remains a challenge. For this reason businesses and their management should constantly be on the watch for tips and tools ate them in this endeavor.
The United States government’s annual Stop Bullying Month observances each October provide an excellent opportunity for US businesses and employers to strengthen their anti-harassment risks and compliance by joining in the celebration in October and using the resources available in their anti-harassment efforts throughout the year.
Businesses also may want to take advantage of resources like stopbullying.gov that provide tips and training for identifying and addressing bullying of children and others requiring special protection.
Stopbullying.gov, for instance includes a multitude of resources for Parents, Educators, Communities, and others that can be reworked and applied and workplace and other business contexts. Beyond these generally applicable tips, The website also includes videos and other materials addressing special topics like Cyberbullying and what to do about it, Sexual Preference Harassment and many others.
Human resources and other business leaders should check out these resources and leverage them to expand their tools and strengthen their anti-harassment efforts and risk management.
About The Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney and management consultant, author, public policy advocate and lecturer widely known for work, teachings and publications.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, internal controls and regulatory compliance, change management and other performance and operations management and compliance. She supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares shared her thought leadership, experience and advocacy on these and other concerns by her service in the leadership of a broad range of other professional and civic organization including her involvement as the Vice Chair of the North Texas Healthcare Compliance Association, Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE: Coalition on Patient Empowerment, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Board Compliance Chair and Board member of the National Kidney Foundation of North Texas, current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative and current RPTE Representative to the ABA Health Law Coordinating Council, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposia chair and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clients on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. For additional information about Ms. Stamer, see www.CynthiaStamer.com or contact Ms. Stamer via email here or via telephone to (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at http://www.solutionslawpress.com such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here.
©2016 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc. All other rights reserved.
Comments Off on Stop Bullying Month Opportunity to Strengthen Workplace Anti-Harassment Efforts |
Accommodation, ADA, Affirmative Action, board of directors, Child Safety, Civil Rights, compliance, Corporate Compliance, Cybercrime, Data Security, directors, Disability, Disability Discrimination, Disease Management, Drug & Alcohol, E-Verify, Education, EEOC, employee, Employer, Employers, Employment, Employment Agreement, Employment Discrimination, fiduciary duty, FLSA, GINA, Government Contractors |
Permalink
Posted by Cynthia Marcotte Stamer
October 27, 2016
Compliance with the Privacy and Security Rules of the Health Insurance Portability & Accountability Act (HIPAA) is a living process that requires employer and other health plans, health insurers, health care providers and healthcare clearinghouses to recurrently reevaluate their HIPAA enterprise risk and timely act to mitigate security threats to electronic (ePHI) and other protected health information and other HIPAA compliance concerns on an ongoing basis. That’s the clear take away applicable to all HIPAA-Covered Entities and business associates from the St. Joseph Health Resolution Agreement and Corrective Action Plan (SJH Settlement) and the Oregon Health & Science University Resolution Agreement and Corrective Action Plan (OHSU Settlement) announced by the Department of Health & Human Services Office of Civil Rights (OCR) in the past 30 days. Health plans, their sponsors, fiduciaries and vendors, health care providers and health care clearinghouses should carefully heed this message and in response take documented steps to ensure
- Their existing policies, practices and procedures properly are updated in response to changing guidance and events;
- They in place the current, comprehensive enterprise risk assessment along with a mitigation plan documenting actions taken to address these risks;
- Ensure that the organization has and is administering appropriate, documented processes and procedures to ensure that the organization reassesses its enterprise risk assessment and compliance on a timely basis as warranted by changes or other events that could impact ePHI, regulatory developments or other events that might impact its compliance; and
- Have an appropriate, documented process for oversight by C-level management.
OHSU Charges & Settlement
The OHSU Settlement Agreement announced by OCR on September 23, 2016 requires OHSU to pay a $2.7 million settlement payment and adopt and implement a comprehensive three-year corrective action plan to address “widespread and diverse” HIPAA compliance problems OCR reports uncovering while investigating multiple HIPAA breach reports the large public academic health center and research university centered in Portland, Oregon.
OCR began investigating OHSU after the large public academic health center and research university centered in Portland, Oregon, submitted three HIPAA breach reports affecting thousands of individuals, including two reports involving unencrypted laptops and another large breach involving a stolen unencrypted thumb drive:
- On March 23, 2013, HHS received notification from OHSU regarding a breach of its unsecured electronic protected health information (“ePHI”) resulting from a stolen laptop computer;
- On July 28, 2013, HHS received notification from OHSU regarding a breach of its ePHI resulting from storing ePHI at an internet-based service provider without a business associate agreement; and.
These incidents each garnered significant local and national press coverage. OCR’s investigation uncovered evidence of widespread vulnerabilities within OHSU’s HIPAA compliance program, including the storage of the ePHI of more than 3,000 individuals on a cloud-based server without a business associate agreement. OCR found significant risk of harm to 1,361 of these individuals due to the sensitive nature of their diagnoses.
OCR’s investigation showed the reported breaches resulted from widespread, long-term, systematic and unresolved HIPAA violations by OHSU that OCR attributed to an inadequate commitment to and oversight of HIPAA compliance by OHSU C-level management which resulted in the failure by OHSU to appropriately monitor the adequacy of its ongoing compliance and to assess and address changes in its enterprise-wide risk and compliance obligations on an ongoing basis. OHSU performed risk analyses in 2003, 2005, 2006, 2008, 2010, and 2013, but OCR’s investigation found that these analyses did not cover all ePHI in OHSU’s enterprise, as required by the Security Rule. While the analyses identified vulnerabilities and risks to ePHI located in many areas of the organization, OHSU did not act in a timely manner to implement measures to address these documented risks and vulnerabilities to a reasonable and appropriate level. OHSU also lacked policies and procedures to prevent, detect, contain, and correct security violations and failed to implement a mechanism to encrypt and decrypt ePHI or an equivalent alternative measure for ePHI maintained on its workstations, despite having identified this lack of encryption as a risk.
OCR concluded that the reported breaches were the result of long-standing, systematic deficiences in OHSU’s processes and procedures for HIPAA compliance, including the following:
- While OHSU reportedly performed risk analyses in 2003, 2005, 2006, 2008, 2010, and 2013, OCR says its investigation found that these analyses did not cover all ePHI in OHSU’s enterprise, as required by the Security Rule;
- While the analyses identified vulnerabilities and risks to ePHI located in many areas of the organization, OHSU did not act in a timely manner to implement measures to address these documented risks and vulnerabilities to a reasonable and appropriate level;
- OHSU also lacked policies and procedures to prevent, detect, contain, and correct security violations and failed to implement a mechanism to encrypt and decrypt ePHI or an equivalent alternative measure for ePHI maintained on its workstations, despite having identified this lack of encryption as a risk;
- OHSU failed to comply with its duty under HIPAA to enter into a business associate agreement with a vendor before allowing a vendor business associate to store ePHI; and
- The absence of meaningful C-suite leadership oversight and commitment to HIPAA compliance.
Based on these investigations, OCR concluded that while OHSU initially adopted HIPAA Policies, the reported breaches were the result of a series of widespread and ongoing breaches of HIPAA resulted including the following:
- From January 5, 2011, until July 3, 2013, OHSU disclosed the ePHI of 3,044 individuals in violation of Privacy Rules §§160.103 and 164.502(a) when workforce members disclosed the ePHI to a third party internet-based service provider without obtaining a business associate agreement or other satisfactory assurance that the internet-based service provider would safeguard the ePHI;
- From January 5, 2011 until July 3, 2013 OHSU failed to obtain a business associate agreement from an internet-based service provider that was storing ePHI on its behalf as a business associate as required by 45 C.F.R. § 164.308(b);
- From January 5, 2011 until July 3, 2013 OHSU failed to implement policies and procedures to prevent, detect, contain, and correct security violations as required under Privacy Rule § 164.308(a)(1)(i);
- From July 12, 2010 to present, OHSU failed to implement a mechanism to encrypt and decrypt ePHI or an equivalent alternative measure for all ePHI maintained in OHSU’s enterprise as required by Privacy Rules §§ 164.312(a)(2)(iv) and 164.306(d)(3)); and
- From May 29, 2013 until July 3, 2013, OHSU failed to implement policies and procedures to address security incidents in violation of Privacy Rule § 164.308(a)(6)(i).
According to statements made by OCR Director Jocelyn Samuels in OCR’s announcement of the OHSU Settlement, the breaches should not have happened. “From well-publicized large scale breaches and findings in their own risk analyses, OHSU had every opportunity to address security management processes that were insufficient,” said OCR Director Jocelyn Samuels. OCR’s announcement also signals that OCR views inadequate commitment and oversight by OHSU’s senior management to have played a key role in the creation and perpetuation of the OHSU violations. It quotes OCR Director Jocelyn Samuels as stating, “This settlement underscores the importance of leadership engagement and why it is so critical for the C-suite to take HIPAA compliance seriously.”
OCR’s announcement of the OHSU Settlement emphasizes its determination that a lack of commitment and oversight by C-level management resulted in the failure by OHSU to periodically perform a comprehensive enterprise risk analysis and to reevaluate and update that analysis and its policies, practices, procedures and training as warranted by changing events and guidance.
To resolve the HIPAA charges, the OHSU Settlement requires OHSU to pay OCR $2,700,000 as well as take a long series of corrective actions detailed in the Corrective Action Plan incorporated into the Settlement Agreement. The requirements of the Corrective Action Plan both seek to address the specific weaknesses that lead to the breaches of unsecured ePHI reported by OHSU in its breach notifications as well as the broader deficiencies in OHSU’s overall HIPAA compliance practice by requiring among other things that OHSU:
- Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI at all OHSU facilities and on all systems, networks, and devices that create, receive, maintain, or transmit ePHI;.
- Develop and present to OCR for approval a comprehensive written risk management plan that explains OHSU’s strategy for implementing security measures sufficient to reduce the risks and vulnerabilities identified in the risk analysis to a reasonable and appropriate level based on OHSU’s circumstances as well as a comprehensive, enterprise-wide plan to implement effective oversight of OHSU workforce members to ensure their adherence to HIPAA Rules and OHSU’s internal privacy and security policies and procedures with specific timelines for their expected completion and compensating controls identified in the interim to safeguard OHSU’s ePHI;
- Implement and administer the written risk management plan and other safeguards as approved by OCR;
- Provide updates to OCR about OHSU’s implementation of required encryption including a Mobile Device Management (MDM) solution that ensures all OHSU- owned and personally-owned mobile devices (tablets, smart phones, and other mobile devices) that access ePHI on OHSU’s secure network are encrypted other than mobile devices for which OHSU has granted exceptions based on documented evidence of the implementation of alternative reasonable compensating controls to protect the ePHI on such devices;
- Report to OCR on OHSU’s efforts to a solution to enforce encryption of ePHI on OHSU-owned and personally- owned devices (laptops, desktops, and medical equipment) connecting to OHSU’s secure wired and wireless networks except for any devices for which OHSU has granted exceptions to the encryption requirement;
- Report to OCR about its implementation of policies that prohibit the transfer of data containing ePHI from OHSU-owned and personally-owned devices to unencrypted removable storage devices (USB drives and portable hard drives) and implementation of a technical solution that enforces the policies prohibiting transfers of this type when attached to the OHSU secure network, except for any removable storage devices for which OHSU has granted exceptions based on documented evidence of reasonable compensating controls that have been implemented to protect the ePHI on such devices;
- Send a communication to all members of the OHSU community describing its commitment to enterprise encryption;
- Prepare to the satisfaction of OCR security awareness training materials needed to implement its security management processing including specific privacy and security awareness related to a) use of internet-based information storage services; b) disclosures to third party entities that require a business associate agreement or other reasonable assurance in place to ensure that the business associate will safeguard the protected health information (PHI) and/or ePHI; c) regarding managers, effective oversight of workforce members’ uses and disclosures of PHI, including ePHI, to ensure the workforce members’ compliance with the Privacy and Security Rules and OHSU’s internal policies and procedures; d) security incident reporting; and e) password management;
- Initially train all workforce members with access to PHI and/or ePHI with 120 days of OCR’s approval of the training and thereafter ensure that new workforce members are trained with 15 days of hire and that all workforce members subsequently continue to receive training on an on-going basis;
- Review the security awareness training materials annually, and, where appropriate, update the training to reflect changes in Federal law or HHS guidance, any issues discovered during audits or reviews, and any other relevant developments;
- Management oversight and supervision of the implementation and administration of the corrective actions required by the Corrective Action Plan and HIPAA compliance; and
- Management reporting to OCR on its actions and compliance with the Corrective Action Plan.
SJH Settlement
Similarly, the SJH Settlement OCR announced on October 18, 2016 with St. Joseph Health (SJH) requires SJH to pay a $2.4 million plus settlement payment, conduct an enterprise-wide risk analysis and implement and administer a comprehensive correction plan to settle OCR charges that SJH violated HIPAA by allowing files containing ePHI of 31,800 individuals that SJH created for its participation in the Medicare meaningful use program to be publicly accessible on the internet from February 1, 2011, until February 13, 2012.
A nonprofit integrated Catholic health care delivery system sponsored by the St. Joseph Health Ministry, who through its 24,000 employees and 6,000 physicians provides a range of health care services to more than 137,000 inpatients and 3.6 million outpatients each year at SHS’ 4 acute care hospitals, home health agencies, hospice care, outpatient services, skilled nursing facilities, community clinics and physician organizations located throughout California and in parts of Texas and New Mexico.
OCR’s charges against SJH arose out of OCR’s investigation into a 2012 breach notification report SJS filed with OCR. On February 14, 2012, SJH reported to OCR that files containing electronic protected health information (ePHI) of 31,800 individuals from five of the SJH hospitals-St. Jude Medical Center, Mission Hospital, Queen of the Valley Medical Center, Santa Rosa Memorial Hospital, and Petaluma Valley Hospital that SJH created for its participation in the meaningful use program were publicly accessible on the internet from February 1, 2011, until February 13, 2012, via Google and possibly other internet search engines.
SJH’s report to OCR indicated that this public access resulted from a configuration within its network server in which PDF files containing following patient information were uploaded: patient names; BMI; blood pressure; lab results; smoking status; diagnoses lists; medication allergies; advance directive status and demographic information (language, ethnicity, race, sex, and birth date). The server SJH purchased to store the files included a file sharing application whose default settings allowed anyone with an internet connection to access them. Upon implementation of this server and the file sharing application, SJH did not examine or modify it. As a result, the public had unrestricted access to PDF files containing the ePHI of 31,800 individuals, including patient names, health statuses, diagnoses, and demographic information from February 14, 2012 until SJH blocked external access to the ePHI when it shut down the application February 13, 2012.
OCR’s investigation indicated the following potential violations of the HIPAA Rules:
- From February 1, 2011 to February 13, 2012, SJH potentially disclosed the PHI of 31,800 individuals;
- Evidence indicated that SJH failed to conduct an evaluation in response to the environmental and operational changes presented by implementation of a new server for its meaningful use project, thereby compromising the security of ePHI;
- Although SJH hired a number of contractors to assess the risks and vulnerabilities to the confidentiality, integrity and availability of ePHI held by SJH, evidence indicated that this was conducted in a patchwork fashion and did not result in an enterprise-wide risk analysis, as required by the HIPAA Security Rule.
To resolve charges resulting from these findings, the SJH Resolution Agreement requires SJH to pay OCR a $2,140,500 settlement payment and adopt a comprehensive corrective action plan which among other things, requires SJH to conduct an enterprise-wide risk analysis, develop and implement a risk management plan, revise its policies and procedures, and train its staff on these policies and procedures. SJH’s Chief Executive Officer, Annette M. Walker, is named in the Corrective Action Plan as the SJH authorized representative and contact person responsible for overseeing the CAP implementation.
Among other things, the Corrective Action Plan specifically requires that SJH:
- Within 240 days, conduct an enterprise-wide analysis and provide a report to OCR which includes a complete inventory of all electronic equipment, data systems, and applications that contain or store ePHI, and prepare and deliver to OCR for review an enterprise-wide risk analysis that identifies all security risks and vulnerabilities that incorporates all electronic equipment, data systems, and applications controlled, administered, or owned by SJH, its workforce members, and affiliated staff that contains, stores, transmits, or receives electronic protected health information (ePHJ);
- Revise this risk analysis plan as directed by OCR based on its review of the presented risk analysis;
- Develop and implement to the satisfaction of OCR an organization-wide risk management plan to address and mitigate any security risks and vulnerabilities identified in the risk analysis;
- Distribute the risk management plan as finally approved by OCR to to workforce members involved with implementation of the plan within 30 days of OCR approval;
- Revise to OCR’s satisfaction, adopt and implement within 30 days of OCR’s approval compliant HIPAA policies and procedures;
- Prepare for review of OCR training materials and once approved by OCR, provide initial training to required workforce members, and obtain certification of completion of that training from each required workforce member within 60 days of OCR’s approval of the training and thereafter at least annually as long as the Corrective Action Plan remains in force;
- Promptly conduct a documented investigation of any information indicating a potential workforce member violation of the new HIPAA policies in the manner required by OCR and if the investigation confirms a violation (Reportable Event), notify OCR of the relevant facts, findings, corrective actions and sanctions imposed against the violating workforce member in the manner required by the Corrective Action Plan;
- Submit annual report to OCR signed and attested to by an SJH officer, which contains the information and attestations of compliance with the requirements of the Corrective Action Plan in accordance with the Corrective Action Plan;
- Retain for inspection and copying and provide to OCR upon request all documents and records relating to compliance with this Corrective Action Plan for six (6) years from the Effective Date of the SJH Settlement Agreement.
Take Away For Other Covered Entities & Business Associates
The OHSU and SJH Settlement Agreements send a clear message to all Covered Entities and business associates that they must be prepared to demonstrate not only that their initial adoption and implementation of required HIPAA Privacy and Security policies and safeguards, but also that their organization’s leadership needs to be prepared to demonstrate their commitment to HIPAA compliance by making adequate provision for HIPAA compliance, and appropriately monitoring developments that could impact the adequacy of their existing measures and timely update their systems and security, policies, procedures, training and other relevant safeguards.
The Settlements make clear that Covered Entities and their business associates should ensure that their organization possesses a well-documented current enterprise-wide risk assessment, as well as has in place and is administering as necessary to maintain the currency and adequacy of its risk assessment strong practices for conducting documented evaluations of their own HIPAA security, policies, practices, audits and investigations and other procedures necessary to comply with HIPAA, taking into account recent OCR guidance, its initiation of its Phase II audit program, the insights offered by OCR’s ever growing list of enforcement actions and compliance tools, as well as changes in systems, documentation, software, equipment or other occurrences within the operations of the Covered Entity or business associate’s operations that could impact the currency and adequacy of its risk assessment or otherwise raise compliance risks.
In this respect, Covered Entities and business associates are encouraged to take special note of the advisability of specifically reviewing and updating their HIPAA policies, practices, business associate agreements, training, oversight and documentation to in response to the guidance and insight that OCR provides, including:
- A series of recent OCR Resolution Agreements emphasizing the need for Covered Entities and their Business Associates to verify that have in place, and review and update as necessary business associate agreements e.g. HIPAA Settlement Illustrates The Importance Of Reviewing And Updating, As Necessary, Business Associate Agreements (September 23, 2016); Business Associate’s Failure to Safeguard Nursing Home Residents’ PHI Leads to $650,000 HIPAA Settlement (June 29, 2016);
- Clarification of Permissible Fees for HIPAA Right of Access – Flat Rate Option Up to $6.50 is Not a Cap on All Fees for Copies of PHI (May 23, 2016)
- Guidance On HIPAA & Cloud Computing released October 6, 2016, which provides guidance for Covered Entities and business associates about contracting and other procedures that HIPAA-regulated Covered Entities and their business associates should implement when contracting for and using Cloud Computing Services;
- Joint Guidance published October 21, 2016 by the Federal Trade Commission and OCR reminding Covered Entities and their business associates of the need to ensure that in addition to fulfilling the technical content requirements of HIPAA, their HIPAA authorizations, privacy practices notices and other HIPAA notices and communications are written and presented in plan language, include required specific terms and descriptions and in a manner that does not mislead individuals about their rights or about what is happening with their PHI. Furthermore, where Covered Entities and their business associates contemplate that businesses associates may request that individuals sign HIPAA authorizations, Covered Entities and their business associates should the Covered Entity and business associate have in place a current, signed HIPAA-compliant business associate agreement that that expressly authorizes the business associate to request the HIPAA authorization in light of statements in the Joint Guidance indicating that OCR views the Privacy Rules as prohibiting a business associate from asking a consumer to sign a HIPAA authorization unless its business associate contract expressly permits the business associate to do so; and
- Other OCR enforcement actions, tools and guidance. See, e.g. All Covered Entities Should Learn Lessons From Mississippi Medical Center’s $2.75 Million HIPAA Resolution Agreement; Providers, Health Plans Should Confirm Copy Charges Comply With New OCR HIPAA Guidance; $2 Million+ HIPAA Settlement, FAQ Warn Providers Protect PHI From Media, Other Recording Or Use; Addressing Gaps in Cybersecurity: OCR Releases Crosswalk Between HIPAA Security Rule and NIST Cybersecurity Framework; HIPAA Security Rule Crosswalk to NIST Cybersecurity Framework.
Employer and other health plan sponsors, health plan fiduciaries and business associates, and their service providers also generally will want to consider their responsibilities to provide and enforce employer certifications, as well as the fiduciary obligations health plan fiduciaries under the fiduciary responsibility rules of the Employee Retirement Income Security Act (ERISA). Among other things, wrongful disclosure of PHI to a sponsoring employer or others could violate HIPAA or other plan terms. Furthermore, Department of Labor officials have indicated stated that a fiduciary’s general fiduciary responsibilities can apply to the protection and administration of PHI and other health plan information as well as create a duty by a responsible fiduciary to prudently investigate and take steps to address breaches or other potential concerns that place PHI at risk. See, HIPAA Settlement Warns Health Plans, Sponsoring Employers & Business Associates To Manage HIPAA Risks.
Furthermore, as breaches of PHI and other violations of HIPAA also frequently give rise to responsibilities or risks under a broad range of other federal and state laws medical and financial privacy and data security, Medicare and other terms of federal program participation, medical credentialing, licensure and ethics, insurance and Employee Retirement Income Security Act fiduciary responsibilities in the case of health plans, contractual, tort and other exposures, Covered Entities and their business associates also generally are best served to take into account these other responsibilities and exposures in conjunction with the design and administration of their HIPAA compliance and risk management policies and practices.
Covered Entities and their business associates also should seek advice from legal counsel regarding the adequacy of their compliance, investigatory, training, management oversight, training, reporting, documentation, document retention and other processes and procedures that could reduce risks of HIPAA violations and position the organization to effectively and more efficiently respond to a potential breach, audit, investigation or enforcement action and mitigate the costs and potential liability exposures that increasingly attends these events. In addition, given the typically high financial, operational and legal costs typically incurred to conduct investigations, report and redress breaches, and respond to OCR audits or investigations, much less make any payments and implement any corrective actions required to settle OCR changes, most Covered Entities and their business associations will want to consider the advisability and adequacy of insurance and other sources of funding or indemnification for the often substantial costs that often attend a HIPAA breach, audit or enforcement event. Since HIPAA violations under certain circumstances also can give rise to felony criminal liability, boards of directors and other leaders of Covered Entities and business associates also will want to ensure that their HIPAA compliance policies and practices also are incorporated and monitored by management as part of their organization’s overall Federal Sentencing Guideline Compliance programs and practices.
About The Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,”“Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney and management consultant, author, public policy advocate and lecturer widely known for work, teachings and publications on HIPAA and other privacy and data security concerns earned in connection with her more than 28 years’ of involvement advising and representing business and government clients domestically and internationally about workforce and human resources, employee benefits; health care; insurance and financial; privacy and data security and other performance management, regulatory, internal controls and other compliance, risk management, public policy and operational other key concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a Fellow in the American College of Employee Benefit Counsel, past Group Chair and current Defined Contribution Plans Committee Co-Chair, Groups and Substantive Committee and Membership Committee Members, past Welfare Plans Committee Chair and Co-Chair, and former Fiduciary Responsibility Vice Chair of the American Bar Association (ABA) RPTE Section Employee Benefits Group, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current ABA International Section Life Sciences Committee Vice Chair, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, former ABA Joint Committee on Employee Benefits Council Representative and Marketing Committee Chair and a prolific author and highly popular speaker and consultant, Ms. Stamer helps management manage.
Ms. Stamer’s legal and management consulting work throughout her nearly 30-year career has focused on helping organizations and their management use the law and process to manage people, process, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer helps public and private, domestic and international businesses, governments, and other organizations and their leaders manage their employees, vendors and suppliers, and other workforce members, customers and other’ performance, compliance, compensation and benefits, operations, risks and liabilities, as well as to prevent, stabilize and cleanup workforce and other legal and operational crises large and small that arise in the course of operations.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, internal controls and regulatory compliance, change management and other performance and operations management and compliance. She supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
As a core component of her work, Ms. Stamer has worked extensively throughout her career with health care providers, health plans, health care clearinghouses, their business associates, employers, banks and other financial institutions, their technology and other vendors and service providers, and others on legal and operational risk management and compliance with HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and concerns; prevention, investigation, response, mitigation and resolution of known or suspected data or privacy breaches or other incidents; defending investigations or other actions by plaintiffs, OCR, FTC, state attorneys’ general and other federal or state agencies; reporting and redressing known or suspected breaches or other violations; business associate and other contracting; insurance or other liability management and allocation; process and product development, contracting, deployment and defense; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; enforcement, and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others.
Beyond her extensive involvement advising and representing clients on privacy and data security concerns and other health industry matters, Ms. Stamer also has served for several years as a scrivener for the ABA JCEB’s meeting with OCR, the Chair of the Southern California ISSA Health Care Privacy & Security Summit, and an editorial advisory board member, author, program chair or steering committee member, and faculties for a multitude of other programs and publications regarding privacy, data security, technology and other compliance, risk management and operational concerns in the health care, health and other insurance, employee benefits and human resources, retail, financial services and other arenas.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares shared her thought leadership, experience and advocacy on HIPAA and other concerns by her service in the leadership of a broad range of other professional and civic organization including her involvement as the Vice Chair of the North Texas Healthcare Compliance Association, Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE: Coalition on Patient Empowerment, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Board Compliance Chair and Board member of the National Kidney Foundation of North Texas, current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative and current RPTE Representative to the ABA Health Law Coordinating Council, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposia chair and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clientson the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. For additional information about Ms. Stamer, see CynthiaStamer.com or contact Ms. Stamer via email here or via telephone to (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at http://www.solutionslawpress.com such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here.
©2016 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Health Plans, Other Covered Entities Have Continuing Duty To Reevaluate HIPAA Enterprise Risk To PHI & Address Security Risks & Other Compliance Concern On Ongoing Basis |
ARRA, board of directors, Brokers, Cafeteria Plans, CHIP, Civil Monetary Penalties, Civil Rights, Claims, compliance, Consumer Protection, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, directors, EBSA, Electronic Medical Record, employee, Employee Benefits, Employer, Employers, Employment, EMR, fiduciary duty, Fiduciary Responsibility, GINA, HIPAA, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Technology, third party administrators, Uncategorized, Union, Workforce | Tagged: Breach Notification, broker, Covered Entity, Data Breach, Data Security, EPHI, ERISA, health care providers, Health Plans, HIPAA, Medical Privach, Medical Privacy, Personal Health Information, Privacy, Technology |
Permalink
Posted by Cynthia Marcotte Stamer
July 28, 2016
Employers, insurers and other health plan sponsors or issuers (health plans), health care providers, healthcare clearinghouses (covered entities) and their business associates should reevaluate the adequacy of their practices and procedures for the protection of electronic protected health information (ePHI) on or accessible through laptops or other mobile devices in light of the $2.75 million penalty and other schooling the Department of Health and Human Services Office for Civil Rights (OCR) just gave the University of Mississippi (UM) Medical Center (UMMC) documented in a July 7, 2016 Resolution Agreement and Corrective Action Plan (Resolution Agreement) resolving OCR charges of multiple violations of the privacy, security and breach notification requirements of the Health Insurance Portability and Accountability Act (HIPAA) OCR says it uncovered while investigating UMMC’s breach notification report to OCR of the loss a laptop containing 328 files containing the ePHI of an estimated 10,000 patients.
UMMC Report of Missing Laptop Leads To Multiple Charges & Resolution Agreement
Mississippi’s sole public academic health science center, UMMC provides patient care in four specialized hospitals on the Jackson campus and at clinics throughout Jackson and the State as well as conducts medical education and research functions. Its designated health care component, UMMC, includes University Hospital, the site of the breach in this case, located on the main UMMC campus in Jackson.
The settlement agreed to by UMMC stems from charges resulting from an OCR investigation of UMMC triggered by a breach of unsecured electronic protected health information (“ePHI”) affecting approximately 10,000 individuals.
Like many prior resolution agreements previously announced by OCR, UMMC’s HIPAA woes came to light after a laptop went missing. OCR learned of the breach and opened its investigation in response to a March 21, 2013 notification UMMC filed with OCR. UMMC made the breach notification to comply with HIPAA’s Breach Notification Rule requirement that health care providers, health plans and healthcare clearinghouses (Covered Entities) timely notify affected individuals, OCR and others of breaches of unsecured ePHI.
UMMC’s breach notification disclosed that UMMC’s privacy officer had discovered a password-protected laptop containing ePHI of thousands of UMMC patients missing from UMMC’s Medical Intensive Care Unit (MICU). UMMC additionally reported that based on its investigation, UMMC believed that the missing laptop likely was stolen by a visitor to the MICU who had inquired about borrowing one of the laptops.
After discovering the loss, UMMC disclosed the breach to local media and on its website and notified OCR of the breach but apparently did not individually notify the subjects of the missing ePHI.
In keeping with its announced policy of investigating all breach reports impacting 500 or more individuals, OCR opened an investigation into UMMC’s breach report. Based on this investigation, OCR concluded that while the laptop apparently was password protected, UMMC had breached the Security Rules because ePHI stored on a UMMC network drive was vulnerable to unauthorized access via UMMC’s wireless network because users could use a generic username and password to access an active directory containing 67,000 files including 328 files containing the ePHI of an estimated 10,000 patients.
While OCR’s investigation confirmed that UMMC had implemented policies and procedures pursuant to the HIPAA Rules, OCR’s additionally found that the theft of the laptop that prompted UMMC’s breach report resulted from broad deficiencies in UMMC’s implementation and administration of these policies and its practices.
Based on these findings, OCR charged UMMC with the following HIPAA violations:
- From the compliance date of the Security Rule, April 20, 2005, through the settlement date, UMMC violated 45 C.F.R. §164.308(a)(1)(i) by failing to implement policies and procedures to prevent, detect, contain, and correct security violations, including conducting an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all of the ePHI it holds, and implementing security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level;
- From January 19, 2013, until March 1, 2014, UMMC violated 45 C.F.R. §164.310(c) by failing to implement physical safeguards for all workstations that access ePHI to restrict access to authorized users;
- From the compliance date of the Security Rule, April 20, 2005, to March 14, 2013, UM violated 45 C.F.R. § 164.312 (a)(2)(i) by failing to assign a unique user name and/or number for identifying and tracking user identity in information systems containing ePHI including, for example, allowing workforce members to access ePHI on a shared department network drive through a generic account, preventing UMMC from tracking which specific users were accessing ePHI; and
- While UMMC provided notification on UMMC’s website and in local media outlets following the discovery of the reported breach of unsecured ePHI,, UMMC violated the Breach Notification Rule by failing to notify each individual whose unsecured ePHI was reasonably believed to have been accessed, acquired, used, or disclosed as a result of the breach.
Finally, OCR determined that UMMC was aware of risks and vulnerabilities to its systems as far back as April 2005, yet took no significant risk management activity until after the breach, due largely to organizational deficiencies and insufficient institutional oversight.
To resolve these charges, UMMC agrees in the Resolution Agreement to pay OCR $2.75 million and implement a comprehensive compliance plan which among other things, requires UMMC to conduct a sweeping review and correct its HIPAA privacy, security and breach notification policies and their implementation and administration to comply with HIPAA as well as implement and administer detailed management and OCR oversight and reporting processes over the implementation and administration of these procedures.
Lessons For Other Covered Entities From UMMC Resolution Agreement
The UMMC charges and Resolution Agreement contains several key lessons for other covered entities and their business associates, which OCR’s July 21, 2016 announcement warns other covered entities and business associates to heed..
Certainly, the $2.75 million settlement amount reaffirms that covered entities and their business associates risk substantial liability for failing to properly assess and protect the security of ePHI in accordance with HIPAA’s Privacy and Security Rule.
Furthermore, the charges and Resolution Agreement also adds a new twist to OCR’s now well established to stiffly sanction covered entities and their business associates that fail appropriately assess and address risks to the security of their ePHI on or accessible from laptops or other mobile devices. Through previous resolution agreements and guidance, OCR has made clear that it interprets the HIPAA Security Rule as generally requiring that covered entities and business associates encrypt all laptops or other mobile devices containing ePHI. The UMMC charges and Resolution Agreement makes clear that the responsibility to protect ePHI on or accessible through laptops or other mobile devices does not end with encryption. Rather, the Resolution Agreement makes clear that covered entities and their business associates also must take appropriate, well-documented steps to monitor, assess, identify, and timely and effectively address other potential risks to the security of the ePHI.
The Resolution Agreement makes clear that these additional responsibilities include, but are not necessarily limited to ensuring that proper safeguards are implemented and enforced to secure access not only to the ePHI contained on the laptop as well as other data bases and systems containing ePHI accessible through the laptop. In this respect, the Resolution Agreement particularly highlights the need for covered entities and their business associates to assess risks and take appropriate steps:
- To safeguard the physical security of laptops and other mobile devices;
- To prevent the use of generic or other unsecure passwords to access ePHI on or accessible through the laptop or other mobile device;
- To establish and administer appropriate, well-documented processes for assessing and addressing the adequacy of safeguards for and potential threats to the security of ePHI both initially and on an ongoing basis in a manner that meaningfully assesses the actual risks and effectiveness of safeguards against these risks, including those resulting from nonadherence to required safeguards and practices such as the sharing of passwords, changing systems or circumstances, and other developments that potentially threaten the adequacy of ePHI security.
Furthermore, OCR’s July 21, 2016 press release concerning the Resolution Agreement also sends a clear message to all covered entities and business associates that OCR views HIPAA as requiring organizations not only to adopt written policies and procedures that comply on paper or in theory with HIPAA, but also to take steps to monitor and maintain the effectiveness of their safeguard by continuously assessing and monitoring their HIPAA risks and acting as necessary to ensure that required safeguards of protected health information and ePHI and other HIPAA requirements are effectively implemented and administered in operation as well as form.
In OCR’s Press Release announcing the Resolution Agreement, OCR Director Jocelyn Samuels. Stated, “We at OCR remain particularly concerned with unaddressed risks that may lead to impermissible access to ePHI.” She also warned “In addition to identifying risks and vulnerabilities to their ePHI, entities must also implement reasonable and appropriate safeguards to address them within an appropriate time frame.”
Additionally, the Resolution Agreement also illustrates need for covered entities and business associates to timely provide all individual and other notifications and otherwise fully comply with all requirements of the Breach Notification Rules.
Since the risk of a breach is ever-present even for Covered Entities and business associates exercising the highest degree of care to safeguard PHI and maintain compliance with HIPAA, Covered Entities and business associates are wise to take steps to position themselves to be able to demonstrate the adequacy of both their written policies and procedures and the effectiveness of their implementation and enforcement including ongoing documented practices for assessing, monitoring and addressing security risks and other compliance concerns as well as prepare to comply with the breach notification requirements in the event they experience their own breach of unsecured ePHI.
About The Author
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, current American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, former scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting and JCEB Council Representative, former Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, the former Board President and Treasurer of the Richardson Development Center for Children Early Childhood Intervention Agency, and past Board Compliance Chair of the National Kidney Foundation of North Texas, and Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, the author of this update, attorney Cynthia Marcotte Stamer, is AV-Preeminent (the highest) rated attorney repeatedly recognized for her nearly 30 years of experience and knowledge representing and advising healthcare, health plan and other health industry and others on these and other regulatory, workforce, risk management, technology, public policy and operations matters as a Martindale-Hubble as a “LEGAL LEADER™” and “Texas Top Rated Lawyer” in Health Care Law, Labor and Employment Law, and Business & Commercial Law and among the “Best Lawyers In Dallas” by D Magazine.
Ms. Stamer’s health industry experience includes advising hospitals, nursing home, home health, rehabilitation and other health care providers and health industry clients to establish and administer compliance and risk management policies; prevent, conduct and investigate, and respond to peer review and other quality concerns; and to respond to Board of Medicine, Department of Aging & Disability, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD and other health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns.
Ms. Stamer also is known for her experience in HIPAA and other privacy and data security and breach concerns. The scribe for ABA JCEB annual agency meeting with OCR for many years, Ms. Stamer has worked extensively with health care providers, health plans, health care clearinghouses, their business associates, employers and other plan sponsors, banks and other financial institutions, and others on risk management and compliance with HIPAA, FACTA, trade secret and other information privacy and data security rules, including the establishment, documentation, implementation, audit and enforcement of policies, procedures, systems and safeguards, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns. Her clients include public and private health care providers, health insurers, health plans, technology and other vendors, and others. In addition to representing and advising these organizations, she also has conducted training on Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her insights on these and other related matters appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications.
You can get more information about her health industry experience here or contact Ms. Stamer via telephone at (469) 767-8872 or via e-mail here.
About Solutions Law Press Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns.
If you found these updates of interest, you may be interested in other recent Solutions Law Press, Inc. updates like the following:
Go here to register to receive other Solutions Law Press, Inc. updates and announcements about other upcoming briefings, training or other programs, products, services, and activities or to learn more about Solutions Law Press, Inc., its publications, programs and training, PROJECT COPE: Coalition on Patient Empowerment community service and education projects, event management and other resources and services.
For important information concerning this communication see here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2016 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved.
Comments Off on Health Plans & Other HIPAA Entities Should Learn From $2.75M UMMC HIPAA Settlement |
Civil Rights, Claims Administration, Consumer Protection, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, employee, Employee Benefits, Employer, Employers, Employment, Employment Discrimination, ERISA, FACTA, GINA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Mental Health Parity, Uncategorized | Tagged: Business Associate, Corporate Compliance, Data Breach, employee benefitsd, Employer, Health Insurance, Health Insurer, HIPAA, Insurance, Medical Privacy, OCR, Office of Civil Rights, Privacy, Protected Health Information |
Permalink
Posted by Cynthia Marcotte Stamer
July 1, 2016
Employers, employee benefit plan fiduciaries and others caught violating Federal employment, employee benefit, and a wide range of other laws and regulations ranging from the Fair Labor Standards Act (FLSA) to the Employee Retirement Income Security Act (ERISA), and many other Federal Labor and employment laws should brace for increased civil penalties and other changes in the calculation of these penalties under interium rules just released by the DOL. Employers and other parties must comply with these rules but if concerned with these Interium Rules, will have 45 days to comment before DOL will publish any final rule.
In 2015, Congress passed the Federal Civil Penalties Inflation Adjustment Act Improvements Act, which requires the Department of Labor (DOL) and other agencies adjust their penalties for inflation each year.
In response to this mandate, the DOL has published two interim final rules to adjust its penalties for inflation effective August 1:
Both rules define rules that DOL plans to use to apply the 2015 Inflation Adjustment Act’s formula on how to determine the proper adjustment for each penalty effective August 1, 2016 to civil penalties that DOL can assess against employers for violations.
The new method will adjust penalties for inflation, though the amount of the increase is capped at 150 percent of the existing penalty amount. The baseline is the last increase other than for inflation. The new civil penalty amounts are applicable only to civil penalties assessed after August 1, 2016, whose associated violations occurred after Nov. 2, 2015.
The rules published under the 2015 law will increase some penalties that DOL perceives have lost ground to inflation including:
- OSHA’s maximum penalties, which have not been raised since 1990, will increase by 78 percent. The top penalty for serious violations will rise from $7,000 to $12,471. The maximum penalty for willful or repeated violations will increase from $70,000 to $124,709.
- OWCP’s penalty for failure to report termination of payments made under the Longshore and Harbor Workers’ Compensation Act, has only increased $10 since 1927, and will rise from $110 to $275.
- WHD’s penalty for willful violations of the minimum wage and overtime provisions of the Fair Labor Standards Act will increase from $1,100 to $1,894.
A list of each agency’s individual penalty adjustments is available here.
In addition to increasing its civil penalties, the DOL has indicated that in response to these changes, it will update the FLSA Minimum Wage Poster and other required labor posters before the August 1, 2016 effective date.
Since these impending increases raise the civil penalty exposures for employers in the most heavily enforced by the DOL, employers now have an even greater need to tighten their compliance and risk management practices under these laws.
About The Author
Cynthia Marcotte Stamer is a noted Texas-based management lawyer and consultant, author, lecture and policy advocate, recognized for her nearly 30-years of cutting edge management work as among the “Top Rated Labor & Employment Lawyers in Texas” by LexisNexis® Martindale-Hubbell® and as among the “Best Lawyers In Dallas” for her work in the field of “Tax: Erisa & Employee Benefits” and “Health Care” by D Magazine.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a Fellow in the American College of Employee Benefit Counsel, past Chair and current committee Co-Chair of the American Bar Association (ABA) RPTE Section Employee Benefits Group, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, a former ABA Joint Committee on Employee Benefits Council Representative and , Ms. Stamer helps management manage.
Ms. Stamer’s legal and management consulting work throughout her nearly 30-year career has focused on helping organizations and their management use the law and process to manage people, process, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer helps public and private, domestic and international businesses, governments, and other organizations and their leaders manage their employees, vendors and suppliers, and other workforce members, customers and other’ performance, compliance, compensation and benefits, operations, risks and liabilities, as well as to prevent, stabilize and cleanup workforce and other legal and operational crises large and small that arise in the course of operations.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, internal controls and regulatory compliance, change management and other performance and operations management and compliance. She supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Well known for her extensive work with health care, insurance and other highly regulated entities on corporate compliance, internal controls and risk management, her clients range from highly regulated entities like employers, contractors and their employee benefit plans, their sponsors, management, administrators, insurers, fiduciaries and advisors, technology and data service providers, health care, managed care and insurance, financial services, government contractors and government entities, as well as retail, manufacturing, construction, consulting and a host of other domestic and international businesses of all types and sizes. Common engagements include internal and external workforce hiring, management, training, performance management, compliance and administration, discipline and termination, and other aspects of workforce management including employment and outsourced services contracting and enforcement, sentencing guidelines and other compliance plan, policy and program development, administration, and defense, performance management, wage and hour and other compensation and benefits, reengineering and other change management, internal controls, compliance and risk management, communications and training, worker classification, tax and payroll, investigations, crisis preparedness and response, government relations, safety, government contracting and audits, litigation and other enforcement, and other concerns.
Ms. Stamer uses her deep and highly specialized health, insurance, labor and employment and other knowledge and experience to help employers and other employee benefit plan sponsors; health, pension and other employee benefit plans, their fiduciaries, administrators and service providers, insurers, and others design legally compliant, effective compensation, health and other welfare benefit and insurance, severance, pension and deferred compensation, private exchanges, cafeteria plan and other employee benefit, fringe benefit, salary and hourly compensation, bonus and other incentive compensation and related programs, products and arrangements. She is particularly recognized for her leading edge work, thought leadership and knowledgeable advice and representation on the design, documentation, administration, regulation and defense of a diverse range of self-insured and insured health and welfare benefit plans including private exchange and other health benefit choices, health care reimbursement and other “defined contribution” limited benefit, 24-hour and other occupational and non-occupational injury and accident, expat and medical tourism, onsite medical, wellness and other medical plans and insurance benefit programs as well as a diverse range of other qualified and nonqualified retirement and deferred compensation, severance and other employee benefits and compensation, insurance and savings plans, programs, products, services and activities. As a key element of this work, Ms. Stamer works closely with employer and other plan sponsors, insurance and financial services companies, plan fiduciaries, administrators, and vendors and others to design, administer and defend effective legally defensible employee benefits and compensation practices, programs, products and technology. She also continuously helps employers, insurers, administrative and other service providers, their officers, directors and others to manage fiduciary and other risks of sponsorship or involvement with these and other benefit and compensation arrangements and to defend and mitigate liability and other risks from benefit and liability claims including fiduciary, benefit and other claims, audits, and litigation brought by the Labor Department, IRS, HHS, participants and beneficiaries, service providers, and others. She also assists debtors, creditors, bankruptcy trustees and others assess, manage and resolve labor and employment, employee benefits and insurance, payroll and other compensation related concerns arising from reductions in force or other terminations, mergers, acquisitions, bankruptcies and other business transactions including extensive experience with multiple, high-profile large scale bankruptcies resulting in ERISA, tax, corporate and securities and other litigation or enforcement actions.
Ms. Stamer also is deeply involved in helping to influence the Affordable Care Act and other health care, pension, social security, workforce, insurance and other policies critical to the workforce, benefits, and compensation practices and other key aspects of a broad range of businesses and their operations. She both helps her clients respond to and resolve emerging regulations and laws, government investigations and enforcement actions and helps them shape the rules through dealings with Congress and other legislatures, regulators and government officials domestically and internationally. A former lead consultant to the Government of Bolivia on its Social Security reform law and most recognized for her leadership on U.S. health and pension, wage and hour, tax, education and immigration policy reform, Ms. Stamer works with U.S. and foreign businesses, governments, trade associations, and others on workforce, social security and severance, health care, immigration, privacy and data security, tax, ethics and other laws and regulations. Founder and Executive Director of the Coalition for Responsible Healthcare Policy and its PROJECT COPE: the Coalition on Patient Empowerment and a Fellow in the American Bar Foundation and State Bar of Texas, Ms. Stamer annually leads the Joint Committee on Employee Benefits (JCEB) HHS Office of Civil Rights agency meeting and other JCEB agency meetings. She also works as a policy advisor and advocate to many business, professional and civic organizations.
Author of the thousands of publications and workshops these and other employment, employee benefits, health care, insurance, workforce and other management matters, Ms. Stamer also is a highly sought out speaker and industry thought leader known for empowering audiences and readers. Ms. Stamer’s insights on employee benefits, insurance, health care and workforce matters in Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, Modern Healthcare, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications. Ms. Stamer also regularly serves on the faculty and planning committees for symposia of LexisNexis, the American Bar Association, ALIABA, the Society of Employee Benefits Administrators, the American Law Institute, ISSA, HIMMs, and many other prominent educational and training organizations and conducts training and speaks on these and other management, compliance and public policy concerns.
Ms. Stamer also is active in the leadership of a broad range of other professional and civic organizations. For instance, Ms. Stamer serves on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and as an editorial advisor and contributing author of many other publications. Her leadership involvements with the American Bar Association (ABA) include year’s serving many years as a Joint Committee on Employee Benefits Council representative; ABA RPTE Section current Practice Management Vice Chair and Substantive Groups & Committees Committee Member, RPTE Employee Benefits & Other Compensation Committee Past Group Chair and Diversity Award Recipient, current Defined Contribution Plans Committee Co-Chair, and past Welfare Benefit Plans Committee Chair Co-Chair; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; current Vice Chair of the ABA TIPS Employee Benefit Committee; International Section Life Sciences Committee Policy Vice Chair; and a speaker, contributing author, comment chair and contributor to numerous Labor, Tax, RPTE, Health Law, TIPS, International and other Section publications, programs and task forces. Other selected service involvements of note include Vice President of the North Texas Healthcare Compliance Professionals Association; past EO Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division; founding Board Member and President of the Alliance for Healthcare Excellence, as a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early childhood development intervention agency, The Richardson Development Center for Children; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a former Southwest Benefits Association Board of Directors member, Continuing Education Chair and Treasurer; former Texas Association of Business BACPAC Committee Member, Executive Committee member, Regional Chair and Dallas Chapter Chair; former Society of Human Resources Region 4 Chair and Consultants Forum Board Member and Dallas HR Public Policy Committee Chair; former National Board Member and Dallas Chapter President of Web Network of Benefit Professionals; former Dallas Business League President and others. For additional information about Ms. Stamer, see CynthiaStamer.com or contact Ms. Stamer via email here or via telephone to (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal control and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at Solutionslawpress.com including:
- OFCCP Ups Government Contractor Vet Hiring Targets
- Average American Family 2016 Healthcare
- Brace For OCR HIPAA Audits
- Health Plans Disclosing Data To State All Payer Data Banks Face HIPAA Risks
- Confirm Copy Charges Comply With New HIPAA Guidance
- Frontier Says “Conversion Issues” for
- Obama Offers Grants To States To Boost Paid Leave Availability With State Grants
- Business Associate Rule Violations Behind $750K HIPAA Settlement
- Final Investment Advice Fiduciary Rules Mean Work For Employers, Fiduciaries & Advisors
- Employers, Insurers & TPAS: Budget Time, $ For 2017 Summary of Benefits and Coverage Updates
- Expect New Fed Regs To Increase Childcare Costs
- OSHA Raises Silica Safety Requirements
- DOL “Persuader Rule” Changes Broaden Employer & Consultant Anti-Union Contract Disclosure Duties
- Check Health Plan Privacy For New Guidance Compliance
- Marketplace Data Deficiencies Signal Employer ACA Headaches
- SCOTUS: States Can’t Require Reporting of ERISA Health Plan Data
- IRS OK’s Skipping Certain 2015 Form 5500 Questions
- DOL Proposes Changes To Summary of Benefit & Coverage Rules
- More proof government should stay out of healthcare
- Health Care Quality: Different Meaning For Care Vs. Coverage
- IRS Changes Plan Qualification Procedures, Returns, Other Procedures
- Remember Microsoft: The Need for Effective Risk Management as to Contract Employees
- Obama Administration Proposes Rules Giving Jobseeker Equal Opportunity Protections
- Health Benefit Still Top Employer Benefit Cost
- S. Businesses & Their Leaders Face Rising FLSA Collective Action Liability Risks
- Improve HR Value To Company By Making HR A Performance Rather Than People Department
- Sponsoring Employers Face Excise Taxes, Other Liabilities Unless Health Plans Comply With ACA Out-Of-Pocket & Other Federal Rules
- Legal Review Of Health Plan Documents, Processes Needed To Mitigate Employer’s Excise Tax & Other Health Plan Risks
- EEOC ADA Suit Against Magnolia Health Highlights US Employer’s Growing Disability Discrimination Risks
- Proposed OSHA Regs Will Clarify Employer’s Continuing Duty To Ensure OSHA 300 Log Completeness
- 10 Practical Pointers To Use Law To Better Strengthen The Legal Defensibility Of Your Business & Its Leaders
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here. ©2016 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc. ™. All other rights reserved.
Comments Off on DOL Employer & Employee Benefit Fines Going Up |
Accommodation, ADA, compliance, Contraception, Cybercrime, directors, E-Verify, EEOC, Employment, Employment Agreement, Employment Discrimination, ERISA, fiduciary duty, FMLA, GINA, h-2A Visa, health reform, HIPAA, Hiring, Insurance, Internal Controls, Labor Management Relations, LEP, mine safety, Obamacare, OFCCP, Rehabilitation Act, SBC, Uncategorized, Union, Union certification, Union elections, visas, Wellness, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
March 22, 2016

Employer and union sponsored health plans, their sponsors, fiduciaries, and business associates should brace for audits and enforcement of the Privacy, Security, and Breach Notification rules by the Department of Health & Human Service Office of Civil Rights (OCR) follow OCR’s 2016 audit program on the heels of its announcement last week of two large HIPAA settlements last week.
OCR confirmed today it is sending emails notifying health plans, healthcare providers, healthcare clearing houses (Covered Entities) and their business associates identified as part of the kickoff of its next phase of audits of Covered Entities. In light of the HIPAA verification rules and the notorious spread of opportunistic identity theft and other fraud by opportunistic Cybercriminals following these types of announcements, Covered Entities and business associates should carefully verify the requests validity and manage the response to avoid violating HIPAA in responding and position for defensibility against potential penalties.
Even if health plans or other Covered Entities reviewed their practices in the last 12-months, most will want to update this review in response to new OCR guidance and enforcement actions, including new guidance on obligations to provide plan members or other subjects of protected health information with access to or copies of their records and other guidance, as well as the ever-expanding list of enforcement actions by OCR.
To catch up on this latest guidance, Solutions Law Press, Inc. ™ invites you to register to participate in a special WebEx briefing on “HIPAA Update: The Latest On Security, Patient Access & Other HIPAA Developments” on Wednesday, March 30, 2016 beginning at Noon Central Time on Wednesday, March 30, 2016.
2016 Audit Program
In its 2016 Phase 2 HIPAA Audit Program, OCR will review the policies and procedures adopted and employed by Covered Entities and their business associates to meet selected standards and implementation specifications of the Privacy, Security, and Breach Notification Rules. OCR says it will primarily conduct these audits as desk audits, although some on-site audits will be conducted.
According to today’s announcement, the 2016 audit process begins with verification of an entity’s address and contact information. OCR is sending emails to Covered Entities and business associates requesting that contact information be provided to OCR on time. OCR will then send a pre-audit questionnaire to gather data about the size, type, and operations of potential audit targets. OCR says this data will be used with other information to create potential audit subject pools. Recipients should contact qualified legal counsel immediately for advice and assistance about proper procedures to verify the email is in fact from OCR and for assistance in responding.
If an entity does not respond to OCR’s request to verify its contact information or pre-audit questionnaire, OCR will use publicly available information about the entity to create its audit subject pool. Therefore an entity that does not respond to OCR may still be selected for an audit or subject to a compliance review. Communications from OCR will be sent via email and may be incorrectly classified as spam. If your entity’s spam filtering and virus protection are automatically enabled, OCR expects entities to check their junk or spam email folder for emails from OCR.
The announcement also reflects that OCR is still developing other aspects of the audit program. OCR will post updated audit protocols on its website closer to conducting the 2016 audits. The audit protocol will be updated to reflect the HIPAA Omnibus Rulemaking and can be used as a tool by organizations to conduct their own internal self-audits as part of their HIPAA compliance activities.
OCR says its audits will enhance industry awareness of compliance obligations and enable OCR to better target technical assistance regarding problems identified through the audits. Through the information gleaned from the audits, OCR will develop tools and guidance to aid the industry in compliance self-evaluation and in preventing breaches. OCR plans to use results and procedures used in the phase 2 audits to develop its permanent HIPAA audit program.
OCR Settlements Show Enforcement Risk
The audit program announcement comes less than a week after OCR announced millions of dollars of new penalties under settlements with two Covered Entities:
- A $1,555,000 settlement with North Memorial Health Care of Minnesota;
- A $3.9 million settlement with Feinstein Institute for Medical Research.
The two settlements drive home again the substantial liability that health care providers, health plans, health care clearinghouses and their business associates risk for violating HIPAA.
Feinstein Settlement
Feinstein is a biomedical research institute organized as a New York not-for-profit corporation sponsored by Northwell Health, Inc., formerly known as North Shore Long Island Jewish Health System, a large health system headquartered in Manhasset, New York comprised of 21 hospitals and over 450 patient facilities and physician practices.
OCR’s investigation began after Feinstein filed a breach report indicating that on September 2, 2012, a laptop computer containing the electronic protected health information (ePHI) of approximately 13,000 patients and research participants was stolen from an employee’s car. The ePHI stored in the laptop included the names of research participants, dates of birth, addresses, social security numbers, diagnoses, laboratory results, medications, and medical information about potential participation in a research study.
OCR’s investigation discovered that Feinstein’s security management process was limited in scope, incomplete, and insufficient to address potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the entity. Further, Feinstein lacked policies and procedures for authorizing access to ePHI by its workforce members, failed to implement safeguards to restrict access to unauthorized users, and lacked policies and procedures to govern the receipt and removal of laptops that contained ePHI into and out of its facilities. For electronic equipment procured outside of Feinstein’s standard acquisition process, Feinstein failed to implement proper mechanisms for safeguarding ePHI as required by the Security Rule.
“Research institutions subject to HIPAA must be held to the same compliance standards as all other HIPAA-covered entities,” said OCR Director Jocelyn Samuels. “For individuals to trust in the research process and for patients to trust in those institutions, they must have some assurance that their information is kept private and secure.”
The resolution agreement and corrective action plan may be found on the OCR website at http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/Feinstein/index.html.
North Memorial
The Feinstein settlement announcement follows yesterday’s announcement of a $1.5 million plus settlement with North Memorial to resolve HIPAA charges that it failed to implement a business associate agreement with a major contractor and failed to institute an organization-wide risk analysis to address the risks and vulnerabilities to its patient information. North Memorial is a comprehensive, not-for-profit health care system in Minnesota that serves the Twin Cities and surrounding communities.
The settlement highlights the importance for healthcare providers, health plans, healthcare clearinghouses and their business associates to comply with HIPAA’s business associate agreement and other HIPAA organizational, risk assessment, privacy and security, and other requirements.
OCR’s announcement emphasizes the importance of meeting these requirements. “Two major cornerstones of the HIPAA Rules were overlooked by this entity,” said Director Samuels. “Organizations must have in place compliant business associate agreements as well as an accurate and thorough risk analysis that addresses their enterprise-wide IT infrastructure.”
The settlement comes from charges filed after OCR initiated its investigation of North Memorial following receipt of a breach report on September 27, 2011, which indicated that an unencrypted, password-protected laptop was stolen from a business associate’s workforce member’s locked vehicle, impacting the ePHI of 9,497 individuals.
OCR’s investigation indicated that North Memorial failed to have in place a business associate agreement, as required under the HIPAA Privacy and Security Rules, so that its business associate could perform certain payment and health care operations activities on its behalf. North Memorial gave its business associate, Accretive, access to North Memorial’s hospital database, which stored the ePHI of 289,904 patients. Accretive also received access to non-electronic protected health information as it performed services on-site at North Memorial.
The investigation further determined that North Memorial failed to complete a risk analysis to address all of the potential risks and vulnerabilities to the ePHI that it maintained, accessed, or transmitted across its entire IT infrastructure — including but not limited to all applications, software, databases, servers, workstations, mobile devices and electronic media, network administration and security devices, and associated business processes.
In addition to the $1,550,000 payment, North Memorial is required to develop an organization-wide risk analysis and risk management plan, as required under the Security Rule. North Memorial will also train appropriate workforce members on all policies and procedures newly developed or revised pursuant to this corrective action plan.
The Resolution Agreement and Corrective Action Plan can be found on the HHS website at: http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/north-memorial-health-care/index.html.
Settlement Latest Reminder To Manage HIPAA Risks.
Following up on OCR’s imposition of its second-ever HIPAA Civil Monetary Penalty (CMP) and the latest in an ever-growing list of settlements by Covered Entities under HIPAA, these latest settlements illustrate the substantial liability that Covered Entities face for violating HIPAA. To avoid these liabilities, Covered Entities must constantly be diligent to comply with the latest guidance of OCR about their obligations under HIPAA.
As OCR continues to issue additional guidance as well as supplement this guidance through information shared in settlement agreements like the North Memorial settlement, even if Covered Entities reviewed their practices in the last 12-months, most will want to update this review in response to new OCR guidance and enforcement actions, including new guidance on obligations to provide plan members or other subjects of protected health information with access to or copies of their records and other guidance, as well as the ever-expanding list of enforcement actions by OCR.
Since the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH) amended HIPAA, Covered Entities face growing responsibilities and liability for maintaining the security of ePHI.
In response to HITECH, OCR continues to use a carrot and stick approach to encouraging and enforcing compliance. As demonstrated by OCR’s imposition of the second-ever HIPAA Civil Monetary Penalty (CMP) of $239,000 against Lincare and the ever-growing list of Resolution Agreements OCR announces with other Covered Entities, OCR continues to step up enforcement against Covered Entities that breach the Privacy and Security Rules. See OCR’s 2nd-Ever HIPAA CMP Nails Lincare For $239,000.
On the other hand, OCR also continues to encourage voluntary compliance by Covered Entities by sharing guidance and tools to aid Covered Entities to understand fulfill their HIPAA responsibilities such as the HIPAA Security Rule Crosswalk to NIST Cybersecurity Framework (Crosswalk) unveiled by OCR on February 24, 2016.The crosswalk that maps the HIPAA Security Rule to the standards of the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity (the Cybersecurity Framework) as well as mappings to certain other commonly used security frameworks.
While stating that the HIPAA Security Rule does not require use of the NIST Cybersecurity Framework, OCR says it hopes the Crosswalk will provide “a helpful roadmap” for HIPAA Covered Entities and their business associates to understand the overlap between the NIST Cybersecurity Framework, the HIPAA Security Rule, and other security frameworks that can help Covered Entities safeguard health data in a time of increasing risks and help them to identify potential gaps in their programs.
At the same time, OCR’s announcement of its release of the Crosswalk also cautions users that “use of the Framework does not guarantee HIPAA compliance.” Rather, OCR says “the crosswalk provides an informative tool for entities to use to help them more comprehensively manage security risks in their environments.
With a USA Today report attributing more than 40 percent of data breaches to the healthcare industry over the last three years 91 percent of all health organizations having reporting breaches over the last two years, OCR has made clear that it intends to zealously investigate and enforce the Security Rules against Covered Entities that violate the Security Rules against Covered Entities that fail to take suitable steps to safeguard the security of PHI as required by the HIPAA Security Rule.
To meet these requirements, the HIPAA Security Rule requires that Covered Entities conduct and be prepared to product documentation of their audit and other efforts to comply with the Security Rule Most Covered Entities will want to consider including an assessment of the adequacy of their existing practices under the Crosswalk and other requirements disclosed by OCR in these assessments to help position the Covered Entity to defend or mitigate HIPAA CMP and other liabilities in the event of a HIPAA breech or audit.
Changing Rules Complicate Compliance
In addition to maintaining adequate security, HIPAA also requires Covered Entities to provide individuals with the right to access and receive a copy of their health information from their providers, hospitals, and health insurance plans in accordance with the HIPAA Privacy Rule. In response to recurrent difficulties experienced by individuals in exercising these rights, OCR recently published supplemental guidance to clarify and promote better understanding and compliance with these rules by Covered Entities. OCR started this process in January, 2015 by releasing a comprehensive fact sheet (Access fact sheet) and the first in a series of topical frequently asked questions (FAQs) addressing patients’ right to access their medical records, which set forth requirements providers must follow in sharing medical records with patients, including that they must do so in a timely manner and in a format that works for the patient.
Earlier this month, OCR followed up by publishing on March 1, 2016 a second set of FAQs addresses additional issues, including the fees individuals may be charged for copies of their health information and the right of individuals to have their health information sent directly to a third party if they so choose.
Covered entities and their business associates should expect OCR to ask about use of these tools in audits and investigations. Accordingly, they should move quickly to review and update their business associate agreements and other practices to comply with this new guidance as well as watch for further guidance and enforcement about these practices from OCR.
Other Key HIPAA Regulatory & Enforcement Changes Raise Responsibilities & Risks
OCR’s new guidance on access to PHI follows a host of other regulatory and enforcement activities. While the particulars of each of these new actions and guidance vary, all send a very clear message: OCR expects Covered Entities and their business associates to comply with HIPAA and is offering tools and other guidance to aid them in that process. In the event of a breach or audit, Covered Entities and their business associates need to be prepared to demonstrate their efforts to comply.
Those that cannot show adequate compliance efforts should be prepared for potentially substantial CMP or Resolution Agreement payments and other sanctions.
Register For 3/30 Webex Briefing
Solutions Law Press, Inc.™ invites to catch up on the latest guidance on the Covered Entities’ responsibility under HIPAA to provide access to patients to PHI by registering here to participate in the “HIPAA Update: The Latest On Security, Patient Access & Other HIPAA Developments” Webex briefing by attorney Cynthia Marcotte Stamer that Solutions Law Press, Inc.™ will host beginning at Noon Central Time on Wednesday, March 30, 2016.
About The Author
Cynthia Marcotte Stamer is a practicing attorney and management consultant, author, public policy advocate and lecturer widely recognized for her extensive work and pragmatic thought leadership, experience, publications and training on HIPAA and other privacy, medical records and data and other health care and health plan concerns.
Recognized as “LEGAL LEADER™ Texas Top Rated Lawyer” in both Health Care Law and Labor and Employment Law, a “Texas Top Lawyer,” an “AV-Preeminent” and “Top Rated Lawyer” by Martindale-Hubble and as among the “Best Lawyers In Dallas” in employee benefits 2015 by D Magazine; Ms. Stamer has more than 28 years of extensive proven, pragmatic knowledge and experience representing and advising health industry clients and others on operational, regulatory and other compliance, risk management, product and process development, public policy and other key concerns.
As a core component of her work as the Managing Shareholder of Cynthia Marcotte Stamer, PC, the Co-Managing Member of Stamer Chadwick Soefje PLLC, Ms. Stamer has worked extensively throughout her nearly 30 year career with health care providers, health plans, health care clearinghouses, their business associates, employers, banks and other financial institutions, their technology and other vendors and service providers, and others on legal and operational risk management and compliance with HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and concerns; prevention, investigation, response, mitigation and resolution of known or suspected data or privacy breaches or other incidents; defending investigations or other actions by plaintiffs, OCR, FTC, state attorneys’ general and other federal or state agencies; reporting and redressing known or suspected breaches or other violations; business associate and other contracting; insurance or other liability management and allocation; process and product development, contracting, deployment and defense; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; enforcement, and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others.
Beyond her extensive involvement advising and defending clients on these matters, Ms. Stamer also has served for several years as the scrivener for the ABA JCEB’s meeting with OCR for many years. She returns as Chair of the Southern California ISSA Health Care Privacy & Security Summit for the third year in 2016, as well as speaks and serves on the steering committee of a multitude of other programs.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares shared her thought leadership, experience and advocacy on HIPAA and other concerns by her service in the leadership of a broad range of other professional and civic organization including her involvement as the Vice Chair of the North Texas Healthcare Compliance Association, Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE; Coalition on Patient Empowerment, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Board Compliance Chair and Board member of the National Kidney Foundation of North Texas, current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative and current RPTE Representative to the ABA Health Law Coordinating Counsel, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposia chair and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clientson the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. For additional information about Ms. Stamer, see CynthiaStamer.com or the Stamer│Chadwick │Soefje PLLC or contact Ms. Stamer via email here or via telephone to (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at www.solutionslawpress.com such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here. ©2016 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Brace For Health Plan OCR HIPAA Audits |
Brokers, Civil Rights, compensation, compliance, Corporate Compliance, Cybercrime, Data Breach, Data Security, employee, Employee Benefits, FACTA, fiduciary duty, Fiduciary Responsibility, Financial Security, GINA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, HIPAA, Hospitality, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Management, Medicare Part D, Mental Health, Mental Health Parity, MEWA, Obamacare, Patient Empowerment, Prescription Drugs, Privacy, Professional Liability, Risk Management, third party administrators, Uncategorized, Wellness, Wellness Programs, Workforce | Tagged: Data Breach, Data Security, Employee Benefits, ERISA, Fiduciary Liability, financial privacy, Health Insurance, Health Plan, Health Plans, HIPAA, Medical Privacy, OCR, Office of Civil Rights, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
July 11, 2015
Health plans, insurers and other health plan industry service providers widespread use and reliance on internet applications to access and share protected health information when performing online enrollment, claims administration and payment, reporting, member and provider communications and a host of other key health plan functions makes it particularly important for health plans, their employer or other sponsors, fiduciaries, insurers and other vendors and their management to respond quickly to a warning from Department of Health & Human Services (HHS) Office of Civil Rights (OCR) warning to ensure applications and systems properly safeguard protected health information (PHI) as required by the Health Insurance Portability & Accountability (HIPAA) Privacy, Security & Breach Notification Rules (HIPAA Rules) and other laws made in its July 10, 2015 announcement of its latest HIPAA settlement.
The new Resolution Agreement with the Massachusetts based hospital system, St. Elizabeth’s Medical Center (SEMC) settles charges OCR made that SEMC reached HIPAA by failing to protect the security of PHI when using internet applications to access and share PHI. The Resolution Agreement also shows how complaints filed with OCR by workforce members can create additional compliance headaches for Covered Entities or their business associates while the “robust corrective action plan” imposed under the Resolution Agreement shares examples of ladder reporting and management oversight and documentation Covered Entities and business associates can expect to need to prove their organizations maintains the “culture of compliance” with HIPAA OCR expects in the event of an OCR audit or investigation.
With recent reports on massive health plan HIPAA and other data breaches fueling widespread participant and regulatory concern over identity theft and other data security, Covered Entities and their business associates should prepare to defend the adequacy of their own HIPAA and other data security practices in the event of an OCR breach investigation or audit. Accordingly, health plans and their employer or other sponsors, health plan fiduciaries, health plan vendors acting as business associates and others dealing with health plans and their management should contact legal counsel experienced in these matters for advice within the scope of attorney-client privilege about how to respond to the OCR warning and other developments to manage their HIPAA and other privacy and data security legal and operational risks and liabilities.
SEMC Resolution Agreement Overview
The SEMC Resolution Agreement settles OCR charges that SEMC violated HIPAA stemming from an OCR investigation of a November 16, 2012 complaint by SEMC workforce members and a separate data breach report SEMC separately made to OCR of a breach of unsecured electronic PHI (ePHI) stored on a former SEMC workforce member’s personal laptop and USB flash drive affecting 595 individuals. In their complaint, SEMC workers complained SEMC violated HIPAA by allowing workforce members to use an internet-based document sharing application to share and store documents containing electronic protected health information (ePHI) of at least 498 individuals without adequately analyzing the risks. OCR says its investigation of the complaint and breach report revealed among other things that:
- SEMC improperly disclosed the PHI of at least 1,093 individuals;
- SEMC failed to implement sufficient security measures regarding the transmission of and storage of ePHI to reduce risks and vulnerabilities to a reasonable and appropriate level; and
- SEMC failed to timely identify and respond to a known security incident, mitigate the harmful effects of the security incident, and document the security incident and its outcome.
To resolve OCR’s charges, SMCS agreed to pay $218,400 to OCR and implement a “robust corrective action plan” to correct these alleged HIPAA violations. While the required settlement payment is relatively small, the Resolution Agreement’s focus security requirements for internet application and data use and sharing activities engaged in by virtually every Covered Entity and business associate make the Resolution Agreement merit the immediate attention of all Covered Entities, their business associates and their management.
SEMC HIPAA Specific Compliance Lessons For Health Plans & Business Associates
In announcing the Resolution Agreement, OCR Director Jocelyn Samuels sent a clear warning to all Covered Entities and their business associates “to pay particular attention to HIPAA’s requirements when using internet-based document sharing applications,” stating “In order to reduce potential risks and vulnerabilities, all workforce members must follow all policies and procedures, and entities must ensure that incidents are reported and mitigated in a timely manner.”
The Resolution Agreement makes clear that OCR expects health plans and other Covered Entities and their business associates to be able to show both their timely investigation of reported or suspected HIPAA susceptibilities or violations as well as to self-audit and spot test HIPAA compliance in their operations. The SEMC corrective action plan also indicates Covered Entities and business associates must be able to produce documentation and other evidence needed to show the top to bottom dedication to HIPAA compliance necessary to prove a “culture of compliance” with HIPAA permeates their organizations.
In light of OCR’s warning and expectations, Covered Entities and business associates should start by considering the advisability for their own organization to take one or more of the steps outlined in the “robust corrective action plan” included in the Resolution Agreement, starting with the specific steps the corrective action plan requires SEMC to address its internet application security concerns such as:
- Conducting self-audits and spot checks of workforce members’ familiarity and compliance with HIPAA policies and procedures on transmitting ePHI using unauthorized networks; storing ePHI on unauthorized information systems, including unsecured networks and devices; removal of ePHI from SEMC; prohibition on sharing accounts and passwords for ePHI access or storage; encryption of portable devices that access or store ePHI; security incident reporting related to ePHI; and
- Inspecting laptops, smartphones, storage media and other portable devices, workstations and other devices containing ePHI and other data devices and systems and their use; and
- Conducting other tests and audits of security and compliance with policies, processes and procedures; and
- Documenting results, findings, and corrective actions including appropriate up the ladder reporting and management oversight of these and other HIPAA compliance expectations, training and other efforts.
Broader HIPAA Compliance & Risk Management Lessons
Beyond the specific internet applications and other security of ePHI lessons in the Resolution Agreement, Covered Entities and their business associates also should be mindful of other more subtle, but equally important broader HIPAA compliance and risk management lessons provided in the Resolution Agreement and other recent OCR guidance about their overall HIPAA compliance responsibilities.
One of the most significant of these lessons is the need for proper workforce training, oversight and management. The Resolution Agreement sends an undeniable message that OCR expects Covered Entities, business associates and their leaders to be able to show their effective oversight and management of the operational compliance of their systems and members of their workforce with HIPAA policies. The SEMC corrective action plan should prompt Covered Entities and business associates to weigh the adequacy of their existing workforce training, reporting, investigation and other management processes and documentation. Meanwhile, OCR’s report that an OCR complaint made by SEMC insiders to OCR prompted its investigation also should sensitize Covered Entities and their business associates of the need to ensure that their workforce training and management processes are appropriate to position their organization both to show their processes encourage proper internal reporting and investigation of compliance concerns, as well as manage the inevitable HIPAA and other human resources retaliation and whistleblower exposures that can arise out of such reports.
The Resolution Agreement also provides insights to the internal corporate processes and documentation of compliance efforts that Covered Entities and business associates may need to show their organization has the required “culture of compliance” needed to mitigate consequences of breaches or other compliance glitches. Particularly notable are Resolution Agreement’s terms on the documentation and up the ladder reporting to management and OCR of SEMC’s self-audit and self-correction activities and management oversight and management of these activities. Like tips shared by HHS in the recently released Practical Guidance for Health Care Governing Boards on Compliance Oversight, these details in the Resolution Agreement provide invaluable tips to Boards and other leaders of Covered Entities and business associates about steps they can take to promote their ability to demonstrate their organizations have the necessary culture of HIPAA compliance OCR expects.
Health Plan HIPAA Compliance Risks & Responsibilities of Employers & Their Leaders
While HIPAA places the primary duty for complying with HIPAA on Covered Entities and business associates, health plan sponsors and their management still need to make HIPAA compliance a priority for many practical and legal reasons.
As employers forced to cope with the deluge of fears and questions of employees and other health plan members impacted by recent massive PHI breach reports shared by Blue Cross association health insurance plan giants, Anthem and Premera can attest, HIPAA data breach or other compliance reports often trigger significant financial, administrative, workforce satisfaction and other operational costs employer health plan sponsors. Inevitable employee concern about health plan data breaches undermines employee value and satisfaction of the health benefit plan as an employee benefit. These concerns also usually require employers to expend significant management and financial resources to respond to these concerns and address other employer fallout from the breach.
The costs of investigation and redress of a known or suspected HIPAA data or other breach typically far exceed the actual damages to participants resulting from the breach. While HIPAA technically does not make sponsoring employers directly responsible for these duties or the costs of their performance, as a practical matter sponsoring employers typically can expect to pay costs and other expenses that its health plan incurs to investigate and redress a HIPAA breach. For one thing, except in the all too rare circumstances where employers as plan sponsors have specifically negotiated more favorable indemnification and liability provisions in their vendor contracts, employer and other health plan sponsors usually agree in their health plan vendor contracts to pay the expenses and to indemnify health plan insurers, third party administrators, and other vendors for costs and liabilities arising from HIPAA breaches or other events arising in the course of the administration of the health plan. Since employers typically are obligated to pay health plan costs in excess of participant contributions, employers also typically would be required to provide the funding their health plan needs to cover these costs even in the absence of such indemnification agreements.
Sponsoring employers and their management also should be aware the employer’s exception from direct liability for HIPAA Rule compliance does not fully insulate the employer or its management from legal risks in the event of a health plan data breach or other HIPAA violation.
While HIPAA generally limits direct responsibility for compliance with the HIPAA Rules to a health plan or other Covered Entity and their business associates, HIPAA hybrid entity and other organizational rules and criminal provisions of HIPAA, as well as various other federal laws arguably could create liability risks for the employer. See, e.g., Cyber Liability, Healthcare: Healthcare Breaches: How to Respond; Restated HIPAA Regulations Require Health Plans to Tighten Privacy Policies and Practices; Cybercrime and Identity Theft: Health Information Security Beyond. For example, hybrid entity and other organizational provisions in the HIPAA Rules generally require employers and their health plan to ensure that health plan operations are appropriately distinguished from other employer operations in order for otherwise non-covered human resources, accounting or other employer activities to avoid subjecting their otherwise non-covered employer operations and data to HIPAA Rules. To achieve this required designation and separation, the HIPAA rules typically also require that the health plan include specific HIPAA language and the employer and health plan take appropriate steps to designate and separate health plan records and data, workforces, and operations from the non-covered business operations and records of the sponsoring employer. Failure to fulfill these requirements could result in the unintended spread of HIPAA restrictions and liabilities to other aspects of the employer’s human resources or other operations. Sponsoring employers will want to confirm that health plan and other operations and workforces are properly designated, distinguished and separated to reduce this risk.
When putting these designations and separations in place, employers also generally will want to make arrangements to ensure that their health plan includes the necessary terms and the employer implements the policies necessary for the employer to provide the certifications to the health plan that HIPAA will require that the health plan receive before HIPAA will allow health plan PHI to disclosed to the employer or its representative for the limited underwriting and other specified plan administration purposes permitted by the HIPAA Rules.
Once these arrangements are in place, employers and their management also generally will want to take steps to minimize the risk that their organization or a member of the employer’s workforce honors these arrangements and does not improperly access or use health plan PHI, systems in violation of these conditions or other HIPAA Rules. This or other wrongful use or access of health plan PHI or systems could violate criminal provisions of HIPAA or other federal laws making it a crime for any person – including the employer or a member of its workforce – from wrongfully accessing health plan PHI, electronic records or systems. Since health plan PHI records also typically include personal tax, social security information that the Internal Revenue Code, the Social Security Act and other federal laws generally would require the employer to keep confidential and to protect against improper use, employers and their management also generally should be concern about potential exposures for their organization that could result from improper use or access of this information in violation of these other federal laws. Since HIPAA and some of these other laws under certain conditions make it a felony crime to violate these rules, employer and their management generally will want to treat compliance with these federal rules as critical elements of the employer’s Federal Sentencing Guideline and other compliance programs.
Beyond the already discussed concerns, employers or members of their management also may have an incentive to promote health plan compliance with HIPAA or other health plan privacy or data security requirements to many the exposure of the employer or management or other staff to statutory, regulatory, contractual or ethical liabilities arising under ERISA, Internal Revenue Code, the Fair & Accurate Credit Transaction Act (FACTA), trade secret, insurance, disability, identity theft, cybersecurity or other federal or state laws.
For instance, health plan sponsors and management involved in health plan decisions, administration or oversight could face personal fiduciary liability risks under ERISA for failing to act prudently to ensure that the health plan compliance with HIPAA and other federal privacy and data security requirements.. ERISA’s broad functional fiduciary definition encompasses both persons and entities appointed as “named” fiduciaries and others who functionally exercise discretion or control over a plan or its administration. Consequently, the sponsoring employer and certain members of its human resources or other executive management team who functionally possess or exercise responsibility or authority over the administration of the employer’s health plan or its data or other assets, the selection or oversight of plan fiduciaries, vendors, or other workforce members its administration, or other key health plan operations risk ERISA fiduciary liability for their own failures to act prudently in carrying out HIPAA compliance or other responsibilities or to take action when they know or should know that another fiduciary is or has breached these duties. This fiduciary status and risk can occur even if the entity or individual does not is not named a named fiduciary, expressly disclaims fiduciary responsibility or does not realize it bears fiduciary status or responsibility. Since fiduciaries generally bear personal liability for their own breaches of fiduciary duty as well as potential co-fiduciary liability for fiduciary breaches committed by others that they knew or prudently should have known, most employers and members of their management will make HIPAA health plan compliance a priority to avoid or minimize these potential ERISA fiduciary exposures.
Furthermore, most employers and their management also will appreciate the desirability of taking reasonable steps to manage potential exposures that the employer or members of its management could face if their health plan or the employer violates the anti-retaliation rules of HIPAA or other laws through the adoption and administration of appropriate human resources, internal investigation and reporting, risk management policies and practices. See Employee & Other Whistleblower Complaints Common Source of HIPAA Privacy & Other Complaints.
Act To Manage HIPAA & Other Related Risks
OCR’s release of the Resolution Agreement on the heels of widespread publicity about massive health plan and other data breaches at Blue Cross health care giants, Anthem and Premera and other U.S. businesses and the potential legal and financial exposures that a HIPAA data breach or other violation could create, health plans and their sponsors, insurers, business associates, and leaders should appreciate the advisability of acting promptly to ensure that their health plans and business associates are taking appropriate steps to comply with the HIPAA Rules and manage other associated risks and liabilities. At minimum, health plans and their business associates should move quickly to conduct a documented assessment of the adequacy of their health plan internet applications and other HIPAA compliance in in light of the Resolution Agreement and other developments. Given the scope and diversity of the legal responsibilities, risks and exposures associated with this analysis, most health plan sponsors, fiduciaries, business associates and their management also will want to consider taking other steps to mitigate various other legal and operational risks that lax protection or use of health plan PHI or systems could create for their health plan, its sponsors, fiduciaries, business associates and their management. Health plan fiduciaries, sponsors and business associates and their leaders also generally will want to explore options to use indemnification agreements, liability insurance or other risk management tools as a stop gap against the costs of investigation or defense of a HIPAA security or other data breach.
For Legal or Consulting Advice, Legal Representation, Training Or More Information
If you need help responding to these new or other workforce, benefits and compensation, performance and risk management, compliance, enforcement or management concerns, help updating or defending your workforce or employee benefit policies or practices, or other related assistance, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A practicing attorney and Managing Shareholder of Cynthia Marcotte Stamer, P.C., a member of Stamer│Chadwick │Soefje PLLC, Ms. Stamer’s more than 27 years’ of leading edge work as an practicing attorney, author, lecturer and industry and policy thought leader have resulted in her recognition as a “Top” attorney in employee benefits, labor and employment and health care law.
Board certified in labor and employment law by the Texas Board of Legal Specialization, a Fellow in the American College of Employee Benefit Counsel, past Chair and current Welfare Benefit Committee Co-Chair of the American Bar Association (ABA) RPTE Section Employee Benefits Group, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, an ABA Joint Committee on Employee Benefits Council Representative and Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, Ms. Stamer is recognized nationally and internationally for her practical and creative insights and leadership on HIPAA and other health and other employee benefit, human resources, and related insurance, health care, privacy and data security and tax matters and policy.
Ms. Stamer’s legal and management consulting work throughout her 27 plus year career has focused on helping organizations and their management use the law and process to manage people, process, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer helps public and private, domestic and international businesses, governments, and other organizations and their leaders manage their employees, vendors and suppliers, and other workforce members, customers and other’ performance, compliance, compensation and benefits, operations, risks and liabilities, as well as to prevent, stabilize and cleanup workforce and other legal and operational crises large and small that arise in the course of operations.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce management operations and compliance. She supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Well known for her extensive work with health care, insurance and other highly regulated entities on corporate compliance, internal controls and risk management, her clients range from highly regulated entities like employers, contractors and their employee benefit plans, their sponsors, management, administrators, insurers, fiduciaries and advisors, technology and data service providers, health care, managed care and insurance, financial services, government contractors and government entities, as well as retail, manufacturing, construction, consulting and a host of other domestic and international businesses of all types and sizes.
As a key part of this work, Ms. Stamer uses her deep and highly specialized health, insurance, labor and employment and other knowledge and experience to help employers and other employee benefit plan sponsors; health, pension and other employee benefit plans, their fiduciaries, administrators and service providers, insurers, and others design legally compliant, effective compensation, health and other welfare benefit and insurance, severance, pension and deferred compensation, private exchanges, cafeteria plan and other employee benefit, fringe benefit, salary and hourly compensation, bonus and other incentive compensation and related programs, products and arrangements.
She is particularly recognized for her leading edge work, thought leadership and knowledgeable advice and representation on the design, documentation, administration, regulation and defense of a diverse range of self-insured and insured health and welfare benefit plans including private exchange and other health benefit choices, health care reimbursement and other “defined contribution” limited benefit, 24-hour and other occupational and non-occupational injury and accident, ex-patriate and medical tourism, onsite medical, wellness and other medical plans and insurance benefit programs as well as a diverse range of other qualified and nonqualified retirement and deferred compensation, severance and other employee benefits and compensation, insurance and savings plans, programs, products, services and activities. In these and other engagements, Ms. Stamer works closely with employer and other plan sponsors, insurance and financial services companies, plan fiduciaries, administrators, and vendors and others to design, administer and defend effective legally defensible employee benefits and compensation practices, programs, products and technology. She also continuously helps employers, insurers, administrative and other service providers, their officers, directors and others to manage fiduciary and other risks of sponsorship or involvement with these and other benefit and compensation arrangements and to defend and mitigate liability and other risks from benefit and liability claims including fiduciary, benefit and other claims, audits, and litigation brought by the Labor Department, IRS, HHS, participants and beneficiaries, service providers, and others. She also assists debtors, creditors, bankruptcy trustees and others assess, manage and resolve labor and employment, employee benefits and insurance, payroll and other compensation related concerns arising from reductions in force or other terminations, mergers, acquisitions, bankruptcies and other business transactions including extensive experience with multiple, high-profile large scale bankruptcies resulting in ERISA, tax, corporate and securities and other litigation or enforcement actions.
In the course of this work, Ms. Stamer has accumulated an impressive resume of experience advising and representing clients on HIPAA and other privacy and data security concerns. The scribe for the American Bar Association (ABA) Joint Committee on Employee Benefits annual agency meeting with the Department of Health & Human Services Office of Civil Rights for several years, Ms. Stamer has worked extensively with health plans, health care providers, health care clearinghouses, their business associates, employer and other sponsors, banks and other financial institutions, and others on risk management and compliance with HIPAA and other information privacy and data security rules, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns. Her clients include public and private health plans, health insurers, health care providers, banking, technology and other vendors, and others. Beyond advising these and other clients on privacy and data security compliance, risk management, investigations and data breach response and remediation, Ms. Stamer also advises and represents clients on OCR and other HHS, Department of Labor, IRS, FTC, DOD and other health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She also is the author of numerous highly acclaimed publications, workshops and tools for HIPAA or other compliance including training programs on Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
Ms. Stamer also is deeply involved in helping to influence the Affordable Care Act and other health care, pension, social security, workforce, insurance and other policies critical to the workforce, benefits, and compensation practices and other key aspects of a broad range of businesses and their operations. She both helps her clients respond to and resolve emerging regulations and laws, government investigations and enforcement actions and helps them shape the rules through dealings with Congress and other legislatures, regulators and government officials domestically and internationally. A former lead consultant to the Government of Bolivia on its Social Security reform law and most recognized for her leadership on U.S. health and pension, wage and hour, tax, education and immigration policy reform, Ms. Stamer works with U.S. and foreign businesses, governments, trade associations, and others on workforce, social security and severance, health care, immigration, privacy and data security, tax, ethics and other laws and regulations. Founder and Executive Director of the Coalition for Responsible Healthcare Policy and its PROJECT COPE: the Coalition on Patient Empowerment and a Fellow in the American Bar Foundation and State Bar of Texas. She also works as a policy advisor and advocate to health plans, their sponsors, administrators, insurers and many other business, professional and civic organizations.
Author of the thousands of publications and workshops these and other employment, employee benefits, health care, insurance, workforce and other management matters, Ms. Stamer also is a highly sought out speaker and industry thought leader known for empowering audiences and readers. Ms. Stamer’s insights on employee benefits, insurance, health care and workforce matters in Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, Modern Healthcare, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications. Ms. Stamer also regularly serves on the faculty and planning committees for symposia of LexisNexis, the American Bar Association, ALIABA, the Society of Employee Benefits Administrators, the American Law Institute, ISSA, HIMMs, and many other prominent educational and training organizations and conducts training and speaks on these and other management, compliance and public policy concerns.
Ms. Stamer also is active in the leadership of a broad range of other professional and civic organizations. For instance, Ms. Stamer presently serves on an American Bar Association (ABA) Joint Committee on Employee Benefits Council representative; Vice President of the North Texas Healthcare Compliance Professionals Association; Immediate Past Chair of the ABA RPTE Employee Benefits & Other Compensation Committee, its current Welfare Benefit Plans Committee Co-Chair, on its Substantive Groups & Committee and its incoming Defined Contribution Plan Committee Chair and Practice Management Vice Chair; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; current Vice Chair of the ABA TIPS Employee Benefit Committee; the former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division; on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. She also previously served as a founding Board Member and President of the Alliance for Healthcare Excellence, as a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early childhood development intervention agency, The Richardson Development Center for Children; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a member of the Board of Directors of the Southwest Benefits Association. For additional information about Ms. Stamer, see www.cynthiastamer.com, or http://www.stamerchadwicksoefje.com the member of contact Ms. Stamer via email here or via telephone to (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also may be interested reviewing other Solutions Law Press, Inc.™ resources at www.solutionslawpress.com such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile at here.
©2015 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on HIPAA Settlement Warns Health Plans, Sponsoring Employers & Business Associates To Manage HIPAA Risks |
105(h), ADA, ARRA, Cafeteria Plans, Civil Rights, Claims Administration, Corporate Compliance, Defined Contribution Plans, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, GINA, Government Contractors, Health Plans, HIPAA, Human Resources, Mental Health, MEWA, Retaliation, Risk Management | Tagged: Breach Notification, Data Breach, Employer, ERISA, Federal Sentencing Guidelines, Fiduciary Duties, Health Plans, HIPAA, Privacy, Risk Managemnet |
Permalink
Posted by Cynthia Marcotte Stamer
January 28, 2015
The EEOC has declared war on many employer sponsored wellness programs. The Senate Health, Education, Labor, and Pensions Committee will hold a hearing about how to improve employer wellness programs on Thursday, January 29. Employers and others should urge the Committee and other Congressional leaders to overrule the EEOC’s attacks on wellness programs as illegal disability discrimination under the Americans with Disabilities Act.
1 Comment |
ADA, Affordable Care Act, Disability, Discrimination, EEOC, EEOC, Employee Benefits, Employers, ERISA, GINA, Health Care Reform, Health Plans, Human Resources, Insurance, Internal Controls, MEWA, Patient Empowerment, Patient Protection and Affordable Care Act, Privacy, Rehabilitation Act, Wellness, Wellness Programs |
Permalink
Posted by Cynthia Marcotte Stamer
November 10, 2014
Human resources and other management leaders are watching Washington to see if the change in Congressional control resulting from the November 4, 2014 mid-term election ushers in a more management friendly federal legal environment. Since President Obama took office, the Democrats aggressive pursuit of health care, minimum wage and other federal pro-labor legislation, regulations and enforcement has increased management responsibilities, costs and liabilities.
Nationally recognized management attorney, public policy advisor and advocate, author and lecturer Cynthia Marcotte Stamer will help human resources and other management leaders prepare for 2015 when she speaks on “2015 Federal Legislative, Regulatory & Enforcement Update: What HR & Benefit Leaders Should Expect & Do Now” at the 2015 Dallas HR monthly luncheon series kickoff meeting on January 13, 2014.
About The Program
While November 4, 2014 Republican election victories gave Republicans a narrow majority in both the House and Senate when the new Congress takes office January 3, 2015, the new Republican Majority may face significant challenges delivering on their promises to move quickly to enact more business-friendly health care, guest worker, tax and other key reforms Republicans say will boost the employment and the economy.
While President Obama and Democrat Congressional leaders say they plan to work with the new majority, President Obama already is threatening to use vetoes, regulations and executive orders to block Republicans from obstructing or rolling back his pro-labor policy and enforcement agenda. When the new Congress takes office, the narrowness of the Republican Majority in the Senate means Republicans can’t block a Democratic filibuster or override a Presidential veto without recruiting some Democratic support.
As the Democrats and Republicans head into battle again, Board Certified Labor & Employment attorney and public policy advocate Cynthia Marcotte Stamer will help human resources and other management leaders get oriented for the year ahead by sharing her insights and predictions on the legislative, regulatory and enforcement agendas that HR, benefit and other business leaders need to plan for and watch in 2015. Among other things, Ms. Stamer will:
- Discuss how management can benefit from monitoring and working to influence potential legislative, regulatory and enforcement developments when planning and administering HR and related workforce policies;
- Discuss the key workforce and other legislative, regulatory and enforcement priorities and proposals Democrats and Republicans plan to pursue during 2015;
- Share her insights and predictions about how the narrow Republican majority, Mr. Obama’s lame duck presidency and other factors could impact each Party’s ability to pursue its agenda
- Share tips management leaders can use to help monitor developments and to help shape legislation, regulation and enforcement through Dallas HR, SHRM and other organizations as well as individually;
- Learn tips for anticipating and maintaining flexibility to respond to legislative, regulatory and enforcement developments; and
- More
To register or get more details about the program, DallasHR, or both, see http://www.dallashr.org.
About Ms. Stamer
Board certified labor and employment attorney, public policy leader, author, speaker Cynthia Marcotte Stamer is nationally and internationally recognized and valued for her more than 25 years of work advising and representing employers, insurers, employee benefit plans, their fiduciaries and advisors, business and community leaders and governments about workforce, employee benefits, social security and pension, health and insurance, immigration and other performance and risk management, public policy and related regulatory and public policy, management and other operational concerns.
Throughout her career, Ms. Stamer continuously both has helped businesses and their management to monitor and respond to federal and state legislative, regulatory and enforcement concerns and to anticipate and shape federal, state and other laws, regulations, and enforcement in the United States and internationally.
Well known for her leadership on workforce, health and pension policy through her extensive work with clients as well as through her high profile involvements as the Founder and Executive Director of the Coalition for Responsible Healthcare Policy and its PROJECT COPE: the Coalition on Patient Empowerment, a founding Board member of the Alliance for Health Care Excellence, a Fellow in the American College of Employee Benefit Counsel, the American Bar Association (ABA), and the State Bar of Texas leadership and other involvements with the ABA including her annual service leading the annual agency meeting of Joint Committee on Employee Benefits (JCEB) representatives with the HHS Office of Civil Rights and participation in other JCEB agency meetings, past involvements with legislative affairs for the Texas Association of Business and Dallas HR and others, and many speeches, publications, and other educational outreach efforts, Ms. Stamer has worked closely with Congress and federal and state regulators on the Patient Protection & Affordable Care Act and other health care, pension, immigration, tax and other workforce-related legislative and regulatory reforms for more than 30 years. One of the primary drafters of the Bolivian Social Security reform law and a highly involved leader on U.S. workforce, benefits, immigration and health care policy reform, Ms. Stamer’s experience also includes working with U.S. and foreign government, trade association, private business and other organizations to help reform other countries’ and U.S. workforce, social security and severance, health care, immigration, privacy and data security, tax, ethics and other laws and regulations. Ms. Stamer also contributes her policy, regulatory and other leadership to many professional and civic organizations including as Vice President of the North Texas Healthcare Compliance Professionals Association; Immediate Past Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Committee and its current Welfare Benefit Plans Committee Co-Chair, a Substantive Groups & Committee Member; a member of the leadership council of the ABA Joint Committee on Employee Benefits; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; the current Vice Chair of the ABA TIPS Employee Benefit Committee, and the past Coordinator of the Gulf Coast TEGE Council TE Division.
The publisher and editor of Solutions Law Press, Inc. who serves on the Editorial Advisory Boards of Employee Benefit News, HR.com, InsuranceThoughtLeadership.com and many other publications, Ms. Stamer also is a prolific and highly respected author and speaker, National Public Radio, CBS, NBC, and other national and regional news organization, Atlantic Information Services, The Bureau of National Affairs, HealthLeaders, Telemundo, Modern Healthcare, Business Insurance, Employee Benefit News, the Employee Benefits News, World At Work, Benefits Magazine, InsuranceThoughtLeadership.com, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, CEO Magazine, CFO Magazine, CIO Magazine, the Houston Business Journal, and many other prominent news and publications. She also serves as a planning faculty member and regularly conducts training and speaks on these and other management, compliance and public policy concerns for these and a diverse range of other organizations. For additional information about Ms. Stamer, see www.cynthiastamer.com.
For Added Information and Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
For Help Or More Information
If you need assistance in auditing or assessing, updating or defending your organization’s compliance, risk manage or other internal controls practices or actions, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469)767-8872.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 24 years of work helping employers and other management; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work helping employers implement, audit, manage and defend union-management relations, wage and hour, discrimination and other labor and employment laws, privacy and data security, internal investigation and discipline and other workforce and internal controls policies, procedures and actions. The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer works, publishes and speaks extensively on management, reengineering, investigations, human resources and workforce, employee benefits, compensation, internal controls and risk management, federal sentencing guideline and other enforcement resolution actions, and related matters. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters.Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see hereor contact Ms. Stamer directly.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2014 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Stamer Kicks Off Dallas HR 2015 Monthly Lunch Series With 2015 Federal Legislative, Regulatory & Enforcement Update |
105(h), ACA, ADA, Affirmative Action, Affordable Care Act, Bankruptcy, Cafeteria Plans, Child Labor, CHIP, Civil Rights, Claims Administration, COBRA, compensation transparency, Corporate Compliance, Defined Benefit Plans, Defined Contribution Plans, Disability, Disability, Disability Plans, Discrimination, Disease Management, Drug & Alcohol, E-Verify, EEOC, EEOC, Employee Benefits, Employers, Employment Agreement, Employment Tax, ERISA, ESOP, Excise Tax, Executive Compensation, family leave, Fiduciary Responsibility, FMLA, GINA, Government Contractors, Health Care Reform, Health Plans, HIPAA, Human Resources, I-9, Immigration, Income Tax, Insurance, Internal Controls, Internal Investigations, Labor Management Relations, Leave, medical leave, Mental Health, Mental Health Parity, MEWA, Military Leave, Non-Compete, Non-Competition Agreement, Nonresident aliens, OFCCP, OSHA, Patient Protection and Affordable Care Act, Payroll Tax, Preemption, Premium Subsidies, Prescription Drugs, Privacy, Professional Liability, Protected Health Information, Public Policy, Rehabilitation Act, Reporting & Disclosure, Restructuring, Retaliation, Retirement Plans, Risk Management, Safety, Sexual Harassment, Tax, Tax Credit, Telecommuting, Unemployment Benefits, Unemployment Insurance, Union, USERRA, VEVRRA, Wage & Hour, Wellness, Wellness Programs | Tagged: Administrative Simplification, CMS, Health Benefits, Health Insurance, Health insurers, Health Plans, HHS, HPID, HPOES, out-of-pocket maximum, TPAs |
Permalink
Posted by Cynthia Marcotte Stamer
November 4, 2014
Learn More Details By Participating In November 13, 2014 WebEx Briefing
Employers of 100 or more full-time employees that plan currently offering or planning to offer after November 4, 2014 health plans with mandate only or other “skinny” plan designs which do not provide “substantial coverage” for both in-patient hospitalization and physician services should re-evaluate the implications of their proposed plan design as well as existing and planned employee enrollment or other communications about those plans, in light of the new guidance provided by Notice 2014-69 released by the Internal Revenue Service (IRS) today. Learn all the details about this new guidance and its implication by participating in our November 13 , 2014 briefing.
Plans Must Provide “Substantial Coverage” for Both In-Patient Hospitalization & Physician Services To Provide Minimum Value
Notice 2014-69 makes it official that the Department of Treasury (including the IRS) and Department of Health and Human Services (collectively the Departments) believe that group health plans that fail to provide substantial coverage for in-patient hospitalization services or for physician services (or for both) (referred to in the Notice as Non-Hospital/Non-Physician Services Plans) do not provide the “minimum value” necessary to fulfill the minimum value requirements of Code §36B and 4080H(b).
The Notice also notifies sponsoring employers about the Departments expectations about notifications and other communications to employees about Non-Hospital/Non-Physician Services Plans) as well as shares details about the Departments plans for implementing their interpretation in planned final regulations by March, 2015.
Standards On Employer Communications About Non-Hospital/Non-Physician Services Plans
The Notice cautions employers about the need to use care in communicating with employees about Non-Hospital/Non-Physician Services Plan. Among other things, the Notice states that an employer that offers a Non-Hospital/Non-Physician Services Plan (including a Pre-November 4, 2014 Non-Hospital/Non-Physician Services Plan) to an employee must:
- Not state or imply in any disclosure that the offer of coverage under the Non-Hospital/Non-Physician Services Plan precludes an employee from obtaining a premium tax credit, if otherwise eligible, and
- Timely correct any prior disclosures that stated or implied that the offer of the Non-Hospital/Non-Physician Services Plan would preclude an otherwise tax-credit-eligible employee from obtaining a premium tax credit.
- Without such a corrective disclosure, the Notice warns that a statement (for example, in a summary of benefits and coverage) that a Non-Hospital/Non-Physician Services Plan provides minimum value will be considered to imply that the offer of such a plan precludes employees from obtaining a premium tax credit. However, an employer that also offers an employee another plan that is not a Non-Hospital/Non/-Physician Services Plan and that is affordable and provides minimum value (MV) is permitted to advise the employee that the offer of this other plan will or may preclude the employee from obtaining a premium tax credit.
Anticipated Approach In Planned Regulations
Regarding the Departments plans to adopt regulations implementing the interpretation of Code § 36B announced in the Notice, the Notice indicates:
- HHS intends to promptly propose amending 45 CFR 156.145 to provide that a health plan will not provide minimum value if it excludes substantial coverage for in-patient hospitalization services or physician services (or both).
- Treasury and the IRS intend to issue proposed regulations that apply these proposed HHS regulations under Code section 36B. Accordingly, under the HHS and Treasury regulations, an employer will not be permitted to use the MV Calculator (or any actuarial certification or valuation) to demonstrate that a Non-Hospital/Non-Physician Services Plan provides minimum value.
- Treasury and IRS anticipate that the proposed changes to regulations will be finalized in 2015 and will apply to plans other than Pre-November 4, 2014 Non-Hospital/Non-Physician Services Plans on the date they become final rather than being delayed to the end of 2015 or the end of the 2015 plan year. As a result, a Non-Hospital/Non-Physician Services Plan (other than a Pre-November 4, 2014 Non-Hospital/Non-Physician Services Plan) should not be adopted for the 2015 plan year.
- Solely in the case of an employer that has entered into a binding written commitment to adopt, or has begun enrolling employees in, a Non-Hospital/Non-Physician Services Plan prior to November 4, 2014 based on the employer’s reliance on the results of use of the MV Calculator (a Pre-November 4, 2014 Non-Hospital/Non-Physician Services Plan), however, Notice 2014-69 states the Departments anticipate that final regulations, when issued, will not be applicable for purposes of Code section 4980H with respect to the plan before the end of the plan year (as in effect under the terms of the plan on November 3, 2014) if that plan year begins no later than March 1, 2015.
- Employers offering Non-Hospital/Non-Physician Services Plans should “exercise caution in relying on the Minimum Value Calculator to demonstrate that these plans provide minimum value for any portion of a taxable year after publication of the planned final regulations.
- The IRS will not require an employee to treat a Non-Hospital/Non-Physician Services Plan as providing minimum value for purposes of an employee’s eligibility for a premium tax credit under Code section 36B, regardless of whether the plan is a Pre-November 4, 2014 Non-Hospital/Non-Physician Services Plan before final regulations take effect.
Employers & Plans Most Likely To Be Affected
The interpretation of minimum value and planned future regulatory changes announced in Notice 2014-69 primarily will impact large employers subject to the “pay or play” shared responsibility rules of Code § 4980H that offer a health plan providing coverage that meets the “minimum essential coverage” standards of Code § 4980H.
Under Code § 4980H(a), large employers that fail to offer employee and dependent coverage under a health plan providing “minimum essential coverage” to each full-time employee generally become liable to pay an employer shared responsibility payment of $165 per month ($2000 per year) (commonly referred to as the “A Penalty”) for each full-time employee.
In contrast, the penalties (commonly referred to as the “B Penalty”) created under Code § 4980H(b) generally comes into play when a covered large employer offers health plan coverage under a health plan providing minimum essential coverage but the plan either:
- Does not provide minimum value; or
- The cost to the employee for coverage exceeds 9.5% of the employee’s family adjusted gross income or an otherwise applicable safe harbor amount allowed under IRS regulations.Register For Briefing To Learn More
- To learn more about Notice 2014-69 and its implications on employer health plan obligations and Code § 4980H shared responsibility exposures, register to participate in a special Solutions Law WebEx Briefing on the new guidance conducted by Attorney Cynthia Marcotte Stamer on Thursday, November 13, 2014 from Noon to 1:00 p.m. Central Time here.
- Assuming at least one full-time employee of a covered large employer receives a subsidy for enrolling in health coverage through a health care exchange or “Marketplace” established under ACA, the B Penalty generally is equal to $250 per month ($3000 per year) multiplied by the number of such subsidized employees of the employer.
Learn More By Joining November 13, 2014 Solutions Law Press, Inc. Virtual Briefing Register Now!
To learn more about Notice 2014-69 and its implications on employer health plan obligations and Code § 4980H shared responsibility exposures, register to participate in a special Solutions Law WebEx Briefing on the new guidance conducted by Attorney Cynthia Marcotte Stamer on Thursday, November 13, 2014 from Noon to 1:00 p.m. Central Time here.
During the briefing, Ms. Stamer will:
- Explain what health benefits, if any, employers must offer employees under current ACA guidance
- Brief participants on this new guidance and other related guidance
- Discuss potential implications for employers and their health plans
- Discuss potential options for employers dealing with these plans and
- Take questions from virtual audience participants as time permits.
Registration Fee is $35.00 per person Registration required for each virtual participant. Payment required via website registration in advance of the program.. Payment only accepted via website PayPal. No checks or cash accepted. Participation is limited and available on a first come, first serve basis. Persons not registered at least 24 hours in advance not guaranteed to receive access information or materials prior to commencement of the briefing.
This briefing will be conducted via WebEx over the internet. Participants may have the opportunity to participate via telephone, provided that participants electing to participate may incur added charges for telephone connectivity. Solutions Law Press, Inc. is not responsible for any power or system failures. Solutions Law Press, Inc. also expects to offer the opportunity for individuals unable to participate in the live briefing to listen to a recording of the briefing beginning approximately one week after the program via the Internet by registering, paying the required registration fee and following listening instructions received in response to such registration.
Interested persons can register here now!
About The Speaker
A Fellow in the American College of Employee Benefits Counsel, recognized in International Who’s Who, and Board Certified in Labor & Employment Law, attorney and health benefit consultant Cynthia Marcotte Stamer has 25 years experience advising and representing private and public employers, employer and union plan sponsors, employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental leaders and others on health and other employee benefit. employment, insurance and related matters. A well-known and prolific author and popular speaker Board Certified in Labor & Employment Law, Ms. Stamer presently serves as Co-Chair of the ABA RPTE Section Welfare Plan Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Representative, an Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com), Insurance Thought Leadership,com and Employee Benefit News, and various other publications. With extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on public policy and regulatory advocacy on health and other employee benefits, human resources, insurance, tax, compliance and other matters and representing clients in dealings with the US Congress, Departments of Labor, Treasury, Health & Human Services, as well as state legislatures, attorneys general, insurance and labor departments, and other agencies and regulators. A prolific author and popular speaker, Ms. Stamer regularly authors materials and conducts workshops and professional, management and other training and serves on the faculty and planning committees of a multitude of symposium and other educational programs. See http://www.CynthiaStamer.com for more details.
A Fellow in the American College of Employee Benefits Counsel, recognized in International Who’s Who, and Board Certified in Labor & Employment Law, attorney and health benefit consultant Cynthia Marcotte Stamer has 25 plus years’ experience advising and representing private and public employers, employer and union plan sponsors, employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental leaders and others on health and other employee benefit. employment, insurance and related matters. A well-known and prolific author and popular speaker Board Certified in Labor & Employment Law, Ms. Stamer presently serves as Co-Chair of the ABA RPTE Section Welfare Plan Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Representative, an Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com), Insurance Thought Leadership,com and Employee Benefit News, and various other publications. With extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on public policy and regulatory advocacy on health and other employee benefits, human resources, insurance, tax, compliance and other matters and representing clients in dealings with the US Congress, Departments of Labor, Treasury, Health & Human Services, as well as state legislatures, attorneys general, insurance and labor departments, and other agencies and regulators. A prolific author and popular speaker, Ms. Stamer regularly authors materials and conducts workshops and professional, management and other training and serves on the faculty and planning committees of a multitude of symposium and other educational programs. See http://www.CynthiaStamer.com. for more details.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assist businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs.
For Added Information and Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
For additional information about upcoming programs, to inquire about becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. If you would prefer not to receive communications from Solutions Law Press, Inc. send an e-mail with “Solutions Law Press Unsubscribe” in the Subject to support@solutionslawyer.net. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN. If you are an individual with a disability who requires accommodation to participate, please let us know when you register so that we may consider your request. ©2014 Solutions Law Press, Inc. All rights reserved.
Comments Off on IRS Guidance Raises Concerns For Many Employers Offering “Skinny” & Other Limited Coverage Health Plans |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Disability, EEOC, EEOC, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, HIPAA, Human Resources, MEWA, Tax, Wellness Programs | Tagged: 4980H, ACA, ADA, Affordable Care Act, employer shared responsibility, GINA, HIPAA, HIPAA Portability, HIPAA Privacy, minimum value, MV, Pay or Play, Skinny Plans, Wellness, Wellness Programs |
Permalink
Posted by Cynthia Marcotte Stamer
September 16, 2013
A week before the September 23, 2013 deadline for all health care providers, health plans, health care clearinghouses (Covered Entities) and their business associates to have updated their business associate agreements to comply with the Final Omnibus HIPAA Rule, the Department of Health & Human Services Office of the National Coordinator for Health Information Technology (ONC) and the Office for Civil Rights (OCR) today (September 16, 2013) released Model Notices of Privacy Practices (Notices) for health care providers and health plans to use to communicate with their patients and plan members. With penalties and enforcement continuing to rise, Covered Entities and their business associates should take appropriate steps to review and update their privacy and breach notification policies and procedures, privacy officer appointments, notices of privacy practices, business associate agreements and other HIPAA compliance and risk management documentation, practices, procedures and coverage, breach notification and other HIPAA compliance and risk management practice.
Model HIPAA Notices
Developed collaboratively by ONC and OCR the Notices available here designed in the following three different styles are designed for users to customize to fit their specific needs and practices:
- A notice in the form of a booklet;
- A layered notice with a summary of the information on the first page and full content on the following pages; and
- A notice with the design elements of the booklet, but that is formatted for full-page presentation.
Use of these model Notices is optional. While the agencies designed the Notices to let Covered Entities to use these models by entering some of their own information into the model, such as contact information, and then printing for distribution and posting on their websites, Covered Entities should consult with legal counsel to determine the suitability of the Notices generally for their entity’s use and any customization, if any, that may be recommended or required to a Notice if the Covered Entity decides rely upon a model Notice to prepare its Notice of Privacy Practices. To facilitate any tailoring, the agencies provided a text-only version for Covered Entities wishing only wish to use the content with or without tailoring.
September 23 Business Associate Agreement Update Deadline
September 23, 2013 also is the final deadline established in the Final Omnibus HIPAA Rule for Covered Entities and their business associations to update the business associate agreements required by HIPAA to reflect application of the breach notification, business associate, and many of HIPAA’s requirements to directly cover business associates and other aspects of the Health Information Technology for Economic and Clinical Health (HITECH) Act enacted as part of the American Recovery and Reinvestment Act of 2009. While HHS published a Sample Business Associate Agreement last June to aid Covered Entities and their business associates with understanding the business associate agreement requirements as impacted by the Omnibus Final HIPAA Rule, it also made clear that Covered Entities and their business associates should tailor their business associate agreements to fit their specific circumstances and relationships. OCR National Office and regional officials speaking about their findings about past business associate agreement compliance have indicated that their audit and enforcement activities show widespread compliance issues among Covered Entities and business associates with the original business associate agreements. OCR clearly expects Covered Entities and their business associates to address and resolve these compliance issues going forward.
Covered Entities and their business associates are increasingly at peril if caught violating HIPAA’s Privacy, Security or Breach Notification rules. With the HITECH Act Breach Notification rules now requiring Covered Entities to self-disclose breaches, OCR becomes aware of breaches much more easily. Coupled with the HITECH Act’s increase in sanctions for HIPAA violations, Covered Entities and, beginning September 23, 2013, their business associates face rising risks for violating HIPAA. See, e.g. HHS Settles with Health Plan in Photocopier Breach Case; WellPoint Settles HIPAA Security Case for $1,700,000; Shasta Regional Medical Center Settles HIPAA Security Case for $275,000; Idaho State University Settles HIPAA Security Case for $400,000; and HHS announces first HIPAA breach settlement involving less than 500 patients.
In response to the updated Final Regulations and these expanding HIPAA enforcement and exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.
For Help or More Information
If you need assistance responding to HIPAA or other health industry regulatory, enforcement or other developments, reviewing or tightening your policies and procedures, conducting training or audits, responding to or defending an investigation or other enforcement actions; with 2014 health plan decision-making, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer for help.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer is widely recognized for her extensive work, publications, and thought leadership on HIPAA and other privacy and data security issues. Scribe for the ABA JCEB annual Technical Sessions meeting with OCR for the past three years, Ms. Stamer’s experience includes extensive work advising, representing and training health plan, health insurance, health IT, health care and other clients on HIPAA and other privacy, data protection and breach and other related matters and represents and advises these and other clients in responding to OCR Privacy and Civil Rights and other HHS agencies, Labor Department, IRS regulations, investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She also is recognized for her extensive publications and programs including numerous highly regarding publications and programs on HIPAA and other privacy and data security concerns as well as a wide range of other workshops, programs and publications.
Beyond her HIPAA involvement, Ms. Stamer also continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, HR.com, Insurance Thought Leadership, Solutions Law Press, Inc. and other publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
- CMS Hosts Webinar Celebrating National Health IT Week 9/16-20
- New DOL Guidance Makes Many Employers Rethink Giving FLSA 18B Exchange Notices
- Tell HHS What You Think About Obamacare & Other Rules
- Insist President & Congress Get Real About Health Care Reform
- Employers Beware! DOL-Model FLSA Section 18B Exchange Notice Requires Tailoring!
- IRS Publishes Final Health Reform Individual Shared Responsibility Rules
- Cascom Inc. Owner Must Pay Nearly $1.5 M After Company Misclassified Employees As Independent Contractors
- Government Contractors To Face Hiring “Targets” for Vets & Disabled Under Impending Rules.
- Impending 10/1 Exchange Notice & Other New Notice Deadlines Cut Time Short For Employers To Finalize 2014 Health Plan Terms & Contracts
- Health Plan Pays $1.2M+ HIPAA Settlement For Not Protecting PHI On Copiers
- Report Questions Security As HHS Invites Consumers To Set Up Personal Accounts To Prepare For Exchange Enrollment Period
- Justice Department Sues Texas Bus Company For Illegal Discrimination Against Citizens When Hiring H-2B Program Workers
- Legislation Proposes To Change Obama Care Full-Time Employee Definition
- IRS Releases Updated Healthcare Law Online Resources Publication
- IRS Extends Remedial Amendment On Cycle Opinion Deadline For Some Defined Benefit Plans
- Self-Dealing Or Other Mishandling of Employee Benefit Plan Funds Risky For Fiduciaries & Those Appointing Them
- Employers & Insurers Reminded Of July 31 Deadline To Pay New ACA-Required PCORI Fees
- Use New Government Health Care Reform Resources With Care
- OCR Warns Others Learn From WellPoint’s $1.7 M HIPAA Settlement
- “Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines
- HHS Continues Preparations For New Health Insurance Marketplace By Awarding Grants To Promote Kids Enrollment
- HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns
- HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce
- Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- CMS Publishes FY 2014 Final Inpatient Rehabilitation Facility Prospective Payment Rule
- Tighten Disability Compliance To Avoid ADA Suits, Program Disqualification & Other Risks
- Doc Caught Submitting Conflicting Patient Records to Private Payer Versus Medicare Criminally Sentence, Pays Civil Settlement
- OCR To Covered Entities: Learn From WellPoint $1.7 Settlement
- Improper Billing Of Private Payers Increasing Source Of Liability & Risk For Providers
- Ambulatory Care Orgs Face New Joint Commission Standards Beginning January 1, 2014
- Hollywood Pavillion & Other Fraud Convictions Show Individuals Risk Prison Time For Health Care Fraud Involvement
- 55 Hospitals To Pay $35M+ To Settle FCA Claims Charges On Kyphoplasty Procedures
- Whistleblower Collects $2.7 M of $14.5M Sound Inpatient Physicians Overbilling Settlement
- OIG Urges CMS To Step Up Efforts To Recover “Overpayments”
- HHS Continues Preparations For Health Care Marketplace By Awarding $32M Of Grants To Up CHIP & Medicaid Enrollment
- Hospital Pay $275K To Settle HIPAA Charges After Sharing PHI With Press, Workforce In Response To Fraud Reports
- OCR Makes Technical Corrections To HIPAA Omnibus Final Rule; September 2013 Enforcement Deadline Looming
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- IRS Witholding Calculator Can Help Avoid Over & Underwithholding
- Responding To West, Texas, Boston & Other Tragedies: Information and Reassurance Resources
- Justice Department Charges Employer, Pension Plan With Violating USERRA Reemployment Rights
- Administration Proposes To Let PBGC Board Set Premiums In Effort To Shore Up Finances
- Administration Proposes Expanding Eligibility, Simplifying Small Employer Health Care Tax Credit
- Health Care Transparency Effectiveness & Value Depends On Data Quality, Understanding & Awareness
- Test Your Health Care Reform Knowledge On 3rd Anniversary of Reform Passage
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- OCR Plans To Survey Health Plans, Other Covered Entities Hit With HIPAA Audits in 2012
- Businesses Urged To Strengthen Their Worker Classification Defenses As IRS, Other Agencies Step Up Audits & Enforcement
- Alert Employees Claiming Qualified Adoption Expenses and Education Credits About Changed IRS Procedures
- 13 Employer Tips For Coping With Health Care Reform Now!
- Sequester Will Cut ACA Small Businesses Health Care Tax Credits
For important information about this communication see here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C.
Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved.
[*] On January 24, 2013, the Department of Labor (the Department) issued guidance stating the Department’s conclusion that the notice requirement under FLSA section 18B will not take effect on March 1, 2013 for several reasons until further guidance setting the extended deadline was published.
Comments Off on HHS Share Model HIPAA Notices 1 Week Before Deadline For Updating Business Associate Agreements |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: 4980H, ACA, Afffordable Care Act, Breah Notification, Covered Entities, Exchange Notice, Health Care Provider, Health Care Reform, Health Plans, health reform, HIPAA, OCR, Pay or Play, SBC |
Permalink
Posted by Cynthia Marcotte Stamer
September 1, 2013
Starting in 2014, the Individual Shared Responsibility mandate of the Patient Protection & Affordable Care Act (ACA) dictates that each individual American either have minimum essential coverage for each month, qualify for an exemption, or make a payment when filing his or her federal income tax return. In anticipation of the implementation of this Individual Shared Responsibility mandate, the Department of the Treasury and the Internal Revenue Service (IRS) published final regulations implementing the Individual Shared Responsibility mandate in the Internal Revenue Code. The guidance contained in these final regulations provide each American with critical information about their families’ potential exposure to liability for the individual shared responsibility tax in 2014 as well as key insights for employers. Solutions Law Press, Inc. authors are finalizing various articles on certain key aspects of these new regulations for publication over the next few days. Stay tuned for more details!
For each month beginning after December 31, 2013, Internal Revenue Code Section 5000A’s Individual Shared Responsibility mandate requires that individual Americans either qualify as exempt, maintain minimum essential coverage for themselves and any nonexempt family members, or pay an individual shared responsibility payment when paying their Federal income tax return. A taxpayer will be obligated to pay the individual shared responsibility tax under Internal Revenue Code Section 5000A for any non-exempt individual the taxpayer claims on his or her individual tax return as a dependent who is not exempt or enrolled in minimum essential coverage.
Under § 5000A(f)(2), minimum essential coverage includes coverage under an eligible employer-sponsored plan.
The final regulations set the rules that the IRS will use to decide when an individual American will become liable for paying the tax imposed by ACA for failing to maintain the minimum required health insurance coverage mandated by ACA beginning January 1, 2013 and other related rules. While specifically addressing the obligations of individual Americans to pay the Individual Shared Responsibility payment, the final rules coupled with the availability of the new option for individual Americans to buy coverage through an ACA-qualified federal health care exchange and, depending on the adjusted household income of the individual, potentially also to receive tax credits for enrolling in coverage through an exchange is likely to impact the enrollment choices that employed individuals make about enrolling in coverage offered by their employer versus in coverage through a federally qualified health insurance exchange. Accordingly, both individual Americans and the businesses that employ them should act quickly to understand the key aspects of the final regulations and their implications.
When considering the effect of these final regulations, employers and individual Americans should keep in mind that Notice 2013-42, issued on June 26, 2013, provides limited transition relief from the Individual Shared Responsibility mandate for employees and their families who are eligible to enroll in certain employer-sponsored health plans with a plan year other than a calendar year if the plan year begins in 2013 and ends in 2014. For additional information on the Individual Shared Responsibility provision, the final regulations and Notice 2013-42, see the IRS questions and answers.
Coming slightly less than a month before the October 1, 2013 scheduled opening of the first enrollment period for individual Americans to enroll in health care coverage through a federally qualified health insurance exchange created pursuant to ACA and the deadline for employers to deliver the notice of the availability of this option dictated by Fair Labor Standards Act 18B, the final regulations and Obama Administration’s announced plans to enforce its provisions has drawn criticism from a number of groups. While the Obama Administration has indicated that it still plans to enforce the Individual Shared Responsibility mandate against individual Americans, it announced in July, 2013 that it would delay enforcement of the Employer Shared Responsibility Mandate rules of Internal Revenue Code Section 4980H until 2015. Many consumer rights groups and others are arguing that the Administration should also delay its enforcement of the Individual Shared Responsibility Mandate in light of its delay of enforcement of Internal Revenue Code Section 4980H against businesses. Pending a reversal of its position or Congressional relief, the final regulation signal to individual Americans and their employers to prepare to deal with the new Individual Shared Responsibility Mandate beginning in January, 2014.
While the delay in enforcement of the Section 4980H employer shared responsibility payment until 2015 means that employers will not incur liability for failing to provide coverage meeting the minimum essential coverage, minimum value and affordability standards of Internal Revenue Code Section 4980H, the impending implementation of the Individual Shared Responsibility mandate of Internal Revenue Code Section 5000A and the impending availability of tax credits for certain individuals with Household Adjusted Gross Incomes of less than 400 percent of the poverty level almost certainly will influence enrollment decisions that employees make concerning coverage offered by their employer, if any. Employers can expect that employee choices about enrolling in employer-sponsored group health coverage will be influenced by the impending obligation to enroll in coverage or pay the individual shared responsibility tax in 2014 governed by the final regulations. Employers can expect that employee concern about these exposures will prompt many employees to carefully scrutinize and in some cases question the information and implications of information provided by the employer or its plan such as the Section 18B notice that employers must provide by October 1, 2013, the summary of benefits and coverage (SBC) that the Affordable Care Act obligations the employer or plan to provide as the employees work to sort out their choices. As these and other plan communications are likely to face significant scrutiny, employers and their employee benefit plan fiduciaries and administrators should use extra care to ensure that these and other plan documents and communications are carefully and precisely tailored to accurately convey all material plan terms.
For Help or More Information
If you need help understanding or dealing with these impending notification requirements, with other 2014 health plan decision-making or preparation, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, HR.com, Insurance Thought Leadership, Solutions Law Press, Inc. and other publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
- Health Plan Pays $1.2M+ HIPAA Settlement For Not Protecting PHI On Copiers
- Report Questions Security As HHS Invites Consumers To Set Up Personal Accounts To Prepare For Exchange Enrollment Period
- Justice Department Sues Texas Bus Company For Illegal Discrimination Against Citizens When Hiring H-2B Program Workers
- Legislation Proposes To Change Obama Care Full-Time Employee Definition
- IRS Releases Updated Healthcare Law Online Resources Publication
- IRS Extends Remedial Amendment On Cycle Opinion Deadline For Some Defined Benefit Plans
- Self-Dealing Or Other Mishandling of Employee Benefit Plan Funds Risky For Fiduciaries & Those Appointing Them
- Employers & Insurers Reminded Of July 31 Deadline To Pay New ACA-Required PCORI Fees
- Use New Government Health Care Reform Resources With Care
- OCR Warns Others Learn From WellPoint’s $1.7 M HIPAA Settlement
- “Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines
- HHS Continues Preparations For New Health Insurance Marketplace By Awarding Grants To Promote Kids Enrollment
- HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns
- HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce
- Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- CMS Publishes FY 2014 Final Inpatient Rehabilitation Facility Prospective Payment Rule
- Tighten Disability Compliance To Avoid ADA Suits, Program Disqualification & Other Risks
- Doc Caught Submitting Conflicting Patient Records to Private Payer Versus Medicare Criminally Sentence, Pays Civil Settlement
- OCR To Covered Entities: Learn From WellPoint $1.7 Settlement
- Improper Billing Of Private Payers Increasing Source Of Liability & Risk For Providers
- Ambulatory Care Orgs Face New Joint Commission Standards Beginning January 1, 2014
- Hollywood Pavillion & Other Fraud Convictions Show Individuals Risk Prison Time For Health Care Fraud Involvement
- 55 Hospitals To Pay $35M+ To Settle FCA Claims Charges On Kyphoplasty Procedures
- Whistleblower Collects $2.7 M of $14.5M Sound Inpatient Physicians Overbilling Settlement
- OIG Urges CMS To Step Up Efforts To Recover “Overpayments”
- HHS Continues Preparations For Health Care Marketplace By Awarding $32M Of Grants To Up CHIP & Medicaid Enrollment
- Hospital Pay $275K To Settle HIPAA Charges After Sharing PHI With Press, Workforce In Response To Fraud Reports
- OCR Makes Technical Corrections To HIPAA Omnibus Final Rule; September 2013 Enforcement Deadline Looming
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- IRS Witholding Calculator Can Help Avoid Over & Underwithholding
- Responding To West, Texas, Boston & Other Tragedies: Information and Reassurance Resources
- Justice Department Charges Employer, Pension Plan With Violating USERRA Reemployment Rights
- Administration Proposes To Let PBGC Board Set Premiums In Effort To Shore Up Finances
- Administration Proposes Expanding Eligibility, Simplifying Small Employer Health Care Tax Credit
- Health Care Transparency Effectiveness & Value Depends On Data Quality, Understanding & Awareness
- Test Your Health Care Reform Knowledge On 3rd Anniversary of Reform Passage
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- OCR Plans To Survey Health Plans, Other Covered Entities Hit With HIPAA Audits in 2012
- Businesses Urged To Strengthen Their Worker Classification Defenses As IRS, Other Agencies Step Up Audits & Enforcement
- Alert Employees Claiming Qualified Adoption Expenses and Education Credits About Changed IRS Procedures
- 13 Employer Tips For Coping With Health Care Reform Now!
- Sequester Will Cut ACA Small Businesses Health Care Tax Credits
For important information about this communication see here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C.
Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved.
[*] On January 24, 2013, the Department of Labor (the Department) issued guidance stating the Department’s conclusion that the notice requirement under FLSA section 18B will not take effect on March 1, 2013 for several reasons until further guidance setting the extended deadline was published.
Comments Off on IRS Publishes Final Health Reform Individual Shared Responsibility Rules |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: 4980H, ACA, Afffordable Care Act, Breah Notification, Covered Entities, Exchange Notice, Health Care Provider, Health Care Reform, Health Plans, health reform, HIPAA, OCR, Pay or Play, SBC |
Permalink
Posted by Cynthia Marcotte Stamer
August 21, 2013
Employer and union group health plan sponsors and insurers of group and individual health plans (Health Plans) agonizing over 2014 plan design decisions are running out of time. Impending deadlines to update and deliver the initial Exchange Notice by October 1, 2013, the Summary of Benefits and Communications (SBC) disclosure before their next enrollment period begins, and 60-day prior notice of material reductions in benefits or services under the plan mandated by the Patient Protection and Affordable Care Act (ACA) require employers or other sponsors to finalize design decisions and amendments well in advance of January 1, 2014. These new notification obligations create added urgency and pressure for Health Plans and their employer and other sponsors to finalize and implement their decisions on their Health Plans 2014 plan designs and coverages and make the necessary determinations to prepare and timely deliver the required notifications in accordance with these new notification mandates well before the start of the 2014 plan year or its enrollment period. Employers who in the past have put off these decisions until the last month of the plan year no longer can legally do so.
ACA Exchange Notices Due By October 1
One of the biggest time constraints for finalizing 2014 plan designs, contracts and terms is the impending October 1, 2014 deadline for employers to provide the notice required by Fair Labor Standards Act Section 18B.
Regardless of if the employer sponsors a health plan or when the next plan enrollment period begins, all employers covered by the FLSA generally are required deliver a notice to employees about the new option beginning January 1, 2014 to get health care coverage through a health care exchange (now rebranded by the Obama Administration as a “Marketplace”)(Marketplace) created by ACA that meets the requirements of new FLSA Section 18B enacted Section 1512 of ACA.
Absent a delay or other reprieve from the Obama Administration or Congress, Open enrollment for health insurance coverage through the Marketplace begins October 1, 2013. Individuals and employees of small businesses beginning October 1, 2013 can apply for and, beginning January 1, 2014 to buy health care coverage offered through the Marketplace established under ACA for their state (including the Federal Marketplace for states that did not elect to establish their own Marketplace). Some individuals who earn less than 400% of the federal poverty level and meet certain other conditions also are slated to qualify to receive federal subsidies that will pay all or part of the cost of buying coverage through a Marketplace.
To promote awareness among employees of the Marketplace as an option for getting health coverage, creates a new FLSA Section 18B requiring a notice (Exchange Notice) to employees of coverage options available through the Marketplace. Originally required by March 1, 2013,[*] the Department of Labor (DOL) extended the deadline for providing the Exchange Notice to October 1, 2013. Employers must provide a notice of coverage options to each employee, regardless of plan enrollment status (if applicable) or of part-time or full-time status. Employers are not required to provide a separate notice to dependents or other individuals who are or may become eligible for coverage under the plan but who are not employees.
All FLSA-Covered Employers Must Provide Exchange Notices Beginning October 1, 2013
Under FLSA Section 18B of the FLSA, each applicable employer must provide each employee at the time of hiring (or with respect to current employees, by October 1, 2013), a written notice that fulfills the applicable Exchange Notice requirements as set forth in the DOL Regulations.
The FLSA section 18B requirement to provide a notice to employees of coverage options applies to all employers subject to the FLSA. In general, the FLSA applies to employers that employ one or more employees who are engaged in, or produce goods for, interstate commerce. For most firms, a test of not less than $500,000 in annual dollar volume of business applies. The FLSA also specifically covers the following entities: hospitals; institutions primarily engaged in the care of the sick, the aged, mentally ill, or disabled who reside on the premises; schools for children who are mentally or physically disabled or gifted; preschools, elementary and secondary schools, and institutions of higher education; and federal, state and local government agencies. Employers questioning whether their business is subject to the FLSA should seek the assistance of legal counsel experienced with the FLSA.
Timing and Delivery of Notice
Employers are required to provide the Exchange Notice to each new employee at the time of hiring beginning October 1, 2013. For 2014, the Department will consider a notice to be provided at the time of hiring if the notice is provided within 14 days of an employee’s start date.
For employees who are current employees before October 1, 2013, employers must provide the Exchange Notice no later than October 1, 2013.
The Exchange Notice must be provided in writing in a manner calculated to be understood by the average employee. Employers may deliver the Exchange Notice by first-class mail or, if the electronic notification requirements of the Department of Labor’s electronic disclosure safe harbor at 29 CFR 2520.104b-1(c) are met, electronically.
Required Content of Exchange Notice
The Exchange Notice content mandated by FLSA Section 18B is fairly limited. Section 18B requires that the Exchange Notice only dictates three required elements:
- Inform employees of coverage options, including information about the existence of the new Marketplace as well as contact information and description of the services provided by a Marketplace;
- Inform the employee that the employee may be eligible for a premium tax credit under Section 36B of the Code if the employee purchases a qualified health plan through the Marketplace; and
- Include a statement informing the employee that if the employee purchases a qualified health plan through the Marketplace, the employee may lose the employer contribution (if any) to any health benefits plan offered by the employer and that all or a portion of such contribution may be excludable from income for Federal income tax purposes. At minimum, this generally requires that the Exchange Notice distributed by an employer must inform the employee.
Interim DOL guidance implementing these requirements construes the content requirements as requiring that the Exchange Notice tell the employee:
- Of the existence of the Marketplace (referred to in the statute as the Exchange) including a description of the services provided by the Marketplace, and the way the employee may contact the Marketplace to request assistance;
- That the employee may be eligible for a premium tax credit or subsidy under Section 36B of the Internal Revenue Code (the Code) if the employee purchases a qualified health plan through the Marketplace and the employer does not offer coverage to the employee under a group health plan that is considered to provide “Minimum Value” for purposes of ACA; and
- That if the employee purchases a qualified health plan through the Marketplace, the employee may lose the employer contribution (if any) to any health benefits plan offered by the employer and that all or a portion of such contribution may be excludable from income for Federal income tax purposes.
Allow Adequate Time To Do Analysis, Complete Other Steps To Prepare Exchange Notices
Employers should resist the urge to allow the shortness of the list of information required that FLSA Section 18B requires in the Exchange Notice lure them into underestimating the time and effort required to prepare the Exchange Notification. For many employers, determining if the Health Plan provides Minimum Value can be time-consuming and complex.
For this, the SBC notice discussed later in this update and other purposes, Code Section 36B(c)(2)(C)(ii) provides that an employer-sponsored Health Plan provides Minimum Value if the ratio of the share of total costs paid by the Health Plan relative to the total costs of covered services is no less than 60% of the anticipated covered medical spending for covered benefits paid by a group health plan for a standard population, computed in accordance with the plan’s cost-sharing, and divided by the total anticipated allowed charges for covered benefits provided to a standard population is no less than 60%. See Patient Protection and ACA: Standards Related to Essential Health Benefits, Actuarial Value, and Accreditation Regulation.
Existing regulations require the employers to get an actuarial certification to determine if its Health Plan provides Minimum Value unless the employer can show that the Health Plan fits the criteria to use and satisfies this test using either the Minimum Value Calculator or an applicable safe harbor design approved by HHS, Treasury and DOL. These determinations often are time consuming and complex requiring careful review and analysis of the group health plan coverage and benefits. Many self-insured or other group health plans have plan designs that prevent the employer from relying on the Minimum Value Calculator or design safe harbors. If the employer cannot rely upon the Minimum Value Calculator or one of the design safe harbors, an actuarial certification will be needed. Employers need to allow sufficient time to make these determinations in time to complete and deliver the Exchange Notices.
Employers should particularly expect to need to obtain an actuarial certification to determine if the Health Plan provides Minimum Value determination if the Health Plan is taking advantage of temporary relief from the cost sharing limitations of ACA for 2014 announced by the Obama Administration in February and reconfirmed in July, that for 2014 allows Health Plans to apply a separate ACA-compliant out-of-pocket maximum to prescription drug benefits from the ACA-compliant out-of-pocket maximum applied to all other benefits subject to ACA’s cost sharing restrictions. Since the Minimum Value Calculator cannot take into account this option, however, employers planning to apply a separate out-of-pocket maximum for prescription drug coverage versus other plan benefits should be prepared to get an actuarial certification of whether the plan provides Minimum Value.
DOL Model Exchange Notices Not Panacea
Employers may want to use some or all of the language that the DOL included in Model Notices that DOL published in conjunction with its publication of interim guidance on FLSA Section 18B in Technical Release No. 2013-02 on May 8, 2013 here. Because employers must tailor the content of the Exchange Notice for their group health plan based on specific information about their group health plan, employers are cautioned not to underestimate the time or effort that will be required to properly prepare the Exchange Notice for their group health plan, whether or not the employer makes use of the Model Notices in whole or part.
DOL published three model exchange notices (Model Notices) to assist employers in preparing the Exchange Notice for their Health Plan for 2014. One Model Notice is intended for employers who do not offer a Health Plan. The second Model Notice is designed for employers who offer a health plan to some or all employees. The third Model Notice is designed for employers to use to notify individuals who are enrolled or eligible to enroll in continuation coverage under the Health Plan under the Consolidated Omnibus Budget Reconciliation Act of 1985 (COBRA). Technical Release No. 2013-02 says employers may use the applicable of these models or a modified version, provided the Exchange Notice meets the content requirements described above.
Despite the availability of these Model Notices, preparing and providing the required Exchange Notices required by Section 18B typically requires significant evaluation and presents a variety of challenges for most employers. While intended to facilitate the ability of employers to prepare and provide the required Exchange Notices, preparing the Model Notices generally is challenging for many employers.
First, even using the Model Notices, the employer must decide if the Health Plan provides Minimum Value.
Another challenge with wholesale use of the Model Notices involves deciding how much of the optional language contained in the Model Notices to include in the Exchange Notice and what optional information, if any, to provide as part of that Notice.
For one thing, the Model Notices propose that the Exchange Notice include statements that many critics view as inappropriately promoting enrollment in coverage through the Marketplace rather than employer sponsored group health plans. Critics complain, for instance that the Model Notice’s statement that the Marketplaces offer “one-stop shopping” that allows the employee to get coverage that the Model Notice states is more “affordable” are inaccurate or misleading. Many critics view the assertion that coverage obtained through the exchange is more “affordable” to be inaccurate as it does not take into account a comparison of the actual benefits and costs of the respective plan options and whether the employee can afford the typically richer (and therefore often more expensive) benefit packages ACA’s essential health benefits mandates require be included in coverage offered for sale through the Marketplaces and presumes that these higher costs will be defrayed by tax credits or subsidies that are only available if the employee earns less than 400% of the federal poverty level and is not offered the option to enroll in an employer sponsored group health plan coverage that provides “minimum essential coverage” (MEC) and Minimum Value and is “affordable” within the meaning of ACA.
Employers considering using the Model Notices also need to decide if their Exchange Notices will include the optional factual disclosures about their group health plan suggested in the Model Notices, but not required to fulfill the requirements of FLSA Section 18B.
The Model Notices propose that an employer also voluntarily provide a significant amount of other information about its group health plan that FLSA Section permits, but does not require that the Exchange Notice include. The DOL says it designed the Model Notices to help employers to identify and disclose information that the DOL expects employees interested in the tax credit to subsidize the employee’s cost of enrolling in coverage through the Marketplace will need to get from employers to show eligibility. DOL assumes that many employers might want to voluntarily provide this information in the Exchange Notice to avoid receiving a multitude of anticipated inquiries from employees interested seeking tax credits to subsidize their enrollment in coverage through the Marketplace. Since collection the data necessary to make these optional disclosures can add significant complexity and time to the preparation of the Exchange Notice, employers should carefully weigh the pros and cons of making the optional disclosures. The anticipated demand for this information has declined since the Obama Administration announced it plans to use an “honor system” approach to determine if individuals can claim eligibility for tax credit subsidies for buying coverage through the Marketplaces in 2014. Meanwhile, the interim nature of the existing guidance on the Exchange Notice and other key aspects of ACA make it reasonable to expect further changes in the expected content of the Exchange Notice, ACA requirements that it is intended to communicate or both which could impact the need for or accuracy of these disclosures. For this reason, employers should carefully consider whether and what optional disclosures to include in their Exchange Notices.
Don’t Forget To Notify COBRA Qualified Beneficiaries
Technical Release No. 2013-02 indicates that in addition to sending an Exchange Notice to employees, employers or their group health plan administrators also must notify COBRA eligible or enrolled individuals.
In general, under COBRA, an individual who was covered by a group health plan on the day before a qualifying event occurred may be able to elect COBRA continuation coverage upon a qualifying event (such as termination of employment or reduction in hours that causes loss of coverage under the plan). Individuals with such a right are called qualified beneficiaries. A group health plan must provide qualified beneficiaries with an election notice, which describes their rights to continuation coverage and how to make an election. The election notice must be provided to the qualified beneficiaries within 14 days after the plan administrator receives the notice of a qualifying event.
Technical Release No. 2013-02 says that the DOL considers the required disclosures for the Exchange Notice information to be disclosed to qualified beneficiaries and that the DOL is revising previously published model COBRA notices to incorporate this information.
DOL says in Technical Release No. 2013-02 that the group health plans can use the revised model COBRA election notice to satisfy the requirement to provide the election notice under COBRA including the disclosure of information required by FLSA Section 18B. The DOL cautions that as with the earlier model COBRA notices, in order to use this model election notice properly, the plan administrator must complete it by filling in the blanks with the appropriate plan information. Technical Release 2013-02 states that use of the model election notice, appropriately completed, will be considered by the Department of Labor to be good faith compliance with the election notice content requirements of COBRA.
ACA SBC Mandate Overview
In addition to the Exchange Notice requirement, the need to prepare and timely delivery the “Summary of Benefits and Coverage or “SBC”) required by ACA also pressures employers to finalize their health plan terms and contracts for 2014 as soon as possible.
ACA amended the Public Health Services Act (PHS) Section 2715, Employee Retirement Income Security Act (ERISA) Section 715 and the Internal Revenue Code (Code) Section 9815 to require that Health Plans and health insurance issuers provide a SBC and a “Uniform Glossary” that “accurately describes the benefits and coverage under the applicable plan or coverage” in a way that meets the format, content and other detailed SBC standards set for ACA as implemented by the Departments regulatory guidance. Like the Exchange Notice, proper preparation of the SBC requires determination of whether the Health Plan provides Minimum Value, as well as other detailed analysis of the plan terms and coverages to complete the other disclosures required in the SBC.
The Summary of Benefits and Coverage and Uniform Glossary Final Regulation (Final Regulation) implementing this requirement published February 14, 2012 generally requires Health Plans at specified times including before the first offer of coverage under the Plan as well as following certain material changes to the Plan. For Health Plans providing group health plan coverage, FAQs About ACA Implementation (Part VII)[*] set the deadline for Health Plan to deliver a SBC as follows, while at the same time indicating that the Departments would not impose penalties on plans and issuers “working diligently and in good faith” to provide the required SBC content in an appearance consistent with the Final Regulations:
- To covered persons enrolling or re-enrolling in an open enrollment period (including late enrollees and re-enrollees) as the first day of the first open enrollment period that begins on or after September 23, 2012; and
- For individuals enrolling in coverage other than through an open enrollment period (including individuals who are newly eligible for coverage and special enrollees) as the first day of the first plan year that begins on or after September 23, 2012. See FAQs About ACA Implementation (Part VIII).
While the SBC doesn’t prohibit an employer from amending its Health Plan terms after the enrollment period begins, employers that change Health Plan terms or designs after distributing a SBC must incur the expense and effort to prepare and redistribute an updated SBC. Accordingly, most Health Plans and their sponsors or insurers will want to finalize Health Plan terms before the enrollment period begins to avoid the need to and expense of sending updated SBCs as a result of a later change in Health Plan terms.
The Final Regulation and other existing guidance generally dictates that Health Plans follow a required template for providing the SBC and accompanying glossary. When publishing the Final Regulation, the Departments also published the required SBC template form (2013 SBC Template) and instructions for Health Plans to use to prepare and provide the required SBC for coverage beginning before January 1, 2014 and promised updated guidance and templates for use in providing SBCs for post-2013 coverage. While the Agencies clarified certain other details about the SBC rules, they did not materially change the required content or form of the 2013 SBC Template until their April 23, 2013 release of FAQs About ACA Implementation (Part XIV). See e.g. FAQs About ACA Implementation Part IX and Part X.
FAQ Part XIV Requires MEC and Minimum Value Disclosures In SBC
FAQs About ACA Implementation (Part XIV) published April 23, 2013 announces the updated required 2014 SBC Template that the Agencies are requiring to SBCs for periods of health coverage from January 1, 2014 to December 31, 2014. Along with the 2014 SBC Template, the Agencies also published 2014 Sample Completed SBC, which provides an example of a SBC completed for a hypothetical health plan prepared by the Agencies.
The 2014 SBC Template updates the 2013 SBC Template and Sample Completed Template to add information the Agencies believe individuals eligible for Health Plan coverage should know in light of the impending implementation of the individual shared responsibility requirements of Internal Revenue Code (Code) Section 5000A and the employer shared responsibility rules of Code Section 4980H commonly called ACA’s “pay-or-play” rules. These were the “penalty” provisions that the Supreme Court ruled are taxes in 2013.
The April 23, 2013 FAQ expressly requires that SBCs for periods of coverage after December 31, 2013 disclose if the Health Plans provide MEC and Minimum Value to enable participants and beneficiaries to understand if enrollment in the Health Plan will suffice to allow the employee to avoid paying the individual penalty under Code Section 5000(a)’s individual “shared responsibility” rules, to compare the coverage and costs to enroll in the employer’s Health Plan versus to enroll in health care coverage through a Marketplace and to predict how their eligibility for enrollment in the employer’s Health Plan will impact their eligibility to qualify to claim tax credits under Code Section 32G to help subsidize the cost to purchase coverage through a Marketplace.
Code Section 5000A generally imposes a penalty tax on individuals that fail to maintain enrollment in MEC within the meaning of Code Section 5000A(f) and not otherwise exempt under Code Section 5000A(d). As of the publication of this update, the Obama Administration has not announced any delay in the enforcement of this penalty against individuals, but legislation is pending in Congress that would delay its applicability, along with approving the delay of enforcement of the Code Section 4980H penalties previously announced by the Obama Administration.
Although the Obama Administration announced in early July, 2013 that it will not enforce collection of the Code Section 4980H provisions against employers until 2015, Code Section 4980H generally requires employers of 50 or more full-time employees to pay a penalty if the employer fails to offer a group health plan providing MEC and Minimum Value Minimum Value is determined for this purpose in the same manner that it is determined for purposes of making the required disclosure in the Exchange Notice.
60-Day Advance Notice of Material Changes Requirement
In addition to providing the required Exchange Notice and SBCs, employers, group health plans and their plan administrators also must ensure that participants and beneficiaries are given at least 60 days prior notice before the effective date of any “material reduction in covered services or benefits.” See 29
CFR Section 2520.104b-3(d)(3); also see 29 CFR Section 2520.104b-3(d)(2) regarding a 90-day alternative rule.
Section 102 of ERISA has been amended to require 60-day advance notice of material plan changes for plan years beginning on or after September 23, 2012 before the change can be effective. The 60-day advance notification requirement is a modification to the summary plan description/summary of material modification requirements generally applicable to employee benefit plans under ERISA.
The rule’s definition of “material modification” is the same as the definition in the summary of material modifications rule generally applicable to employee benefit plans under ERISA Section 102.
DOL guidance indicates that group health plans can meet the 60-day advance notice requirement by providing an updated Summary of Benefits and Coverage if the change is reflected on the summary or by sending a separate written notice describing the material modification.
Group health plan issuers or sponsors that willfully (intentionally) fail to provide the notice of material modification can face a fine of up to $1,000 for each failure. Each covered individual equates to a separate offense for purposes of these penalties.
Employer and other group health sponsors, issuers, fiduciaries and administrators also should keep in mind that courts historically refuse to enforce reductions in benefits or services provided under the plan until participants and beneficiaries are notified of the change. For purposes of the ERISA notification rules, group health plans, their sponsors, insurers, administrators and fiduciaries are cautioned to take into account whether health care providers or other parties who have assignments of benefits should be provided with notification under these or other ERISA rules in addition to the employees and dependents who are enrolled in coverage under the group health plan.
Notice Deadlines Mean Time Short To Adopt & Communicate 2014 Plan Terms
Employer and other health plan sponsors, insurers, administrators and others involved in 2014 group health plan decisions and preparations must take into account these notification deadlines and allow adequate lead time to properly finalize, adopt and communicate their 2014 health plan terms.
Since group health plan design decisions must be finalized to properly prepare the Minimum Value disclosures required in the Exchange Notice and the SBC and any material reductions required by the 60-day advance notice requirement, time running short to finalize 2014 plan designs.
Employer and other plan sponsors, fiduciaries, administrators, and insurers are cautioned that their preparations should ensure both the necessary disclosures are made and that all disclosures are carefully prepared so that the notifications and the plan terms are consistent.
These preparations should include the critical review and coordination of the language of health plan documents and summary plan descriptions in light of these other notifications to identify and address potential differences between the government-mandated terms and language in the Glossary and SBC, the Exchange Notice and 60-day notice and the plan terms and summary plan description.
Arrangements also must include proper structuring and formatting of all of these documents and timely distribution in accordance with applicable regulations to participants and beneficiaries entitled to receive these documents in a manner that positions the employer, the group health plan and its fiduciaries and insurers to show compliance. In regard to distributions, parties planning to distribute notifications electronically need to ensure that any electronic or other methods of distribution meet applicable requirements and that the Health Plans timely send copies to all entitled parties – employees and dependents – in accordance with the applicable rules.
When planning these activities, group health plans, their sponsors, insurers and administrators also generally will want to minimize distribution costs by coordinating distribution of these ACA mandated notices with other notifications required for group health plans about privacy, coverage for newborns and mothers, mental health coverage, post-mastectomy reconstructive surgery and the like.
For Help or More Information
If you need help understanding or dealing with these impending notification requirements, with other 2014 health plan decision-making or preparation, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, HR.com, Insurance Thought Leadership, Solutions Law Press, Inc. and other publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
- Health Plan Pays $1.2M+ HIPAA Settlement For Not Protecting PHI On Copiers
- Report Questions Security As HHS Invites Consumers To Set Up Personal Accounts To Prepare For Exchange Enrollment Period
- Justice Department Sues Texas Bus Company For Illegal Discrimination Against Citizens When Hiring H-2B Program Workers
- Legislation Proposes To Change Obama Care Full-Time Employee Definition
- IRS Releases Updated Healthcare Law Online Resources Publication
- IRS Extends Remedial Amendment On Cycle Opinion Deadline For Some Defined Benefit Plans
- Self-Dealing Or Other Mishandling of Employee Benefit Plan Funds Risky For Fiduciaries & Those Appointing Them
- Employers & Insurers Reminded Of July 31 Deadline To Pay New ACA-Required PCORI Fees
- Use New Government Health Care Reform Resources With Care
- OCR Warns Others Learn From WellPoint’s $1.7 M HIPAA Settlement
- “Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines
- HHS Continues Preparations For New Health Insurance Marketplace By Awarding Grants To Promote Kids Enrollment
- HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns
- HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce
- Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- CMS Publishes FY 2014 Final Inpatient Rehabilitation Facility Prospective Payment Rule
- Tighten Disability Compliance To Avoid ADA Suits, Program Disqualification & Other Risks
- Doc Caught Submitting Conflicting Patient Records to Private Payer Versus Medicare Criminally Sentence, Pays Civil Settlement
- OCR To Covered Entities: Learn From WellPoint $1.7 Settlement
- Improper Billing Of Private Payers Increasing Source Of Liability & Risk For Providers
- Ambulatory Care Orgs Face New Joint Commission Standards Beginning January 1, 2014
- Hollywood Pavillion & Other Fraud Convictions Show Individuals Risk Prison Time For Health Care Fraud Involvement
- 55 Hospitals To Pay $35M+ To Settle FCA Claims Charges On Kyphoplasty Procedures
- Whistleblower Collects $2.7 M of $14.5M Sound Inpatient Physicians Overbilling Settlement
- OIG Urges CMS To Step Up Efforts To Recover “Overpayments”
- HHS Continues Preparations For Health Care Marketplace By Awarding $32M Of Grants To Up CHIP & Medicaid Enrollment
- Hospital Pay $275K To Settle HIPAA Charges After Sharing PHI With Press, Workforce In Response To Fraud Reports
- OCR Makes Technical Corrections To HIPAA Omnibus Final Rule; September 2013 Enforcement Deadline Looming
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- IRS Witholding Calculator Can Help Avoid Over & Underwithholding
- Responding To West, Texas, Boston & Other Tragedies: Information and Reassurance Resources
- Justice Department Charges Employer, Pension Plan With Violating USERRA Reemployment Rights
- Administration Proposes To Let PBGC Board Set Premiums In Effort To Shore Up Finances
- Administration Proposes Expanding Eligibility, Simplifying Small Employer Health Care Tax Credit
- Health Care Transparency Effectiveness & Value Depends On Data Quality, Understanding & Awareness
- Test Your Health Care Reform Knowledge On 3rd Anniversary of Reform Passage
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- OCR Plans To Survey Health Plans, Other Covered Entities Hit With HIPAA Audits in 2012
- Businesses Urged To Strengthen Their Worker Classification Defenses As IRS, Other Agencies Step Up Audits & Enforcement
- Alert Employees Claiming Qualified Adoption Expenses and Education Credits About Changed IRS Procedures
- 13 Employer Tips For Coping With Health Care Reform Now!
- Sequester Will Cut ACA Small Businesses Health Care Tax Credits
For important information about this communication see here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C.
Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved.
[*] On January 24, 2013, the Department of Labor (the Department) issued guidance stating the Department’s conclusion that the notice requirement under FLSA section 18B will not take effect on March 1, 2013 for several reasons until further guidance setting the extended deadline was published.
Comments Off on Impending 10/1 Exchange Notice & Other New Notice Deadlines Cut Time Short For Employers To Finalize 2014 Health Plan Terms & Contracts |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: 4980H, ACA, Afffordable Care Act, Breah Notification, Covered Entities, Exchange Notice, Health Care Provider, Health Care Reform, Health Plans, health reform, HIPAA, OCR, Pay or Play, SBC |
Permalink
Posted by Cynthia Marcotte Stamer
August 15, 2013
Affinity Health Plan, Inc. (Affinity) will pay $1,215,780 and take other corrective actions to settle alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules under the Affinity Resolution Agreement and CAP (Affinity Settlement) with the U.S. Department of Health and Human Services (HHS) Office of Civil Rights (OCR). The settlement comes as the September 24, 2013 deadline for health plans, health care providers, health care clearinghouses (Covered Entities) and their business associates to update the written business associate agreements that HIPAA requires exist before business associates can be allowed to create, use, access or disclose personally identifiable health care information protected by HIPAA (PHI) to carry out HIPAA-covered functions on behalf of a Covered Entity to comply with changes to HIPAA’s implementing regulations adopted by OCR earlier this year. Health plans and other Covered Entities should take timely action to confirm that their existing procedures appropriate safeguards to protect PHI when using or disposing of copiers or other equipment or media as well as to implement business associate or other policy, procedures or training updates required to comply with the updated HIPAA rules.
HIPAA Updates Require Breach Notification, Tightened Other HIPAA Requirements
HIPAA generally requires that Covered Entities (and after September 24, 2013, their business associates) safeguard and restrict the use, access or disclosure of PHI as required by HIPAA. The HITECH Act amended these requirements to tighten certain of these requirements and restrictions, to expand the sanctions for violation of these requirements, to require Covered Entities and their business associates to provide notification of breaches of unsecured PHI to individuals whose information was breached, OCR and in some cases, the media, and made certain other changes to the original requirements of HIPAA. Earlier this year, OCR amended and restated its original Privacy and Security Rules here (2013 Final Rule) to comply with changes in the regulations resulting from these HITECH Act amendments beginning last March, but set the deadline for updating business associate agreements to meet these updated requirements at September 23, 2013.
The 2013 Final Rule and other OCR guidance makes clear that OCR expects Covered Entities and their business associates appropriately to safeguard PHI stored in computers, hard drives, and other digital media until it is properly disposed in accordance with the updated standards required by HIPAA as implemented under the 2013 Final Rule. HITECH Breach Notification Rule requires HIPAA-covered entities to tell HHS of a breach of unsecured protected health information, including breaches resulting from failure to properly secure PHI stored in digital format until it has been destroyed in accordance with the standards established by the 2013 Final Rule. OCR previously has sanctioned other Covered Entities for failed to properly destroy or safeguard PHI stored in digital format on computer or other equipment before abandoning or disposing of that equipment. The Affinity Settlement reaffirms OCR’s concern that Covered Entities meet these disposal requirements when replacing or abandoning equipment containing electronic PHI.
Affinity Settlement Highlights
According to the August 14, 2013 OCR announcement of the settlement, the settlement resulted from an investigation initiated after Affinity filed a breach report with OCR on April 15, 2010, as required by the Health Information Technology for Economic and Clinical Health Act (HITECH Act.)
In its breach report, Affinity indicated that a representative of CBS Evening News told Affinity that, as part of an investigatory report, CBS had purchased a photocopier previously leased by Affinity. CBS informed Affinity that the copier that Affinity had used contained confidential medical information on the hard drive.
Affinity estimated in its breach report that up to 344,579 individuals may have been affected by this breach. OCR’s investigation indicated that Affinity impermissibly disclosed the protected health information of these affected individuals when it returned multiple photocopiers to leasing agents without erasing the data contained on the copier hard drives. In addition, OCR reports its investigation revealed that Affinity failed to incorporate the electronic protected health information (ePHI) stored on photocopier hard drives in its analysis of risks and vulnerabilities as required by the Security Rule, and failed to implement policies and procedures when returning the photocopiers to its leasing agents.
In addition to the $1,215,780 payment, the Affinity Settlement includes a corrective action plan requiring Affinity to use its best efforts to retrieve all hard drives that were contained on photocopiers previously leased by the plan that remain in the possession of the leasing agent, and to take certain measures to safeguard all ePHI.
Learn From Affinity Lesson On Proper Disposal Procedures
Like prior OCR settlements stemming from inadequate security for PHI when transitioning equipment, media or facilities, the Affinity Settlement sends another reminder to Covered Entities and their business associates again of the importance of using appropriate procedures to protect or dispose of PHI when replacing or redeploying equipment or media that may contain PHI.
“This settlement illustrates an important reminder about equipment designed to retain electronic information: Make sure that all personal information is wiped from hardware before it’s recycled, thrown away or sent back to a leasing agent,” said OCR Director Leon Rodriguez. “HIPAA covered entities are required to undertake a careful risk analysis to understand the threats and vulnerabilities to individuals’ data, and have appropriate safeguards in place to protect this information.”
OCR has published guidance concerning HIPAA’s requirements for the proper safeguarding and disposal of media and equipment in the 2013 Final Rule and other guidance. Concerning the proper disposition of copiers that may have PHI stored on their hard drives or in other digital formal, OCR in the Affinity Settlement recommended that Covered Entities and their associates also review the Federal Trade Commission’s Guidance On Safeguarding Sensitive Data Stored In The Hard Drives Of Digital Copiers and the National Institute of Standards and Technology has issued Guidance On Assessing The Security Of Multipurpose Office Machines. Covered Entities and their business associates should use this and other guidance to ensure that they can demonstrate that appropriate practices and procedures have been used to when disposing of or repurposing copies or other equipment that may contain electronic PHI.
HIPAA Regulation Updates Require Other Updates Beyond Disposal Procedures
In addition to addressing the concerns that lead to the Affinity Settlement, Covered Entities and their business associates also should verify that their practices, policies, privacy notices, business associate agreements, and training also are updated to comply with updates to the updated 2013 Final Rule adopted by OCR earlier this year here.
Since passage of the HITECH Act, OCR officials have warned Covered Entities to expect an omnibus restatement of its original regulations. While OCR had issued certain regulations implementing some of the HITECH Act changes, it waited to publish certain regulations necessary to implement other HITECH Act changes until it could complete a more comprehensive restatement of its previously published HIPAA regulations to reflect both the HITECH Act amendments and other refinements to its HIPAA Rules. The 2013 Regulations published today fulfill that promise by restating OCR’s HIPAA Regulations to reflect the HITECH Act Amendments and other changes and clarifications to OCR’s interpretation and enforcement of HIPAA.
In response to the updated Final Regulations and these expanding HIPAA enforcement and exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.
For Help or More Information
If you need help monitoring or providing input on this legislation or to understand and respond to these or other legislation, laws and regulations, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues. Author of numerous prominent publications on HIPAA and other data security and privacy concerns impacting health plans, health care providers, employers, financial services providers and others, Ms. Stamer also serves as the scribe for the ABA JCEB annual Technical Sessions meeting with OCR and has represented numerous health plans, employers, health care providers and others in investigating, redressing, reporting data breach, identity theft and other compliance concerns.
She advises clients on, publishes, and speaks on HIPAA and other health plan, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
- IRS Releases Updated Healthcare Law Online Resources Publication
- IRS Extends Remedial Amendment On Cycle Opinion Deadline For Some Defined Benefit Plans
- Self-Dealing Or Other Mishandling of Employee Benefit Plan Funds Risky For Fiduciaries & Those Appointing Them
- Employers & Insurers Reminded Of July 31 Deadline To Pay New ACA-Required PCORI Fees
- Use New Government Health Care Reform Resources With Care
- OCR Warns Others Learn From WellPoint’s $1.7 M HIPAA Settlement
- “Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines
- HHS Continues Preparations For New Health Insurance Marketplace By Awarding Grants To Promote Kids Enrollment
- HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns
- HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce
- Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- CMS Publishes FY 2014 Final Inpatient Rehabilitation Facility Prospective Payment Rule
- Tighten Disability Compliance To Avoid ADA Suits, Program Disqualification & Other Risks
- Doc Caught Submitting Conflicting Patient Records to Private Payer Versus Medicare Criminally Sentence, Pays Civil Settlement
- OCR To Covered Entities: Learn From WellPoint $1.7 Settlement
- Improper Billing Of Private Payers Increasing Source Of Liability & Risk For Providers
- Ambulatory Care Orgs Face New Joint Commission Standards Beginning January 1, 2014
- Hollywood Pavillion & Other Fraud Convictions Show Individuals Risk Prison Time For Health Care Fraud Involvement
- 55 Hospitals To Pay $35M+ To Settle FCA Claims Charges On Kyphoplasty Procedures
- Whistleblower Collects $2.7 M of $14.5M Sound Inpatient Physicians Overbilling Settlement
- OIG Urges CMS To Step Up Efforts To Recover “Overpayments”
- HHS Continues Preparations For Health Care Marketplace By Awarding $32M Of Grants To Up CHIP & Medicaid Enrollment
- Hospital Pay $275K To Settle HIPAA Charges After Sharing PHI With Press, Workforce In Response To Fraud Reports
- OCR Makes Technical Corrections To HIPAA Omnibus Final Rule; September 2013 Enforcement Deadline Looming
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- IRS Witholding Calculator Can Help Avoid Over & Underwithholding
- Responding To West, Texas, Boston & Other Tragedies: Information and Reassurance Resources
- Justice Department Charges Employer, Pension Plan With Violating USERRA Reemployment Rights
- Administration Proposes To Let PBGC Board Set Premiums In Effort To Shore Up Finances
- Administration Proposes Expanding Eligibility, Simplifying Small Employer Health Care Tax Credit
- Health Care Transparency Effectiveness & Value Depends On Data Quality, Understanding & Awareness
- Test Your Health Care Reform Knowledge On 3rd Anniversary of Reform Passage
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- OCR Plans To Survey Health Plans, Other Covered Entities Hit With HIPAA Audits in 2012
- Businesses Urged To Strengthen Their Worker Classification Defenses As IRS, Other Agencies Step Up Audits & Enforcement
- Alert Employees Claiming Qualified Adoption Expenses and Education Credits About Changed IRS Procedures
- 13 Employer Tips For Coping With Health Care Reform Now!
- Sequester Will Cut ACA Small Businesses Health Care Tax Credits
For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved
Comments Off on Health Plan Pays $1.2M+ HIPAA Settlement For Not Protecting PHI On Copiers |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: 4980H, ACA, Afffordable Care Act, Breah Notification, Covered Entities, Health Care Provider, Health Care Reform, Health Plans, health reform, HIPAA, OCR, Pay or Play, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
August 6, 2013
A federal lawsuit against Houston-based bus company Autobuses Ejecutivos LLC, d/b/a Omnibus Express, reminds U.S employers hiring foreign workers under the H-2B or other special worker visa programs to use care to ensure that they can prove that their need for foreign workers is not the result of recruitment and hiring practices that illegally discriminate against work-eligible members of the U.S. workforce already in the United States.
The Justice Department announced on August 6, 2013 that it and the Executive Office of Immigration Review’s Office of the Chief Administrative Hearing Officer (OCAHO) are suing Omnibus Express for allegedly violating the Immigration and Nationality Act’s (INA) anti-discrimination provisions by preferring to hire for bus driver positions temporary nonimmigrant visa holders on H-2B visas over work-eligible U.S. citizens, certain lawful permanent residents and other protected individuals.
H-2B Program Hiring Prohibited If Need Based On Illegal Discrimination
The H-2B program allows U.S. employers to bring foreign nationals to the United States to fill temporary nonagricultural jobs only when there are not enough U.S. workers who are able, willing or qualified to do the temporary work. While H-2B program hiring can be invaluable when a legitimate need exists, businesses contemplating or using the program need to be prepared to show their need to hire workers on H-2B visas is not the result of discriminatory hiring practices prohibited by the INA or other federal employment discrimination laws.
The INA generally protects work-eligible individuals in the United States, such as U.S. citizens, certain lawful permanent residents, refugees and asylees, from unlawful discrimination in hiring based on their citizenship status prohibiting employers from discriminating in hiring against these protected work-eligible workers based on their citizenship status.
Accordingly, while the H-2B program provides a valid opportunity to hire foreign workers consistent with the H-2B visa program requirements when in fact there are insufficient work-eligible, qualified applicants already in the U.S. to fill the position, employers hiring workers under the H-2B or other visa programs need to ensure that they are not inappropriately discriminating against U.S. citizens, permanent residents or other work-eligible individuals already in the U.S. in their recruitment and hiring practices when taking advantage of the H-2B program to hire workers.
In addition to the anti-discrimination provisions of the INA, hiring practices that discriminate in favor of hiring workers over other qualified applicants based on the respective citizenship, national origin, race or other protected status of the respective applicants or workers also can expose a business to liability under various other laws. In addition to suits brought by the Justice Department, prohibited discrimination by an employer under these other employment discrimination laws may expose a business to liability to actions brought by private litigants, the Equal Employment Opportunity Commission (EEOC), Office of Federal Contract Compliance (OFCCP) or other agencies, or both.
Omnibus Express Suit Highlights Risks Of H-2B Visa Hiring Need Based On Illegal Discrimination
The Justice Department complaint charges that Omnibus Express failed to fulfill this obligation. It claims that Omnibus Express violated the INA by actively discouraging or failing to consider the applications of many qualified U.S. citizens and other protected individuals between September 2012 to February 2013 while at the same time petitioning the U.S. Department of Labor (DOL) and U.S. Citizenship and Immigration Services (USCIS) for permission to hire up to 50 foreign workers on H-2B visas. The Justice Department alleges that Omnibus Express violated the INA by hiring 42 H-2B workers during this period based on its representation to the DOL and USCIS that there were not enough qualified workers in the United States to fill the 50 bus driver positions when in fact, its practices illegally discriminated against work-eligible U.S. citizens, lawful permanent residents and other INA-protected individuals who could have filled the positions.
The Justice Department asks the court to redress these alleged violations of the INA by ordering Omnibus Express to pay back pay for injured parties and civil penalties prohibiting future discrimination by Omnibus Express, and ordering other injunctive relief.
INA Discrimination Prosecution Part Of Obama Administration’s Emphasis on Enforcing Discrimination Laws
Businesses also should keep in mind that the Justice Department’s prosecution of Omnibus Express for alleged illegal citizenship discrimination also is part of the Obama Administration’s larger agenda prioritizing the expansion of non-discrimination safeguards for protected classes and the enforcement of these non-discrimination laws.
Since Mr. Obama took office, the Administration has sought regulatory and statutory changes that expand the federal employment and other anti-discrimination for a broad range of groups. The Administration also continues to proactively seek to expand the individuals protected by these and other Federal anti-discrimination laws even as the Departments of Justice, Labor, Health & Human Services, Education, Housing & Urban Development and other federal agencies have expanded their investigation, prosecution and public outreach of these laws.
In light of these developments, businesses should recognize that this proactive anti-discrimination agenda makes it wise for private businesses and state and local government agencies to take greater care to prevent and position their organizations to defend against potential discrimination and retaliation claims under the INA and a broad range of other employment and other anti-discrimination laws.
While this activist agenda in the anti-discrimination law area merits tighter compliance and risk management for all organizations, government contractors or subcontractors particularly face heightened risk as a result of recent expansions to the reach and requirements of nondiscrimination requirements.
Act To Mitigate Citizenship, National Origin & Other Employment Discrimination Exposures
Accordingly, while the Omnibus Express particularly highlights the importance for businesses subject to U.S. law to use care before hiring foreign workers on H-2B or other special visas to ensure that they can demonstration the need for foreign workers does not stem from recruitment and hiring practices that illegally discriminate against applicants already in and eligible to work in the U.S. who would be qualified to fill those positions.
Furthermore, businesses should use care not to underestimate their exposure to liability from charges of illegal discrimination in violation of the INA or other federal employment discrimination laws. Prohibited discrimination against workers based on citizenship, national origin or other prohibited grounds exposes employers to private lawsuits by workers seeking damages, attorneys’ fees and costs, and other remedies. In addition to these private exposures, the suit against Omnibus Express shows that the readiness of the Justice Department to enforce the INA so that work-authorized individuals have equal access to employment in the United States free from prohibited discrimination based on citizenship.
Jocelyn Samuels, Acting Assistant Attorney General for the Justice Department’s Civil Rights Division affirmed this commitment in the announcement of the Justice Department suit against Omnibus Express, stating “We are committed to enforcing the INA so that work-authorized individuals have equal access to employment in the United States.”
Accordingly, all businesses should make the tightened risk management of their INA anti-discrimination risks part of a broader emphasis on the prevention and management of their organization’s discrimination exposures generally.
As part of these risk management efforts, organizations should:
- Review and update their understanding of current anti-discrimination rules under the INA and other laws;
- Evaluate the adequacy of and tighten existing practices and documentation to mitigate exposures with discrimination and other laws;
- Update and tighten management controls, investigation and other procedures to promote compliance with anti-discrimination policies and identify and mitigate exposures arising in the course of operations;
- Conduct well-documented periodic training on these and other anti-discrimination compliance and risk management practices; and take other actions to monitor and enforce compliance by staff, contractors and others with whom they do business.
For Help With Compliance & Risk Management and Defense
If you need help in auditing or assessing, updating or defending your organization’s compliance, risk manage or other internal controls practices or actions, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469)767-8872.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 25 years of work helping private and governmental organizations and their management; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; schools and other governmental agencies and others design, administer and defend innovative compliance, risk management, workforce, compensation, employee benefit, privacy, procurement and other management policies and practices. Her experience includes extensive work helping employers implement, audit, manage and defend against employment and other anti-discrimination and anti-retaliation, union-management relations, wage and hour, and other labor and employment laws, other regulatory requirements, procurement, conflict of interest, discrimination management, privacy and data security, internal investigation and discipline and other workforce and internal controls policies, procedures and actions. The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee, a member of the HR.com editorial advisory board, a past National Consultants Board Member and Region IV Chair for SHRM, past Legislative Chair for the Dallas Human Resources Management Association, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer works, publishes and speaks extensively on workforce and risk management, reengineering, investigations, human resources and workforce, employee benefits, compensation, internal controls and risk management, federal sentencing guideline and other enforcement resolution actions, and related matters. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications.
You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here. For information about engaging Ms. Stamer for representation, training or other assistance, contact Ms. Stamer directly at (469) 767-8872.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer including:
For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved
Comments Off on Justice Department Sues Texas Bus Company For Illegal Discrimination Against Citizens When Hiring H-2B Program Workers |
ADA, Affirmative Action, Affordable Care Act, Corporate Compliance, E-Verify, EEOC, Employers, Excise Tax, GINA, Government Contractors, Health Care Reform, HIPAA, Human Resources, I-9, Immigration, Insurance, Patient Protection and Affordable Care Act, Rehabilitation Act, Retaliation, Uncategorized, Wellness Programs | Tagged: Citizenship discriminaton, Employer Liability., employment discrimination, H-2A Visa, H-2B, Immigration, INA, National Origin Discrimination |
Permalink
Posted by Cynthia Marcotte Stamer
August 5, 2013
Businesses and workers concerned that the definition of “full-time” employment as 30 hours per week in the “pay-or-play” penalties of the Patient Protection and Affordable Care Act (commonly referred to by the public as “Obamacare”) is hurting American workers may want to share their input on recently introduced legislation that would raise the number of hours an employee must work to qualify as “full-time” for purposes of the pay-or-pay penalty from 30 to 40 hours per week with members of the key Congressional Committees that will decide whether this legislation advances when Congress returns from its Summer vacation.
Growing concern about the costs and other implications of Obamacare are fueling renewed debate in Congress about the pay-or-play and other provisions of Obamacare. Only 57 days before enrollment in coverage slated to be available as an alternative to employer coverage beginning January 1, 2014 through new federally mandated health insurance exchanges is prompting renewed debate in Congress about the full-time employee, pay-or play and other provisions of Obamacare. As Congress takes its summer break, both sides are talking and listening to voters about health care reform. Concerned parties should share their input on Congress during this break to help shape the decisions Congress makes when it returns to work in September.
“Full-Time Employee” Definition Key Element Of Employer’s “Pay-Or Play” Liability
Originally scheduled to take effect on January 1, 2014 until the Administration on July 2, 2013 announced it would not enforce its provisions until 2015, the employer “shared responsibility” or “pay-or-play” rules of Internal Revenue Code (Code) Section 4980H enacted as part of Obamacare have been widely criticized as killing jobs and reducing employment.
When effective, Code Section 4980H will require that businesses employing 50 or more “full-time” employees (Large Employers”) pay a tax penalty calculated in accordance with Code Section 4980H unless the Large Employer offers each “full-time employee” the opportunity to enroll himself and each of his dependent children in coverage under a qualifying health plan that meets the minimum essential coverage, minimum value and affordability standards of Obamacare.
Under the current provisions of Code Section 4980H, the amount of the penalty that a Large Employer must pay is:
- $168 per employee per month for any month that the employer doesn’t offer minimum essential coverage to each full-time employee and has at least one full-time employee who receives a subsidy or tax credit for enrolling in coverage under one of the health insurance exchanges created by Obamacare (Subsidized Employee);
- $250 per employee month multiplied by the number of full-time employees of the business that are Subsidized Employees if the employer offers coverage under the health plan that provides minimum essential coverage but the health plan fails to meet the minimum value or affordability standards of Code Section 4980H; or
- $0 if the employer either offers health plan coverage that meets the minimum essential coverage, minimum value and affordability requirements of Code Section 4980H or doesn’t have any full-time employees who are Subsidized Employees.
30-Hour Full-Time Definition Reducing Full-Time Employment Opportunities
As the original January 1, 2014 implementation date of Code Section 4980H has approached, original largely Republican concern about its unintended adverse impact on employment increasingly has grown amid widespread reports that businesses are avoiding hiring and reducing employee hours to minimize exposures to Code Section 4980H-driven costs. See, e.g. Obamacare’s Employer Penalty And Its Impact On Temporary Workers; States Cutting Employee Hours To Avoid Obama Care Costs; Americans Who Voted For Obama Now Seeing Weekly Job Hours Slashed Below 30 As Obamacare Kicks In. Particularly embarrassing among these reports include the recent report that even a call center hired by the Administration to help promote enrollment coverage offered through the Obamacare-created exchanges is limiting the hours its employees can work to under 30 hours per week. ObamaCare Call Center To Keep Employees Under 30 Hours/Week.
As businesses already struggling to deal with a tough economy moved to minimize the number of their full-time employees, even labor unions that originally supported Obamacare joined the cry for reform of its provisions to mitigate employment losses resulting from employer efforts to minimize Code Section 4980H exposures. See Companies Cut Hours Of Full-Time Employees To Avoid Providing Health Care Under New Rules.
S. 1188/H.R. 2575 Would Make Full-Time Mean 40 Hours Per Week
Prompted by growing concern about the apparent adverse impact of Obamacare on job opportunities for hourly workers, legislation now is pending in both the House and Senate to amend the Obamacare’s definition of “full-time.” In June, Senators Susan Collins (R-ME) and Joe Donnelly (D-IN) Collins introduced a bill to amend Code Section 4980H to change the definition of full-time employee for purpose of the shared responsibility provisions of Obamacare, S. 1188: Forty Hours Is Full Time Act to change the definition of “full-time” from 30 to 40 hours per week and the number of hours counted toward a “full-time equivalent” employee to 174 hours per month. Representative Todd Young (R-IN) then introduced a similar provision in the House on June 28, 2013, H.R. 2575, Save American Workers Act of 2013.
H.R. 2575 has garnered the support of 144 Cosponsors. H.R. 2575. Following its introduction, the House assigned H.R. 2575 to the House Ways and Means Committee, whose members now must decide when and if the bill will advance in the House. Key members of the House Ways and Means Committee who will make this decision on include the following Committee Members: Dave Camp; Sander Levin; Charles Boustany Jr.; Kevin Brady (Chair, Subcommittee on Health); Sam Johnson; Devin Nunes; David Reichert (Chair, Subcommittee on Human Resources); Patrick “Pat” Tiberi; Xavier Becerra; Diane Black Earl Blumenauer; Vern Buchanan; Joseph Crowley; Danny Davis; Lloyd Doggett; Jim Gerlach; Tim Griffin; Lynn Jenkins; Mike Kelly; Ron Kind; John Larson; John Lewis; Kenny Marchant; Jim McDermott; Richard Neal; Bill Pascrell Jr.; Erik Paulsen; Tom Price; Charles Rangel; Tom Reed II, James Renacci; Peter Roskam; Paul Ryan; Aaron Schock; Allyson Schwartz; Adrian Smith; Linda Sánchez; Mike Thompson; and the Bill’s sponsor, Todd Young.
Although introduced before H.R. 2575, S. 1188 to date has drawn less interest among members of the Senate. The Senate referred S. 1188 to the Senate Finance Committee, where to date, that Committee has not taken any further action. It presently has 8 cosponsors, 7 of which are Republicans. See S. 1181 Cosponsors. With Democrats the Majority Party in the Senate, many expect the bill to require significant public pressure and support for the Committee to report the bill out from the Committee, which presently is Chaired by Democrat Max Baucus. Other Senate Finance Committee members include Orrin Hatch; Michael Bennet; Sherrod Brown; Robert “Bob” Casey Jr.; John “Jay” Rockefeller IV; Debbie Stabenow; Ron Wyden; Richard Burr; Maria Cantwell; Benjamin Cardin; John Cornyn; Michael Crapo; Michael Enzi; Charles “Chuck” Grassley; John “Johnny” Isakson; Robert “Bob” Menéndez; Bill Nelson; Robert “Rob” Portman; Pat Roberts; Charles Schumer; John Thune; and Patrick “Pat” Toomey.
This past weekend, S. 1188’s sponsor, Maine Senator Susan Collins sought to beef up support for the bill. In urging support for her bill, Senator Collins said the health care law’s 30-hour per week definition kills jobs. “Obamacare is actually discouraging small businesses from creating jobs and hiring new employees,” she said. “The law also has perverse incentives for employers to reduce the number of hours that their employees can work.”
How To Contact Key Committees To Show Support or Share Other Feedback
Individuals wishing to share their support or other input about S. 1181 with the Senate Finance Committee can call (202) 224-4515 or send their written input to the Senate Committee on Finance members via fax to (202) 228-0554.
Support or other input on H.R. 2575 should be sent via fax to House Ways & Means Committee members via fax to (202) 225-2610 or by calling the Committee office at (202) 225-3625.
Committee members and other members of Congress also generally can be contacted via e-mail through the link provided on each member’s webpage. Because security precautions generally delay delivery of mail to members of Congress for 7-10 days, concerned individuals generally are encouraged to contact the Committee or other members of Congress via fax or e-mail.
Stay In Touch & Join The Discussion On Health Care Reform
Want to stay in touch with the latest developments on health care reform and get involved with helping to share meaningful improvements in U.S. health care and workforce policy and our health care and health care insurance system? The Coalition For Responsible Health Care Policy provides a resource that concerned Americans can use to share, monitor and discuss the Health Care Reform law and other health care, insurance and related laws, regulations, policies and practices and options for promoting access to quality, affordable healthcare through the design, administration and enforcement of these regulations. We also encourage you to participate in our Project COPE: Coalition for Patient Empowerment initiative here to share ideas, discuss issues, and access and share tools and other resources.
For Help or More Information
If you need help monitoring or providing input on this legislation or to understand and respond to these or other legislation, laws and regulations, or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
- IRS Releases Updated Healthcare Law Online Resources Publication
- IRS Extends Remedial Amendment On Cycle Opinion Deadline For Some Defined Benefit Plans
- Self-Dealing Or Other Mishandling of Employee Benefit Plan Funds Risky For Fiduciaries & Those Appointing Them
- Employers & Insurers Reminded Of July 31 Deadline To Pay New ACA-Required PCORI Fees
- Use New Government Health Care Reform Resources With Care
- OCR Warns Others Learn From WellPoint’s $1.7 M HIPAA Settlement
- “Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines
- HHS Continues Preparations For New Health Insurance Marketplace By Awarding Grants To Promote Kids Enrollment
- HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns
- HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce
- Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- CMS Publishes FY 2014 Final Inpatient Rehabilitation Facility Prospective Payment Rule
- Tighten Disability Compliance To Avoid ADA Suits, Program Disqualification & Other Risks
- Doc Caught Submitting Conflicting Patient Records to Private Payer Versus Medicare Criminally Sentence, Pays Civil Settlement
- OCR To Covered Entities: Learn From WellPoint $1.7 Settlement
- Improper Billing Of Private Payers Increasing Source Of Liability & Risk For Providers
- Ambulatory Care Orgs Face New Joint Commission Standards Beginning January 1, 2014
- Hollywood Pavillion & Other Fraud Convictions Show Individuals Risk Prison Time For Health Care Fraud Involvement
- 55 Hospitals To Pay $35M+ To Settle FCA Claims Charges On Kyphoplasty Procedures
- Whistleblower Collects $2.7 M of $14.5M Sound Inpatient Physicians Overbilling Settlement
- OIG Urges CMS To Step Up Efforts To Recover “Overpayments”
- HHS Continues Preparations For Health Care Marketplace By Awarding $32M Of Grants To Up CHIP & Medicaid Enrollment
- Hospital Pay $275K To Settle HIPAA Charges After Sharing PHI With Press, Workforce In Response To Fraud Reports
- OCR Makes Technical Corrections To HIPAA Omnibus Final Rule; September 2013 Enforcement Deadline Looming
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- IRS Witholding Calculator Can Help Avoid Over & Underwithholding
- Responding To West, Texas, Boston & Other Tragedies: Information and Reassurance Resources
- Justice Department Charges Employer, Pension Plan With Violating USERRA Reemployment Rights
- Administration Proposes To Let PBGC Board Set Premiums In Effort To Shore Up Finances
- Administration Proposes Expanding Eligibility, Simplifying Small Employer Health Care Tax Credit
- Health Care Transparency Effectiveness & Value Depends On Data Quality, Understanding & Awareness
- Test Your Health Care Reform Knowledge On 3rd Anniversary of Reform Passage
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- OCR Plans To Survey Health Plans, Other Covered Entities Hit With HIPAA Audits in 2012
- Businesses Urged To Strengthen Their Worker Classification Defenses As IRS, Other Agencies Step Up Audits & Enforcement
- Alert Employees Claiming Qualified Adoption Expenses and Education Credits About Changed IRS Procedures
- 13 Employer Tips For Coping With Health Care Reform Now!
- Sequester Will Cut ACA Small Businesses Health Care Tax Credits
For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved
1 Comment |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: 4980H, ACA, Afffordable Care Act, Health Care Reform, health reform, Pay or Play |
Permalink
Posted by Cynthia Marcotte Stamer
July 26, 2013
Employers sponsoring self-insured group health plans and insurers are reminded that the deadline to report and pay the fee new fees required by the Patient Protection and Affordable Care Act (ACA) to help fund the Patient-Centered Outcomes Research Institute (PCORI) is July 31, 2013.
The PCORI fee, required to be reported annually on the second quarter Form 720 and paid by its due date, July 31, is based on the average number of lives covered under the policy or plan. The annually required PCORI fee applies to policy or plan years ending on or after October 1, 2012, and before October. 1, 2019.
The PCORI fee is just one of a number of new fees and costs that ACA imposes upon employers and individuals as part of the health care reforms enacted under ACA.
Employers of more than 50 full-time employees recently received a temporary retrieve from another of these looming potential fees, the employer “shared responsibility” payment that ACA added to the Internal Revenue Code (Code) under new Code Section 4980H.
Earlier this month, the Internal Revenue Service (IRS) announced that it will delay until 2015 enforcement of the employer shared responsibility or “pay-or-play” rules of Code Section 4980H. See July 2 Blog and Notice 2013-45. Slated prior to the delayed enforcement announcement to take effect January 1, 2014, the employer shared responsibility rules generally will require employers which individually or collectively with other commonly controlled or affiliated employers employee 50 or more full-time employees that do not offer group health coverage that meets the minimum essential coverage, minimum value and affordability standards of the Affordable Care Act to pay an “assessment” that the Supreme Court ruled last year to be a tax, as well as to comply with certain reporting requirements.
While Notice 2013-45 gives large more time to prepare to comply with Code Section 4980H, it provides no relief from the obligation to pay the PCORI fee or from other group health plan mandates imposed by ACA or other applicable federal laws. Consequently, as businesses continue to prepare for the delayed implementation of Code Section 4980H in 2015, they also need to ensure that they timely pay any required PCORI fees and meet other applicable federal group health plan mandates as they continue to diligently prepare to deal with Code Section 4980H.
While businesses work to meet current and impending federal health plan responsibilities, most business leaders also will want to continue to closely monitor and provide regular input to members of Congress and regulators on proposed regulatory and enforcement guidance and potential Congressional amendments to the Affordable Care Act or other health care or tax policy reforms.
For Help or More Information
If you need help with preparing these or other ACA compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
- HHS Continues Preparations For New Health Insurance Marketplace By Awarding Grants To Promote Kids Enrollment
- HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns
- HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce
- Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- IRS Witholding Calculator Can Help Avoid Over & Underwithholding
- Responding To West, Texas, Boston & Other Tragedies: Information and Reassurance Resources
- Justice Department Charges Employer, Pension Plan With Violating USERRA Reemployment Rights
- Administration Proposes To Let PBGC Board Set Premiums In Effort To Shore Up Finances
- Administration Proposes Expanding Eligibility, Simplifying Small Employer Health Care Tax Credit
- Health Care Transparency Effectiveness & Value Depends On Data Quality, Understanding & Awareness
- Test Your Health Care Reform Knowledge On 3rd Anniversary of Reform Passage
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- OCR Plans To Survey Health Plans, Other Covered Entities Hit With HIPAA Audits in 2012
- Businesses Urged To Strengthen Their Worker Classification Defenses As IRS, Other Agencies Step Up Audits & Enforcement
- Alert Employees Claiming Qualified Adoption Expenses and Education Credits About Changed IRS Procedures
- 13 Employer Tips For Coping With Health Care Reform Now!
- Sequester Will Cut ACA Small Businesses Health Care Tax Credits
For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved
Comments Off on Employers & Insurers Reminded Of July 31 Deadline To Pay New ACA-Required PCORI Fees |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: 4980H, ACA, Afffordable Care Act, Health Care Reform, health reform, Pay or Play |
Permalink
Posted by Cynthia Marcotte Stamer
July 22, 2013
While large employers are getting an additional year to collect data and make other preparations to comply with the “pay-or-play” rules in the shared responsibility provisions of new Internal Revenue Code Section 4980H under the extension announced by the Administration in early July, all employers still have much to do stay on top of the developing rules and make the arrangements necessary to prepare to comply with the current and 2014 federal health plan mandates of the Patient Protection & Affordable Care Act (ACA) and other federal laws.
As the Departments of Health & Human Services, Labor and Treasury continue to refine and roll out guidance implementing these rules, the agencies recently released various updated resources discussing these evolving rules. Among others, Publication 5093, Healthcare Law Online Resources, lists ACA resources from the IRS, the Departments of Health & Human Services and Labor, and the Small Business Administration. Meanwhile, IRS.gov and HealthCare.gov also have new ACA webpages.
While these updated resources are intended by the agencies to help acquaint businesses with ACA’s requirements, businesses and the insurers and administrators that offer health benefit services need to keep in mind that these resources have risk and limitations. As the agencies are continuing to refine the rules, these resources often do not reflect the most current or emerging guidance or status of rules. Additionally, government provided explanations, model forms and resources often incorporate provisions or interpretations that are biased against the interests of the businesses, or contain other provisions that may not fully inform the business to all of its options. Furthermore, because of limitations in jurisdiction and other constraints, guidance issued by an agency or agency that reflects that certain approaches may satisfy the requirements of the rules specifically addressed by the guidance often do not disclose or adequately communicate potential concerns with certain types of actions under other applicable requirements.
For instance, model exchange notices published by the Department of Labor this Spring to assist employers to provide the notifications about federal exchange coverage options that ACA requires employers distribute by October 1 contain many provisions beyond the content actually required to meet the notice requirements. The Labor Department in announcing the model notices indicated that its model language includes discretionary provisions which the Department thought some employers might want to include to minimize questions from employees about employer provided benefits that employees interested in pursuing subsidized coverage could be expected to need to apply for subsidies. While as of now, exchanges and subsidies still are scheduled to come on line January 1, 2014, the Obama Administration extended the employer “pay-or-play” mandate of Code Section 4980 and its associated employer reporting requirements, as well as has established that it does not plan to verify eligibility for subsidies requested by individuals enrolling in exchanges in 2014. Given this, most employers will want to consider carefully the specific content that they wish to include in the exchange notice as they prepare the notice in anticipation of its distribution in October.Accordingly, all businesses dealing with these issues are encouraged to arrange for comprehensive advice from qualified legal counsel familiar with these requirements and other related human resources, health care, insurance and employee benefit issues.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
“Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Use New Government Health Care Reform Resources With Care |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
July 12, 2013
WellPoint $1.7 M HIPAA Settlement Expensive Lesson On HIPAA Risks Of Leaving PHI Too Accessible In Web-Based Applications
As health plans and health care organizations increasingly jump on the Web-based application bandwagon, managed care company WellPoint Inc. (WellPoint) is learning a $1.7 million lesson about the importance of ensuring Web-based applications and portals that allow access to members or other consumers protected health information (PHI) have the administrative, technical and other security safeguards required by the Health Insurance Portability & Accountability Act (HIPAA) Privacy and Security rules.
The U.S. Department of Health and Human Services (HHS) Office of Civil Rights (OCR) announced late yesterday (July 11, 2013) that WellPoint has agreed to pay $1.7 million to settle OCR charges that WellPoint violated the HIPAA Security Rule and left the electronic protected health information (ePHI) of 612,402 individuals accessible to unauthorized individuals over the Internet by failing to implement appropriate administrative and technical safeguards in its Web-based applications. See WellPoint HIPAA Settlement Press Release.
Web-based application use is increasingly popular among health plans and their wellness programs, as well as health care providers. Employers and health plans use them both in plan administration and offer them to members to use as member tools. Health care providers use them for health care operations, as well as patient engagement and communication tools. The WellPoint settlement illustrates that managed care and other health insurers, health plans and their employer or other sponsors, health care providers, health care clearinghouses (Covered Entities) and their business associates can’t let their enthusiasm for the ease of use of these products to compromise the security of PHI.
Rather, health plans and other Covered Entities, employer and other health plan sponsors, their business associates, and the Web and other technology developers, providers and consultants marketing products, services or other solutions should learn from WellPoint’s hard lesson by ensuring that current and future Web-based applications, portals and other information system components that are or could be used to provide access to PHI incorporate the Security Rule safeguards both when originally implemented and with each subsequent upgrade.
HIPAA Privacy, Security & Breach Notification Rules Require PHI Safeguards & Other Protections
The Breach Notification Rule added to HIPAA under the Health Information Technology for Economic and Clinical Health, or HITECH Act requires HIPAA-covered entities to notify OCR, affected individuals and the media promptly of a breach of “unsecured protected health information” (UPHI) impacting more than 500 individuals. For smaller breaches, the Breach Notification Rule still requires prompt notice to affected individuals, but allows Covered Entities to disclose the breach to OCR as part of an annual breach report and to forego notification to the media. UPHI generally includes any PHI, whether or not ePHI that is not either secured or destroyed in the way described by the Breach Notification Rules.
In addition to the Breach Notification Rule, most Covered Entities and their business associates also are subject to state laws or regulations that impose similar or additional breach notification and other standards and responsibilities on the protection of personal health or other data including required notification and other responses following a breach of the security of UPHI or other PHI.
WellPoint’s $1.7 HIPAA Security Mistake
WellPoint’s $1.7 million settlement lesson resulted from an OCR investigation started in response to a breach report WellPoint submitted to comply with the Breach Notification Rules.
According to OCR, the Breach Report indicated that security weaknesses in an online application database left the electronic protected health information (ePHI) of 612,402 individuals accessible to unauthorized individuals over the Internet.
OCR says its investigation indicated that WellPoint did not implement appropriate administrative and technical safeguards as required under the HIPAA Security Rule. According to OCR, WellPoint did not:
- Adequately implement policies and procedures for authorizing access to the on-line application database;
- Perform an appropriate technical evaluation in response to a software upgrade to its information systems; or
- Have technical safeguards in place to verify the person or entity seeking access to electronic protected health information maintained in its application database.
As a result, OCR concluded that from October 23, 2009 until March 7, 2010, WellPoint impermissibly disclosed the ePHI of 612,402 individuals by allowing access to their ePHI maintained in the application database. This data included names, dates of birth, addresses, Social Security numbers, telephone numbers and health information.
Under the resulting WellPoint HIPAA Resolution Agreement, WellPoint must pay OCR a $1.7 million settlement payment as well as take a series of corrective actions to correct the deficiencies in its policies and practices that resulted in the reported breach to minimize future risks of breaches resulting from these deficient.
OCR Warns Learn From WellPoint’s Experience
All Covered Entities and their business associates and leaders should heed the lesson sent to them by OCR in announcing the WellPoint settlement and take appropriate steps other to ensure that appropriate policies and safeguards are adopted and applied in selecting and implementing future application or system upgrades, as well as review existing systems to ensure that the security of existing systems and applications have incorporated and apply the requisite safeguards.
OCR made clear that the WellPoint settlement is intended to send a message to Covered Entities and their business associates to ensure that these steps are appropriately taken. The settlement announcement states:
This case sends an important message to HIPAA-covered entities to take caution when implementing changes to their information systems, especially when those changes involve updates to Web-based applications or portals that are used to provide access to consumers’ health data using the Internet. Whether systems upgrades are conducted by covered entities or their business associates, HHS expects organizations to have in place reasonable and appropriate technical, administrative and physical safeguards to protect the confidentiality, integrity and availability of electronic protected health information – especially information that is accessible over the Internet.
The settlement announcement also reminds business associates that OCR will begin holding them directly accountable along with their Covered Entity clients for complying with many HIPAA requirements beginning in September, stating:
Beginning Sept. 23, 2013, liability for many of HIPAA’s requirements will extend directly to business associates that receive or store protected health information, such as contractors and subcontractors.
Take Documented Steps To Show You Hear OCR’s Messages
Covered entities and their business associates and leaders, and vendors and consultants offering services or products to them should take care to conduct careful and well-documented reviews and implement corrective actions necessary to show their applications and systems, policies and practices reflect their strong commitment and action to appropriately protect PHI in accordance with the expectations shown by the WellPoint HIPAA Resolution Agreement and other OCR settlements, OCR’s updated HIPAA regulations, and other OCR and industry information.
In addition to the guidance set forth in OCR’s Resolution Agreements with WellPoint and other Covered Entities, revisions to OCR’s Privacy and Security Rules in OCR’s 2013 restatement of its regulations here cause all Covered Entities and their business associates conduct a well-documented reassessment of the adequacy of their existing policies, systems and practices and steps taken to redress any uncovered gaps.
Among other things, the 2013 Regulations:
- Revise OCR’s HIPAA regulations to reflect the HITECH Act’s amendment of HIPAA to add the contractors and subcontractors of health plans, health care providers and health care clearinghouses that qualify as business associates to the parties directly responsible for complying with and subject to HIPAA’s civil and criminal penalties for violating HIPAA’s Privacy, Security, and Breach Notification rules;
- Update previous interim regulations implementing HITECH Act breach notification rules that require Covered Entities including business associates to give specific notifications to individuals whose PHI is breached, HHS and in some cases, the media when a breach of unsecured information happens;
- Update interim enforcement guidance OCR previously published to implement increased penalties and other changes to HIPAA’s civil and criminal sanctions enacted by the HITECH Act;
- Implement HITECH Act amendments to HIPAA that tighten the conditions under which Covered Entities are allowed to use or disclose PHI for marketing and fundraising purposes and prohibit Covered Entities from selling an individual’s health information without getting the individual’s authorization in the manner required by the 2013 Regulations;
- Update OCR’s rules about the individual rights that HIPAA requires that Covered Entities to afford to individuals who are the subject of PHI used or possessed by a Covered Entity to reflect tightened requirements enacted by the HITECH Act that allow individuals to order their health care provider not to share information about their treatment with health plans when the individual pays cash for the care and to clarify that individuals can require Covered Entities to provide electronic PHI in electronic form;
- Revise the regulations to reflect amendments to HIPAA made as part of the Genetic Information Nondiscrimination Act of 2008 (GINA) which added genetic information to the definition of PHI protected under the HIPAA Privacy Rule and prohibits health plans from using or disclosing genetic information for underwriting purposes; and
- Clarifies and revises other provisions to reflect other interpretations and information guidance that OCR has issued since HIPAA was passed and to make certain other changes that OCR found appropriate based on its experience administering and enforcing the rules.
Covered Entities were required to begin complying with most of these rule changes earlier this year. However, delayed compliance dates in the 2013 Regulations allowed Covered Entities and Business Associates to delay updates to pre-existing business associate agreements and the date that OCR would begin enforcing many of the HIPAA Rules directly against business associates to September 23, 2013.
Even without the necessity Settlements like that involving WellPoint, these 2013 Regulations make it imperative that Covered Entities to take the necessary steps to conduct an appropriate and well-documented review and update as needed their systems, policies and practices, business associate agreements, training and documentation.
With self-disclosures of breaches mandated by the Breach Notification Rules and OCR audits and enforcement rising, careful documentation of these activities and its analysis is necessary so that Covered Entities can be in a position to show OCR that the risk assessments required by the Security Rules was conducted as well as the efforts and commitment of the Covered Entity or business associate in the event of a breach investigation or audit. Yesterday’s WellPoint HIPAA announcement is just the latest in an ever-growing list of examples of the expensive consequences that can result if a Covered Entity or business associate cannot produce this documentation in response to an OCR audit or investigation. See, e.g. OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website; Providence To Pay $100000 & Implement Other Safeguards. In contrast, the OCR website also provides a multitude of examples showing how the ability to produce documentation and other evidence showing diligent efforts to comply has helped other covered entities that fall under OCR investigation to avoid or mitigate serious sanctions.
Coupled with statements by OCR about its intolerance, the WellPoint and other settlements provide a strong warning to covered entities of the need to carefully and appropriately manage their HIPAA encryption and other Privacy and Security responsibilities. Covered entities are urged to heed these warning by strengthening their HIPAA compliance and adopting other suitable safeguards to minimize HIPAA exposures.
In response to the 2013 Regulations and these expanding exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions against WellPoint and others, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. Covered Entities and business associates should document this review in a manner that both reflects the scope and diligence of their activities including relevant considerations and decision-making about identified potential susceptibilities and reasoning about the adequacy of safeguards and other solutions.
Because this review is likely to uncover existing or past deficiencies or breaches, most covered entities and business associates will want to discuss with qualified legal counsel the planned assessment within the scope of attorney-client privilege to understand when and how to conduct the assessment to preserve options to claim attorney-client privilege to protect sensitive work product or discussions that may result in the course of the investigation within the attorney-client communication, work product or other evidentiary privileges, evaluation of the adequacy and appropriateness of the audit and resulting investigations and its documentation, and other assistance in strengthening the defensibility of compliance and risk management activities.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
“Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
1 Comment |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
July 11, 2013
The Internal Revenue Service (IRS) yesterday (July 10, 2013) shared its first “formal” guidance officially implementing the Obama Administration’s decision to delay until 2015 enforcement of certain of the employer shared responsibility or “pay-or-play” rules of new Internal Revenue Code (Code) Section 4980H first informally announced by Department of Treasury Assistant Secretary for Tax Policy Mark Mazar in this July 2 Blog.
Notice 2013-45 outlines the specific “transition relief” rules under which the IRS says it will forego during 2014 enforcement of the employer shared responsibility penalty tax rules and associated and information reporting requirements that are slated to take effect for single employers or groups of commonly controlled or affiliated employers that employ 50 or more full-time employees (Large Employers) beginning January 1, 2014 as part of the sweeping health care reforms enacted under the Patient Protection and Affordable Care Act (Affordable Care Act). Even with the extension of time allowed by Notice 2013-45 to prepare to comply with Code Section 4980H, however, employers and insurers have much to do to prepare.
The first priority for employers wishing to take advantage of added time to comply with Affordable Care Act’s pay or play penalty to maximize their planning opportunities and to minimize their potential Code Section 4980H consequences should be to clean up worker classifications, to track all hours worked for all employees and collect all other relevant employee data.
Notice 2013-45 Confirms IRS Won’t Enforce Code Section 4980H In 2014
The transitional relief in Notice 2013-45 comes as businesses have struggled to understand and come to grips with the requirements of new Internal Revenue Code Section 4980H that beginning January 1, 2014, a Large Employer calculate and pay the applicable “assessable payment” tax under Section 4980H for each month that it fails to offer each full-time employee group health plan coverage meeting Code Section 4980H’s “minimum essential coverage,” “minimum value” and “affordability standards” if any full-time employee receives a subsidy for enrolling in coverage through a health insurance exchange.
Specifically, Notice 2013-45 waives IRS enforcement only for 2014 and only of:
- The information reporting requirements applicable to insurers, self-insuring employers, and certain other providers of minimum essential coverage (MEC) under Code Section 6055 (6055 Reporting);
- The information reporting requirements applicable to applicable large employers under Code Section 6056 (6056 Reporting); and
- The obligation to pay tax penalties under the employer shared responsibility provisions under Code Section 4980H (4980H Tax).
This relief is limited in both scope and duration. Notably, Notice 2013-58 states:
- Its provisions have no effect on the effective date or application of the multitude of other new mandates that have or will kick in coming months in connection with the impending 2014 Affordable Care Act reforms; and
- The IRS plans that the tax penalty provisions of Code Section 4980H and the information reporting requirements of Code Sections 6055 and 6056 “will be fully effective for 2015.”
While the IRS is promising in Notice 2013-45 that the IRS will not require any payments by any employer under Code Section 4980H for 2014, it also urges Large Employers other affected entities to prepare for 2015 by voluntarily complying with the information reporting provisions (once the information reporting rules have been issued) in 2014 including conducting “real-world testing of reporting systems and plan designs” and continuing employer-provided coverage.
Relief Leaves Large Employers & Other Employers With Much Work To Do
While Notice 2013-45 gives Large Employers more time to prepare to comply as well as to communicate with the IRS about the need and options for simplification, employers should continue to aggressively prepare for compliance. The IRS says it intends to fully enforce the rules against Large Employers beginning in 2015 and to implement other Affordable Care Act provisions. Consequently, employers that know or question if they may be Large Employers, their insurers, service providers and advisors should continue to diligently prepare to deal with Code Section 4980H, as well as other federal health plan rules. Accordingly, Large Employers, their insurers and advisors could continue to diligently prepare to prepare to manage their impending Code Section 4980H responsibilities and liabilities.
1. Start With Worker Classification, Time & Income Data Collection & Recordkeeping
Employers wishing to use this reprieve to their best advantage should start by ensuring that they clean up and tighten their worker classification and time tracking practices. This should start with auditing the classification of all workers providing services as employees, contractors or otherwise to be sure that they are properly classified. Code Section 4980H takes into account all workers who are under they facts and circumstances test applied by the Code “common law employees” for purposes of deciding what employers are covered by Code Section 4980H and calculating the penalties, if any owning. Many businesses mistakenly fail to recognize a wide range of workers considered by the business to work as contractors, leased employees or in other capacities are likely to be considered by the IRS to be common law employees for purposes of these rules. Ensuring that the business has properly accounted for all workers that the IRS is likely to view as common law employees is essential to any reliable planning or cost projection.
Beyond having an appropriate understanding of what individuals are considered common law employees, businesses also should seek to track accurately all hours worked, regardless of whether the employees are non-exempt workers that the Fair Labor Standards Act (FLSA) requires the employer pay hourly, or exempt employees under the FLSA that the employer pays on a salaried, commission or other non-hourly basis. Under existing Code Section 4980H rules, employers that don’t have accurate time records for employees must rely upon safe-harbor rules for identifying workers that are considered full-time. These safe harbor rules credit hours in such a way that tends to overstate the number of full-time employees and full-time equivalent employees.
In workforces where many employees many receive significant additional family income from the earnings of a spouse, another job or other sources, employers also may want to add processes to verify actual household adjusted gross income (HAGI) for purposes of identifying which of its full-time employees, whose HAGI actually is below the 400 percent of the poverty level required to qualify to receive subsidies when enrolling in coverage through a Health Insurance Exchange.
2. Other To Dos
Other helpful preparations also generally will include:
- Seeking and monitoring developing guidance about the meaning of minimum essential coverage and other associated rules;
- Providing meaningful input to the IRS, the Department of Health & Human Services, Congress and others on the need for and options to simplify time and other data and reporting requirements, employer interactions and data requests for verification of exchange subsidy eligibility and other purposes;
- Evaluating and adjusting workforce and benefit practices, time and other record keeping systems, and plan designs;
- Evaluating workflow and staffing practices to determine the potential advantages of using certain measurement, stability or administrative periods, safe harbors and other options for purposes of applying Code Section 4980H, making changes in workforce or staffing practices, redesigning benefits or other adjustments; and
- Working with management, vendors and others to identify and change plan designs; and
- Completing other preparations to cope with the rules.
While continuing these preparations to comply with Code Section 4980H in 2015, Large Employers as well as other businesses also need to get busy finalizing preparations for the upcoming 2014 plan year, particularly in the face of fast approaching notice deadlines. Employers are under the gun to finalize and implement plan design, vendor and other decisions and complete other preparations to prepare and deliver these and other materials on time, updated in time to meet new or revised federal health plan requirements under the Affordable Care Act and other laws. The impending Affordable Care Act-imposed deadlines to deliver newly mandated exchange notices by October 1 and updated “Summaries of Benefits and Coverage” or “SBCs” by the beginning of their next enrollment period significantly shortens the time for employers to finalize their plan designs. Under existing SBC rules, employers that amend their plans after the beginning of an annual enrollment period must update and resend SBCs to plan members. Furthermore, Federal rules also now generally require health plan administrators provide 60 days advance notice to plan members of plan amendments that materially reduce coverage or benefits. Therefore all employers regardless of size will want to ensure that their plans and associated contracts are finalized quickly to adequately meet these requirements without incurring the added expense of updating and redistributing their SBCs.
As part of these efforts, all businesses generally should act quickly and diligently to:
- Carefully credential and contract with insurers, administrators, consultants and other plan service providers and advisors to document expectations and commitments about compliance, quality assurance, fiduciary and other responsibility and status, indemnification and other accountability and other matters including updated business associate commitments where required to comply with recently changes in the privacy rules of the Health Insurance Portability & Accountability Act generally required no later than September 24, 2013 for all existing plan business associates);
- Audit within the scope of attorney-client privilege all existing employee and alternative workforce arrangements and patterns to confirm that all common law employees properly are identified and classified and that appropriate arrangements are in place to track and document time and other relevant information to position the business reliably its responsibilities and defend its action for Code Section 4980H and other federal health plan, Fair Labor Standards Act and other compliance purposes;
- Consult with legal counsel within the scope of attorney-client privilege about any legally required or otherwise desired adjustments to worker classification or other workforce practices to minimize Affordable Care Act or other liabilities;
- Finalize decisions about what health benefits, if any that their business will offer to what employees in the upcoming plan years and carefully contract with vendors, update plan documents, the SBCs, summary plan descriptions and other materials for the upcoming plan year before the first day of the next enrollment period;
- Carefully amend and update plan documents, summary plan descriptions, SBCs, privacy practices notices and other required notices, communications and forms to the extent possible, before the upcoming enrollment period to minimize inconsistencies, and to be able to package required notices, summary plan descriptions and other communication and enrollment materials to take advantage of the opportunity to minimize distribution expenses;
- Complete the necessary decisions and arrangements to prepare and send the exchange notice that the Affordable Care Act requires be delivered for the first time by October 1, 2013; and
- Finalize other preparations for the upcoming plan year.
Monitor & Provide Input On Proposed Tax & Health Care Reform
While businesses work to meet current and impending federal health plan responsibilities, most business leaders also will want to continue to closely monitor and provide regular input to members of Congress and regulators on proposed amendments to the Affordable Care Act or other health care or tax policy reforms.
Despite a projected $ 5 billion reduction in federal budget revenue from non-enforcement of Code Section 4980H in 2014, the Administration is moving ahead aggressively to implement other Affordable Care Act reforms as scheduled. Notice 2013-45 states that the Administration plans to continue to provide subsidies pursuant to the Affordable Care Act for individuals earning less than 400% of the Federal poverty level who enroll in health coverage through a Health Insurance Exchange, which the Administration has rebranded and now refers to as “Marketplaces.” Furthermore, the Administration separately announced on July 5, 2013 that individuals will be allowed to apply for and claim these subsidies based on an “honor system” in 2014; the Administration will not require verification of eligibility.
Even before the IRS announced the relief now formalized by Notice 2013-45, the rising federal budget costs of the Affordable Care Act was fueling concern. In March, the General Accounting Office (GAO) reported that after having already spent more than $394 million on exchange efforts, the Obama administration needs Congress to approve an extra $1.5 billion added to the budget to cover the additional $2 billion that the GAO projects the Administration will need over the next fiscal year to create and run the federal exchanges. See GAO Report and GAO Report. Foregoing enforcement of Code Section 4980H, verification of subsidy eligibility and other unexpected costs resulting from glitches in the preparation and rollout of the Affordable Care Act reforms for 2014 are adding to the growing costs and projected budgetary impact of the Affordable Care Acts on the federal budget. With existing budget shortfalls already fueling pressure for increased tax revenues, businesses and individuals concerned about tax liability will want to carefully monitor and provide input to Congressional leaders on health care and tax reform.
For Help or More Information
If you need help with preparing these or other ACA compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
- HHS Continues Preparations For New Health Insurance Marketplace By Awarding Grants To Promote Kids Enrollment
- HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns
- HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce
- Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- IRS Witholding Calculator Can Help Avoid Over & Underwithholding
- Responding To West, Texas, Boston & Other Tragedies: Information and Reassurance Resources
- Justice Department Charges Employer, Pension Plan With Violating USERRA Reemployment Rights
- Administration Proposes To Let PBGC Board Set Premiums In Effort To Shore Up Finances
- Administration Proposes Expanding Eligibility, Simplifying Small Employer Health Care Tax Credit
- Health Care Transparency Effectiveness & Value Depends On Data Quality, Understanding & Awareness
- Test Your Health Care Reform Knowledge On 3rd Anniversary of Reform Passage
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- OCR Plans To Survey Health Plans, Other Covered Entities Hit With HIPAA Audits in 2012
- Businesses Urged To Strengthen Their Worker Classification Defenses As IRS, Other Agencies Step Up Audits & Enforcement
- Alert Employees Claiming Qualified Adoption Expenses and Education Credits About Changed IRS Procedures
- 13 Employer Tips For Coping With Health Care Reform Now!
- Sequester Will Cut ACA Small Businesses Health Care Tax Credits
For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved
1 Comment |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: 4980H, ACA, Afffordable Care Act, Health Care Reform, health reform, Pay or Play |
Permalink
Posted by Cynthia Marcotte Stamer
July 2, 2013
As part of its continuing efforts to promote enrollment in the Health Insurance Marketplace slated to take effect January 1, 2014, the Department of Health and Human Services (HHS) today (July 2, 2013) announced the award of nearly $32 million in grants for efforts to identify and enroll children eligible for Medicaid and the Children’s Health Insurance Program (CHIP). The Connecting Kids to Coverage Outreach and Enrollment Grants were awarded to 41 state agencies, community health centers, school-based organizations and non-profit groups in 22 states; two grantees are multistate organizations. The announcement comes as employers and others continue to express concern about the sufficiency of preparations and HHS’ recent rollout of online tools to aid consumers enroll in the new Health Care Marketplace scheduled to launch January 1, 2014 as part of the continuing implementation of reforms enacted as part of the Patient Protection & Affordable Care Act (Affordable Care Act).
Announced Grants Target Increased CHIP & Medicaid Enrollment In Preparation For Health Care Marketplace
In amounts ranging from $190,000 to $1 million out of the $140 million included in the Affordable Care Act and the Children’s Health Insurance Program Reauthorization Act (CHIPRA) of 2009 for enrollment and renewal outreach, HHS Reports the grants awarded to the grantees listed here focus on 5 areas:
- Engaging schools in outreach, enrollment and retention activities (9 awards);
- Reducing health coverage disparities by reaching out to subgroups of children that are less likely to have health coverage (8 awards);
- Streamlining enrollment for individuals participating in other public benefit programs such as nutritional or other assistance programs (3 awards);
- Improving application assistance resources to provide high quality, reliable Medicaid and CHIP enrollment and renewal services in local communities (13 awards); and
- Training communities to help families understand the new application and enrollment system and to deliver effective assistance to families with children eligible for Medicaid or CHIP (8 awards).
According to HHS, the grants will build on the Secretary’s Connecting Kids to Coverage Challenge to find and enroll all eligible children and support outreach strategies that have been shown to be successful.
According to HHS, Connecting Kids to Coverage Outreach and Enrollment Grant Awards (Cycle III) Efforts to streamline Medicaid and CHIP enrollment and renewal practices, combined with robust outreach activities, have helped reduce the number of uninsured children. Since 2008, HHS claims 1.7 million children have gained coverage and the rate of uninsured children has dropped to 6.6 percent in 2012
“Today’s grants will ensure that more children across the nation have access to the quality health care they need,” said Secretary Sebelius. “We are drawing from successful children’s health coverage outreach and enrollment efforts to help promote enrollment this fall in Medicaid and the new Health Insurance Marketplace.”
Continuing Preparations For New Health Care Marketplace
The grant awards are part of a much broader effort by HHS to prepare Americans to enroll in the newly reformed Health Insurance Marketplace that the Obama Administration is working to implement as part of the sweeping reforms enacted by the Affordable Care Act.
Enrollment is the Health Insurance Exchanges also to be included in the new federal health care marketplace is scheduled to begin October 1, 2013. In anticipation of this deadline, HHS recently also announced its rollout of new consumer health care education and decision-making tools on its newly designed www.healthcare.gov website.
In announcing its launch of its Health Insurance Marketplace educational tools here on June 24, 2013, the Department of Health & Human Services (HHS) repeated recent claims that HHS and the states are on target to begin enrollment on October 1, 2013 in the federal and state health care exchanges now retitled “Health Insurance Marketplace” by the Administration, to meet other key milestones and to the beginning coverage under the newly created Health Insurance Marketplaces beginning January 1, 2014.
As part of these preparations, HHS kicked off an aggressive Health Insurance Marketplace education effort by announcing the deploying of with newly designed “consumer-focused” HealthCare.gov website and the 24-hours-a-day consumer call center that HHS claims provide all the necessary tools to prepare Americans for open enrollment and ultimately sign up for private health insurance.
While HHS says its tools and other preparations will get the Health Care Marketplaces and Americans ready for the conversion of the U.S. health care system slated to begin January 1, 2014, others are less confident. For instance, GAO officials recently found that major work that federal and state officials must complete to timely begin enrollment by October 1 remains unfinished, making it unclear if they will meet the impending October 1, 2013 enrollment kickoff deadline. See GAO Report and GAO Report.
Meanwhile, employers of 50 or more full-time employees and others also have complained that delayed and incomplete guidance has prevented them from understanding their obligations and moving to complete preparations to comply with the new employer mandates by delaying private market reforms and employer preparations. These problems have been further complicated by recent media coverage and public debate about the access to sensitive personal health care, financial information and the role of the Internal Revenue Service and other government agencies under the Affordable Care Act following recent charges that certain Internal Revenue Service officials improperly targeted certain charitable organization and their organizers as part of application approval and audits.
Despite these concerns, HHS is marching ahead on its efforts to implement the law by launching these and other enrollment and educational outreach.
For Help or More Information
If you need help with preparing these or other Affordable Care Act compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
- HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns
- HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce
- Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- IRS Witholding Calculator Can Help Avoid Over & Underwithholding
- Responding To West, Texas, Boston & Other Tragedies: Information and Reassurance Resources
- Justice Department Charges Employer, Pension Plan With Violating USERRA Reemployment Rights
- Administration Proposes To Let PBGC Board Set Premiums In Effort To Shore Up Finances
- Administration Proposes Expanding Eligibility, Simplifying Small Employer Health Care Tax Credit
- Health Care Transparency Effectiveness & Value Depends On Data Quality, Understanding & Awareness
- Test Your Health Care Reform Knowledge On 3rd Anniversary of Reform Passage
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- Insured “Expatriate Plans” Get Temporary Reprieve From Affordable Care Act Compliance Thru 2015 If Meet Other Health Plan Mandates
- OCR Plans To Survey Health Plans, Other Covered Entities Hit With HIPAA Audits in 2012
- Businesses Urged To Strengthen Their Worker Classification Defenses As IRS, Other Agencies Step Up Audits & Enforcement
- Alert Employees Claiming Qualified Adoption Expenses and Education Credits About Changed IRS Procedures
- 13 Employer Tips For Coping With Health Care Reform Now!
- Sequester Will Cut ACA Small Businesses Health Care Tax Credits
For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved
Comments Off on HHS Continues Preparations For New Health Insurance Marketplace By Awarding Grants To Promote Kids Enrollment |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: ADA, Affordable Care Act, GINA, Group Health plans, Health Care Marketplace, Health Care Reform, Health Insurance Exchange, Health Plans, HIPAA, Privacy, Wellness, Wellness Programs |
Permalink
Posted by Cynthia Marcotte Stamer
June 26, 2013
Despite growing concerns expressed by the General Accounting Office (GAO) and others about arrangements and the need for added funding to prepare for the massive conversion in the U.S. health care system slated to take effect January 1, 2014 under the Patient Protection & Affordable Care Act (“ACA), Obama Administration officials are continuing to claim readiness to begin enrollment of Americans In federal health care marketplace on schedule on October 1, 2013 and to meet other crucial deadlines necessary to effectively implement the next wave of ACA’s health care reforms in the Department of Health & Human Service’s rollout of new consumer health care education and decision-making tools on its newly designed healthcare.gov website.
In announcing its launch of its Health Insurance Marketplace educational tools here on June 24, 2013, the Department of Health & Human Services (HHS) repeated recent claims that HHS and the states are on target to begin enrollment on October 1, 2013 in the federal and state health care exchanges now retitled “Health Insurance Marketplace” by the Administration, to meet other key milestones and to the beginning coverage under the newly created Health Insurance Marketplaces beginning January 1, 2014.
As part of these preparations, HHS kicked off an aggressive Health Insurance Marketplace education effort by announcing the deploying of with newly designed “consumer-focused” HealthCare.gov website and the 24-hours-a-day consumer call center that HHS claims provide all the necessary tools to prepare Americans for open enrollment and ultimately sign up for private health insurance.
According to HHS, “The new tools will help Americans understand their choices and select the coverage that best suits their needs when open enrollment in the new Health Insurance Marketplace begins October 1.”
According to Centers for Medicare & Medicaid Services Administrator Marilyn Tavenner, “In October, HealthCare.gov will be the online destination for consumers to compare and enroll in affordable, qualified health plans.”
Between now and the start of open enrollment, HHS says the Marketplace call center will provide educational information and, beginning Oct. 1, 2013, will help consumers with application completion and plan choice. In addition to English and Spanish, the call center provides assistance in more than 150 languages through an interpretation and translation service. Customer service representatives are available for assistance via a toll-free number at 1-800-318-2596 and hearing impaired callers using TTY/TDD technology can dial 1-855-889-4325 for assistance.
While HHS says its tools and other preparations will get the Health Care Marketplaces and Americans ready for the conversion of the U.S. health care system slated to begin January 1, 2014, others are less confident. For instance, GAO officials recently found that major work that federal and state officials must complete to timely begin enrollment by October 1 remains unfinished, making it unclear if they will meet the impending October 1, 2013 enrollment kickoff deadline. See GAO Report and GAO Report such as::
- 17 states committed to run their own exchanges have missed March 2013 deadlines on 44% of key activities;
- Officials creating the small business exchanges still must review plans and train and certify the “navigators” that are supposed to help companies and individuals enroll in plans and complete other key arrangements;
- A federal the “data hub” designed to help individuals determine their eligibility and enroll in plans offered through the exchanges has only undergone initial testing; and
- The current planned process for coordination of data between employer and insurer plans and the health care exchanges to evaluate eligibility of the millions of Americans expected to apply for subsidies for enrolling in coverage through the exchange presently is for HHS to contact employers by telephone employers to ask if that employer asked that employee enrollee minimum essential coverage providing minimum essential value at an affordable cost that would disqualify the applicant for the subsidy.
Meanwhile, the GAO Reports also provide a glimpse at what the federal government has spent so far on preparing the federal exchanges and the data hub. They indicate that hat the Obama Administration had approximately $394 million on exchange efforts as of March 2013 including:
- $84 million to CGI Federal, which is building the federal exchange computer infrastructure;
- $55 million to Quality Software Services, which is building the data hub; and
- $38 million to Booz Allen Hamilton to provide technical assistance for enrollment and eligibility.
Contractor Booz Allen Hamilton recently has drawn attention as the National Security Association contractor through which the notorious fugitive Edward Snowden allegedly accessed information he disclosed to the public about NSA surveillance of “big data” on Americans and others through the internet.
The GAO also estimated the Obama administration needs Congress to approve an extra $1.5 billion from the budget to provide the Administration with the additional $2 billion that the GAO projects the Administration will need over the next fiscal year to create and operate the federal exchanges. Existing budget concerns make it unlikely that Congress will approve these extra funds.
For Help or More Information
If you need help with preparing these or other ACA compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved
Comments Off on HHS Touts Enrollment Tools, Says Exchange Enrollment Ready Despite GAO Concerns |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: ADA, Affordable Care Act, GINA, Group Health plans, Health Care Reform, Health Plans, HIPAA, Privacy, Wellness, Wellness Programs |
Permalink
Posted by Cynthia Marcotte Stamer
June 14, 2013
Health plans, health care providers, health care clearinghouses (covered entities) and their business associates should confirm their existing policies, practices and training for communicating with the media and others comply with the Privacy Rule requirements of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in light of a Resolution Agreement with Shasta Regional Medical Center (SRMC) announced by the U.S. Department of Health and Human Services (HHS) Office of Civil Rights today (June 14, 2013).
Under the Resolution Agreement, SRMC agrees to pay $275,000 and implement a comprehensive corrective action plan (CAP) to settle an investigation that resulted when SRMC used and disclosed protected health information (PHI) of a patient to members of the media and its workforce while trying to do damage control against fraud or other allegations of misconduct involving individual patient information or circumstances. The Resolution Agreement shows how efforts to respond to press or media reports, patient or other complaints, physician or employee disputes, high profile accidents, or other events that may involve communications not typically run by privacy officers can create big exposures. While the Resolution Agreement targets a health care provider, the lessons are equally applicable to health plans and health care clearinghouses, who increasingly face their own pressure to communicate with the media and others about enforcement actions, workforce claims and other matters.
Talking Out Of Turn To Media & Others Violated HIPAA
OCR investigated SRMC after a January 4, 2012 Los Angeles Times article reported two SRMC senior leaders had met with media to discuss medical services provided to a patient. OCR’s investigation indicated that SRMC failed to safeguard the patient’s protected health information (PHI) from impermissible disclosure by intentionally disclosing PHI to multiple media outlets on at least three separate occasions, without a valid written authorization. OCR’s review also revealed senior management at SRMC impermissibly shared details about the patient’s medical condition, diagnosis and treatment in an email to the entire workforce. Further, SRMC failed to sanction its workforce members for impermissibly disclosing the patient’s records pursuant to its internal sanctions policy.
Among other things, the specific misconduct uncovered by HHS’s investigation indicated that from December 13 – 20, 2011, SRMC failed to safeguard the patient’s PHI from any impermissible intentional or unintentional disclosure on multiple occasions in connection with its response to media coverage arising from a Medicare fraud story including:
- On December 13, 2011, for instance, OCR reports SRMC’s parent company sent a letter to California Watch, responding to a story about Medicare fraud. The letter described the patient’s medical treatment and provided specifics about her lab results even though SRMC did not have a written authorization from the patient to disclose this information to this news outlet.
- On December 16, 2011, two of SRMC’s senior leaders also met with The Record Searchlight’s editor to discuss the patient’s medical record in detail even though SRMC did not have a written authorization from the patient to disclose this information to this newspaper.
- On December 20, 2011, SRMC sent a letter to The Los Angeles Times, which contained detailed information about the treatment the patient received when, again, SRMC did not have a written authorization from the patient to disclose this information to this newspaper.
In addition, OCR found SRMC impermissibly used the affected party’s PHI when on December 20, 2011, SRMC sent an email to its entire workforce and medical staff, approximately 785-900 individuals, describing, in detail, the patient’s medical condition, diagnosis and treatment. SRMC did not have a written authorization from the patient to share this information with SRMC’s entire workforce and medical staff.
SRMC Must Correct & Pay $$275K Penalty
Under the Resolution Agreement, SRMC pays a $275,000 monetary settlement and agrees to comply with a CAP for the next year.
The CAP requires SRMC to update its policies and procedures on safeguarding PHI from impermissible uses and disclosures and to train its workforce members. The CAP also requires fifteen other hospitals or medical centers under the same ownership or operational control as SRMC to attest to their understanding of permissible uses and disclosures of PHI, including disclosures to the media.
The Resolution Agreement specifically requires that Shasta Regional Medical Center, among other things:
- To update policies to include specific policies about sharing PHI with the media, members of the workforce not involved in an individual patient’s care and others to comply with HIPAA;.
- To provide updated policies to OCR for approval;
- To provide training documented with certification of all workforce members before allowing them to get access to PHI;
SRMC is one of several Prime Healthcare Services facilities under common ownership and control. The Resolution Agreement also requires corrective action at these commonly owned facilities including California-based Alvarado Hospital Medical Center in San Diego, Centinela Hospital Medical Center in Inglewood, Chino Valley Medical Center in Chino, Desert Valley Hospital in Victorville, Garden Grove Hospital Medical Center in Garden Grove, La Palma Intercommunity Hospital in La Palma, Paradise Valley Hospital in National City, San Dimas Community Hospital in San Dimas, Shasta Regional Medical Center in Redding, and West Anaheim Medical Center in Anaheim; Saint Mary’s Regional Medical Center in Reno, Nevada; Pennsylvania based Lower Bucks Hospital in Bristol and Roxborough Memorial Hospital in Philadelphia;and Texas-based Dallas Medical Center in Dallas, Harlingen Medical Center in Harlingen, Pampa Regional Medical Center in Pampa. Among other things, the Resolution Agreement requires that for each of these related facilities:
- The CEO and Privacy Officer of each facility must give OCR a signed affidavit stating that they understand that the Privacy Rule protects an individual’s PHI is protected by Privacy Rule even if such information is already in the public domain or even though it has been disclosed by the individual; and that disclosures of PHI in response to media inquiries are only permissible pursuant to a signed HIPAA authorization; and
- Ensure all members of their respective workforce are informed of this policy.
The Resolution Agreement highlights the difficulty that health care providers and other covered entities often face in properly recognizing and handling PHI in the case of fraud or other disputes. While health care providers have an understandable wish to defend themselves in the media and elsewhere in response to charges of misconduct, today’s settlement shows that improperly sharing PHI of each patient in the process will make matters much worse. It’s important to keep in mind that just omitting to mention the name or other common identifying information may not overcome this concern because information about a patient can be considered individually identifiable and to enjoy protection under HIPAA where the facts and circumstances would allow another person to know or determine who the individual is, even if the specific name, address or more common identifying information is not shared.
Furthermore, the settlement also makes clear that merely because the patient or some other party has shared the same information with the media or others does not excuse the health care provider or other covered entity or business associate from the obligation to keep confidential the PHI unless it gets proper consent or otherwise can show that an exception to HIPAA applies.
Finally, the Resolution Agreement also makes clear that OCR expects covered entities to connect their HIPAA compliance with other policies and operations and will hold covered entities and associates accountable for properly integrating, training workforce and enforcing compliance with these policies. While this means that covered entities and business associates may find themselves in the uncomfortable situation of facing unsavory reports and rumors without the ability to respond, the significant civil and even criminal penalties that can arise from violation of HIPAA make it critical that covered entities exercise discipline in responding to avoid sharing PHI improperly.
The 2013 Regulations Overview
Adding a review and update of HIPAA and other policies for communicating with the media and internally on matters that may involve use or discussions of PHI in unusual contexts outside the purview of typically HIPAA policies is a good idea while health plans and other covered entities and business associates are updating their existing policies and practices for compliance with updated Omnibus HIPAA Rules (2013 Regulations) implementing HITECH Act amendments to the Privacy and Security Rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The Rulemaking announced January 17, 2013 may be viewed here.
Since 2003, HIPAA generally has required that health care providers, health plans, health care clearinghouses and their business associates (“Covered Entities”) restrict and safeguard individually identifiable health care information (“PHI”) of individuals and afford other protections to individuals that are the subject of that information. The 2013 Regulations published today complete the implementation of changes to HIPAA that Congress enacted when it passed the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009 as well as make other changes to the prior regulations that OCR found desirable based on its experience administering and enforcing the law over the past decade.
Since passage of the HITECH Act, OCR officials have warned Covered Entities to expect an omnibus restatement of its original regulations. While OCR had issued certain regulations implementing some of the HITECH Act changes, it waited to publish certain regulations necessary to implement other HITECH Act changes until it could complete a more comprehensive restatement of its previously published HIPAA regulations to reflect both the HITECH Act amendments and other refinements to its HIPAA Rules. The 2013 Regulations published today fulfill that promise by restating OCR’s HIPAA Regulations to reflect the HITECH Act Amendments and other changes and clarifications to OCR’s interpretation and enforcement of HIPAA.
Among other things, the 2013 Regulations:
- Revise OCR’s HIPAA regulations to reflect the HITECH Act’s amendment of HIPAA to add the contractors and subcontractors of health plans, health care providers and health care clearinghouses that qualify as business associates to the parties directly responsible for complying with and subject to HIPAA’s civil and criminal penalties for violating HIPAA’s Privacy, Security, and Breach Notification rules;
- Update previous interim regulations implementing HITECH Act breach notification rules that require Covered Entities including business associates to give specific notifications to individuals whose PHI is breached, HHS and in some cases, the media when a breach of unsecured information happens;
- Update interim enforcement guidance OCR previously published to implement increased penalties and other changes to HIPAA’s civil and criminal sanctions enacted by the HITECH Act;
- Implement HITECH Act amendments to HIPAA that tighten the conditions under which Covered Entities are allowed to use or disclose PHI for marketing and fundraising purposes and prohibit Covered Entities from selling an individual’s health information without getting the individual’s authorization in the way required by the 2013 Regulations;
- Update OCR’s rules about the rights that HIPAA requires that Covered Entities to afford to individuals who are the subject of PHI used or possessed by a Covered Entity to reflect tightened requirements enacted by the HITECH Act that allow individuals to order their health care provider not to share information about their treatment with health plans when the individual pays cash for the care and to clarify that individuals can require Covered Entities to provide electronic PHI in electronic form;
- Revise the regulations to reflect amendments to HIPAA made as part of the Genetic Information Nondiscrimination Act of 2008 (GINA) which added genetic information to the definition of PHI protected under the HIPAA Privacy Rule and prohibits health plans from using or disclosing genetic information for underwriting purposes; and
- Clarifies and revises other provisions to reflect other interpretations and information guidance that OCR has issued since HIPAA was passed and to make certain other changes that OCR found appropriate based on its experience administering and enforcing the rules.
Liability & Enforcement Risks Heighten Need To Act To Review & Update Policies & Practices
The new Resolution Agreement and the growing list of others like it, as well as restated rules in the 2013 Regulations make it imperative that Covered Entities review the revised rules carefully and updated their policies, practices, business associate agreements, training and documentation to comply with the updated requirements and other enforcement and liability risks. OCR even prior to the regulations has aggressively investigated and enforced the HIPAA requirements.
OCR increasingly is imposing sanctions against a covered entity for data breaches to show the potential risks of HIPAA violations are significant and growing. OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website; Providence To Pay $100000 & Implement Other Safeguards.
In response to the 2013 Regulations and these expanding exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.
Enforcement Actions Highlight Growing HIPAA Exposures For Covered Entities
The SRMC Resolution Agreement again shows the growing risk of enforcement that health care providers, health plans, health care clearinghouses and their business associates face as OCR continues its audits and enforcement, new Omnibus HIPAA Regulations implementing the HITECH Act amendments to HIPAA and state and federal liability grows.. See e.g., $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website.
In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to determine if additional steps are necessary or advisable.
As part of this process, covered entities should ensure they look outside the four corners of their Privacy Policies to ensure that appropriate training and clarification is provided to address media, practice transition, workforce communication and other policies and practices that may be covered by pre-existing or other policies of other departments or operational elements not typically under the direct oversight and management of the Privacy Officer such as media relations. Media relations, physician and patients affairs, outside legal counsel, media relations, marketing and other internal and external departments and consultants dealing with the media, the public or other inquiries or disputes should carefully include and coordinate with the privacy officer both to ensure appropriate policies and procedures are followed and proper documentation created and retained to show authorization, account, or meet other requirements.
For more information about HIPAA compliance and risk management tips, see here.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- OCR Makes Technical Corrections To HIPAA Omnibus Final Rule; September 2013 Enforcement Deadline Looming;
- OCR Gives HIPAA Guidance On Safety Disclosures
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- OCR Audit Program Kickoff Further Heats HIPAA Privacy RisksProvidence To Pay $100000 & Implement Other Safeguards
- Former White House Cybersecurity Coordinator Schmidt, Stamer & Others Share Key HIPAA & Other Privacy & Data Security Insights 5/21 In LA
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Employer, Employment, Health Care, Health Plans, HIPAA, Hospitals, OCR, Office of Civil Rights, PHI, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
June 6, 2013
The Department of Health & Human Services Office of Civil Rights (OCR) on June 6, 2013 released an advance copy of to Technical Corrections (Technical Corrections) to the Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notifications Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules; Final Rule (Omnibus Rule) previously published on January 25, 2013. Health plans, health care clearinghouses, health care providers and their business associates will want to be sure to take into account the Technical Corrections as they rush to update business associate agreements, policies, practices, training and other HIPAA compliance to comply with the Omnibus Rule changes by the September 2013 deadline.
Technical Corrections To Omnibus Rule Released
OCR published the Omnibus Rule to implement changes to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules (“the HIPAA Rules”) enacted by the Health Information Technology for Economic and Clinical Health Act (“the HITECH Act”) and section 105 of Title I of the Genetic Information Nondiscrimination Act of 2008, as well as to address public comment received on the interim final Breach Notification Rule and to other changes to the HIPAA Rules. The Technical Corrections are scheduled for publication in the Federal Register on June 7, 2013.
The Technical Corrections correct various typographical errors and other oversights in the Omnibus Regulations as originally published. While many of these corrections have limited material impact, certain corrections do have substantive implications. For instance, by correcting errors in references to other provisions of the Omnibus Regulations, the Technical Corrections clarify that the authority of OCR to grant an extension of time pursuant to § 160.508(c)(5) for violations before February 18, 2009 also applies to violations occurring on or after February 18, 2009, as there is for violations occurring prior to February 18, 2009.
Health plans, health care clearinghouses and their business associates will need to review and take into account the Technical Corrections as they work to review and update their policies and practices for handling and disclosing personally identifiable health care information (“PHI”) in response to the Omnibus Rule.
Get Moving To Update HIPAA Compliance For New Omnibus Rule Requirements As Amended By Technical Corrections
Covered entities and their business associates have a lot to accomplish between now and September to update their business associates and comply with other changes made by the Omnibus Rule by its September 2013 deadline. Among other things, the Omnibus Regulations:
- Revise OCR’s HIPAA regulations to reflect the HITECH Act’s amendment of HIPAA to add the contractors and subcontractors of health plans, health care providers and health care clearinghouses that qualify as business associates to the parties directly responsible for complying with and subject to HIPAA’s civil and criminal penalties for violating HIPAA’s Privacy, Security, and Breach Notification rules;
- Update previous interim regulations implementing HITECH Act breach notification rules that require Covered Entities including business associates to give specific notifications to individuals whose PHI is breached, HHS and in some cases, the media when a breach of unsecured information happens;
- Update interim enforcement guidance OCR previously published to implement increased penalties and other changes to HIPAA’s civil and criminal sanctions enacted by the HITECH Act;
- Implement HITECH Act amendments to HIPAA that tighten the conditions under which Covered Entities are allowed to use or disclose PHI for marketing and fundraising purposes and prohibit Covered Entities from selling an individual’s health information without getting the individual’s authorization in the way required by the Omnibus Regulations;
- Update OCR’s rules about the individual rights that HIPAA requires that Covered Entities to afford to individuals who are the subject of PHI used or possessed by a Covered Entity to reflect tightened requirements enacted by the HITECH Act that allow individuals to order their health care provider not to share information about their treatment with health plans when the individual pays cash for the care and to clarify that individuals can require Covered Entities to provide electronic PHI in electronic form;
- Revise the regulations to reflect amendments to HIPAA made as part of the Genetic Information Nondiscrimination Act of 2008 (GINA) which added genetic information to the definition of PHI protected under the HIPAA Privacy Rule and prohibits health plans from using or disclosing genetic information for underwriting purposes; and
- Clarifies and revises other provisions to reflect other interpretations and information guidance that OCR has issued since HIPAA was passed and to make certain other changes that OCR found appropriate based on its experience administering and enforcing the rules.
Liability & Enforcement Risks Heighten Need To Act To Review & Update Policies & Practices
The restated rules in the Omnibus Rule make it imperative that Covered Entities review the revised rules carefully and updated their policies, practices, business associate agreements, training and documentation to comply with the updated requirements and other enforcement and liability risks. OCR even prior to the regulations has aggressively investigated and enforced the HIPAA requirements. See, e.g., OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website; Providence To Pay $100000 & Implement Other Safeguards.
Coupled with statements by OCR about its intolerance, the HONI and other settlements provide a strong warning to covered entities of the need to carefully and appropriately manage their HIPAA encryption and other Privacy and Security responsibilities. Covered entities are urged to heed these warning by strengthening their HIPAA compliance and adopting other suitable safeguards to minimize HIPAA exposures.
All Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- OCR Gives HIPAA Guidance On Safety Disclosures
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Former White House Cybersecurity Coordinator Schmidt, Stamer & Others Share Key HIPAA & Other Privacy & Data Security Insights 5/21 In LA
- Strengthen Health Plan Privacy Compliance & Risk Management Using Lessons From New OCR Provider & Consumer Tools
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
May 30, 2013
Register Now For 6/4 Solutions Law Press, Inc. Virtual Briefing
Employer, union and sponsors of employment-based group health plans that include health risk assessment (HRA) or other wellness plan features that reward participants for engaging in certain assessments or other activities designed to promote wellness or disease management, and fiduciaries insurers, and administrators of these health plans should review and update their programs in light of final wellness program rules jointly published by the Department of Health and Human Services (HHS), Department of Labor Employee Benefit Security Administration (EBSA) and the Department of Treasury (collectively the “Agencies”) today (May 29, 2013) here (Wellness Regulations).
While these final Wellness Regulations implementation of changes to the “bona fide wellness program exception” to nondiscrimination rules contained in the Portability Rules of the Health Insurance Portability & Accountability Act (HIPAA) as amended by the Patient Protection and Affordable Care Act (ACA) allow group health plans to provide bigger rewards to members for cooperating in wellness activities required under a “bona wellness program” within the meaning of the Wellness Regulations, the Wellness Regulations and other federal rules still need care to design and administer these health plan features meet all applicable Wellness Regulations for qualification as a “bona fide wellness program while also safeguarding the use of “personal health information” and “genetic health information in accordance with the privacy rules of HIPAA as amended by the Genetic Information Nondiscrimination Act (GINA) managing potential employment disability discrimination exposures under the Equal Employment Opportunity Commission’s (EEOC’s) current interpretation of the employment discrimination rules of Americans With Disabilities Act (ADA) and GINA.
Wellness Rules Implement ACA Changes To HIPAA “Bona Fide Wellness Program Rules
The nondiscrimination prohibitions of the Health Insurance Portability & Accountability Act (HIPAA), as amended by the Genetic Information Nondiscrimination Act (GINA) and the Patient Protection and Affordable Care Act (ACA) generally prohibit health plans from discriminating against an individual based on eligibility or premium based on a health factor. Wellness or disease management programs that vary premiums or contributions, cost-sharing or other benefit mechanisms, or provide other rewards or inducements can run afoul of this HIPAA nondiscrimination prohibition if not properly designed and administered to fall within the “bona fide wellness program” exception.
The Wellness Regulations as finalized continue to interpret HIPAA’s general prohibition against group health plan provisions that discriminate based on a health factor to prohibit group health plans to vary benefits (including cost-sharing mechanisms) or the premium or contribution for similarly situated individuals when wellness program that satisfies the requirements of the Wellness Regulations for a “bona fide wellness program
The Affordable Care Act generally increased the maximum permissible reward under a health-contingent wellness program from 20 percent to 30 percent of the cost of health coverage for qualifying bona fide wellness programs and to as much as 50 percent of the cost of health coverage for bona fide wellness programs designed to prevent or reduce tobacco use. In keeping with these ACA amendments to HIPAA, the Wellness Regulations allow group health plans and insurers to offer these greater rewards as long as the wellness program otherwise meets the conditions that the Wellness Regulations set for qualification as a bona fide wellness program.
In order to offer these incentives, however, the Wellness Regulations make clear that group health plans, their insurers and fiduciaries still need to tread carefully to properly design and administer these arrangements to ensure that their wellness program meet the applicable conditions of the Wellness Regulations for qualification as a bona fide wellness program.
In keeping with the approach announced in proposed regulations the Agencies previously published here last Fall, the Wellness Regulations have different requirements for “participatory wellness programs” versus “health contingent wellness programs.”
- “Participatory wellness programs” generally are programs that reward plan members for participating in wellness activities based on participation in specified activities without regard to an individual’s health status. These include programs that reimburse for the cost of membership in a fitness center; that provide a reward to employees for attending a monthly, no-cost health education seminar; or that reward employees who complete a health risk assessment, without requiring them to take further action
- “Health-contingent wellness programs” generally are programs where individuals must meet a specific standard related to their health to qualify for the specified reward or avoid a specified penalty. Examples of health-contingent wellness programs include programs that provide a reward to those who do not use, or decrease their use of, tobacco, or programs that reward those who achieve a specified health-related goal, such as a specified cholesterol level, weight, or body mass index, as well as those who fail to meet such goals but take certain other healthy actions.
Group health plan sponsors, fiduciaries, insurers and administrators should use care to properly understand which type of program or programs their group health plans contain and ensure that their programs are properly designed and administered to meet these conditions. While fulfillment of these requirements can allow the arrangement to avoid violation of HIPAA’s nondiscrimination rules, however, it is important also to ensure that other applicable federal requirements for the use of these arrangements also are fulfilled along with these HIPAA nondiscrimination requirements.
Meeting Other Federal Rules For Wellness Programs Also Important
In addition to fulfilling the Wellness Regulations, health plans, their sponsors, fiduciaries, insurers and administrators also need to ensure that any wellness program included in a group health plan also meets other federal rules about the protection of sensitive personal health information and genetic health information and do not violate the employment discrimination rules of the ADA and GINA
- Update Privacy Compliance
.Since wellness programs generally inherently involve some collection, use, access or disclosure of “protected health information” within the meaning of the Privacy Rules of HIPAA, it is particularly important to review and tighten plan provisions and other documentation, processes, procedures, and training to reduce the risk of violating HIPAA. A review of the adequacy of these arrangements is made particularly important in light of recent changes to in the implementing regulations of these HIPAA Privacy Rules adopted earlier this year to implement changes enacted by the HITECH Act. Among other things, these changes may require updates to the health plan’s definition of personal health care information to clarify that it includes family health information and other “genetic information” that wellness programs often collect. Other updates to plan provisions, privacy policies, vendor agreements or other practices also may be needed to comply with modifications to the HIPAA Privacy Rules on business associates, marketing, breach notification, training or other rules.
- Manage Disability Discrimination Risks
In addition to ensuring compliance with current requirements about privacy, group health plans, their sponsors, fiduciaries, insurers and vendors also should take steps to minimize potential employment discrimination challenges under the ADA and GINA.
Despite ACA’ amendments to HIPAA’s bona fide wellness program rules and the 11th Circuit’s rejection of an EEOC challenge in Broward County v. Seff, EEOC officials continue to take the position that testing and inquiries about medical conditions made in connection with wellness programs presumptively violate the Americans With Disabilities Act physical testing and other disability discrimination rules as raising concerns about wellness and disease management programs.. See, e.g., EBSA Issues Guidance on Health Plan Wellness & Disease Management Programs Subject to HIPAA Nondiscrimination Rules; ADAAA Amendment Broader “Disability Definition Not Retroactive, Employer Action Needed To Manage Post 1/1/2009 Risks; Businesses Face Rising Disability Discrimination Enforcement Risks; EEOC Finalizes Updates To Disability Regulations In Response to ADA Amendments Act.
The ADA is not the only employment discrimination risk to manage, however. In addition to the amendments to the group health plan nondiscrimination and Privacy Rules of HIPAA, GINA’s employment discrimination rules generally prohibit employment discrimination based on “genetic health information.” For instance, GINA’s genetic information nondiscrimination rules:
- Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
- Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
- Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
- Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
- Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
- Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
- Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
EEOC officials have stated publicly on certain occasions and reportedly have challenged health risk assessments or other wellness program features that request or collect family medical history or other genetic information as violating GINA’s employment discrimination rules.
Learn More At 6/4 Solutions Law Briefing
Solutions Law Press, Inc. invites employer and other employment-based group health plan sponsors, fiduciaries insurers, administrators, brokers, consultants and others to learn the key details of new Final Wellness Program regulations jointly published May 29, 2013 by the Departments of Health and Human Services, Labor and Treasury (collectively the “Agencies”) by participating in an informative and timely virtual briefing on “Making Wellness Programs Work Under New Final Tri-Agency Regulations” on June 4, 2013 beginning at Noon Central Time. To register or for additional details, see here.
For Help or More Information
If you need help with preparing these or other ACA compliance or with reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 25 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters including extensive experience on HIPAA and other privacy and data security issues.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
For important information about this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Nonexclusive license to republish granted to Solutions Law Press, Inc. All other rights reserved
1 Comment |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Disability, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, MEWA, Patient Protection and Affordable Care Act, Reporting & Disclosure, Tax, Uncategorized, Wellness Programs | Tagged: ADA, Affordable Care Act, GINA, Group Health plans, Health Care Reform, Health Plans, HIPAA, Privacy, Wellness, Wellness Programs |
Permalink
Posted by Cynthia Marcotte Stamer
May 30, 2013
Solutions Law Press, Inc. Invites Employer & Other Group Health Plan Sponsors, Insurers, Administrators, Brokers, Advisors & Consultants to A Virtual Briefing On
Making Wellness Programs Work Under New Tri-Agency Final Wellness Regulations
Tuesday, June 4, 2013
1:00 P.M.-2:00 P.M. Eastern | 12:00 P.M.-1:00 P.M. Central | 11:00 A.M-12:00 P.M. Mountain | 10 A.M-11:00 A.M. Pacific
Register Now!
Solutions Law Press, Inc. invites employer and other employment-based group health plan sponsors, fiduciaries insurers, administrators, brokers, consultants and others to learn the key details of new Final Wellness Program regulations jointly published May 29, 2013 by the Departments of Health and Human Services, Labor and Treasury (collectively the “Agencies”) by participating in an informative and timely virtual briefing on “Making Wellness Programs Work Under New Final Tri-Agency Regulations” on June 4, 2013.
New final wellness program regulations jointly published May 29, 2013 by the Departments of Labor, Health & Human Services and Labor tell employers and insurers how to design health risk assessment and other wellness and disease management tools in their group health plans and policies to incentivize and reward employees and other plan members to better manage their health and help manage health plan costs without violating the HIPAA Portability Rules against group health plan discrimination in premiums or eligibility based on health status.
Participants in this briefing will learn key information about:
- The final wellness program regulation’s requirements for designing HRA and other group health plan wellness and disease management programs that avoid violating HIPAA’s prohibition against discrimination based on health factors as “bona fide wellness programs;”
- How group health plans can take advantage of the option allowed beginning in 2014 to offer greater incentives to plan members to participate in group health plan wellness programs by amendments made under the Patient Protection and Affordable Care Act;
- How new Omnibus HIPAA Privacy Rules may require group health plans and insurers to update their marketing and other privacy policies, procedures, documentation, vendor agreements and other practices for collecting, using, disclosing and safeguarding “personal health information” and “genetic health information” when administering wellness programs and other group health plan provisions;
- When the EEOC views wellness programs incentives as potentially violating the Americans With Disabilities Act discrimination exposures under the Equal Employment Opportunity Commission’s (EEOC’s) current interpretation of the employment discrimination rules of Americans With Disabilities Act (ADA) and GINA; and
- Other tips for designing legally compliant, effective group health plan disease management and wellness programs.
Ms. Stamer also will take questions from virtual audience participants as time permits.
About The Speaker
A Fellow in the American College of Employee Benefits Counsel, recognized in International Who’s Who, and Board Certified in Labor & Employment Law, attorney and health benefit consultant Cynthia Marcotte Stamer has 25 years experience advising and representing private and public employers, employer and union plan sponsors, employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental leaders and others on health and other employee benefit. employment, insurance and related matters. A well-known and prolific author and popular speaker Board Certified in Labor & Employment Law, Ms. Stamer presently serves as Co-Chair of the ABA RPTE Section Welfare Plan Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Representative, an Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com), Insurance Thought Leadership,com and Employee Benefit News, and various other publications. With extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on public policy and regulatory advocacy on health and other employee benefits, human resources, insurance, tax, compliance and other matters and representing clients in dealings with the US Congress, Departments of Labor, Treasury, Health & Human Services, as well as state legislatures, attorneys general, insurance and labor departments, and other agencies and regulators. A prolific author and popular speaker, Ms. Stamer regularly authors materials and conducts workshops and professional, management and other training and serves on the faculty and planning committees of a multitude of symposium and other educational programs. See http://www.CynthiaStamer.com. for more details.
Registration
Registration Fee is $95.00 per person Registration required for each virtual participant. Payment required via website registration in advance of the program.. Payment only accepted via website PayPal. No checks or cash accepted. Participation is limited and available on a first come, first serve basis. Persons not registered at least 24 hours in advance not guaranteed to receive access information or materials prior to commencement of the briefing.
Equipment Requirements For Virtual Briefing Participation
This briefing will be conducted via WebEx over the internet. Participants may have the opportunity to participate via telephone, provided that participants electing to participate may incur added charges for telephone connectivity. Solutions Law Press, Inc. is not responsible for any power or system failures. Solutions Law Press, Inc. also expects to offer the opportunity for individuals unable to participate in the live briefing to listen to a recording of the briefing beginning approximately one week after the program via the Internet by registering, paying the required registration fee and following listening instructions received in response to such registration.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assist businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to inquire about becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. If you would prefer not to receive communications from Solutions Law Press, Inc. send an e-mail with “Solutions Law Press Unsubscribe” in the Subject to support@solutionslawyer.net. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN. If you are an individual with a disability who requires accommodation to participate, please let us know at the time of your registration so that we may consider your request. ©2013 Solutions Law Press, Inc. All rights reserved.
Comments Off on Register For 6/4 Virtual Briefing On DOL/IRS/HHS Final Group Health Plan Wellness Program Regulations |
ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Disability, EEOC, EEOC, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, HIPAA, Human Resources, MEWA, Tax, Wellness Programs | Tagged: ACA, ADA, Affordable Care Act, GINA, HIPAA, HIPAA Portability, HIPAA Privacy, Wellness, Wellness Programs |
Permalink
Posted by Cynthia Marcotte Stamer
March 1, 2013
The U.S. Department of Labor’s Occupational Safety and Health Administration (OSHA) citation of the Battle Creek Veterans Administration Medical Center, following a safety inspection conducted in July as part of OSHA’s Federal Agency Targeting Inspection Program for seven notices of unsafe or unhealthful working conditions reminds employers that OSHA expects employers to maintain safe workplaces.
Under the Occupational Safety and Health Act, federal agencies must comply with the same safety standards as private-sector employers. According to OSHA, its inspection uncovered several repeat safety violations, as well as certain other serious safety violations.
OSHA reports that three repeat safety violations involved failing to evaluate the workplace to identify if permit-required confined spaces were present and label such spaces with danger signs; failing to adequately guard automated laundry equipment to prevent employees from entering the work area, and failing to fully guard the belt and pulley of an air compressor. To issue notices for repeat violations, OSHA must have issued at least one other notice for the same violation at one of the agency’s establishments within the same standard industrial classification code, commonly known as the SIC code. OSHA previously has cited U.S. Department of Veterans Affairs facilities in Danville and North Chicago, Illinois, and Minneapolis, Minnesota for the same safety and health violations.
The serious safety violations found included three serious safety violations for unguarded floor openings in the general repair shop; failing to inspect powered industrial trucks prior to placing them in service, and failing to remove trucks from service in need of repair. Additionally, OSHA found a circuit breaker panel was not mounted correctly. OSHA issues a serious notice when it finds a substantial probability that death or serious physical harm could result from a hazard about which the employer knew or should have known.
Beyond the repeated and serious violations, OSHA reports it also found one other-than-serious violation for failing to close unused openings on electrical cabinets and junction boxes. An other-than-serious violation is one that has a direct relationship to job safety and health, but probably would not cause death or serious physical harm.
The medical center has 15 business days from receipt of the notices to comply, request an informal conference with OSHA’s area director or appeal the notices by submitting a summary of the agency’s position on the unresolved issues to OSHA’s regional administrator.
While the medical center and other federal agencies are required to comply with the same OSHA rules as private sector employers, the VA and other federal agencies don’t face the same liabilities when cited. OSHA cannot propose monetary penalties against another federal agency for failure to comply with OSHA standards.
The risks for private sector employers is illustrated by another recent OSHA. OSHA recently cited Riddell All-American Sports Co. with eight serious violations following an OSHA investigation, which found that the company exposed workers to multiple safety and health hazards at its San Antonio facility. The violations include failing to ensure electrical equipment was free from recognized hazards, provide adequate machine guarding while employees operate industrial sewing machines and provide a fall protection program to prevent falls from the basket of a powered industrial truck. The Elyria, Ohio-based company, which employs about 25 workers in San Antonio, paints helmets for various sports. Proposed penalties total $44,000. Read the News Release.
Since private sector employers that don’t enjoy the VA’s immunity liability run much greater risks for failing to maintain workplace safety, including significant civil and in the case of a workplace death, potentially even criminal penalties, private sector hospitals and other organizations should exercise special care to ensure appropriate safety in their workplaces. “The Battle Creek Veterans Administration Medical Center failed to properly ensure the facility was in compliance with established safety and health procedures,” said Robert Bonack, director of OSHA’s Lansing Area Office. “All employers, including federal employers, are responsible for knowing what hazards exist in their facilities and taking appropriate precautions by following OSHA standards so workers are not exposed to such hazards.”
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help in conducting a risk assessment of or responding to an IRS, DOL, Justice Department, or other federal or state agencies or other private plaintiff or other legal challenges to your organization’s existing workforce classification or other labor and employment, compliance, employee benefit or compensation practices, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469) 767-8872 .
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 23 years of work helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- FTC, HIPAA Rules Require Health Plans & Employers Strengthen Data Security on Mobile Devices and Applications
- 3/13 JCEB Teleconference Explores Foreign Transferees: Outbound, Inbound, Equity And Treaty Issues
- Stamer Talks on “What the Wind Blew In: Coping with Health Care Reform: 2013 and Beyond” May 2 At 24th Annual RPTE Spring Symposia In Washington, D.C.
- IRS Will Begin Accepting Returns Claiming Education Credits By Mid-February
- IRS Shares Procedures Employers Use To Claim Increased Monthly Transit Benefit Exclusion Allowed By Administrative Taxpayer Relief Act
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on OSHA Citation Of Michigan VA Reminder To Manage Workplace Safety |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, Health, Hospital, IT, Labor Department, Medical Center, Minimum Wage, OSHA, Safety, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
February 25, 2013
From handling requests for light duty or other modifications follow a leave to investigating the medical justification for leaves or the fitness of an employee to return to work following a medical absence, employers need to use care to manage disability discrimination exposures.
Today’s announcement by the Equal Employment Opportunity Commission (EEOC) that Wal-Mart Stores, Inc. and Wal-Mart Stores East, L.P. (Wal-Mart) will pay $50,000 in back pay and damages to settle an EEOC disability discrimination lawsuit highlights the potential disability discrimination risks that employers can face when deciding not to provide a requested accommodation to a worker returning from medical leave while other recent enforcement actions show ADA risks from simply making medical inquiries to a worker on or returning from medical leave.
In its lawsuit against Wal-Mart, Case No. 2:11-CV-00834, filed in the U.S. District Court for the District of New Mexico, the EEOC charged that a Carlsbad, N.M Wal-Mart store violated the Americans With Disabilities Act (ADA) by firing a part-time sales clerk, Marcia Arney because the store refused to provide temporary accommodations ordered by her physician following a period of medical leave.
According to the EEOC lawsuit, when Arney, a 22-year Wal-Mart employee, showed the store manager a note from her doctor requesting an accommodation involving periodic breaks off her feet, the manager refused to return her to her job unless she obtained a medical release with no restrictions. The EEOC claims that had Wal-Mart inquired further, it would have known the accommodation need was temporary and in any case, that Wal-Mart easily could have accommodated the restriction.
Under the consent decree settling the suit, Wal-Mart will conduct annual live ADA training of management officials at its Carlsbad store and post a notice on its agreement with the EEOC so that employees are aware of procedures for reporting disability discrimination. Wal-Mart also committed to not require disabled workers to produce a full release from their doctor upon returning from a medical leave. Further, Wal-Mart agreed to engage in an interactive process with disabled employees to find a reasonable accommodation to assist them in performing their jobs and to report future requests for accommodation, as well as charges and lawsuits alleging disability discrimination to the EEOC for the duration of the decree.
Title I of the ADA prohibits employers from discriminating against individuals on the basis of disability in various aspects of employment. The ADA’s provisions on disability-related inquiries and medical examinations reflect Congress’s intent to protect the rights of applicants and employees to be assessed on merit alone, while protecting the rights of employers to make sure that individuals in the workplace can efficiently perform the essential functions of their jobs. An employer generally violates the ADA if it requires its employees to undergo medical examinations or submit to disability-related inquiries that are not related to how the employee performs his or her job duties, or if it requires its employees to disclose overbroad medical history or medical records. Title I of the ADA also generally requires employers to make reasonable accommodations to employees’ and applicants’ disabilities as long as this does not pose an undue hardship or the employer the employer otherwise proves employing a disabled person with reasonable accommodation could not eliminate significant safety concerns. Employers generally bear the burden of proving these or other defenses. Employers are also prohibited from excluding individuals with disabilities unless they show that the exclusion is consistent with business necessity and they are prohibited from retaliating against employees for opposing practices contrary to the ADA. Violations of the ADA can expose businesses to substantial liability.
As reflected by the Wal-Mart, violations of the employment provisions of the ADA may be prosecuted by the EEOC or by private lawsuits and can result in significant judgments. Disabled employees or applicants that can prove they fully were denied reasonable accommodations or otherwise subjected to prohibited disability discrimination under the ADA generally can recover actual damages, attorneys’ fees, and up to $300,000 of exemplary damages (depending on the size of the employer).
The lawsuit against Wal-Mart is part of a wave of lawsuits in which the EEOC or other agencies under the Obama Administration are aggressively challenging medical examination and other medical screenings by private and public employers. In the Wal-Mart case, the suit challenged an employer’s refusal to provide requested accommodations. In other cases, however, the EEOC or other agencies under the Obama Administration also have challenged medical inquiries made by an employer to employees during or returning from leave. Both types of suits send clear signals that employers should use care in making medical inquiries and responding to requests for accommodation from employees taking or returning from medical leaves. See, e.g., Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s.
To help mitigate the expanded employment liability risks , businesses generally should act to manage their exposures. Management needs to recognize the likely need to defend medical inquiries, decisions to refuse accommodation requests or other similar actions that arise when dealing with employees taking or returning from medical leave due to a disability, illness or injury. Employers need to critically check and document the legitimate business justification for making a medical inquiry or refusing a requested accommodation based on a well-documented investigation and analysis tailored to the specific situation of each requesting employee.
Businesses also should consider tightening their documentation regarding their procedures and processes governing the collection and handling records and communications that may contain information that could be helpful or hurtful in the event of a discrimination charge. Businesses need to ensure that all required records and statistics are collected. In addition, businesses also should consider strengthening record creation and retention efforts to help preserve other evidence that could be invaluable to defending charges and change the way that decisions are made and documented to position their organizations to more effectively demonstrate the defensibility of their employment and other business activities against potential nondiscrimination charges.
As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under the new genetic information nondiscrimination and privacy rules enacted as part of the Genetic Information and Nondiscrimination Act (GINA) signed into law by President Bush on May 21, 2008. Effective November 21, 2009, Title VII of GINA amends the Civil Rights Act to prohibit employment discrimination based on genetic information and restricts the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws. For instance, GINA’s employment related provisions include rules that will:
- Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
- Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
- Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
- Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
- Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
- Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
- Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
- Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.
These employment provisions of GINA are in addition to amendments to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the ADAAA, GINA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Cynthia Marcotte Stamer.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mailto cstamer@solutionslawyer.net
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation |
Permalink
Posted by Cynthia Marcotte Stamer
February 25, 2013
The U.S. Department of Health and Human Services (HHS) on February 22, 2013 released its Final Rule implementing many of the key market reform provisions of the Patient Protection and Affordable Care Act, as amended by the Health Care and Education Reconciliation Act of 2010 (the “Affordable Care Act”) applicable to non-grandfathered health plans and health insurance issuers.
The 145 page regulations and associated guidance package scheduled for official publication in the Federal Register on February 27, 2013 clarifies and implements the Affordable Care Act’s provisions relating to Guaranteed Availability and Renewability; Health Insurance Premiums; Single Risk Pool; Catastrophic Plans, Utilization Data Collection and Reporting under the Federal Rate Review Program and certain other matters.
Among other thing, the Final Regulations:
- Clarify the approach HHS will use to enforce the applicable requirements of the Affordable Care Act with respect to health insurance issuers and group health plans that are nonfederal governmental plans
- Amend the standards for health insurance issuers and states on reporting, utilization, and collection of data under the federal rate review program
- Revise the timeline for states to propose state-specific thresholds for review and approval by the Centers for Medicare & Medicaid Services (CMS)
- Allow health insurance issuers to vary the premium rate for health insurance coverage in the individual and small group markets only based on family size, geography, and age and tobacco use within limits
- Direct health insurance issuers to offer coverage to and accept every employer or individual who applies for coverage in the group and individual market, subject to certain exceptions including how these requirements inter-relate with the Affordable Care Act’s restrictions on pre-existing condition limitations and exclusions
- Direct health insurance issuers to renew or continue in force coverage in the group and individual market, subject to certain exceptions
- Codify the requirement that issuers maintain a single risk pool for the individual market and a single risk pool for the small group market (unless a state decides to merge the markets into a single risk pool)
- Outline standards for enrollment in catastrophic plans for young adults and people who cannot otherwise afford health insurance
- Amend the standards under the rate review program in 45 CFR part 154 by among other things, changing the timeline for states to propose state-specific thresholds for review and approval by CMS, requiring health insurance issuers to submit data relating to proposed rate increases in a standardized format specified by the Secretary of HHS and modifying criteria and factors for states to have an effective rate review program
Along with responding to these regulations, health insurers, group health plans and their insurers and others need to stay tuned. These regulations are just one of a deluge of regulations and other interpretations that HHS and other agencies are rolling out in the rush to meet the impending deadlines for the implementaton of the Affordable Care Act. For instance, along with this guidance, HHS along with the Internal Revenue Service and Employee Benefit Security Administration also last week issued FAQ XII, which discusses the co-pay, deductible and certain other aspects of the cost sharing limits of the Affordable Care Act. In previous weeks, the agencies also have issued or proposed regulations about waiting period, employer shared responsibility, essential health benefits, and various other elements of the rules. Additional guidance is impending.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized as a knowledgable and innovative health benefit thought leader by business and government leaders for her extensive work, publications and leadership on health benefit and insurance and other related employee benefits, insurance, human resources and health care matters, Ms. Stamer has advised and defended employer and other health plan sponsors, administrators and fiduciaries, insurers, and others about benefit design, compliance, administration and defense for more than 25 years. Her work includes highly pragmatic, leading edge work helping clients to design, deploy, administer and defend catastrophic, mini-med, expatriate and medical tourism, occupational injury and 24-hour coverage, HRA, HSA HFSA and other defined contribution, Medicare Advantage, and other health plans, policies and practices to comply with the Affordable Care Act, HIPAA, ERISA, COBRA, Mental Health Parity, Internal Revenue Code, labor and employment, privacy, managed care and insurance and other federal and state laws and regulations.
In addition to her extensive legal resume, Ms. Stamer also is a highly regarded industry thought leader and author with extensive involvement in the leadership of a broad range of professional and civic organizations. For instance, Ms. Stamer is the founder and executive director of the Coalition for Responsible Health Care Policy and its PROJECT COPE; The Coalition on Patient Empowerment; a Fellow in the American College of Employee Benefits Counsel, the American Bar Association and the State Bar of Texas; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group; the Immediate Past Chair of the ABA RPTE Employee Benefit & Other Compensation Committee and the current ABA RPTE Employee Benefit & Other Compensation Committee Welfare Benefits Committee Co-Chair; a Council Member of the ABA Joint Committee on Employee Benefits; Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee; Immediate Past Gulf States Area TEGE Council Exempt Organization Coordinator; a current or former Editorial Advisory Board Member of Insurance Thought Leadership, HR.com, Employee Benefit News, the BNA Employee Benefits CD-Rolm and various other BNA HR and Employee Benefits publications; a former national board member and Dallas Chapter President of WEB, Network of Benefits Professionals; a former Southwest Benefits Association Board Member; the past Dallas HR Government Relations Committee Chair; a former SHRM Region IV Board Member and National Consultants Forum Board Member,; past Dallas Bar Association Employee Benefits & Compensation Committee Chair, and a former Texas Association of Business State Board and Regional and Dallas Chapter Chair.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- FTC, HIPAA Rules Require Health Plans & Employers Strengthen Data Security on Mobile Devices and Applications
- 3/13 JCEB Teleconference Explores Foreign Transferees: Outbound, Inbound, Equity And Treaty Issues
- Stamer Talks on “What the Wind Blew In: Coping with Health Care Reform: 2013 and Beyond” May 2 At 24th Annual RPTE Spring Symposia In Washington, D.C.
- IRS Will Begin Accepting Returns Claiming Education Credits By Mid-February
- IRS Shares Procedures Employers Use To Claim Increased Monthly Transit Benefit Exclusion Allowed By Administrative Taxpayer Relief Act
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on HHS Releases Final Rule on Health Insurance Market, Rate Review, Pre-Existing Conditions & Other ACA Market Reform Rules |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
February 23, 2013
Thinking about or using mobile devices and applications in your heath care, health plan, workforce or related operations or struggling to meet the demands of employees, plan members or others to allow use of these tools? Be sure that you’ve taken appropriate steps to design, implement and manage legal responsibilities and risks associated with the development and use of these tools.
While the popularity, accessibility and cost-effectiveness of mobile devices and applications provides a strong incentive for health and other employee benefit plans, employers, their business associates, workforce members and customers to use mobile devices and applications, the use of these technologies and applications to collect, access, or use personal health care, financial, or other sensitive information presents special challenges and risks. Unfortunately, as the use of these tools proliferates, federal officials are increasingly concerned that the data security protections afforded by many of the devices and applications in use on these highly popular smart phone, tablet and other mobile devices and applications is highly lacking. See FTC Settlement With Mobile Device & App Developer Shows Developers & Businesses Need To Manage Mobile App & Data Security.
As federal regulators and law enforcement responds to growing concerns about cyber security and other risks, heath care, health plan and other businesses, their employees, customers, and other business partners jumping on the mobile device and application bandwagon, health, application bandwagon, and the device and application developers developing and offering these tools must take appropriate steps to manage the personal health, financial, and other sensitive information and data that these tools use, create, access or disclose.
Of course, most health plan sponsors, fiduciaries, administrators and service providers already recognize the need to use care when dealing with health plan data. The Health Insurance Portability & Accountability Act (HIPAA) generally requires that health care providers, health plans, health care clearinghouses and their businesses associates safeguard personal health care information or “PHI” and restrict its use, access and disclosure in accordance with the extensive and highly detailed requirements of the Privacy, Security and Breach Notification Regulations of the Department of Health & Human Services Office of Civil Rights (OCR).
OCR’s collection of several multi-million dollar settlements as well as its statements in its recent restated HIPAA regulations and other OCR guidance make clear that OCR views HIPAA as imposing significant responsibilities upon covered entities and their business associates to safeguard and restrict access to PHI on mobile devices and applications. OCR’s Long-Anticipated Omnibus HIPAA Privacy, Security, Breach Notification & Enforcement Rule Tightens Privacy Requirements, Require Action; Breaches resulting from the loss or theft of unencrypted ePHI on mobile or other computer devices or systems has been a common basis of investigation and sanctions since that time, particularly since the Breach Notification rules took effect. OCR Pops Idaho Hospice In 1st HIPAA Breach Settlement Affecting < 500 Patients; Providence To Pay $100000 & Implement Other Safeguards; OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website. These actions and statements of OCR provide a clear warning to HIPAA-covered entities and their business associates to expect significant consequences for failing to properly encrypt and safeguard ePHI used, accessed or disclosed on mobile devices and applications.
Of course, HIPAA isn’t the only law and health plans should not be the only area of concern when employers or their health or other employee benefit plan fiduciaries and service providers are considering mobile device and application use. In addition to HIPAA’s health plan requirements concerning PHI, mobile devices and applications used in connection with employment, benefit plan, and related operations also can trigger a host of privacy, data security and other rules requiring data security and other safeguards. Federal laws like the Internal Revenue Code, the Fair Credit Reporting Act, Graham-Leech-Biliey, the Fair & Accurate Credit Transactions Act (FACTA) or other Federal Trade Commission (FTC) Rules, state data security, data breach, identity theft or other privacy rules or both are just a few of the many and constantly expanding regulatory requirements that can apply. Depending on the nature of the data and the circumstances of the unanticipated use or disclosure, invasion of privacy or other common or statutory laws also may come into play.
With the use of these applications by consumers and business proliferates, Congress, OCR, the FTC, state regulators and others are upping the responsibilities and the liability of businesses that fail to appropriately consider and implement security in their mobile devices and applications. Following on OCR’s restatement of its HIPAA regulations, the Obama Administration’s announcement of new cyber security initiatives, and a plethora of other federal and state regulatory and enforcement actions against businesses for data security missteps, the FTC recently launched a campaign to ensure that companies secure the software and devices mobile device and application providers provide consumers.
Earlier this month, the FTC introduced Mobile App Developers: Start with Security, a new business guide that encourages app developers to aim for reasonable data security.
On June 4, 2013, the FTC also plans to host a public forum on malware and other mobile security threats in order to examine the security of existing and developing mobile technologies and the roles that various members of the mobile ecosystem can play in protecting consumers.
Along side this educational outreach, the FTC also is moving to punish businesses that fail to act responsibly to protect sensitive data. This trend is illustrated by the FTC’s announcement this week of its first settlement with a mobile device manufacturer.
FTC Charges Against HTC America
This week, the FTC announced that mobile device giant HTC American, Inc. will to settle FTC charges that the company failed to take reasonable steps to secure the software it developed for its smart phones and tablet computers and introduced security flaws that placed sensitive information about millions of consumers at risk.
A leading mobile device manufacturer in the United States, HTC America develops and manufactures mobile devices based on the Android, Windows Mobile, and Windows Phone operating systems. HTC America has customized the software on these devices in order to differentiate itself from competitors and to comply with the requirements of mobile network operators.
In its first-ever complaint against a mobile device or application developer, the FTC charged HTC America failed to incorporate and administer appropriate safeguards for personal financial and other sensitive data accessed and used in these applications when designing or customizing the software on its mobile devices. Among other things, the complaint alleged that HTC America failed to provide its engineering staff with adequate security training, failed to review or test the software on its mobile devices for potential security vulnerabilities, failed to follow well-known and commonly accepted secure coding practices, and failed to establish a process for receiving and addressing vulnerability reports from third parties.
To illustrate the consequences of these alleged failures, the FTC’s complaint details several vulnerabilities found on HTC America’s devices, including the insecure implementation of two logging applications – Carrier IQ and HTC Loggers – as well as programming flaws that would allow third-party applications to bypass Android’s permission-based security model.
Due to these vulnerabilities, the FTC charged, millions of HTC devices compromised sensitive device functionality, potentially permitting malicious applications to send text messages, record audio, and even install additional malware onto a consumer’s device, all without the user’s knowledge or consent. The FTC alleged that malware placed on consumers’ devices without their permission could be used to record and transmit information entered into or stored on the device, including, for example, financial account numbers and related access codes or medical information such as text messages received from healthcare providers and calendar entries about doctor’s appointments. In addition, malicious applications could exploit the vulnerabilities on HTC devices to gain unauthorized access to a variety of other sensitive information, such as the user’s geolocation information and the contents of the user’s text messages.
Moreover, the FTC complaint alleged that the user manuals for HTC Android-based devices contained deceptive representations, and that the user interface for the company’s Tell HTC application was also deceptive. In both cases, the security vulnerabilities in HTC Android-based devices undermined consent mechanisms that would have otherwise prevented unauthorized access or transmission of sensitive information.
HTC America Settlement
The settlement not only requires the establishment of a comprehensive security program, but also prohibits HTC America from making any false or misleading statements about the security and privacy of consumers’ data on HTC devices. Under the settlement agreement, HTC American must:
- Fix vulnerabilities found in millions of HTC devices;
- Establish a comprehensive security program designed to address security risks during the development of HTC devices; and
- Undergo independent security assessments every other year for the next 20 years.
HTC America and its network operator partners are also in the process of deploying the security patches required by the settlement to consumers’ devices. Many consumers have already received the required security updates. The FTC is encouraging consumers using HTC America applications to apply the updates as soon as possible.
The FTC Commission vote to accept the consent agreement package containing the proposed consent order for public comment was 3-0-2, with Chairman Jon Leibowitz not participating and Commissioner Maureen Ohlhausen recused. The FTC will publish a description of the consent agreement package in the Federal Register shortly.
In accordance with FTC procedures, the settlement agreement will be subject to public comment through March 22, after which the Commission will decide whether to make the proposed consent order final. Interested parties can submit comments electronically or in paper form using instructions in the “Invitation To Comment” part of the “Supplementary Information” section. Comments in paper form should be mailed or delivered to: Federal Trade Commission, Office of the Secretary, Room H-113 (Annex D), 600 Pennsylvania Avenue, N.W., Washington, DC 20580. The FTC is requesting that any comment filed in paper form near the end of the public comment period be sent by courier or overnight service, if possible, because U.S. postal mail in the Washington area and at the Commission is subject to delay due to heightened security precautions.
Act To Manage Mobile Application Device & Security
Given the expanding awareness, expectations and enforcement of OCR, FTC and others, health care, health plan and other industry participants deciding whether and when to use, or allow others to use mobile devices or applications to access data or carry out other activities and the mobile device or other technology developers and providers offering products or services to these organizations must get serious about security.
These and other related activities send a clear message that health care, health insurance mobile device and application users and developers must incorporate and administer appropriate processes and safeguards to protect PHI, personal financial and other sensitive data. In response to these developments, industry mobile device and application developers and the health care, health insurance and other businesses must consider carefully before deploying or allowing others to deploy or use these tools in relation to data within their operations or systems. Before and when using or permitting customers, business partners, employees or others to use tools, these organizations must ensure the adequacy of the design and security safeguards for their devices, software and applications, as well as their disclaimers and associated consumer disclosures and consents. Because of the special legal and operational expectations for these organizations, health care, health insurance and other industry provides must resist pressure to allow the use of these tools unless and until they can verify that these legal and operational requisites are fulfilled.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on FTC, HIPAA Rules Require Health Plans & Employers Strengthen Data Security on Mobile Devices and Applications |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
February 19, 2013
Cynthia Marcotte Stamer will share her insights on health and welfare benefit challenges for multinational employers as one of the featured panelists on the “Foreign Transferees: Outbound, Inbound, Equity And Treaty Issues” Teleconference hosted by the American Bar Association Joint Committee on Employee Benefits on March 13, 2013 from 10:00-11:30 a.m. Central Time.
- Intended to help broad-based U.S. and European community benefits attorneys and others seeking to understand common and unique issues associated with employee transferees, granting of equity compensation and associated treaty issues, including:
- Basic issues associated with transfers including granting of past service credits, vesting and distribution issues
- Case studies involving employee transfers between the U.S. and the UK.
- Use of international deferred compensation programs.
- Unique health and welfare issues associated with international transfers.
- Interesting/Global equity issues to avoid.
Moderated by Elizabeth Drigotas, PriceWaterhouseCoopers, Washington, DC, the program will feature a diverse and highly experienced group of distinguished government and private speakers including:
- M. Grace Fleeman, Senior Technical Reviewer, Branch 1, (Associate Chief Counsel International)), Internal Revenue Service, U.S. Department of the Treasury, Washington, DC (invited)
- Andrew C. Liazos, McDermott Will & Emery, Boston, MA
- Matthew Preston, Clifford Chance, London, UK
- Cynthia Marcotte Stamer, Cynthia Marcotte Stamer, PC, Addison, TX.
To register or for additional information, see here.
About Ms. Stamer
Sought out nationally and internationally as an industry thought leader and problem solver, attorney, Cynthia Marcotte Stamer has more than 25 years experience helping domestic and foreign private and public businesses, employer and union plan sponsors, health and other employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental and community leaders and others develop, implement, administer and defend creative, legally compliant and operationally effective health and other employee benefit, employment, insurance, pension and retirement, health care, workers’ compensation and workforce plans, practices, and policies.
Recognized in International Who’s Who, the founder and Executive Director of Project COPE: The Coalition on Patient Empowerment and its affiliate, the Coalition on Responsible Health Policy; a Fellow in the American College of Employee Benefits Counsel, American Bar Association, and State Bar of Texas; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Immediate Past Chair of the ABA RPTE Employee Benefit & Other Compensation Committee, current ABA RPTE Employee Benefit & Other Compensation Committee Welfare Benefits Committee Co-Chair and Substantive Groups Committee Member, and a Council Member of the ABA Joint Committee on Employee Benefits, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, and Immediate Past Gulf States Area TEGE Council Exempt Organization Chair, Ms. Stamer helps these and other clients. to design, document, administer and defend managed care and insurance programs, processes, and products; to monitor and manage evolving regulatory, contractual and fiduciary obligations and risks; to draft, negotiate, interpret and enforce managed care and other contracts, plan documents, insurance policies, administrative services agreements, and other agreements, policies, procedures and controls; to credential, monitor and manage fiduciaries, service providers, consultants and others providing services relating to programs; to conduct and defend litigation, audits, and other enforcement actions; to deal with legislators, regulators, auditors and others; and to fulfill legal obligations, mitigate legal risks and improve operational effectiveness.
As a core focus of her practice, Ms. Stamer continuously counsels, represents and defends self-insured and insured managed care and health, disability and welfare, pension, deferred compensation and other employee benefit plans; employer, association, insurer, and other employee benefit and insurance program sponsors; plan fiduciaries, administrators, brokers, consultants and other service providers; Medicare and Medicaid Advantage and other group, individual, stop-loss and other reinsurance, fiduciary liability and other insurers; health and insurance technology and other outsourcing companies; human resources, insurance and employee benefit consulting organizations; and other insurance, employee benefit and human resources industry clients, domestic and foreign governments and others about a diverse range of employee benefit, insurance, employment, tax, regulatory, risk management, public policy and related matters.
Ms. Stamer’s health benefit experience includes extensive and highly-innovative dealings with insured and self-insured managed care, defined contribution, indemnity and other health benefit, disability, life, occupational injury, Medicare and Medicaid Advantage, and other welfare benefit and insurance plans and policies; and a wide range of other employee benefits, compensation, insurance, equity and other related arrangements. Her work includes leading edge development and use of 24-hour coverage and other occupational injury, ex-pat and other medical tourism products, HRA, HSA, HRA and other defined contribution, hi-deductible, deductible reimbursement, min-med and other limited benefit plans, 24-hour and occupational benefit, fraternal benefit and association, and other medical programs as well as a broad range of claims, appeals, audit, and other administrative processes and tools designed to promote defensibility and mitigate risks.
Along side this domestic work, Ms. Stamer also has extensive international experience. A primary drafter of the Bolivian Social Security privatization law with extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on design, administration, operations, compliance, public policy and regulatory, and other challenges arising in the administration of multinational workforces and populations. Throughout her career, Ms. Stamer has advised both U.S. based businesses and foreign owned or operated businesses about design and administration of employment, employee benefit, worker’s compensation, employment tax, occupational safety, discipline and promotion, collective bargaining, recruiting, compliance, risk management and other personnel practices for multinational workforces. She has worked extensively on the design and administration of pension, severance, health and other benefit and compensation programs for their multinational workforce. She assists businesses with cross-border and domestic employment, consulting, independent contractor, subcontractor, employee leasing and other staffing and vendor agreements; multinational Foreign Corrupt Practices Act, Federal Sentencing Guidelines, and other compliance programs and practices; design, drafting, interpretation, implementation, and coordination pension, health care, severance, education, insurance, employment, tax, unemployment, disability, and other programs and requirements; represents and advises businesses, associations and government agencies before U.S. and foreign governments in connection with tax, employment, and other compliance matters, trade relationships and missions, public policy advocacy.
A widely published author and highly sought out speaker whose HR & Benefits Update has been recognized as among the “Top 50” HR Blogs To Watch, Ms. Stamer also regularly authors materials and conducts workshops and professional, management and other training on employee benefits, human resources, health care and other compliance and management topics for the ABA, Aspen Publishers, the Bureau of National Affairs (BNA), SHRM, World At Work, Insurance Thought Leadership, Government Institutes, Inc., Solutions Law Press, Inc., the Society of Professional Benefits Administrators, HealthLeaders, Managed Care Executive, CEO Magazine, Business Insurance and many other industry, professional and business publications. An Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com), Employee Benefit News, and other publications, Ms. Stamer also regularly serves on the faculty and planning committees of a multitude of symposium and other educational programs. For more details about Ms. Stamer’s services, experience, presentations, publications, and other credentials or to inquire about arranging counseling, training or presentations or other services by Ms. Stamer, see www.CynthiaStamer.com. Ms. Stamer also is widely recognized for her regulatory and public policy advocacy, publications, and public speaking on privacy and other compliance, risk management concerns. For the past two years, Ms. Stamer has serve as the appointed scribe for the ABA Joint Committee on Employee Benefits annual agency meeting with OCR and has lead numerous programs for the ABA and others on this topic. Her insights on HIPAA risk management and compliance frequently appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on 3/13 JCEB Teleconference Explores Foreign Transferees: Outbound, Inbound, Equity And Treaty Issues |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
February 5, 2013
Solutions Law Press, Inc. (SLP) readers qualify for up to a $400 discount on their registration to learn key insights from on strategies for charting the path forward to drive employee wellness, strengthen the workforce and impact global business competitiveness in the face of the impending health care reforms of the Patient Protection & Affordable Care Act from SLP Editor/Author Cynthia Marcotte Stamer and other leading employer health care decision makers at the 8th Annual Employer Health & Human Capital Strategy Congress that the World Health Congress is hosting on February 21-22, 2013 at The Westin Lake Mary, Orlando North Conference Center in Lake Mary, Florida.
About the Program
Nationally recognized industry thought leader and attorney SLP Editor attorney Cynthia Marcotte Stamer will help kick off the program when she joins a panel of prominent HR leaders discussing “Assessing Alternatives and Opportunities: Defined Contribution and Exchanges-What are the Long-Term Implications on Your Human Capital Strategy” beginning at 9:30 a.m. on February 21, 2013.
Following this keynote panel, attendees also will learn other key ideas and strategies to help their organizations cope with Health Care Reform as they participate in a host of other insightful and timely presentations by dynamic team of prominent HR and other industry experts and network with other management and human resources leaders .including:
- John Rother, National Coalition on Health care
- Shawn Leavitt, Carlson Companies
- Rebecca Mariet Lynn-Crockford, Suntrust Banks, Inc
- Jo-Ann Gastin, Lockton Companies, LLC
- Paul Grundy, M.D., Patient-Centered Primary Care Collaborative
- Roger C. Merring, M.D., Perdue Farm Inc.
- Sam Nussbaum, Wellpoint, Inc.
- Benjamin H. Hoffman, M.D., GE Energy
- Bruce Sherman, MD, Employers Health Coalition
For a full agenda and other details on the program, see here.
SLP Reader Registration Discount
SLP is delighted to announce that the World Health Congress is offering SLP readers the opportunity to claim a $400 discount off the otherwise applicable registration fee when registering for the program. To register and claim this discount, enter registration code “GHH925” at the designated location when registering for the program here.
About Ms. Stamer
Sought out nationally and internationally as an industry thought leader and problem solver, SLP Editor and author attorney, Cynthia Marcotte Stamer has spent more than 25 years helping private and public employers, employer and union plan sponsors, health and other employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental and community leaders and others develop, implement, administer and defend creative, legally compliant and operationally effective health and other employee benefit, employment, insurance, health care and workforce plans, policies, practices, operations and policies.
Recognized in International Who’s Who, the founder and Executive Director of Project COPE: The Coalition on Patient Empowerment and its affiliate, the Coalition on Responsible Health Policy; a Fellow in the American College of Employee Benefits Counsel, American Bar Association, and State Bar of Texas; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Immediate Past Chair of the ABA RPTE Employee Benefit & Other Compensation Committee, current ABA RPTE Employee Benefit & Other Compensation Committee Welfare Benefits Committee Co-Chair and Substantive Groups Committee Member, and a Council Member of the ABA Joint Committee on Employee Benefits, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, and Immediate Past Gulf States Area TEGE Council Exempt Organization Chair, Ms. Stamer helps these and other clients. to design, document, administer and defend managed care and insurance programs, processes, and products; to monitor and manage evolving regulatory, contractual and fiduciary obligations and risks; to draft, negotiate, interpret and enforce managed care and other contracts, plan documents, insurance policies, administrative services agreements, and other agreements, policies, procedures and controls; to credential, monitor and manage fiduciaries, service providers, consultants and others providing services relating to programs; to conduct and defend litigation, audits, and other enforcement actions; to deal with legislators, regulators, auditors and others; and to fulfill legal obligations, mitigate legal risks and improve operational effectiveness.
As a core focus of her practice, Ms. Stamer continuously counsels, represents and defends self-insured and insured managed care and health, disability and welfare, pension, deferred compensation and other employee benefit plans; employer, association, insurer, and other employee benefit and insurance program sponsors; plan fiduciaries, administrators, brokers, consultants and other service providers; Medicare and Medicaid Advantage and other group, individual, stop-loss and other reinsurance, fiduciary liability and other insurers; health and insurance technology and other outsourcing companies; human resources, insurance and employee benefit consulting organizations; and other insurance, employee benefit and human resources industry clients, domestic and foreign governments and others about a diverse range of employee benefit, insurance, employment, tax, regulatory, risk management, public policy and related matters.
Ms. Stamer’s health benefit experience includes extensive and highly-innovative dealings with insured and self-insured managed care, defined contribution, indemnity and other health benefit, disability, life, occupational injury, Medicare and Medicaid Advantage, and other welfare benefit and insurance plans and policies; and a wide range of other employee benefits, compensation, insurance, equity and other related arrangements. Her work includes leading edge development and use of 24-hour coverage and other occupational injury, ex-pat and other medical tourism products, HRA, HSA, HRA and other defined contribution, hi-deductible, deductible reimbursement, min-med and other limited benefit plans, 24-hour and occupational benefit, fraternal benefit and association, and other medical programs as well as a broad range of claims, appeals, audit, and other administrative processes and tools designed to promote defensibility and mitigate risks.
A primary drafter of the Bolivian Social Security privatization law with extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on public policy and regulatory advocacy on health and other employee benefits, human resources, insurance, tax, compliance and other matters and representing clients in dealings with the US Congress, Departments of Labor, Treasury, Health & Human Services, Federal Trade Commission, HUD and Justice, as well as a state legislatures attorneys general, insurance, labor, worker’s compensation, and other agencies and regulators. Her Patient Empowerment Toolkit™, Play4Life Community Program™, and other patient empowerment, health care quality, and other industry thought leadership, advocacy and solutions have drawn the attention of business, government and community leaders for their insightfulness and practicality.
A widely published author and highly sought out speaker whose HR & Benefits Update has been recognized as among the “Top 50” HR Blogs To Watch, Ms. Stamer also regularly authors materials and conducts workshops and professional, management and other training on employee benefits, human resources, health care and other compliance and management topics for the ABA, Aspen Publishers, the Bureau of National Affairs (BNA), SHRM, World At Work, Insurance Thought Leadership, Government Institutes, Inc., Solutions Law Press, Inc., the Society of Professional Benefits Administrators, HealthLeaders, Managed Care Executive, CEO Magazine, Business Insurance and many other industry, professional and business publications. An Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com), Employee Benefit News, and other publications, Ms. Stamer also regularly serves on the faculty and planning committees of a multitude of symposium and other educational programs. For more details about Ms. Stamer’s services, experience, presentations, publications, and other credentials or to inquire about arranging counseling, training or presentations or other services by Ms. Stamer, see www.CynthiaStamer.com or contact Ms. Stamer directly via email here or (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on SLP Readers Get $400 Discount To Learn Key Health Care Reform Coping Strategies At 2/21-22 Employer Health & Human Capital Strategy Congress In Lake Mary, FL |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 28, 2013
Cynthia Marcotte Stamer will a featured panelists discussing “What the Wind Blew In: Coping with Health Care Reform: 2013 and Beyond” on Thursday, May 2, 2013 at 24th Annual RPTE Spring Symposia at the Capital Hilton in Washington, DC. The Symposia scheduled to take place on May 2–3, 2013 will cover a broad range of timely topics on real estate, trusts and estates and other related concerns. To register, review the full agenda or get additional information about the Symposium, see here.
About Ms. Stamer
A noted Texas-based employee benefits and employment lawyer with extensive involvement in the leadership of the ABA and other professional organizations involved in employee benefits, health care and workforce matters, is nationally and internationally known for her innovative leadership and work as an attorney, consultant, policy advocate, speaker and author helping businesses, governments, and communities on health and other insurance and employee benefits, patient education and empowerment, wellness and disease management, and other programs, policies, and processes. For more than 24 years, Ms. Stamer’s legal practice has focused on advising and representing employers, insurers, health care providers, community leaders and governments about health care and employee benefits policy and process improvement, quality, performance management, education, compliance, communications, risk management, reimbursement and finance, and other related matters. In addition to her legal practice, Stamer also extensively consults and provides leadership to a broad range of clients, professional and civic organizations, and others on strategies for improving the health care system and the ability of health care providers, payers, employers, community organizations, government agencies to promote the ability of patients and their families to access cost-effective, quality, affordable health care and other resource needs. She also has worked extensively with a broad range of business and government clients on health care, pension, social security, workforce, insurance and many other related policy matters.
In addition to her service with the ABA, Ms. Stamer also is active in the leadership of a broad range of other professional and civil organizations. For instance, Ms. Stamer presently serves as Executive Director of Project COPE, the Coalition on Patient Empowerment and the Coalition for Responsible Healthcare Policy; Vice President of the North Texas Healthcare Compliance Professionals Association; Immediate Past Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Committee and its representative to the ABA Joint Committee on Employee Benefits and Vice Chair of its Welfare Benefits Committee; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; and as the Gulf Coast TEGE Council TE Committee Coordinator. She previously served as a founding Board Member and President of the Alliance for Healthcare Excellence, as a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early retirement intervention agency, The Richardson Development Center for Children; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a member of the Board of Directors of the Southwest Benefits Association; on numerous seminar faculties and in many other professional and civic leadership and volunteer roles.
Author of the hundreds of publications and workshops these and other employment, employee benefits, health care, insurance, workforce and other management matters, Ms. Stamer’s insights on employee benefits, insurance, health care and workforce matters in Atlantic Information Services, The Bureau of National Affairs, HealthLeaders, Modern Healthcare, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other publications. Nationally known for her work on health care reform and related matters, Ms. Stamer also regularly conducts training and speaks on these and other management, compliance and public policy concerns. For additional information about Ms. Stamer, upcoming training, publications or other materials or events, see here or contact Ms. Stamer directly via email here or (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Stamer Talks on “What the Wind Blew In: Coping with Health Care Reform: 2013 and Beyond” May 2 At 24th Annual RPTE Spring Symposia In Washington, D.C. |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 28, 2013
As preparations continue for the Jan. 30 opening of the 2013 filing season for most taxpayers, the Internal Revenue Service has announced that it beginprocessing of tax returns claiming education credits n by the middle of February.
Taxpayers using Form 8863, Education Credits, can begin filing their tax returns after the IRS updates its processing systems. Form 8863 is used to claim two higher education credits — the American Opportunity Tax Credit and the Lifetime Learning Credit.
The IRS emphasized that the delayed start will have no impact on taxpayers claiming other education-related tax benefits, such as the tuition and fees deduction and the student loan interest deduction. People otherwise able to file and claiming these benefits can start filing Jan. 30, 2013
As it does every year, the IRS reviews and tests its systems in advance of the opening of the tax season to protect taxpayers from processing errors and refund delays. The IRS discovered during testing that programming modifications are needed to accurately process Forms 8863. Filers who are otherwise able to file but use the Form 8863 will be able to file by mid-February. No action needs to be taken by the taxpayer or their tax professional. Typically through the mid-February period, about 3 million tax returns include Form 8863, less than a quarter of those filed during the year.
The IRS remains on track to open the tax season on January 30 for most taxpayers. The January 30 opening includes people claiming the student loan interest deduction on the Form 1040 series or the higher education tuition or fees on Form 8917, Tuition and Fees Deduction. Forms that will be able to be filed later are listed on IRS.gov.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on IRS Will Begin Accepting Returns Claiming Education Credits By Mid-February |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 28, 2013
The Administrative Taxpayer Relief Act retroactively increased monthly transit benefit limit that employers can provide to employees on a tax-free basis for 2012 from $125 per month to $240 per month. Notice 2013-8 provides a special correction procedure for employers who paid benefits in excess of $125 per month in 2012 and wish to make corrections on their fourth quarter Form 941.
Notice 2013-8 will be published in Internal Revenue Bulletin 2013-7 on February 11, 2013
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on IRS Shares Procedures Employers Use To Claim Increased Monthly Transit Benefit Exclusion Allowed By Administrative Taxpayer Relief Act |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Employer, Employment, transit benefit exclusion |
Permalink
Posted by Cynthia Marcotte Stamer
January 27, 2013
Since the enactment of the Patient Protection & Affordable Care Act (ACA), many employers searching for health plan solutions may have been asked to consider replacing or modifying their existing insured or self-insured group health plan with a “health reimbursement arrangement” (HRA) or other arrangement which would reimburse employees for premiums paid for individual health insurance policies. New guidance released on Thursday, January 24, 2013 indicates that such arrangements are prohibited as part of the ACA health care reforms.
“FAQS About Affordable Care Implementation (Part XI)” (FAQ) available here issued by the Departments of Labor, Health and Human Services (HHS), and the Treasury (collectively, the Agencies) on January 24, 2013 sends a clear message to employers that trying to escape ACA or other federal group health plan mandates by replacing their traditional insured or group health plans or policies with health reimbursement arrangements (HRAs) or other arrangements under which the employer agrees to provide a fixed defined contribution to be used to buy or reimburses employees for buying individual health insurance generally won’t pass legal muster. The FAQ also indicates that employers sponsoring HRAs that only reimburse medical expenses, not individual health insurance premiums also need to review their arrangements to verify that those programs also comply with ACA and other applicable rules.
Concerning the use of HRAs to pay for individual health insurance policy premiums, the FAQ states that PHS Act Section 2711 generally prohibits an employer-sponsored HRA cannot be integrated with individual market coverage or with an employer plan that provides coverage through individual policies. Under ACA, employers that improperly offer arrangements that violate PHS Section 2711 or other group health plans risk exposing themselves to liability for significant unanticipated health benefit claims, as well as other penalties and costs. Therefore, employers that have or are contemplating arrangements that provide or reimburse premiums for individual health insurance coverage are urged to contact qualified legal counsel with documented experience with ACA and other group health plan requirements for advice before establishing or continuing such arrangements.
The FAQ’s guidance about the use of individual insurance policies to arrange coverage for employees is one of several issues addressed in the FAQ and part of a wave of new guidance that has and is emerging as the Obama Administration moves to full implementation of the ACA reforms. Employers, plan fiduciaries, insurers, and others involved in the design or administration of health benefit programs need to monitor carefully this emerging guidance as they move quickly to tailor their programs in response to these evolving rules. For help monitoring or responding to these evolving rules, contact the author of this update, Cynthia Marcotte Stamer.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 25, 2013
The Justice Department’s recently Lesley University Settlement (Settlement) announced by the Justice Department on December, 21, 2012 should be a reminder to employers and others covered by the Americans With Disabilities Act (ADA) of the potential advisability of establishing policies or taking other steps to position their practices for providing food in the workplace or at workplace events or to the public to withstand challenge under the ADA.
While technically referring to only schools, its recognition of some food allergies as disabilities under the ADA makes the Settlement likely to have significant implications for other businesses and organizations regulated by the employment, public accommodation, education or other disability discrimination rules of the ADA under certain circumstances. Consequently, schools, as well as employers and businesses covered by the ADA should evaluate their practices for offering and providing accommodations for food allergies to minimize their exposure to disability discrimination charges under the ADA in light of the settlement.
Background of Lesley University Settlement
The charges of discrimination against Lesley University resulting in the Settlement challenged a university meal plan that Lesley University required all students living on campus to take part in, and pay for the meal plan. Lesley University mandated that each student buy the meal service plan – even if some students with severe allergies could not eat the food available through the plan without risk of illness. The Justice Department charged that Leslie University violated the ADA by failing to appropriate accommodate the special food needs for these students. The Settlement Agreement resolves Justice Department that Lesley University with illegally discriminating in violation of the ADA by failing to adequately accommodate the special food needs with severe food allergies that constituted a disability under the ADA.
While the Lesley University Settlement specifically concerned a school meal plan, the Justice Department’s treatment of persons with severe food allergies as disabled within the meaning of the ADA has potential implications for all types of entities regulated by the ADA. Meanwhile, schools in particular should carefully review the Settlement as the Justice Department says it expects some but all aspects of the Settlement “will serve as a model for other schools – particularly those that require students to participate in a meal plan.”
Under the Settlement, Lesley University agreed to act to change its food plan to ensure that its students with celiac disease and other food allergies to take advantage of and fully and equally enjoy the university’s food services in compliance with the ADA as well as requires Lesley to consider exempting from its mandatory plan students who cannot, because of disability, take full advantage of the University’s meal service plan.
Among other things, Lesley University agreed to:
- Provide gluten-free and allergen-free food options in its dining hall food lines in addition to its standard meal options;
- Allow students with known allergies to pre-order allergen-free meals;
- Display notices about food allergies and identify foods containing specific allergens;
- Train food service and university staff about food allergy-related issues;
- Provide a dedicated space in its main dining hall to store and prepare gluten-free and allergen-free foods; and
- Work to retain vendors that accept students’ prepaid meal cards that also offer food without allergens.
Food Allergies as Disability Under ADA
According to the Justice Department, a disability as defined by the ADA is a mental or physical impairment that substantially limits a major life activity, such as eating. Major life activities also include major bodily functions, such as the functions of the gastrointestinal system. Some individuals with food allergies have a disability as defined by the ADA – particularly those with more significant or severe responses to certain foods. This would include individuals with celiac disease and others who have autoimmune responses to certain foods, the symptoms of which may include difficulty swallowing and breathing, asthma, or anaphylactic shock.
Settlement Implications For Employers, Schools & Other Businesses
Since the ADA has a common disability definition, this means that the recognition of food allergies as a disability likely will be used in other situations involving employers under the ADA’s employment provisions, businesses under the public accommodation provisions or others.
While the Settlement reflects that food allergies may be disabilities, the Justice Department says the Settlement does not mean that the ADA requires that every place of public accommodation that serves food to the public under all circumstances provide gluten-free or allergen-free food. Accordingly to the Justice Department, the Lesley Agreement involved a mandatory meal program for a defined group of students. Because its meal plan was mandatory for all students living on campus, the Justice Department says the ADA required that the University make reasonable changes to the plan to accommodate students with celiac disease and other food allergies.
The Justice Department has pointed out that the rules governing when accommodation is required are different for schools versus restaurants or others that serve food to the general public. According to the Justice Department, the public accommodation provisions of the ADA may require a restaurant or other business to take some reasonable steps to accommodate individuals with disabilities where it does not result in “fundamental alteration” of that restaurant’s operations. Examples of such accommodations might include answering questions from diners about menu item ingredients, where the ingredients are known, or omitting or substituting certain ingredients upon request if the restaurant normally does this for other customers.
However, the Justice Department has indicated that for purposes of the ADA’s public accommodation provisions, organizations are not required to accommodations that would require that the business to make a “fundamental alteration” to its operations. For this purpose, the Justice Department has indicated that fundamental alteration is “a modification that is so significant that it alters the essential nature of the good or services that a business offers.” For example, the Justice Department says a restaurant is not required to alter its menu or provide different foods to meet particular dietary needs.
While the Equal Employment Opportunity Commission (EEOC) and not the Justice Department has authority for the interpretation and enforcement of the ADA’s employment provisions, employers also can expect that the EEOC and/or private plaintiff’s will follow the lead in arguing that food allergies may qualify as disabilities for purposes of determining when employers serving or offering food in workplaces or at work-related events also may be required to make or offer accommodations to address the special needs of individuals with disabilities.
Although many employers may be tempted to discount the relevance of the Justice Department’s recognition of food allergies as a disability based on pre Americans With Disabilities Act Amendment Act (ADAAA) cases that viewed food allergies as not rising to the level of a disability under the ADA. Since the ADAAA has greatly expanded the definition of a disability and made it easier for an employee to show that a condition is disabling within the meaning of the ADA, employers are cautioned against assuming that food allergies or other disabilities don’t qualify as disabilities based on pre-ADAAA precedent.
The ADAAA makes it more difficult for employers to establish that food allergies or other medical conditions are not disabilities. As amended by the ADAAA, the ADA presently extends covers individuals as disabled when they have conditions that are “episodic or in remission,” as long as the condition causes symptoms which affect a “major life activity” when active.
Also, the ADAAA now provides that employers can no longer consider whether an individual could ameliorate the effects of the condition through medication or whether other actions.
In reliance upon these changes, the EEOC now takes the position that allergies producing life-threatening reactions are per se substantially limiting under the ADAAA.
Given the likelihood that the EEOC and private plaintiffs now are likely to assert that individuals affected by food allergies rights to accommodation or other ADA based claims in reliance upon the ADAAA, the settlement is likely to fuel added claims against employers, as well as schools and businesses under the ADA’s public accommodations provisions. In response to these exposures, schools, businesses and employers should consider whether their existing practices and training of workers about ordering, offering or providing food should be tightened to reduce potential exposures under the ADA.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the ADAAA, GINA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Cynthia Marcotte Stamer.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mailto cstamer@solutionslawyer.net
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2013 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
©2013 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation |
Permalink
Posted by Cynthia Marcotte Stamer
January 25, 2013
The Department of Labor has extended the deadline for employers to notify employees about the existence of and their rights under the health exchanges required by new Section 18B of the Fair Labor Standards Act (FLSA), as added by Section 1512 of the Patient Protection & Affordable Care Act (ACA). The extension announced in Frequently Answered Question (FAQ) here provides a welcome temporary reprieve to employers who otherwise would have been required to notify employees by March 1, 2013.
As part of the impending implementation of ACA’s health care reform, FLSA § 18B generally requires each applicable employer provide each employee a written notice (Exchange Notice) in accordance with regulations promulgated by the Secretary of Labor:
- Informing the employee of the existence of Exchanges including a description of the services provided by the Exchanges, and the way the employee may contact Exchanges to request assistance;
- If the employer plan’s share of the total allowed costs of benefits provided under the plan is less than 60 percent of such costs, that the employee may be eligible for a premium tax credit under section 36B of the Internal Revenue Code (the Code) if the employee purchases a qualified health plan through an Exchange; and
- If the employee purchases a qualified health plan through an Exchange, the employee may lose the employer contribution (if any) to any health benefits plan offered by the employer and that all or a portion of such contribution may be excludable from income for Federal income tax purposes. The Department of Labor expects that the timing for distribution of notices will be the late summer or fall of 2013, which will coordinate with the open enrollment period for Exchanges.
Before the Department’s announcement in the FAQ, the deadline for employers to begin giving employees Exchange Notices was the later of March 1, 2013 or at the time of hiring. The FAQ extends this deadline until a date to be set by the Department in future guidance, which the Department expects will require employers to distribute the notices in the late summer or fall of 2013 to coordinate with the open enrollment period for Exchanges.
According to the announcement of the delay, the Department delayed the impending March 1, 2013 deadline to give the (Exchange Notice) to better coordinate with related Health and Human Service and Internal Revenue Service efforts and to allow more time to comply and to distribute the Exchange Notices to employees at a meaningful time.
In addition to providing added time to provide the Exchange Notice, the Department also has announced that it is considering providing model, generic language that employers could use to provide the Exchange Notice. to satisfy the notice requirement. As a compliance alternative, the Department also is considering allowing employers to meet the Exchange Notice requirement by providing employees with information using the employer coverage template as discussed in the preamble to the Proposed Rule on Medicaid, Children’s Health Insurance Programs, and Exchanges: Essential Health Benefits in Alternative Benefit Plans, Eligibility Notices, Fair Hearing and Appeal Processes for Medicaid and Exchange Eligibility Appeals and Other Provisions Related to Eligibility and Enrollment for Exchanges, Medicaid and CHIP, and Medicaid Premiums and Cost Sharing (78 FR 4594, at 4641), which will be available for download at the Exchange web site as part of the streamlined application that will be used by the Exchange, Medicaid, and CHIP.
The Exchange Notice is just one of a multitude of notices and other mandates that ACA requires that employers or their health plans, insurers, or both to meet. Although the Exchange Notice gives employers a little more time to provide the Exchange Notices, employer and other health plan sponsors, fiduciaries, administrators and insurers are urged to continue to diligently move forward to update their plans, communications, processes and other arrangements to comply with existing and impending ACA mandates while keeping a watchful eye on for additional guidance that may require additional tailoring of these arrangements.
Stay tuned for updates about future guidance on complying with the notice requirement under FLSA section 18B and other developments.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 23, 2013
Cynthia Marcotte Stamer will share key information and practical strategies for “Coping with Health Care Reform Now” at the Dallas Chaper ICEBS Valentines Day luncheon meeting on February 14, 2012. The meeting is scheduled from 11:30 a.m. to 1:30 p.m on February 14, 2012 at Haggar Clothing Company at 11511 Luna Road, Dallas, Texas . Interested persons may register or get other details at http://www.dfwiscebs.org.
With the initial debate about the Constitutionality of the Patient Protection & Affordable Care Act (ACA) decided and making a Congressional reprieve highly improbable, employer and other health plan sponsors, insurers, fiduciaries and administrators are scrambling to update plan documents, communications, processes and procedures to meet current ACA and other health plan rules, while bracing to cope with the sweeping health care reforms slated to take effect in 2014. These already daunting tasks are made more challenging by the continuing uncertainty of the constantly evolving regulations, evolving marketplace, increases in health plan costs and ever-shrinking corporate budgets.
To help health plan sponsors, fiduciaries, administrators and insurers deal with the tough business of implementation, attorney Cynthia Marcotte Stamer will discuss practical strategies, legal updates and other information needed for to cope with health care reform now and to prepare to meet future health plan regulations and challenges including:
- The Latest On Key ACA & Other Health Care Reform Regulations Such As ACA’s Requirements On Fees Employers Sponsoring Self-Insured Health Plans & Insurers Must Pay To Fund The Patient-Centered Outcomes Research Institute, Contraceptive and Other Preventive Services, Nondiscrimination, Essential Health Benefits, Internal Claims and Appeals and External Review, Medical Loss Ratios, Large Employer Automatic Enrollment, Summary of Benefits & Coverage, Culturally & Linguistically Appropriateness, Value-Based Insurance Design, Wellness Programs, Exchanges, the Employer Pay-Or-Plan Mandates, Wellness Reporting, Wellness Programs, W-2 Reporting of Employer Provided Health Coverage, Employer Plan Minimum Value & The Premium Tax Credit And Other ACA & Other Federal Health Plan Mandates;
- Key Changes To HIPAA Privacy Regulations & What Health Plans & Employers Should Expect To Be Required To Do To Comply With These Changes By the September, 2013 Deadline;
- What’s Happened, Happening & Likely To Happen With Exchanges;
- A 12-Step Practical Process For Helping Employers Managing ACA & Other Health Plan Compliance Responsibilities & Risks; and
- Tips On What To Watch For And Options For Maintaining Flexibility To Respond To Evolving Rules; and
- Answer Common Questions That Health Plan Sponsors and Administrators Are Struggling With Submitted By Audience Members
Registrants are encouraged to help shape the program to reflect their questions and concerns by e-mailing their proposed questions prior to the program to cstamer@solutionslawyer.net. The program’s educational* discussion will be tailored taking into account this input with significant time set aside to share practical information and possible approaches for addressing questions and concerns of shared concern identified from this audience input.
About Ms. Stamer
A Fellow in the American College of Employee Benefits Counsel, the American Bar Association & the State Bar of Texas, recognized in International Who’s Who, and Board Certified in Labor & Employment Law, Cynthia Marcotte Stamer is nationally and internationally recognized for her extensive and highly practical, solutions-oriented health plan work, advocacy, publications, programs and leadership.
For more than 25 years, Ms. Stamer has advised and represented private and public employers, employer and union plan sponsors, employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governments and others on health and other employee benefit, employment, insurance and health care compliance, risk management, public policy, administration and defense. Throughout her career, Ms. Stamer has worked extensively with employer and other health plan sponsors, insurers, plan administrators and other service providers, outsourcers and others to develop innovative health benefit programs and solutions and to document, administer and defend those arrangements in the mist of rising costs, evolving regulations and changing markets.
A primary drafter of the Bolivian Social Security privatization law with extensive regulatory and public policy experience, Ms. Stamer has been involved domestically and internationally as an advocate and advisor on health care, pension and Social Security, workforce and insurance reform and regulation. She presently serves as the scribe for the ABA JCEB Annual Agency Meeting with the Office of Civil Rights. She also represents clients in dealings with the US Congress, Departments of Labor, Treasury, Health & Human Services, Federal Trade Commission, HUD and Justice, as well as a state legislatures attorneys general, insurance, labor, worker’s compensation, and other agencies and regulators.
Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and the ABA RPTE Employee Benefits Group, Ms. Stamer presently serves as Co-Chair of the ABA RPTE Section Welfare Plan Committee; Vice Chair of the ABA TIPS Employee Benefit Committee; as a Council Representative of the ABA Joint Committee on Employee Benefits; an Editorial Advisory Board Member for the Institute of Human Resources (IHR/HR.com), Employee Benefit News and Insurance Thought Leadership; Editor and Publisher of various Solutions Law Press, Inc. publications, and previously served on the Editorial Advisor Board of the the BNA Employee Benefits CD-Rolm.
A popular and prolific author and speaker, Ms. Stamer’s Solutions Law Press, Inc. HR & Benefits Update publication was recognized as one of the Top 50 Human Resources Blogs To Watch in 2012. Ms. Stamer regularly authors materials and conducts workshops and professional, management and other training on employee benefits, human resources and related topics for the ABA, Aspen Publishers, the Bureau of National Affairs (BNA), SHRM, World At Work, Government Institutes, Inc., the Society of Professional Benefits Administrators and many other organizations. She also regularly serves on the faculty and planning committees of a multitude of symposium and other educational programs. For more details about Ms. Stamer’s services, experience, presentations, publications, and other credentials or to inquire about arranging counseling, training or presentations or other services by Ms. Stamer, see www.CynthiaStamer.com.
* Registrants are reminded that this discussion is provided for general information and educational purposes. Accordingly, registrants are reminded that the discussion does not constitute legal advice, a substitute for legal advice or establish an attorney-client or other professional relationship.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 17, 2013
Health plans, their employer or other sponsors, insurers, fiduciaries, administrative service providers and other business associates have a lot of work to do.
Health plans, health care clearinghouses and their business associates will need to review and update their policies and practices for handling and disclosing personally identifiable health care information (“PHI”) in response to the omnibus restatement of the Department of Health & Human Services (“HHS”) Office of Civil Rights (“OCR”) of its of its regulations (the “2013 Regulations”) implementing the Privacy and Security Rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The Rulemaking announced January 17, 2013 may be viewed here.
The 2013 Regulations Overview
Since 2003, HIPAA generally has required that health care providers, health plans, health care clearinghouses and their business associates (“Covered Entities”) restrict and safeguard individually identifiable health care information (“PHI”) of individuals and afford other protections to individuals that are the subject of that information. The 2013 Regulations published today complete the implementation of changes to HIPAA that Congress enacted when it passed the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009 as well as make other changes to the prior regulations that OCR found desirable based on its experience administering and enforcing the law over the past decade.
Since passage of the HITECH Act, OCR officials have warned Covered Entities to expect an omnibus restatement of its original regulations. While OCR had issued certain regulations implementing some of the HITECH Act changes, it waited to publish certain regulations necessary to implement other HITECH Act changes until it could complete a more comprehensive restatement of its previously published HIPAA regulations to reflect both the HITECH Act amendments and other refinements to its HIPAA Rules. The 2013 Regulations published today fulfill that promise by restating OCR’s HIPAA Regulations to reflect the HITECH Act Amendments and other changes and clarifications to OCR’s interpretation and enforcement of HIPAA.
Among other things, the 2013 Regulations:
- Revise OCR’s HIPAA regulations to reflect the HITECH Act’s amendment of HIPAA to add the contractors and subcontractors of health plans, health care providers and health care clearinghouses that qualify as business associates to the parties directly responsible for complying with and subject to HIPAA’s civil and criminal penalties for violating HIPAA’s Privacy, Security, and Breach Notification rules;
- Update previous interim regulations implementing HITECH Act breach notification rules that require Covered Entities including business associates to give specific notifications to individuals whose PHI is breached, HHS and in some cases, the media when a breach of unsecured information happens;
- Update interim enforcement guidance OCR previously published to implement increased penalties and other changes to HIPAA’s civil and criminal sanctions enacted by the HITECH Act;
- Implement HITECH Act amendments to HIPAA that tighten the conditions under which Covered Entities are allowed to use or disclose PHI for marketing and fundraising purposes and prohibit Covered Entities from selling an individual’s health information without getting the individual’s authorization in the manner required by the 2013 Regulations;
- Update OCR’s rules about the individual rights that HIPAA requires that Covered Entities to afford to individuals who are the subject of PHI used or possessed by a Covered Entity to reflect tightened requirements enacted by the HITECH Act that allow individuals to order their health care provider not to share information about their treatment with health plans when the individual pays cash for the care and to clarify that individuals can require Covered Entities to provide electronic PHI in electronic form;
- Revise the regulations to reflect amendments to HIPAA made as part of the Genetic Information Nondiscrimination Act of 2008 (GINA) which added genetic information to the definition of PHI protected under the HIPAA Privacy Rule and prohibits health plans from using or disclosing genetic information for underwriting purposes; and
- Clarifies and revises other provisions to reflect other interpretations and information guidance that OCR has issued since HIPAA was passed and to make certain other changes that OCR found appropriate based on its experience administering and enforcing the rules.
Liability & Enforcement Risks Heighten Need To Act To Review & Update Policies & Practices
The restated rules in the 2013 Regulations make it imperative that Covered Entities review the revised rules carefully and updated their policies, practices, business associate agreements, training and documentation to comply with the updated requirements and other enforcement and liability risks. OCR even prior to the regulations has aggressively investigated and enforced the HIPAA requirements.
The commitment of OCR to enforcement most recently was demonstrated by its recent settlement with Hospice of North Idaho (HONI). On January 2, 2013, OCR announced HONI will pay OCR $50,000 to settle potential HIPAA violations that occurred in connection with the theft of an unencrypted laptop computer containing ePHI. The HONI settlement is the first settlement involving a breach of ePHI affecting fewer than 500 individuals.
While the HONI settlement marks the first settlement on a small breach, this is not the first time OCR has sought sanctions against a covered entity for data breaches involving the loss or theft of unencrypted data on a Laptop, storage device or other computer device. Rather, OCR continues to rollout a growing list of enforcement actions demonstrating the potential risks of HIPAA violations are significant and growing. OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website; Providence To Pay $100000 & Implement Other Safeguards.
Coupled with statements by OCR about its intolerance, the HONI and other settlements provide a strong warning to covered entities of the need to carefully and appropriately manage their HIPAA encryption and other Privacy and Security responsibilities. Covered entities are urged to heed these warning by strengthening their HIPAA compliance and adopting other suitable safeguards to minimize HIPAA exposures.
In response to the 2013 Regulations and these expanding exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 17, 2013
Tbe Office of Civil Rights (OCR) has issued a letter to health care providers to ensure that they are aware of their ability under the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule to take action, consistent with their ethical standards or other legal obligations, to disclose necessary information about a patient to law enforcement, family members of the patient, or other persons, when they believe the patient presents a serious danger to himself or other people. For more information, see: http://www.hhs.gov/ocr/office/lettertonationhcp.pdf. The Guidance is released on the same day that OCR released its long-awaited omnibus restatement of its HIPAA regulations.
HIPAAFor Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance frequently appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on OCR Gives HIPAA Guidance On Safety Disclosures |
Data Security, GINA, Health Plans, Insurance | Tagged: HIPAA |
Permalink
Posted by Cynthia Marcotte Stamer
January 16, 2013
IRS Says Eligible Home-Based Businesses May Deduct up to $1,500; Saves Taxpayers 1.6 Million Hours A Year
The Internal Revenue Service (IRS) has announced a simplified option that many owners of home-based businesses and some home-based workers may use to figure their deductions for the business use of their homes.
In tax year 2010, the most recent year for which figures are available, nearly 3.4 million taxpayers claimed deductions for business use of a home (commonly referred to as the home office deduction).
The new optional deduction, capped at $1,500 per year based on $5 a square foot for up to 300 square feet, will reduce the paperwork and recordkeeping burden on small businesses by an estimated 1.6 million hours annually.
“This is a common-sense rule to provide taxpayers an easier way to calculate and claim the home office deduction,” said Acting IRS Commissioner Steven T. Miller. “The IRS continues to look for similar ways to combat complexity and encourages people to look at this option as they consider tax planning in 2013.”
The new option provides eligible taxpayers an easier path to claiming the home office deduction. Currently, the IRS generally requires a home-based business to fill out a 43-line form (Form 8829) often with complex calculations of allocated expenses, depreciation and carryovers of unused deductions. Taxpayers claiming the optional deduction will complete a significantly simplified form.
Though homeowners using the new option cannot depreciate the portion of their home used in a trade or business, they can claim allowable mortgage interest, real estate taxes and casualty losses on the home as itemized deductions on Schedule A. These deductions need not be allocated between personal and business use, as is required under the regular method.
Business expenses unrelated to the home, such as advertising, supplies and wages paid to employees are still fully deductible.
Current restrictions on the home office deduction, such as the requirement that a home office must be used regularly and exclusively for business and the limit tied to the income derived from the particular business, still apply under the new option.
The new simplified option is available starting with the 2013 return most taxpayers file early in 2014. Further details on the new option can be found in Revenue Procedure 2013-13, posted on IRS.gov. Revenue Procedure 2013-13 is effective for taxable years beginning on or after January 1, 2013, and the IRS welcomes public comment on this new option to improve it for tax year 2014 and later years. There are three ways to submit comments.
- E-mail to: Notice.Comments@irscounsel.treas.gov. Include “Rev. Proc. 2013-13” in the subject line.
- Mail to: Internal Revenue Service, CC:PA:LPD:PR (Rev. Proc. 2013-13), Room 5203, P.O. Box 7604, Ben Franklin Station, Washington, DC 20044.
- Hand deliver to: CC:PA:LPD:PR (Rev. Proc. 2013-13), Courier’s Desk, Internal Revenue Service, 1111 Constitution Avenue NW, Washington, DC, between 8 a.m. and 4 p.m., Monday through Friday.
The deadline for comment is April 15, 2013.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 16, 2013
Revenue Procedure 2013-15 provides the 2013 cost-of-living adjustments for inflation for certain items. The guidance includes adjustments to the tax tables, including items whose values were specified in the American Taxpayer Relief Act of 2012 (ATRA), such as:
- The beginning of the 39.6% income tax brackets;
- The beginning income levels for the limitation on certain itemized deductions; and
- The beginning income levels for the phaseout of the personal exemptions[
In addition Revenue Procedure 2013-5 modifies Revenue Procedure 2011-52 to reflect an amendment to section 132(f)(2) made by ATRA concerning qualified transportation fringe benefits. Specifically, for 2012, the monthly limitation regarding the aggregate fringe benefit exclusion amount for transit passes and transportation in a commuter highway vehicle is $240.
Revenue Procedure 2013-15 will be published in Internal Revenue Bulletin 2013-5 on January 28, 2013.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 14, 2013
Employers and others collecting, retaining or reporting employee or other tax identification numbers or other sensitive information for tax withholding or reporting purposes should take appropriate steps to protect that information against possible identity theft or other misuse.
The wealth of sensitive personal identification information and financial records makes tax records a highly attractive source of data for identity thieves. According to the Internal Revenue Service (IRS), tax-related identity theft incidents have risen significantly in recent years. Identity theft case receipts increased by more than 650 percent from FY 2008 to FY 2012. At the end of FY 2012, the IRS had almost 650,000 identity-theft cases in its inventory servicewide. The IRS reports the problem has grown worse as organized criminal actors have found ways to steal the Social Security numbers (SSNs) of taxpayers, file tax returns using those taxpayers’ names and SSNs, and obtain fraudulent tax refunds. Then, when the real taxpayer files a return claiming the refund, that return is rejected. The impact on victims is significant. More than 75 percent of taxpayers filing returns are due refunds, which average some $3,000 and are not paid until the IRS fully resolves a case.
When the IRS Commissioner testified in 2008 about identity theft before a Senate Finance Committee hearing. he stated: “My overall goal as the IRS Commissioner is that when a taxpayer [who is an identity theft victim] contacts us with an issue or concern, we have in place a seamless process that gets the issue resolved promptly.” Later that year, the IRS established an “Identity Protection Specialized Unit” (or “IPSU”), which was designed to provide centralized assistance to victims of identity theft. The National Taxpayer Advocate supported the commitment to centralized and prompt victim assistance.
Since that time, the IRS has created numerous task forces and other teams in recent years in an attempt to improve its identity theft processes, yet victims still face the same “labyrinth of procedures and drawn-out timeframes for resolution” that they faced five years ago. The IRS is instructing its employees to advise identity theft victims that it will take 180 days – half a year – to resolve their cases. Complicated cases inevitably will take longer. Thus, the IRS’s procedural changes are not providing faster relief.
The report also says the IRS has decided to reverse course and decentralize victim assistance. It recently created specialized units within each of 21 individual functions to work on identity theft cases, apparently under the belief that most identity theft cases involve a single issue that the relevant specialized unit can work most efficiently. The report expresses concern about this backtracking from a centralized approach.
The Taxpayer Advocate Service (TAS) itself handled nearly 55,000 identity theft cases in FY 2012, most of which involved multiple issues that required actions by multiple units. The report expresses concern that creation of 21 specialized units will erode the centralized role of the IPSU, require taxpayers to speak with multiple functions, increase the time it takes to resolve cases, and heighten the risk that some issues may not be addressed.
“Taxpayers need ‘one-stop shopping’ – a single point of contact they can work with to resolve all issues in their cases – and the IRS needs a ‘traffic cop’ to make sure that all units complete their actions and that parts of cases do not fall through the cracks,” Olson said. “And six months is an unacceptable period of time to expect taxpayer-victims to wait. The IRS must do more to provide the prompt and seamless assistance to identity theft victims that Commissioner Shulman promised.”
While the IRS continues to work on protecting taxpayer data against theft and investigating and resolving tax-related identity theft cases, businesses that collect, retain and report employee, contractor or other personal financial information for tax related or other purposes are urged to take steps to protect the data that they collect and retain against identity theft. Since identity theft may begin when a worker misrepresents his or her identity at the commencement of employment, many employers find it beneficial to take reasonable steps to verify the identity and veracity of the documentation that a worker presents when commencing employment. Once data is collected, businesses and others that have access to personal financial information or other data collected for tax purposes need to recognize their responsibility to safeguard that information against improper use and disclosure under the Internal Revenue Code as well as other applicable laws. If confronted with a “no-match” letter from the Social Security Administration or a complaint or other indication that a worker may have misrepresented his or her identity, or another indication of a breach of this data, businesses should contact experienced legal counsel to aid in the proper investigation of these concerns and the resolution of concerns resulting from this investigation. Where appropriate, the business may need to report its concerns to the IRS or advise a worker or other party reporting a likely identity theft of taxpayer information to the TAS or other appropriate officials.
Businesses needing assistance with investigation or mitigation of a potential theft of tax or other sensitive data, see www.cynthiastamer.com or contact attorney Cynthia Marcotte Stamer.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Tax-Related ID Theft Growing Problem For IRS, Taxpayers |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 11, 2013
As part of its continuing effort to boost retirement savings among Americans, the Internal Revenue Service is reminding low- and moderate-income workers to take steps now to save for retirement and earn a special tax credit in 2012 and the years ahead. Employers sponsoring retirement plans where low participation by low- and moderate income workers adversely impacts the ability of the plan to meet applicable nondiscrimination tests may want to consider incorporating information about the availability of the saver’s credit into their plan related communications as an added tool for helping these workers recognize the potential benefits of contributing.
The saver’s credit helps qualifying low to moderate income workers offset part of the first $2,000 workers voluntarily contribute to IRAs and to 401(k) plans and similar workplace retirement programs. Also known as the retirement savings contributions credit, the saver’s credit is available in addition to any other tax savings that apply.
The saver’s credit can be claimed by:
- Married couples filing jointly with incomes up to $57,500 in 2012 or $59,000 in 2013;
- Heads of Household with incomes up to $43,125 in 2012 or $44,250 in 2013; and
- Married individuals filing separately and singles with incomes up to $28,750 in 2012 or $29,500 in 2013.
Eligible workers still have until April 15, 2013 to make qualifying retirement contributions and get the saver’s credit on their 2012 tax return by setting up a new individual retirement arrangement or adding money to an existing IRA. However, elective deferrals (contributions) must be made by the end of the year to a 401(k) plan or similar workplace program, such as a 403(b) plan for employees of public schools and certain tax-exempt organizations, a governmental 457 plan for state or local government employees, and the Thrift Savings Plan for federal employees. Employees who are unable to set aside money for this year may want to schedule their 2013 contributions soon so their employer can begin withholding them in January.
Like other tax credits, the saver’s credit can increase a taxpayer’s refund or reduce the tax owed. Though the maximum saver’s credit is $1,000, $2,000 for married couples, the IRS cautioned that it is often much less and, due in part to the impact of other deductions and credits, may, in fact, be zero for some taxpayers.
A taxpayer’s credit amount is based on his or her filing status, adjusted gross income, tax liability and amount contributed to qualifying retirement programs. Form 8880 is used to claim the saver’s credit, and its instructions have details on figuring the credit correctly.
In tax-year 2010, the most recent year for which complete figures are available, saver’s credits totaling just over $1 billion were claimed on more than 6.1 million individual income tax returns. Saver’s credits claimed on these returns averaged $204 for joint filers, $165 for heads of household and $122 for single filers.
The saver’s credit supplements other tax benefits available to people who set money aside for retirement. For example, most workers may deduct their contributions to a traditional IRA. Though Roth IRA contributions are not deductible, qualifying withdrawals, usually after retirement, are tax-free. Normally, contributions to 401(k) and similar workplace plans are not taxed until withdrawn.
Other special rules that apply to the saver’s credit include the following:
- Eligible taxpayers must be at least 18 years of age.
- Anyone claimed as a dependent on someone else’s return cannot take the credit.
- A student cannot take the credit. A person enrolled as a full-time student during any part of 5 calendar months during the year is considered a student.
Certain retirement plan distributions reduce the contribution amount used to figure the credit. For 2012, this rule applies to distributions received after 2009 and before the due date, including extensions, of the 2012 return. Form 8880 and its instructions have details on making this computation.
Begun in 2002 as a temporary provision, the saver’s credit was made a permanent part of the tax code in legislation enacted in 2006. To help preserve the value of the credit, income limits are now adjusted annually to keep pace with inflation. More information about the credit is on IRS.gov.
For Help or More Information
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved
1 Comment |
Corporate Compliance, Employers, GINA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Retirement Plans, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 10, 2013
Employers and other self-insured group health plan sponsors and health insurers, adjust your budgets and prepare to open up your wallets to pay additional fees mandated by the Patient Protection and Affordable Care Act (“PPACA”).
Self-insured employers and health insurers generally must begin paying a new fee imposed as part of PPACA. PPACA generally requires that health insurance policy issuers and plan sponsors of self-insured health plans pay the new fee for policy and plan years ending on or after October 1, 2012, and before October 1, 2019 or policy and plan years ending on or after October 1, 2012, and before October 1, 2019. July 31, 2013 is the deadline for reporting and payment of the first fee payment required by these provisions.
The Internal Revenue Service (IRS) and Department of Treasury published final regulations (“Regulations”) implementing these new rules on December 6, 2012. These Regulations include many provisions that are likely to come as a surprise to many employer and other health plan sponsors. Health insurers, employers and other sponsors of self-insured health plans and others responsible for their funding and administration need to review these regulations and make other arrangements to budget for and timely report and pay this required fee.
New Fees Help Fund New Patient-Centered Outcomes Research Institute
PPACA amended the Internal Revenue Code (“Code”) to require the new fee to help fund the establishment and operation of the new Patient-Centered Outcomes Research Institute (the ‘‘Institute’’) to be created by PPACA. Congress intends that the Institute will be a private, nonprofit corporation charged with conducting research to help assist patients, clinicians, purchasers, and policy-makers in making informed health decisions by advancing the quality and relevance of evidence-based medicine through the synthesis and dissemination of comparative clinical effectiveness research findings.
PPACA added new Sections 4375, 4376, and 4377 to the Code to provide a funding source for the Trust Fund. These new Code Sections impose require issuers of specified health insurance policies and plan sponsors of applicable self-insured health plans to pay the new fee by July 31, 2012 for each plan year beginning after September 30, 2012 and before October 1, 2019 to fund the Patient-Centered Outcomes Research Trust Fund (the “Trust Fund”), which in turn will help pay the costs of the Institute.
Code Section 4377(c) provides that the fees imposed by sections 4375 and 4376 are treated as taxes for purposes of subtitle F of the Code (sections 6001 through 7874 that set forth the rules of federal tax procedure and administration).
Fee Amount Calculation & Payment
As amended by PPACA, the Code requires that employers sponsoring self-insured group health plans and most health insurers file a return and pay a fee equal to $1 multiplied by the average number of lives covered under the plan or policy by July 31, 2012. The amount of this fee will increase to $2 multiplied by the average number of lives for post-September 30, 2013 plan years. For post-September 30, 2014 plan years, the Code provides for further adjustments in the fee based on increases in the projected per capita amount of National Health Expenditures.
To meet this requirement, health insurers and plan sponsors must file a Form 720, Quarterly Federal Excise Tax Return along with the required payment once a year on or before July 31 of the calendar year following the last day of the policy year or plan year for which the fee is required to report and pay the fee.
Overview of ACA Rules Requiring Payment of Fee
The Code now separately assesses a fee on issuers of health insurance policies and on plan sponsors of self-insured health plans for each policy year ending on or after October 1, 2012 and before October 1, 2019. Code Section 4375 requires payment of a fee by “issuers” of “specified health insurance policies.” Code Section 4376 requires “sponsors” of self-insured health plans to pay a fee.
Each of these Code Sections basically uses the same formula to calculate the required fee owing by a health insurance issuer or a self-insured plan sponsor. The amount of the required fee due on July 31, 2013 for plan years beginning on or before October 1, 2013 will be one dollar multiplied by the average number of lives covered by the policy or plan. The fee due on July 31, 2014 for plan years beginning between October 2, 2013 and October 1, 2014 is set to increase to two dollars multiplied by the average number of lives covered under the policy. For policy or plan years ending on or after October 1, 2014, PPACA provides for additional increases in the required fee based on increases in the projected per capita amount of National Health Expenditures. See Treas. Reg. §§ 46.4375–1; Rejecting arguments that Congress only intended to require that either the insurer or the plan sponsor pay a fee annually, the Regulations construe these requirements as obligating both a self-insured health plans sponsor and an insurer to pay a separate fee annually, even if the fee is assessed upon the same lives.
The Preamble to the Regulations states that a self-insured plan sponsor must pay the fee with respect to arrangements where the plan design layers a self-insured portion of the plan with an insured portion, even though the insurer also must pay the fee with respect to the insured portion.
The fee calculation differs slightly for purposes of determining the fee a self-insured plan sponsor owes versus the fee owed by an insurer. Regardless, however, the Regulations state that for purposes of calculating these numbers, retirees and beneficiaries continuing coverage under the group medical coverage continuation rules generally count. The Preamble to the Regulations states that the IRS views retiree-only plans and COBRA coverage subject to the tax imposed under Code § 4375 and plan sponsors may be required to pay the tax under Code § 4376. Concerning retiree-only coverage, the Preamble states:
- Although group health plans that have fewer than two participants who are current employees (such as retiree-only plans) are excluded from the requirements of Code chapter 100 (setting forth requirements applicable to group health plans such as portability, nondiscrimination, and market reform requirements), this exclusion does not apply to Code §§ 4375 and 4376 because these sections are in chapter 34; and
- For self-insured arrangements, Code § 4376(c)(2)(A) states explicitly that an applicable self-insured health plan includes a plan established or maintained by one or more employers for the benefit of their employees or former employees.
Section 4376 Fee For Self-Insured Plan Sponsors
Applicability of Code Section 4376 Fee To Self-Insured Health Plans. The fee under Code Section 4376 applies to the plan sponsor of an applicable self-insured health plan.
Section 4376(c) defines an applicable self-insured health plan as any plan for providing accident or health coverage if any portion of the coverage is provided other than through an insurance policy, and the plan is established or maintained by either:
- One or more employers for the benefit of their employees or former employees;
- One or more employee organizations for the benefit of their members or former members;
- Jointly by one or more employers and one or more employee organizations for the benefit of employees or former employees;
- By a voluntary employees’ beneficiary association described in Code Section 501(c)(9); or
- By any organization described in section 501(c)(6), or (6) if not previously described, by a multiple employer welfare arrangement (as defined in section 3(40) of the Employee Retirement Income Security Act (“ERISA”), a rural electric cooperative under ERISA Section 3(40)(B)(iv), or a rural telephone cooperative association under ERISA Section 3(40)(B)(v). See Code § 4376; Regulation §46.4376–1(a), (b)(1).
Code Section 4376(b)(1) requires that the plan sponsor of a self-insured health plan pay the required fee for self-insured health plans imposed by Section 4376(a). For this purpose, Code Section 4376(b)(2) defines a plan sponsor as:
- The employer in the case of a plan established or maintained by a single employer;
- The employee organization in the case of a plan established or maintained by an employee organization;
- The association, committee, joint board of trustees, or other similar group of representatives of the parties who establish or maintain the plan in the case of: (1) a plan established or maintained by two or more employers or jointly by one or more employers and one or more employee organizations; (2) a multiple employer welfare arrangement; or (3) a voluntary employees’ beneficiary association described in Code Section 501(c)(9); or
- The cooperative or association that establishes the plan in the case of a plan established or maintained by a rural electric cooperative or rural telephone cooperative association within the meaning of ERISA.
Regulation § 46.4376-2(b)(2) defines plan sponsor to mean the following:
- The employer for a self-insured health plan established or maintained by a single employer;
- The employee organization for a self-insured health plan established or maintained by an employee organization;
- The joint board of trustees for a multiemployer plan within the meaning of Code §414(f));
- The committee, in the case of a multiple employer welfare arrangement within the meaning of Section 3(40) of the Employee Retirement Income Security Act (“ERISA”);
- The cooperative or association that establishes or maintains an applicable self-insured health plan established or maintained by a rural electric cooperative under ERISA § 3(40)(B)(iv) or rural cooperative association under ERISA 3(40)(B)(v);
- The trustee, in the case of an applicable self-insured health plan established or maintained by a voluntary employees’ beneficiary association under Code § 501(c)(9) not merely serving as a funding vehicle for a plan that is established or maintained by an employer or other person;
- In the case of an applicable self-insured health plan the plan sponsor of which is not previously described, the person identified by the terms of the document under which the plan is operated as the plan sponsor, or the person designated by the terms of the document under which the plan is operated as the plan sponsor for Code § 4376 purposes, provided that designation is made in writing, and that person has consented to the designation in writing, by no later than the date by which the return paying the fee under section 4376 for that plan year is required to be filed, after which date that designation for that plan year may not be changed or revoked, and provided further that a person may be designated as the plan sponsor only if the person is one of the persons establishing or maintaining the plan (for example, one of the employers that establishes or maintains the plan with one or more other employers or employee organizations); or
- Where an applicable self-insured health plan sponsor is not previously and for which no identification or designation of a plan sponsor has been made under the prior paragraph the plan sponsor means, each employer that establishes or maintains the plan with respect to employees of that employer, each employee organization that establishes or maintains the plan with respect to members of that employee organization, and each board of trustees, cooperative, or association that establishes or maintains the plan.
While the fee will impact most health insurance policies and self-insured plans, the Code does exempt a few arrangements. See Code § 4376. Regulation § 46.4376-1(b)(2) construes these exemptions to include the following categories of programs:
- A plan that provides benefits substantially all of which are excepted benefits for purposes of the HIPAA Portability Rules under Code § 9832(c). Pursuant to this provision, for instance, the Regulations state that a health flexible spending arrangement (health FSA) under Code § 106(c)(2)) that satisfies the requirements to be treated as an excepted benefit under Code § 9832(c) and Regulation § 54.9831–1(c)(3)(v) is not an applicable self-insured health plan. However, a health FSA that is not treated as an excepted benefit under Code § 9832(c) and Regulation § 54.9831–1(c)(3)(v) is an applicable self-insured health plan.
- An employee assistance program, disease management program, or wellness program if the program does not provide significant benefits in the nature of medical care or treatment.
- A plan that, as demonstrated by the facts and circumstances surrounding the adoption and operation of the plan, was designed specifically to cover primarily employees who are working and residing outside the United States (as defined in § 46.4377–1(a)(3)). See Regulation § 46.4376–1(b)(ii).
Where the same plan sponsor maintains multiple self-insured arrangements Regulation § 46.4376(b)(iii) specifies that the employer may treat two or more arrangements established or maintained by the same plan sponsor that provide accident and health coverage other than through an insurance policy and that have the same plan year as a single applicable self-insured health plan for purposes of reporting and calculating the Code § 4376 fee.
Calculation Of Self-Insured Plan Fee Under Code § 4376
Regulation § 46.4376-1 requires that a self-insured plan sponsor determine the number of covered lives for purposes of calculating the fee using on of the following methods:
- The actual count method where the plan sponsor adds the totals of lives covered for each day of the plan year and divides that total by the number of days in the plan year;
- The snapshot method, the plan sponsor adds the totals of lives covered on a date during the first, second, or third month of each quarter of the plan year (or more dates in each quarter if an equal number of dates is used in each quarter), and divides that total by the number of dates on which a count was made in accordance with rules set forth in the Regulations. For instance, Each date used for the second, third and fourth quarter must be within three days of the date in that quarter that corresponds to the date used for the first quarter, and all dates used must fall within the same plan year. If a plan sponsor uses multiple dates for the first quarter, the plan sponsor must use dates in the second, third, and fourth quarters that correspond to each of the dates used for the first quarter or are within three days of such corresponding dates, and all dates used must fall within the same plan year. The 30th and 31st day of a month are treated as the last day of the month for purposes of determining the corresponding date for any month that has fewer than 31 days. The number of lives covered on a designated date using this method may be determined using either the snapshot factor method or the snapshot count method set forth in the Regulations. In the snapshot factor method, the number of lives covered on a date is equal to the sum of: (1) the number of participants with self-only coverage on that date; plus (2) the number of participants with coverage other than self-only coverage on the date multiplied by 2.35. In the snapshot count method, the number of lives covered on a date equals the actual number of lives covered on the designated date. The plan sponsor must use the same method of calculating the average number of lives covered under the plan consistently for the duration of the plan year. However, a plan sponsor may use a different method from one plan year to the next.
- The Form 5500 method, where the plan sponsor determines the average number of lives covered under a plan for a plan year as the result of the sum of the total participants covered at the beginning and the end of the plan year, as reported on the Form 5500 or Form 5500–SF for the applicable self-insured health plan, divided by 2. This method is only available if the Form 5500 is filed by the due date for payment of the fee. This means where a plan administrator extends filing beyond July 31, the plan sponsor cannot use this method.
The Regulations establish a special rule for lives covered solely by the fully-insured options under an applicable self-insured health plan. Under this special rule, when an applicable self-insured health plan provides accident and health coverage through fully insured options and self-insured options, the plan sponsor is permitted to disregard the lives that are covered solely under the fully-insured options in determining the lives covered taken into account for the actual count method, the snapshot method, and the Form 5500 method.
As for insured plans, the Regulations also provide special rules for determining the fee the first year the fee is in effect. Under this rule, for a plan year beginning before July 11, 2012, and ending on or after October 1, 2012, a plan sponsor may determine the average number of lives covered under the plan for the plan year using any reasonable method.
Section 4375 Fee For Insurers
The fee under Code Section 4375 generally applies to issuers of a “specified health insurance policy.” Code Section 4375(c) generally defines a specified health insurance policy as any accident or health insurance policy (including a policy under a group health plan) issued with respect to individuals residing in the United States. Code Section 4377(a)(1) defines accident and health coverage as any coverage that, if provided by an insurance policy, would cause the policy to be a specified health insurance policy under Code Section 4375. See Treas. Reg. § 46.4375–1.
Policies Subject To Fee. Regulation § 46.4377–1(a) defines a “specified health insurance policy” as “any accident and health insurance policy (including a policy under a group health plan) issued with respect to individuals residing in the United States” other than those recognized as exempt by the Regulation. The Regulation makes clear that this includes any policy that provides accident and health coverage to an active employee, former employee, or qualifying beneficiary, as continuation coverage required under the Consolidated Omnibus Budget Reconciliation Act of 1985 (COBRA) or similar continuation coverage under other Federal law or state law.
However Regulation § 46.4377-1(a)(ii) exempts the following arrangements from the definition of a specified health insurance policy.
- Any insurance policy if substantially all of its coverage is of excepted benefits described in Code Section 9832(c);
- Any group policy issued to an employer where the facts and circumstances show that the group policy was designed and issued specifically to cover primarily employees who are working and residing outside of the United States for purposes of Regulation § 46.4377–1(a)(3);
- Any stop loss or indemnity reinsurance policy; or
- Any insurance policy to the extent it provides an employee assistance program, disease management program, or wellness program if the program does not provide significant benefits in the nature of medical care or treatment.
Fee Calculation. The amount of the fee an insurer must pay for a policy for a policy year under Code § 4375 is equal to the product of the average number of lives covered under the policy for the policy year, multiplied by the applicable dollar amount for that policy year.
The applicable dollar amount multiplier is $1 for the fee due on October 1, 2013; $2 for the fee due on October 1, 2014, and the adjusted amount for fees due after October 1, 2014.
Determination Of The Average Number Of Lives Covered. To determine the average number of lives covered under a specified health insurance policy during a policy year, the Regulation requires an issuer to use one of the following methods:
- The actual count method, where the issuer determines the average number of lives covered under a policy for a policy year under the actual count method by adding the total number of lives covered for each day of the policy year and dividing that total by the number of days in the policy year;
- The snapshot method, where the issuer determines the average number of lives covered under a policy for a policy year by adding the totals of lives covered on a date during the first, second, or third month of each quarter (or more dates in each quarter if an equal number of dates is used for each quarter), and dividing that total by the number of dates on which a count is made. Each date used for the second, third and fourth quarters must be within three days of the date in that quarter that corresponds to the date used for the first quarter, and all dates used must be within the same policy year. If an issuer uses multiple dates for the first quarter, the issuer must use dates in the second, third, and fourth quarters that correspond to each of the dates used for the first quarter or are within three days of such corresponding dates, and all dates used must be within the same policy year. The 30th and 31st day of a month are treated as the last day of the month for purposes of determining the corresponding date for any month that has fewer than 31 days (for example, if either March 30 or March 31 is used as a counting date for a calendar year policy, June 30 is the corresponding date for the second quarter);
- The member months method, where the issuer determines the average number of lives covered under all policies in effect for a calendar year based on the member months (an amount that equals the sum of the totals of lives covered on prespecified days in each month of the reporting period) reported on the National Association of Insurance Commissioners (“NAIC”) Supplemental Health Care Exhibit filed for that calendar year. Under this method, the average number of lives covered under the policies in effect for the calendar year equals the member months divided by 12; or
- The state form method, where an insurer not required to file NAIC annual financial statements may determine the number of lives covered under all policies in effect for the calendar year using a form filed with the issuer’s state of domicile and a method similar to the member months method if the form reports the number of lives covered in the same manner as member months are reported on the NAIC Supplemental Health Care Exhibit. See Regulation § 46.4375–1(c)(2)(i).
Issuers must use the same method of calculating the average number of lives covered under a policy consistently for the duration of the year and must use the same method of computing lives for all policies for which a liability is reported on a Form 720, “Quarterly Federal Excise Tax Return,” for a particular year. Regulation § 46.4375–1(c)(2)(ii). However, the Regulation allows an issuer that determines the average number of lives covered by using the actual count method or the snapshot method to change its method of computing the average lives covered to the snapshot method or actual count method, respectively, provided that the issuer uses the same method for computing the average lives covered for all policies for which a liability is reported on the Form 720 for that year. Regulation § 46.4375–1(c)(2).
The Regulations also impose various other special rules. For instance, the Regulations state that if the issuer elects to determine the average number of lives covered for all policies in effect during a calendar year using the member months method or the state form method, the applicable dollar amount with respect to such issuer’s policies for such calendar year is the applicable dollar amount for policy years ending on December 31 of such calendar year, except that the applicable dollar amount with respect to such an issuer’s policies for calendar year 2019 is the applicable dollar amount for policy years ending on September 30, 2019. The Regulations provide various examples of these calculations to illustrate the rules.
The Regulations also provide special rules for the first year and the last year the fee is in effect for an insurer. See Regulation § § 46.4375–1(c).
Plans, Insurers Should Evaluate Options, Plan To Pay Required Fees
The impending obligation provides yet another reason that employers and other self-insured plan sponsors, administrators, insurers, and vendors should re-evaluate their existing health plan designs and costs. Most health insurers and self-insured health plan sponsors will want not only to budget for the impending additional costs associated with these fees, but also evaluate options for mitigating their impact, as well as the costs and administrative burden of tracking and making the required filings. For instance, insurers and plan sponsors of programs subject to these new fees generally will want to evaluate which of the options for collecting the data and calculating the fees will most benefit them. Also, where plan designs used by particular employer or other plan sponsors include both insured and self-insured features, the insurer, plan sponsor and their advisors may want to consider the advisability of restructuring or redesigning plans to mitigate fees or administrative or other expenses. In all cases, parties should audit their programs to ensure that each program and its element is identified and properly taken into account to avoid inadvertent oversights resulting in penalties or other avoidable costs.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 3, 2013
$50K Settlement Shows Small Breach Reports Carry Enforcement Risk
Properly encrypt and protected electronic protected health information (ePHI) on laptops and in other mediums! That’s the clear message of the Department of Health and Human Services (HHS) Office of Civil Rights (OCR) in its announcement of its first settlement under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule involving a breach of ePHI of fewer than 500 individuals by a HIPAA-covered entity, Hospice of North Idaho (HONI).
In announcing the settlement against HONI, OCR sent a clear message that OCR stands ready to penalize these health care providers, health plans, healthcare clearinghouses and their businesses associates (covered entities) when their failure to properly secure and protect ePHI on laptops or in other systems results in a breach of ePHI even when the breach affects fewer than 500 individuals.
OCR Director Leon Rodriguez reiterated OCR’s expectation that covered entities will properly encrypt ePHI on mobile or other devices in OCR’s announcement of the HONI settlement. “This action sends a strong message to the health care industry that, regardless of size, covered entities must take action and will be held accountable for safeguarding their patients’ health information.” said OCR Director Leon Rodriguez. “Encryption is an easy method for making lost information unusable, unreadable and undecipherable.”
In light of this latest clear warning, health plans and their fiduciaries, sponsors and administrators, health care providers, health care clearinghouses and their business associates should review plans, practices and data security as affecting ePHI and other protected health information on mobile and other devices.
HONI Settlement For Small Breach Notification
On January 2, 2013, OCR announced HONI will pay OCR $50,000 to settle potential HIPAA violations that occurred in connection with the theft of an unencrypted laptop computer containing ePHI. The HONI settlement is the first settlement involving a breach of ePHI affecting fewer than 500 individuals. Read the full HONI Resolution Agreement here.
OCR opened an investigation after HONI reported to HHS that an unencrypted laptop computer containing ePHI of 441 patients had been stolen in June 2010. HONI team members regularly use Laptops containing ePHI their field work. Over the course of the investigation, OCR discovered that HONI had not conducted a risk analysis to safeguard ePHI or have in place policies or procedures to address mobile device security as required by the HIPAA Security Rule. Since the June 2010 theft, HONI has taken extensive additional steps to improve their HIPAA Privacy and Security compliance program.
HIPAA Security & Breach Notification For ePHI
The HONI settlement is notable because it marks the first time OCR has sanctioned a covered entity as a result of an OCR investigation stemming from the covered entity’s report of a breach of unsecured protected health information involving fewer than 500 individuals under new breach notification rules added to HIPAA in 2009.
Under the originally enacted requirements of HIPAA, covered entities and their business associates are required to restrict the use, access and disclosure of protected health information and establish and administer various other policies and safeguards in relation to protected health information. Additionally, the Security Rules require specific encryption and other safeguards when covered entities collect, create, use, access, retain or disclose ePHI.
The Health Information Technology for Economic and Clinical Health (HITECH) Act amended HIPAA, among other things to tighten certain HIPAA requirements, expand its provisions to directly apply to business associates, as well as covered entities and to impose specific breach notification requirements. The HITECH Act Breach Notification Rule requires covered entities to report an impermissible use or disclosure of protected health information, or a “breach,” of 500 individuals or more (Large Breach) to the Secretary of HHS and the media within 60 days after the discovery of the breach. Smaller breaches affecting less than 500 individuals (Small Breach) must be reported to the Secretary on an annual basis. Since the Breach Notification Rule took effect, OCR’s announced policy has been to investigate all Large Breaches and such investigations have resulted in settlements or other corrective action in relation to various Large Breaches. Until now, however, OCR has not made public any resolution agreements requiring settlement payments involving any Small Breaches.
Enforcement Actions Highlight Growing HIPAA Exposures For Covered Entities
While the HONI settlement marks the first settlement on a small breach, this is not the first time OCR has sought sanctions against a covered entity for data breaches involving the loss or theft of unencrypted data on a Laptop, storage device or other computer device. In fact, OCR’s first resolution agreement – reached before Congress added the HIPAA Breach Notification Rules to HIPAA – stemmed from such a breach. Providence To Pay $100000 & Implement Other Safeguards. Breaches resulting from the loss or theft of unencrypted ePHI on mobile or other computer devices or systems has been a common basis of investigation and sanctions since that time, particularly since the Breach Notification rules took effect including breaches of ePHI involving compromised health plan information. See, e.g., OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach. Coupled with statements by OCR about its intolerance, the HONI and other settlements provide a strong warning to covered entities to properly encrypt ePHI on mobile and other devices.
Furthermore, the HONI settlement also adds to growing evidence of the growing exposures that health care providers, health plans, health care clearinghouses and their business associates need to carefully and appropriately manage their HIPAA encryption and other Privacy and Security responsibilities. See OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website. Covered entities are urged to heed these warning by strengthening their HIPAA compliance and adopting other suitable safeguards to minimize HIPAA exposures.
In the face of rising enforcement and fines, OCR’s initiation of HIPAA audits and other recent developments, covered entities and their business associates should tighten privacy policies, breach and other monitoring, training and other practices to reduce potential HIPAA exposures in light of recently tightened requirements and new enforcement risks.
In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if additional steps are necessary or advisable.
New OCR HIPAA Mobile Device Educational Tool
While OCR enforcement of HIPAA has significantly increased, compliance and enforcement of the encryption and other Security Rule requirements of HIPAA are a special focus of OCR.
To further promote compliance with the Breach Notification Rule as it relates to ePHI on mobile devices, OCR and the HHS Office of the National Coordinator for Health Information Technology (ONC) recently kicked off a new educational initiative, Mobile Devices: Know the RISKS. Take the STEPS. PROTECT and SECURE Health Information. The program offers health care providers and organizations practical tips on ways to protect their patients’ health information when using mobile devices such as laptops, tablets, and smartphones. For more information, see here. For more information on HIPAA compliance and risk management tips, see here.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help monitoring HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
1 Comment |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
December 27, 2012
Peter Madoff (Madoff), the former Chief Compliance Officer and Senior Managing Director of Bernard L. Madoff Investment Securities LLC (BLMI), was sentenced on December 20, 2012 to 10 years in prison after he pled guilty among other things, to conspiracy to commit securities fraud, tax fraud, mail fraud, ERISA fraud and falsifying records of an investment adviser.
In addition to the prison term, Madoff also was sentenced to one year of supervised release, ordered to pay a $200 special assessment, and ordered to forfeit $143.1 billion, including all of his real and personal property. This amount represents all of the investor funds paid into BLMIS from 1996 – the start of Madoff’s involvement in the conspiracy – through December 2008.
As part of the defendant’s forfeiture, the Government previously entered into a settlement with Madoff’s family that requires the forfeiture of all of his wife Marion’s and daughter Shana’s assets, and assets belonging to other family members. The surrendered assets include, among other things, several homes, a Ferrari and more than $10 million in cash and securities. Marion Madoff was left with approximately $771,733 to live on for the rest of her life.
Madoff’s Sentence Part of Continuing Actions Seeking To Rectify BLMIS Fraud
Among other things, the Superseding Information against Madoff charged that the overt acts in the conspiracy count also included, among other things, making false statements to investors about BLMIS’s compliance program and the nature and scope of its Investment Advisory business. Madoff pled guilty in June 2012. He was sentenced in Manhattan federal court by U.S. District Judge Laura Taylor Swain.
Manhattan U.S. Attorney Preet Bharara said: “Peter Madoff was a gatekeeper, who was supposed to guard against fraud, but instead enabled it – facilitating his brother Bernie’s breathtaking scheme by falsifying compliance records and lying to both regulators and clients of BLMIS. The decade he will spend in prison and the disgorgement of his assets are a just result. Our efforts to hold to account anyone and everyone who played a role in this unprecedented Ponzi scheme continue.”
According to the Superseding Information to which Madoff pled guilty and other court filings:
- Madoff was employed at BLMIS from 1965 through December 2008. Beginning in 1969, he became the Chief Compliance Officer (“CCO”) and Senior Managing Director of BLMIS. In his role as CCO, Madoff created false and misleading BLMIS compliance documents, as well as false reports that were filed with the U.S. Securities and Exchange Commission (“SEC”) that materially misstated the nature and scope of BLMIS’s Investment Advisory (“IA”) business.
- As CCO, Madoff created numerous false compliance documents in which he stated that he had performed compliance reviews of the trading in the BLMIS IA business on a regular basis, when in reality, the reviews were never performed. The false statements were designed to mislead regulators, auditors, and IA clients.
- In August 2006, BLMIS registered as an investment adviser with the SEC. As a registered investment adviser, on at least an annual basis, BLMIS was required to file forms with the SEC that are used as part of the oversight process of investment advisers. Madoff was integrally involved with both the SEC registration process and in the creation of the forms, known as “Forms ADV,” which were materially false and misleading. The numerous false statements in the Forms ADV created the false appearance that BLMIS’s IA business had a small number of highly sophisticated clients and far fewer assets under management than was actually the case. Madoff also misrepresented that he, as CCO, ensured that reviews of the IA trading were being performed.
- From 1998 through 2008, Madoff engaged in a tax fraud scheme involving the transfer of wealth within the Madoff family in ways that allowed him to avoid paying millions of dollars in required taxes to the IRS. Most, if not all of the “wealth,” came directly or indirectly from IA client funds held at BLMIS. The schemes in which he engaged also allowed Bernard L. Madoff to evade his tax obligations.
- The methods by which Madoff engaged in tax fraud included the following:
- Madoff also arranged for his wife to have a “no-show” job at BLMIS from which she received between approximately $100,000 to $160,000 per year in salary, a 401(k), and health benefits to which she was not entitled.
- In December 2008, when the collapse of BLMIS was virtually certain, Madoff agreed with others to send the $300 million that remained in the IA accounts to preferred employees, family members and friends. BLMIS collapsed before the funds were ever disbursed. On December 10, 2008, one day prior to BLMIS’s collapse, Madoff also withdrew $200,000 from BLMIS for his personal use.
- Madoff received approximately $15,700,000 from Bernard L. Madoff and his wife, and executed sham promissory notes to make it appear that the transfers were loans, in order to avoid paying taxes;
- Madoff gave approximately $9,900,000 to family members, and in order to avoid paying taxes, executed sham promissory notes to make it appear that the transfers of these funds were loans;
- Madoff did not pay taxes on approximately $7,750,000 that he received from BLMIS;
- Madoff received approximately $16,800,000 from Bernard L. Madoff from two sham trades, and disguised the proceeds of the trades as long-term stock transactions in order to take advantage of the lower tax rate for long-term capital gains;
- Madoff charged approximately $175,000 in personal expenses to a corporate American Express card and did not report those expenses as income.
Madoff Victim Compensation Process Continues
In addition to the sentencing of Madoff, the Government has taken steps to clear the way to begin distributing assets forfeited by Peter Madoff in connection with the victim compensation process by filing a motion requesting that the Court find restitution to be impracticable, A similar motion was granted by United States Circuit Judge Denny Chin, who as a United States District Judge sentenced Bernard L. Madoff in 2009. The Department of Justice intends to return the assets forfeited as a result of the Madoff fraud to victims through the remission process.
Richard C. Breeden was retained to serve as Special Master on behalf of the Department of Justice to administer the process of compensating the victims of the Madoff fraud with the forfeited funds. A former chairman of the SEC, Mr. Breeden is Chairman of Richard C. Breeden & Co., which has been involved in (among other things) the administration and distribution of securities fraud claims since 1996. Among other things, Mr. Breeden has served as Corporate Monitor of WorldCom, Inc. and KPMG under its deferred prosecution agreement with the U.S. Attorney’s Office. Mr. Breeden also served as remission special master in connection with the fraud committed through Adelphia Communications Corporation. In April 2012, more than $728 million forfeited in connection with this Office’s investigation and prosecution of the Adelphia fraud was distributed to approximately 8,500 victims, the largest single distribution of forfeited assets to victims in Department of Justice history.
Now that a new Special Master has been retained, and given the pledge of SIPC Trustee Irving Picard and his counsel to lend their support and resources to the new Special Master for the benefit of the fraud victims, we expect the victim claims process to begin shortly. It is anticipated that victims who filed claims in the SIPA proceeding will not have to refile their claims to be eligible for remission. New information about the remission Special Master, and information about the victim claims process, will be posted on the Office’s Madoff website at http://www.justice.gov/usao/nys/vw_cases/madoff.html as soon as it becomes available, along with a link to a dedicated website Mr. Breeden’s firm will establish in connection with the remission proceedings.
Investment Advisors and Others With Discretion Over Funds Should Exercise Fiduciary Care
While the Madorf scandle represents an exceptionally large and long-standing stream of mishandling of employee benefit funds, the investigations and prosecutions also serve as a reminder of the need to carefully comply with the fiduciary responsibility and other requirements of ERISA and other laws to investment advisors and other employee benefit plan asset service providers, plan committees and fiduciaries and the plan sponsors, boards and other individuals responsible for investing or handling employee benefit monies or choosing the parties that possess and exercise that discretion.
ERISA generally requires that plan asset investments be made prudently and for the exclusive benefit of participants and beneficiaries. Service providers or others with discretionary responsibiliity or that are investment managers of plan assets must be prudently selected based on careful credentialing and other procedures. e No prohibited transactions should be permitted. Fees and other compensation must be set appropriately and properly reported in accordance with ERISA’s fee disclosure rules. The actions and performance of parties investing in plan assets and their investment performance must be reviewed and monitored prudently. Proper bonding must be maintained. Concerns and questions about these activities must be timely investigated in a prudent manner. Failure to properly conduct these and other ERISA fiduciary responsibilities can expose responsible parties to personal liability for losses, profits improperly realized, a fiduciary administrative penalties, disqualification to serve in plan fiduciary or other positions, and attorneys fees and other costs of recovery, as well as in certain cases like the Madorff fraud, criminal prosecution.
For Help or More Information
If you need help reviewing and updating, administering or defending your employee benefit, human resources, insurance, health care matters or related documents or practices to monitor or respond to evolving laws and regulations, drafting or administering programs, resolving or defending audits, investigations or disputes or other employee benefit, human resources, safety, compliance or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
About Ms. Stamer
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- New OCR HIPAA De-Identification Guidance Among Developments Covered In 12/12 HIPAA Update Web Workshop
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competiting Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
- Supreme Court Decision Puts Health Plans Under Fire To Complete ACA-Required Summary of Benefits & Communications & Other Health Plan Updates
- $27M+ Settlement Highlights Fiduciary Risks Plan Sponsors & Fiduciaries Risk If Plan Vendors, Compensation Improperly Set
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- Model Language May Aid Section 83(b) Elections Even As Executive & Other Special Compensation Carry Growing Liability Traps
- IRS To Offer Help For U.S. Citizens Overseas With Foreign Retirement Plans, Dual Citizenship Tax Issues
- New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow
- IRS Changing Individual Taxpayer ID Number Application Requirements
- Insurer Group Health Inc. To Refund $500,00+ & Change Claims Practices To Settle NY AG Charges It Wrongfully Denied Coverage
- NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage
- Making Wellness Work On A Shoestring Budget
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
1 Comment |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: defined benefit plan, Employer, ERISA, Fiduciary Responsibility, Human Resources, pension plan, plan qualification, profit sharing plan, Retirement Plans, Tax |
Permalink
Posted by Cynthia Marcotte Stamer
December 26, 2012
With employers facing continuing uncertainty about how Congress will address expiring payroll and other tax provisions, the Internal Revenue Service (IRS) plans to issue guidance before December 31 on employer withholding responsibilities in 2013.
In a statement issued this week, the IRS said, “We are aware that employers have questions about 2013 withholding. Since Congress is still considering changes to the tax law, we continue to closely monitor the situation. We intend to issue guidance by the end of the year on appropriate withholding for 2013.”
For Help or More Information
If you need help reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
About Ms. Stamer
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials on regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
:
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- New OCR HIPAA De-Identification Guidance Among Developments Covered In 12/12 HIPAA Update Web Workshop
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competiting Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
- Supreme Court Decision Puts Health Plans Under Fire To Complete ACA-Required Summary of Benefits & Communications & Other Health Plan Updates
- $27M+ Settlement Highlights Fiduciary Risks Plan Sponsors & Fiduciaries Risk If Plan Vendors, Compensation Improperly Set
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- Model Language May Aid Section 83(b) Elections Even As Executive & Other Special Compensation Carry Growing Liability Traps
- IRS To Offer Help For U.S. Citizens Overseas With Foreign Retirement Plans, Dual Citizenship Tax Issues
- New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow
- IRS Changing Individual Taxpayer ID Number Application Requirements
- Insurer Group Health Inc. To Refund $500,00+ & Change Claims Practices To Settle NY AG Charges It Wrongfully Denied Coverage
- NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage
- Making Wellness Work On A Shoestring Budget
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on IRS Plans To Issue 2013 Withholding Guidance By 12/31 |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: Employers, Employment Tax, payroll tax, Withholding |
Permalink
Posted by Cynthia Marcotte Stamer
December 10, 2012
Companies that sponsor employee benefit plans that have purchased or own stock in their sponsor beware. Declines in the stock value of company stock purchased by employee stock ownership plans (ESOP) or other employee benefit plans in their plan sponsor have a growing number of plans and the plan sponsors, sponsoring company owners and management, plan trustees and other plan fiduciaries in hot water with the Department of Labor. ESOP or other employee plans that have purchased or allow investments in company stock and their sponsors, fiduciaries and advisors should carefully review for defensibility the current stock value, the purchase price and analysis supporting that purchase and other aspects of these investments of plan assets and take carefully documented action to prove the prudence and other appropriateness of the investment and continued retention of the investment in these assets.
Company Stock Investments Carry Special ERISA Risks
Purchases of company stock by an ESOP or other employee benefit plan can create a wide range of risks under the fiduciary responsibility rules of the Employee Retirement Income Security Act (ERISA). When making investment or other decisions under an employee benefit plan, the general fiduciary duty standards of ERISA § 404 generally require plan fiduciaries to act prudently and solely in the interest of participants and beneficiaries. Meanwhile, except in certain narrow circumstances and subject to fulfillment of ERISA § 404, the prohibited transaction rules of ERISA § 406 among other things prohibits plan fiduciaries from causing the plan to engage in a transaction, if he knows or should know that such transaction is a direct or indirect:
- Sale or exchange, or leasing, of any property between the plan and a party in interest;
- Furnishing of goods, services, or facilities between the plan and a party in interest;
- Transfer to, or use by or for the benefit of a party in interest, of any assets of the plan; or
- Acquisition, on behalf of the plan, of any employer security or employer real property in violation of section 1107 (a) of this title.
Stock Drops Create Rising Exposures For Plans Invested In Company Stock
Amid economic downturns or other situations where the stock value of company held by plans significantly lower than the price the plan paid for the stock, the Labor Department, plaintiffs in private lawsuits or both may bring “stock drop” or other lawsuits against the plan, its sponsor and its officers and board members, its fiduciaries and others for breach of fiduciary duties under these rules. See e.g., Enron v. Tittle, 463 F.3d 410 (5th Cir. 2006); In Re: BP p.l.c. ERISA Litig., No. 4:10-cv-4214 (S.D. Texas); Vivian v. Worldcom (N.D. Cal. 2002). Since the sponsoring company is a party-in-interest of the plan, using plan assets to purchase company stock or other activities resulting in the inclusion of company stock among the plan assets held by the plan creates presumptions of impropriety that impose higher than usual burdens upon the plan, its sponsor and fiduciaries to prove the appropriateness of the transaction. See e.g., Pfeil v. State Street Bank & Trust Co., 671 F.3d 585 (6th Cir. 2012).
The filing of stock drop cases tends to rise and fall in reflection to the economic times. Following the economic downturn in 2002, federal courts saw a surge in stop drop case challenges as well as Labor Department enforcement actions. The number of these cases dropped as the economy improved later in the decade only to rise again between 2010 and the present in response to the current economic crisis.
Tough Economic Times Fueled Stock Drops Creating Rising Risks & Enforcement
The latest economic downturn is fueling resurgence in these “stock drop” challenges. Fifteen stop drop lawsuits were filed during 2010 and 2011. Additional suits and Labor Department stop drop challenges have emerged this year.
In Griffin v. Flagstar Bancorp, Inc., No. 11-1497 (6th Cir. 2012), for instance, plaintiffs alleged various fiduciaries allegedly breached their duties under ERISA by allowing employer stock to be offered as a 401(k) plan investment option while the company was facing a precarious financial situation. The Griffin court overruled the lower court’s dismissal of the plaintiff’s lawsuit. The Court of Appeals held that the defendants offering of company stock to plan participants made ERISA’s “safe harbor” (Section 404(c)) provision for participant self-directed investments inapplicable. The Sixth Circuit ruled “[a]fter reviewing the factual allegations in the complaint – which go far beyond documenting a simple drop in stock price to recite announcements from Flagstar itself, statements by analysts and financial media publications, and actions taken by Flagstar suggesting a precarious financial situation– we must conclude that the complaint raises a plausible claim for breach of fiduciary duty.”
In addition to private class action lawsuits like Griffin, plans holding company stock, their sponsors, owners, management and fiduciaries also need to be ready to defend against investigations and enforcement by the Labor Department, which often zealously investigates and takes enforcement action against plans, their fiduciaries, sponsors, company boards and management and others for losses to plan asset values resulting due to the investment or retention of investments by their plans in company stock. See also Labor Department Backs M&I Employees In Stock-Plan Suit.
Labor Department Suits Show Particular Risks For ESOPs
Over the past year, the Labor Department has been particularly aggressive in taking action when the value of company stock purchased or held by employee stock purchase plans or “ESOPS” drops significantly.
For instance, the purchase by the Rembar Inc. Employee Stock Ownership Plan (“Rembar Plan”) of all the stock of its sponsor, Rembar Inc. has landed the trust company that served as the Plan’s independent fiduciary and Rembar Inc.’s owner and Chief Executive Officer in hot water.
The Labor Department is suing Rembar Inc.’s Chief Executive Officer and owner, Frank Firor, First Bankers Trust Services Inc. and the Rembar Plan to recover losses that the Labor Department charges Rembar Plan participants suffered because the Rembar Plan paid too much when it purchased all of the stock of Rembar Inc.
Rembar Inc. manufactures and distributes precision parts made from refractory metals. The Labor Department lawsuit alleges that, in June 2005, First Bankers Trust Services allowed the Rembar Plan to purchase 100 percent of the company’s stock from Firor and Firor’s relatives for $15.5 million. A Labor Department investigation found that First Bankers Trust Services failed to comply with its duty to understand the valuation report that set the purchase price, identify and question assumptions in the report, and verify that the conclusions in the report were consistent with the company’s financial data. As a result of First Bankers Trust Services’ failure to comply with its fiduciary duties, the Labor Department claims the Rembar Plan overpaid for the stock and suffered losses. The suit seeks, among other things, to recover jointly from First Bankers Trust Services and Firor all losses suffered by the Rembar Plan.
Similarly, the Labor Department also has filed an ERISA stock drop lawsuit against the Maran Inc. Employee Stock Ownership Plan (Maran Plan), First Bankers Trust Services Inc. and others to recover losses suffered by participants.
According to the pleadings, First Bankers Trust Services was hired as an independent fiduciary and trustee in connection with the company’s ESOP to decide whether, and at what price, to purchase shares of Maran Inc. from majority shareholders. The suit charges First Bankers Trust Services violated ERISA in 2006 when it approved the ESOP’s purchase of 49 percent of the outstanding stock of Maran Inc. for about $71 million, which was more than the fair market value. The Labor Department claims that as a result of the purchase of overvalued stock, the Maran Plan participants suffered significant losses. The suit seeks to recover all losses and have First Bankers Trust Services enjoined from serving as a fiduciary to ESOP plans.
Likewise, the Labor Department in April sued in the U.S. District Court for the Northern District of California seeking to recover losses suffered by participants in the Parrot Cellular Employee Stock Ownership Plan (Parrot Plan).
The suit names as a defendant Dennis Webb, the principal owner of Entrepreneurial Ventures Inc. (EVI), which operates Parrot Cellular telephone retail stores in northern and central California, and is the sponsor of the Parrot Plan; EVI executives Matthew Fidiam and J. Robert Gallucci; Consulting Fiduciaries Inc., an Illinois company that served as the independent fiduciary and investment manager for the Parrot Plan in 2002 when the Parrot Plan bought 90 percent of EVI stock.
According to the pleadings, the Parrot Plan paid for more than $28 million to buy approximately 90 percent of EVI’s stock in 2002. Around the same time as the stock purchase, EVI also set aside $4 million pursuant to a deferred compensation agreement with Webb and entered into a second executive compensation agreement with Webb for $12 million.
The Labor Department charges defendants allegedly violated ERISA by rejecting their fiduciary duties of loyalty and prudence to the plan, engaging in self-dealing, permitting or engaging in prohibited transactions, and failing to monitor the performance of the plan’s appraiser when they caused or permitted the Parrot Plan to purchase EVI stock for more than fair market value. The suit also charges that Webb enriched himself by millions of dollars at the expense of the plan and its participants because a reasonable value for the company as of November 2002 was far less than the amounts the Parrot Plan paid for the stock and the total deferred compensation agreements entered into with Webb.
In addition to seeking the recovery of all losses to the Parrot Plan resulting from the above violations, the Labor Department’s suit seeks the disgorgement of unjust profits from Webb that he received from the two deferred compensation agreements and from his sale of EVI stock to the Parrot Plan.
Plans, Sponsors and Fiduciaries Must Act Continously To Manage Risks
These and other actions send a stong message for ESOP and other employee benefit plans, their fiduciaries and sponsors about the need to continuously and prudently evaluate and monitor the investment of plan assets in company stock,the analysis and decisions about whether to continue to keep and offer this stock under the plan, as well as the qualifications, credentials and conduct of the fiduciaries and others empowered to influence these decisions. The Labor Department’s statement in announcing the Parrot litigation sums up the messages from these cases. “Plan officials are required by law to manage the ESOP in a careful, prudent manner and to act solely to benefit the plan’s participants,” said Jean Ackerman, director of EBSA’s San Francisco Regional Office, which conducted the investigation. “This action underscores the department’s commitment to protect the benefits that employers promise to their employees.” Plan fiduciaries, sponsors and their management, service providers and consultants participating in these activities need to both act with care and carefully document their actions to position to defend potential challenges.
Plans, their sponsors and fiduciaries also should ensure that appropriate steps are taken in selecting the fiduciaries, management and service providers responsible for administering or overseeing the administration of their plans, the selection of vendors, and other critical details. Appropriate background checks and other credentialing should be done both at commencement and periodically. Bonding and fiduciary liability insurance should be arranged and reviewed periodically along with their activities. Documentation of these and other steps should be carefully created and preserved.
When and if a change in stock value or other event that could compromise the investment occurs, consideration should be given as to the responsibilities that such events create under ERISA. As company leaders often have dual responsibilities to both the company and the plan, it is important that the company sponsoring the plan, its management and owners learn in advance how these responsibilities impact each other so that they are aware of the issues and have a good understanding of responsibilities and options as situations evolve.
For Help or More Information
If you need help reviewing and updating, administering or defending your employee benefit, human resources, insurance, health care matters or related documents or practices to monitor or respond to evolving laws and regulations, drafting or administering programs, resolving or defending audits, investigations or disputes or other employee benefit, human resources, safety, compliance or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
About Ms. Stamer
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- New OCR HIPAA De-Identification Guidance Among Developments Covered In 12/12 HIPAA Update Web Workshop
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
- Supreme Court Decision Puts Health Plans Under Fire To Complete ACA-Required Summary of Benefits & Communications & Other Health Plan Updates
- $27M+ Settlement Highlights Fiduciary Risks Plan Sponsors & Fiduciaries Risk If Plan Vendors, Compensation Improperly Set
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- Model Language May Aid Section 83(b) Elections Even As Executive & Other Special Compensation Carry Growing Liability Traps
- IRS To Offer Help For U.S. Citizens Overseas With Foreign Retirement Plans, Dual Citizenship Tax Issues
- New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow
- IRS Changing Individual Taxpayer ID Number Application Requirements
- Insurer Group Health Inc. To Refund $500,00+ & Change Claims Practices To Settle NY AG Charges It Wrongfully Denied Coverage
- NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage
- Making Wellness Work On A Shoestring Budget
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: 404, 406, defined benefit plan, Employer, ERISA, exclusive benefit, Fiduciary Responsibility, Human Resources, pension plan, plan qualification, profit sharing plan, Prudence, Retirement Plans, Tax |
Permalink
Posted by Cynthia Marcotte Stamer
December 9, 2012
Qualified plan sponsors, fiduciaries, administrators and advisors and other service providers should review the 2012 Cumulative List of Changes in Plan Qualification Requirements (2012 Cumulative List) in Notice 2012-76 to identify any required or recommended changes to promote continued fulfillment of applicable qualification requirements.
The Internal Revenue Service (IRS) publishes a cumulative list annually to guide plan sponsors and practitioners submitting qualifed plan determination letter applications for plans during the upcoming year. The 2012 Cumulative Listinforms plan sponsors of issues the Service has specifically identified for review in determining whether a plan filing in Cycle C has been properly updated. Specifically, the 2012 Cumulative List reflects law changes under the Pension Protection Act of 2006 (PPA ’06), Pub. L. 109-280; the U.S. Troop Readiness, Veterans’ Care, Katrina Recovery and Iraq Accountability Appropriations Act, 2007, Pub. L. 110-28; the Heroes Earnings Assistance and Relief Tax Act of 2008 (HEART Act), Pub. L. 110-245; the Worker, Retiree, and Employer Recovery Act of 2008 (WRERA), Pub. L. 110-458; the Small Business Jobs Act of 2010 (SBJA), Pub. L. 111-240; the Preservation of Access to Care for Medicare Beneficiaries and Pension Relief Act of 2010 (PRA 2010), Pub. L. No. 111-192; and the Moving Ahead for Progress in the 21st Century Act (MAP-21), Pub. L. 112-141.
The 2012 Cumulative List sets forth guidance and regulations implementing these requirements and provides certain model amendment language. 2012 Retirement Plan Notices are published here.
The IRS intends that the 2012 Cumulative List will be used by plan sponsors and practitioners submitting determination letter applications for plans during the period beginning February 1, 2013 and ending January 31, 2014. In order to be qualified, a plan must comply with all relevant qualification requirements, not just those on the 2012 Cumulative List including those enacted or effective after publication of the 2012 Cumulative List. The list of changes in the Cumulative List does not extend the deadline for amending a qualified plan to comply with any statutory, regulatory, or guidance changes.
Plans using 2012 Cumulative List will primarily be single employer individually designed defined contribution plans and single employer individually designed defined benefit plans that are in Cycle C, and § 414(d) governmental plans (including governmental multiemployer or governmental multiple employer plans) that choose to file during Cycle C. Generally an individually designed plan is in Cycle C if the last digit of the employer identification number of the plan sponsor is 3 or 8. In addition, the 2012 Cumulative List will be used by sponsors of defined benefit pre-approved plans (that is, defined benefit plans that are master and prototype (M&P) or volume submitter (VS) plans) for the second submission under the remedial amendment cycle described in Rev. Proc. 2007-44.
The IRS issued Notice 2012-76 in conjunction with the determination letter program for individually designed plans eligible for Cycle C. The IRS is scheduled to accept determination letter applications for Cycle C individually designed plans from February 1, 2013 to January 31, 2014. In addition, the Service will start accepting opinion and advisory letter applications for defined benefit pre-approved plans beginning on February 1, 2013. The 12-month submission period for non-mass submitter sponsors and practitioners, word-for-word identical adopters, and M&P minor modifier placeholder applications will end on January 31, 2014. The 9-month submission period for mass submitters will end on October 31, 2013.
For Help or More Information
If you need help reviewing and updating, administering or defending your employee benefit, human resources, insurance, health care matters or related documents or practices to monitor or respond to evolving laws and regulations, drafting or administering programs, resolving or defending audits, investigations or disputes or other employee benefit, human resources, safety, compliance or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
About Ms. Stamer
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and registerto receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
- Supreme Court Decision Puts Health Plans Under Fire To Complete ACA-Required Summary of Benefits & Communications & Other Health Plan Updates
- $27M+ Settlement Highlights Fiduciary Risks Plan Sponsors & Fiduciaries Risk If Plan Vendors, Compensation Improperly Set
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- Model Language May Aid Section 83(b) Elections Even As Executive & Other Special Compensation Carry Growing Liability Traps
- IRS To Offer Help For U.S. Citizens Overseas With Foreign Retirement Plans, Dual Citizenship Tax Issues
- New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow
- IRS Changing Individual Taxpayer ID Number Application Requirements
- Insurer Group Health Inc. To Refund $500,00+ & Change Claims Practices To Settle NY AG Charges It Wrongfully Denied Coverage
- NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage
- Making Wellness Work On A Shoestring Budget
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: defined benefit plan, Employer, Human Resources, pension plan, plan qualification, profit sharing plan, Retirement Plans, Tax |
Permalink
Posted by Cynthia Marcotte Stamer
December 4, 2012
Employers and other health plan sponsors, insurers, and their administrators and service providers are reminded that the $2500 limit on pre-tax contributions to health flexible spending account plans under Internal Revenue Code section 125(i) takes effect on the first day of the 2013 plan year. Notice 2012-40 makes clear that the IRS requires that this limitation be included in the plan document before the first day of the plan year for the plan to remain qualified under Code section 125. Employers making this amendment likely wll want to draft this provision to preserve the option to adjust the limit as adjusted in the Code for post-2013 plan years. Code section 125(i) provides for inflation adjustments the $2500.00 limit after 2013.
Most health flexible spending account plans already cap the annual contribution that employees can contribute to limit exposure to the “at-risk” requirements of current IRS regulations. The at risk rule is a requirement imposed by IRS regulations that mandates that a health flexble spending account plan must make the full amount of the annual contribution of an employee available to the employee beginning with the first day of the plan year. This provision has been highly contested as there is no express Code language authorizing or mandating this at risk requirement. Along with providing guidance about the Code section 125(i) limit Notice 2012-40 also indicates that the IRS is reconsidering the need for and future of the at-risk requirement.
Health FSA Limit Change Just Tip of Iceberg
The new Code section 125(i) limit is only one of a plethora of statutory and regulatory changes impacting health benefit arrangements enacted by health care reform. The effective date of these requirements spans from 2009 to 2017. As implementation of these changes moves forward health plan design and administration requirements are changing rapidly as the Departments of Health and Human Services IRS, Department of Labor and state insurance agencies finalize arrangements and guidance governing the implementation and enforcement of the ACA health care reforms scheduled to take effect and to tweek guidance on provisions already effective under the law. Employers and insurers now must get cracking to update their programs and cost estimates to comply with both existing and new guidance while keeping a close eye out for potential changes to ACA or other federal or state health coverage laws as the new Congress is expected to continue to discuss refinements or other changes when the new Congress begins work in January 2013.
What Should Employers Do To Cope With These & Other Health Plan Mandates?
Facing the operational and financial challenges of meeting these mandates, many business leaders continue report significant concern about what they should do to respond to these requirements. For some practical steps that businesses confronting these issues should take to cope with ACA and other health plan responsibilities, check out the “12 Steps Every Employer With A Health Plan Should Do Now” article by Cynthia Marcotte Stamer in the October 26, 2012 online edition of Texas CEO Magazine. To read the full article, see here.
Clearly in light of the new guidance, employers, insurers, health plan fiduciaries and their service providers need to act quickly to familiarize themselves with the guidance and make any need adjustments to their plans, communications, practices and budgets warranted by the new guidance and remain vigilent for and prepared to do the same with other guidance and reform proposals as it is released.
Beyond responding to the new guidance and other future developments, most health plan sponsors, insurers, administrators and other fiduciaries, and their vendors also should consider conducting this specific analysis and update of their health benefit programs in the context of a broader strategy.
In her 12-Steps Article, Ms. Stamer writes, “While most employers and insurers of employment-based group health plans view with great concern radically expanded health plan responsibilities taking effect in 2014, many are failing to take steps critical to manage exposures and costs already arising from the Affordable Care Act (ACA) and other federal health plan regulations.”
In the article, Ms Stamer discusses the following 12 steps that she suggests most businesses consider to help catch up with current responsibilities and to help their business manage future costs and responsibilities:
- Know The Cast Of Characters & What Hat(s) They Wear
- Know What Rules Apply, and How They Affect a Group Health Plan
- Review and Update Health Plan Documents to Meet Requirements and Manage Exposure
- Update the Plan For Changing Compliance Requirements and Enhanced Defensibility
- Consistency Matters: Build Good Plan Design, Documentation and Processes, and Follow Them
- Ensure the Correct Party Carefully Communicates About Coverage and Claims in a Compliant, Timely, Prudent, Provable Manner
- Prepare For ACA’s Expanded Data Gathering and Reporting Requirements
- Select, Contract and Manage Vendors With Care
- Help Plan Members Build Their Health Care Coping Skills With Training and Supportive Tools
- Pack The Parachute and Locate The Nearest Exit Doors
- Get Moving On Compliance and Risk Management Issues
- Provide Input On Affordable Care Act Rules
For Help or More Information
If you need help reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
About Ms. Stamer
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to watch and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- New OCR HIPAA De-Identification Guidance Among Developments Covered In 12/12 HIPAA Update Web Workshop
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
- Supreme Court Decision Puts Health Plans Under Fire To Complete ACA-Required Summary of Benefits & Communications & Other Health Plan Updates
- $27M+ Settlement Highlights Fiduciary Risks Plan Sponsors & Fiduciaries Risk If Plan Vendors, Compensation Improperly Set
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- Model Language May Aid Section 83(b) Elections Even As Executive & Other Special Compensation Carry Growing Liability Traps
- IRS To Offer Help For U.S. Citizens Overseas With Foreign Retirement Plans, Dual Citizenship Tax Issues
- New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow
- IRS Changing Individual Taxpayer ID Number Application Requirements
- Insurer Group Health Inc. To Refund $500,00+ & Change Claims Practices To Settle NY AG Charges It Wrongfully Denied Coverage
- NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage
- Making Wellness Work On A Shoestring Budget
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation |
Permalink
Posted by Cynthia Marcotte Stamer
November 28, 2012
The yearly maximum guaranteed benefit for a 65-year-old retiree under the Pension Benefit Guaranty Corporation (PBGC) insurance program will increase to almost $57,500 in 2013, up from $56,000 in 2012. Beginning in 2013, the PBGC announced November 27, 2012 that the maximum yearly guarantee for a 65-year-old retiree is $57,477.24. The increase is not retroactive.
The slight increase in the guaranteed benefit is likely to be meaningful for the many pensioners receiving benefits under pension plans covered by the PBGC insurance program. This program insures guaranteed benefits amounts for pensioners of defined benefit plans covered by the PBGC insurance programs that are underfunded under the PBGC rules when terminated and otherwise meet program requirements. Most retirees who get their pension from PBGC — almost 85 percent — receive the full amount of their promised benefit. In some cases, retirees can receive more than the PBGC maximum guarantee.
The PBGC maximum guarantee is based on a formula prescribed by federal law. Yearly amounts are higher for people older than age 65, and lower for those who retire earlier or choose survivor benefits (see chart). If a pension plan ends in 2013, but a retiree does not begin collecting benefits until a future year, the 2013 rates still apply. For plans that terminate as a result of bankruptcy, the maximum yearly rates are guided by the limits in effect on the day the bankruptcy started, not the day the plan ended.
The following chart shows the 2013 annual and monthly maximum benefit guarantees for retirees from ages 45 to 75. The maximum amount is lower for retirees who begin getting benefits at ages below 65, reflecting the fact that younger retirees receive more monthly pension checks over a longer lifetime. The maximum amount is higher for benefits starting at ages above 65, because older retirees receive fewer monthly pension checks over their expected lifetimes.
| PBGC Maximum Monthly Guarantees for 2013 |
| Age |
Annual Maximum |
Monthly Maximum |
Monthly Joint and 50% Survivor Maximum* |
| 75 |
174,730.80 |
14,560.90 |
13,104.81 |
| 74 |
158,867.04 |
13,238.92 |
11,915.03 |
| 73 |
143,003.40 |
11,916.95 |
10,725.26 |
| 72 |
127,139.64 |
10,594.97 |
9,535.47 |
| 71 |
111,275.88 |
9,272.99 |
8,345.69 |
| 70 |
95,412.24 |
7,951.02 |
7,155.92 |
| 69 |
85,641.12 |
7,136.76 |
6,423.08 |
| 68 |
77,019.48 |
6,418.29 |
5,776.46 |
| 67 |
69,547.44 |
5,795.62 |
5,216.06 |
| 66 |
63,225.00 |
5,268.75 |
4,741.88 |
| 65 |
57,477.24 |
4,789.77 |
4,310.79 |
| 64 |
53,453.88 |
4,454.49 |
4,009.04 |
| 63 |
49,430.40 |
4,119.20 |
3,707.28 |
| 62 |
45,407.04 |
3,783.92 |
3,405.53 |
| 61 |
41,383.56 |
3,448.63 |
3,103.77 |
| 60 |
37,360.20 |
3,113.35 |
2,802.02 |
| 59 |
35,061.12 |
2,921.76 |
2,629.58 |
| 58 |
32,762.04 |
2,730.17 |
2,457.15 |
| 57 |
30,462.96 |
2,538.58 |
2,284.72 |
| 56 |
28,163.88 |
2,346.99 |
2,112.29 |
| 55 |
25,864.80 |
2,155.40 |
1,939.86 |
| 54 |
24,715.20 |
2,059.60 |
1,853.64 |
| 53 |
23,565.72 |
1,963.81 |
1,767.43 |
| 52 |
22,416.12 |
1,868.01 |
1,681.21 |
| 51 |
21,266.52 |
1,772.21 |
1,594.99 |
| 50 |
20,117.04 |
1,676.42 |
1,508.78 |
| 49 |
18,967.44 |
1,580.62 |
1,422.56 |
| 48 |
17,817.96 |
1,484.83 |
1,336.35 |
| 47 |
16,668.36 |
1,389.03 |
1,250.13 |
| 46 |
15,518.88 |
1,293.24 |
1,163.92 |
| 45 |
14,369.28 |
1,197.44 |
1,077.70 |
| * Both spouses the same age |
The PBGC insurance program is funded through insurance premiums paid by covered plans. In recent years, the number of underfunded plans has increased due to a lagging economy, declines in market performance and other factors. The demands on the PBGC insurance program prompted Congress to increase premiums, modify pension funding rules and enact various other reforms in an effort to shore up the PBGC insurance program. The PBGC also has undertaken a number of regulatory and operational reforms. Companies sponsoring plans covered by the PBGC insurance program should review their existing funding and insurance requirements to ensure that they are in compliance with existing rules and taking advantage of the most favorable opportunities under these rules. In addition, companies sponsoring defined benefit plans govered by the PBGC insurance program and/or the Internal Revenue Code and Employee Retirement Income Security Act’s minimum funding rules or entities that are part of commonly controlled or affiliated groups of companies, purchasing stock or assets from such company groups or lending to or investing in such entities should evaluate the funding status of these programs and the responsibilities and liability exposures that might impact their interests.
For additional information, see PBGC’s fact sheet “Pension Gurantees” and for information about the benefits guaranteed by the PBGC, see “Making Sense of the Maximum Insurance Benefit.”
For Help or More Information
If you need help reviewing and updating, administering or defending your employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
About Ms. Stamer
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and registerto receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
- Supreme Court Decision Puts Health Plans Under Fire To Complete ACA-Required Summary of Benefits & Communications & Other Health Plan Updates
- $27M+ Settlement Highlights Fiduciary Risks Plan Sponsors & Fiduciaries Risk If Plan Vendors, Compensation Improperly Set
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- Model Language May Aid Section 83(b) Elections Even As Executive & Other Special Compensation Carry Growing Liability Traps
- IRS To Offer Help For U.S. Citizens Overseas With Foreign Retirement Plans, Dual Citizenship Tax Issues
- New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow
- IRS Changing Individual Taxpayer ID Number Application Requirements
- Insurer Group Health Inc. To Refund $500,00+ & Change Claims Practices To Settle NY AG Charges It Wrongfully Denied Coverage
- NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage
- Making Wellness Work On A Shoestring Budget
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013 |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: 401(k), Bankruptcy, defined benefit, Employee Benefits, Employers, ERISA, hardship withdrawals, Hurricane Sandy, PBGC, plan loans, retirement |
Permalink
Posted by Cynthia Marcotte Stamer
November 27, 2012
Get Up To Date On Details of New De-Identification Guidance & Other HIPAA Developments By Participating In 12/12 HIPAA Update Web Workshop
Health care providers, health plans, health care clearinghouses (covered entities) and their business associates and leadership should check and update their policies and practices for the de-identification of protected health information (PHI) in light of newly-released Guidance Regarding Methods for De-identification of Protected Health Information in Accordance With the Health Insurance Portability and Accountablity Act (HIPAA) Privacy Rule (Guidance) released by the Department of Health & Human Services (HHS) Office of Civil Rights yesterday (November 26, 2012).
Solutions Law Press, Inc. will host a one-hour, online HIPAA Update Workshop on the Guidance and other recent regulatory and enforcement developments under HIPAA for covered entities and their business associates on Wednesday, December 12 beginning at Noon Central Time. To register, see here.
PHI collected by health care providers, health plans, their management, sponsors, and vendors often includes a wealth of information valuable for use for functions unrelated to the HIPAA-covered functions and activities that leads covered entities or their business associates to collect or keep this data. While it might be tempting to repurpose this information for business planning and marketing purposes, covered entities and their business partners or associates frequently assume that covered entities and others that they deal with must take proper steps to that no PHI is used, accessed, disclosed or shared unless that action is allowed under the Privacy Rules, properly de-identified, or both.
When planning to rely upon the de-identification of PHI to engage in these activities, parties planning to rely upon HIPAA’s exception for de-identified PHI will want to consult new guidance just released by OCR about the de-identification requirements before moving forward. Existing Privacy Rules and the Guidance recognize two alternative methods that covered entities and their business can use to properly de-identify PHI for purposes of the HIPAA Privacy Rule.
OCR published the Guidance to help covered entities to understand what qualifies as de-identification, the general process by which de-identified information is created, and the options available for performing de-identification for purposes of the HIPAA Privacy Rule. The publication of this guidance was mandated as part of amendments to HIPAA enacted by Health Information Technology for Economic and Clinical Health (HITECH) Act included in the American Recovery and Reinvestment Act of 2009 (ARRA). Section 13424(c) of the HITECH Act requires the HHS to issue guidance on how best to implement the requirements for the de-identification of health information contained in the Privacy Rule.
De-identification & Its Rationale Under Privacy Rule
The Privacy Rule was designed to protect individually identifiable health information through permitting only certain uses and disclosures of PHI provided by the Rule, or as authorized by the individual subject of the information. However, in recognition of the potential utility of health information even when it is not individually identifiable, §164.502(d) of the Privacy Rule permits a covered entity or its business associate to create information that is not individually identifiable by following the de-identification standard and implementation specifications in Privacy Rule §164.514(a)-(b). These provisions allow the entity to use and disclose information that neither identifies nor provides a reasonable basis to identify an individual provided the Covered Entity can show that the PHI has been de-identified in accordance with either the Expert Determination Method or the Safe Harbor Method of the de-identification standard of the Privacy Rule and is not re-identified. Regardless of the method used to de-identify PHI, the Privacy Rule does not restrict the use or disclosure of de-identified health information, as it is no longer considered PHI and is not re-identified.
Privacy Rule De-Identification Implementation Standards Permit Alternative Methods of De-identification
Section 164.514(a) of the HIPAA Privacy Rule provides the standard for de-identification of protected health information. Under this standard, health information is not individually identifiable if it does not identify an individual and if the covered entity has no reasonable basis to believe it can be used to identify an individual. See Privacy Rule § 164.514.
Sections 164.514(b) and (c) of the Privacy Rule contain the implementation specifications that a covered entity must follow to meet the de-identification standard. As summarized in Figure 1, the Privacy Rule provides two methods by which health information can be designated as de-identified:
- The formal determination by a qualified expert in accordance with the Privacy Rule (Expert Determination Method); or
- The removal of specified individual identifiers as well as absence of actual knowledge by the covered entity that the remaining information could be used alone or in combination with other information to identify the individual (Safe Harbor Method).
In order for PHI to qualify as de-identified under the “Expert Determination Method, Privacy Rule § 164.514(b)(1) requires that a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable:
- Applying such principles and methods, determines that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual who is a subject of the information; and
- Documents the methods and results of the analysis that justify such determination.
Alternatively, Privacy Rule § 164.514(b)(2) provides that PHI will qualify as de-identified under the Safe Harbor Method if:
- All of an extensive list of identifiers of the individual or of relatives, employers, or household members of the individual, are removed from the data; and
- The covered entity does not have actual knowledge that the information could be used alone or in combination with other information to identify an individual who is a subject of the information.
As long as the data is not re-identified, the Guidance indicates that a covered entity may prove fulfillment of the de-identification standard of Privacy Rule §164.514(a) by showing satisfaction of all applicable requirements of either method. Under the Privacy Rule, de-identified health information created following these methods is no longer protected by the Privacy Rule because it does not fall within the definition of PHI. Of course, de-identification leads to information loss which may limit the usefulness of the resulting health information in certain circumstances. Consequently, covered entities may wish to select de-identification strategies that minimize such loss.
Both alternatives for de-identification under the Privacy Rule require that covered entities and their business associates decide whether and how to keep the option for re-identification of PHI slated for de-identification and where applicable, appropriately manage the re-identification opportunity and data to avoid violation of the Privacy Rule.
According to the Privacy Rule, if a covered entity or business associate successfully undertook an effort to identify the subject of de-identified information it maintained, the health information now related to a specific individual would again be protected by the Privacy Rule, as it would meet the definition of PHI. Disclosure of a code or other means of record identification designed to enable coded or otherwise de-identified information to be re-identified is also considered a disclosure of PHI. In this regard, Privacy Rule §164.514(c) specifies that if the covered entity assigns a code or other means of record identification to allow information de-identified under this section to be re-identified by the covered entity, themeans of record identification is not derived from or related to information about the individual and is not otherwise capable of being translated so as to identify the individual; it can’t use elements of the protected PHI as the re-identification key,must safeguard the key, and can’t use or disclose the key or other re-identification tool for any other purpose.
Preparing For, Guiding & Documenting The De-identification Process For Defensibility
The Guidance stresses that importance of documentation for which values in health data correspond to PHI, as well as the systems that manage PHI and its risk of identification or re-identification in the de-identification process cannot be overstated.
The Guidance provides guidance to help guide covered entities and their business associates through the steps and analysis of using the Expert Determination versus Safe Harbor Method. A review of this Guidance makes clear that the design and administration of the de-identification process under either method requires careful and well-documented planning, analysis and implementation to fulfill and to keep the documentation that a covered entity or business associate might need to defend its decision to treat and use PHI as de-identified under the Privacy Rule against a potential audit or enforcement inquiry. The Guidance also seeks to further illuminate the requirements for effective de-identification through a series of questions and answers, supplemented by work flow and other charts, examples and other illustrations and tips on the proper use of each alternative Method and managing risks and the process associated with that Method. A Glossary of Terms also is shared. The discussion in the Guidance makes clear that covered entities and their businesses associates using either Method to de-identify PHI should be prepared to make a number of judgments about which Method to use, whether and how to make arrangements for re-identification, and how to properly manage the process to meet the requirements of the implementation standard and manage re-identification or other risks.
Register For 12/12 HIPAA Update Web Workshop To Catch Up On De-Identification Guidance & Other HIPAA & Texas HIPAA Regulatory & Enforcement Developments
Training and compliance mandates applicable to covered entities and their business associates under the newly strengthened Texas HIPAA law and HIPAA’s Privacy and Breach Notification Rules make it more important than ever that covered entities and their business associates get the timely training and other assistance needed to properly comply with requirements for the protection of PHI under the new Guidance and other HIPAA and Texas HIPAA mandates.
To aid in this process, Solutions Law Press, Inc. will host a 2012 HIPAA Update Web Workshop covering the new Guidance on de-identification and other regulatory and enforcement developments under HIPAA and the newly amended Texas HIPAA law on December 12, 2012 from 1:00 P.M.-2:00 P.M. Eastern | Noon – 1:00 P.M. Central | 11:00 A.M-Noon Mountain | 10:00A.M-11:00 A.M. Pacific Time.
Expanded health care privacy mandates of the Texas Medical Records Privacy Act that take effect September 1, 2012 and HIPAA regulations require covered entities and their business associates conduct training and take other steps to protect the privacy and security of PHI.
Complete HIPAA Training While You Catch Up On The Latest On HIPAA & Texas Medical Records Privacy Rules & Get Helpful Compliance And Risk Management Tips!
Health care providers, health plans, health care clearinghouses face new imperatives to strengthen their HIPAA and other procedures for handling protected health information and other sensitive information to manage expanding risks and responsibilities arising from evolving rules, expanding enforcement and oversight, and rising penalties and other liabilities.
Expanded health care privacy mandates of the Texas Medical Records Privacy Act that take effect September 1, 2012 and HIPAA regulations require covered entities and their business associates conduct training and take other steps to protect the privacy and security of personal health information (PHI) and certain other information.
The $4.3 million HIPAA Civil Monetary Penalty and growing list of $1 million plus resolution payments announced by the Office of Civil Rights coupled with its commitment to investigate all large breaches reported under the HITECH Act Breach Notification Rule and other stepped up enforcement and newly initiated audit activities send a clear signal that HIPAA-covered entities and their business associates face significant exposures for failing to appropriately manage their HIPAA and other responsibilities when handling protected health information. Meanwhile, Texas House Bill 300 has raised maximum state civil penalties for unlawful disclosures of Protected Health Information under the Texas Medical Records Privacy Act to from $5,000 to $1.5 million per year. Meanwhile HITECH Act amendments to HIPAA require covered entities provide notification of certain breaches while Texas House Bill 300 adds its own specific requirements to provide notice of certain breaches of computerized data containing sensitive personal information.
With Texas House Bill 300 expanding covered entities responsibilities and liabilities and OCR issuing new regulations and other guidance to implement amendments to the HIPAA Privacy & Security Standards and implement and enforce the HITECH Act Breach Notification Rule, health care providers, health plans and insurers, their brokers, third-party administrators, and other covered entities, as well as their business associates and employer and union clients must review and tighten their policies, practices, business associate and other contracts, and enforcement to manage HIPAA and other compliance and manage risks arising from the access, collection, use, protection and disclosure of PHI to meet expanding mandates and to guard against growing liability exposures under HIPAA and other federal and state laws.
Solutions Law Press, Inc. invites you to catch up on the latest on these and other key HIPAA requirements and enforcement and learn tips for managing risks and liabilities by participating in the “HIPAA Update Workshop” on Wednesday, December 12, 2012 via WebEx for a registration fee of $125.00.
Pre-approved for various types of continuing and professional education credit, the December 12, 2012 HIPAA Update Workshop will brief participants on the De-Identification Guidance as well as the latest on other regulatory and enforcement guidance under the HIPAA Privacy, Security and Breach Notification rules and guidance and share compliance and risk management lessons emerging from recent OCR enforcement and audit activities and other selected federal and state litigation and enforcement actions impacting the handling of protected health information. Among other things, the workshop will cover:
- The De-Identification Guidance just released by OCR on November 26, 2012;
- The latest HIPAA Privacy, Security & Breach Notification Guidance, Audits & Enforcement
- Highlights Texas House Bill’s Amendments To Texas Medical Records Privacy Law That Took Effect September 1, 2012
- Post HITECH Act Heightened Liability Risks: Audits, Civil Penalties, Criminal Penalties & State Lawsuits
- Expansion of HIPAA Responsibilities & Liabilities To Business Associates & What Covered Entities & Business Associates Should Do In Response
- HIPAA Data Breach Notification Requirements
- Practical Challenges & Strategies For Managing These Responsibilities
- Tips For Coordinating HIPAA & Other Federal & State Medical Privacy, Financial Information, Identity Theft & Date Security Compliance and Risk Management
- Practical Strategies For Monitoring & Responding To New Requirements & Changing Rules
- Participant Questions
About The Speaker
The workshop will be conducted by attorney Cynthia Marcotte Stamer. A Fellow in the American College of Employee Benefits Counsel, recognized in International Who’s Who, North Texas Health Care Compliance Professionals Association Vice-President and Board Certified in Labor & Employment Law, attorney Cynthia Marcotte Stamer has 25 years experience advising and representing private and public health care providers, employers, employer and union plan sponsors, employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental leaders and others on privacy and data security, health care, health and other employee benefit. employment, insurance and related matters. A well-known and prolific author and popular speaker, Ms. Stamer has worked extensively with heath care providers, health plans and other payers, health and insurance IT and data systems, and others on HIPAA and other privacy and data security concerns. She served as the scrivener for the ABA JCEB Agency Meetings with the Office of Civil Rights on HIPAA Privacy for the past two years. She presently serves as Co-Chair of the ABA RPTE Section Welfare Plan Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Representative, an Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com) and Employee Benefit News, and various other publications. A primary drafter of the Bolivian Social Security privatization law with extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on public policy and regulatory advocacy on HIPAA and other privacy and data security risks and requirements as well as a broad range of other health, employee benefits, human resources, insurance, tax, compliance and other matters and representing clients in dealings with OCR and other HHS agencies, as well as the Departments of Labor, Treasury, Federal Trade Commission, HUD and Justice, Congress and state legislatures, and various state attorneys general, insurance, labor, worker’s compensation, medical licensure and disciplinary and other agencies and regulators. A prolific author and popular speaker, Ms. Stamer regularly authors materials and conducts workshops and professional, management and other training on HIPAA and other privacy, health care, employee benefits, human resources, insurance and related topics for the ABA, Aspen Publishers, the Bureau of National Affairs (BNA), SHRM, World At Work, Government Institutes, Inc., the Society of Professional Benefits Administrators and many other organizations. Her insights on privacy and other matters are quoted in Modern Healthcare, HealthLeaders, Benefits, Caring for the Elderly, The Wall Street Journal and many other publications. She also regularly serves on the faculty and planning committees of a multitude of symposium and other educational programs. For more details about Ms. Stamer’s services, experience, presentations, publications, and other credentials or to ask about arranging counseling, training or presentations or other services by Ms. Stamer, see www.CynthiaStamer.com.
Registration
The Registration Fee is $125.00 per person. Registration Fee Discounts available for groups of three or more. Pre-payment required via website registration required via website PayPal. No checks or cash accepted. Persons not registered at least 48 hours in advance will only participate subject to system and space availability.
Continuing Education Credit
The HIPAA Update Workshop is approved to be offered for general certification credit by the State Bar of Texas, Texas Department of Insurance, HRCI and WorldAtWork education credit for the time period offered subject to fulfillment all applicable accrediting agency requirements, completion of required procedures. Note that the applicable credentialing agency retain the final authority to determine whether an individual qualifies to receive requested continuing education credit. Neither Solutions Law Press, Inc., the speaker or any of their related parties guarantees the approval of credit for any individual or has any liability for any denial of credit. Special fees or other conditions may apply. CANCELLATION & REFUND POLICY: In order to receive credit, cancellation (either fax or mail) must be received at least 48 hours in advance of the meeting and are subject to a $10.00 refund processing fee. Refunds will be made within 60 days of receipt of written cancellation notice.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assist businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. If you would prefer not to receive communications from Solutions Law Press, Inc. send an e-mail with “Solutions Law Press Unsubscribe” in the Subject to support@solutionslawyer.net. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN. If you are an individual with a disability who requires accommodation to participate, please let us know at the time of your registration so that we may consider your request.
©2012 Solutions Law Press, Inc. All Rights Reserved.
Comments Off on New OCR HIPAA De-Identification Guidance Among Developments Covered In 12/12 HIPAA Update Web Workshop |
ADA, Civil Rights, Consumer Protection, Corporate Compliance, Data Security, Disease Management, Drug & Alcohol, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Medicare Part D, Prescription Drugs, Privacy, Wellness Programs | Tagged: compliance, Health Care, Heatlh Plans, HIPAA, PHI, Texas Medical Records Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
November 23, 2012
A district court judge in Washington has ordered the International Longshore and Warehouse Union (ILWU) to stop processing grievances and filing lawsuits against a competitive union, the International Brotherhood of Electrical Workers (IBEW), and, pending the outcome of further litigation, employers assigning work of plugging in, unplugging and monitoring refrigerated shipping containers at the Port of Portland to IBEW. The litigation between the two competing unions shows how employers can get caught in risky, no-win liability exposures as a result of power battles between competing unions over the right to represent workers performing services for the employers.
The injunctive order steps from a dispute between both unions over which union is entitled to represent a group of workers. Both unions claim the work, citing various contracts and collective bargaining agreements. In August 2012, the National Labor Relations Board issued a decision concluding that the employees represented by the IBEW are entitled to the work. Despite that ruling, the ILWU and two of its locals have continued to file and process grievances against employers serving as carriers at the port, seeking lost wages for work assigned to the IBEW. The ILWU also filed a claim against the IBEW in federal court under the Labor-Management Relations Act.
In granting the petition for injunctive relief from the NLRB’s Regional Office in Seattle late Wednesday, November 22, 2012, U.S. District Judge Michael H. Simon found that, by filing grievances and seeking enforcement of subsequent awards despite the Board’s decision, the ILWU had the unlawful secondary object of pressuring shipping carriers to stop doing business with the Port of Portland. He enjoined the union from filing, processing, maintaining, prosecuting, or threatening grievances or new lawsuits in the matter against the union as well as the carrier employers. With respect to the dispute with IBEW, the court ruled that the continued filing of the grievances against the IBEW constituted an unfair labor practice because the NLRB ruling already had recognized the IBEW as the authorized representative of the covered employees performing the work.
Concerning his decisions to also bar the ILWU from suing and filing charges against the employing carriers that have been caught in the war between the two unions, the Court issued a temporary injunction pending the outcome of the litigation. The court noted that the question of whether the NLRB ruling prohibited the carrier employers from subcontracting work covered by the NLRB order could not be permanently resolved based in the facts on the record, but that the IBEW had produced sufficient evidence of likely success on merits and irreparable harm to justify the court’s issuance of a temporary injunction.
While federal courts rarely enjoin unions under the National Labor Relations Act, the federal court in this matter found in light of the NLRB ruling in favor of the other union, the court’s decision in favor of the IBEW allows the IBEW to move forward for the time being as the representative of the workers. Concurrently, the court’s decision allows the employers caught between the two unions to continue operations for the time being by assigning work to the IBEW workers unless and until the ILWU proves its entitlement to that work.
For Help or More Information
If you need help reviewing and updating, administering or defending your employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
About Ms. Stamer
A Board Certified Labor & Employment attorney and Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
Ms. Stamer is widely known for her extensive and creative knowledge and experienced with these and other labor and employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and registerto receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
- Supreme Court Decision Puts Health Plans Under Fire To Complete ACA-Required Summary of Benefits & Communications & Other Health Plan Updates
- $27M+ Settlement Highlights Fiduciary Risks Plan Sponsors & Fiduciaries Risk If Plan Vendors, Compensation Improperly Set
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- Model Language May Aid Section 83(b) Elections Even As Executive & Other Special Compensation Carry Growing Liability Traps
- IRS To Offer Help For U.S. Citizens Overseas With Foreign Retirement Plans, Dual Citizenship Tax Issues
- New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow
- IRS Changing Individual Taxpayer ID Number Application Requirements
- Insurer Group Health Inc. To Refund $500,00+ & Change Claims Practices To Settle NY AG Charges It Wrongfully Denied Coverage
- NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage
- Making Wellness Work On A Shoestring Budget
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competiting Unions |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: Employer, NLRA, NLRB, unfair labor practices, Union |
Permalink
Posted by Cynthia Marcotte Stamer
November 23, 2012
Retirement plan fiduciaries of plans covering participants impacted by Hurricane Sandy seeking loans or hardship withdrawals received some welcome guidance from the Internal Revenue Service (IRS).
The IRS announced November 16 that 401(k)s and similar employer-sponsored retirement plans can make loans and hardship distributions to victims of Hurricane Sandy and members of their families. Read News Release IR-2012-93. For more information, read Announcement 2012-44.
Plan fiduciaries dealing with requests or wishing to offer this option to participants affected by Hurricane Sandy should check this guidance along with existing plan terms and associated loan and hardship withdrawal rules to confirm that their plan terms contain all necessary provisions to use this guidance and their plan’s loan or hardship withdrawal provisions before moving forward. Assuming that the plan contains appropriate provisions and the necessary requirements are met,the guidance says plan fiduciaries can authorize these requests.
For Help or More Information
If you need help reviewing and updating, administering or defending your employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
About Ms. Stamer
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and registerto receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
- Supreme Court Decision Puts Health Plans Under Fire To Complete ACA-Required Summary of Benefits & Communications & Other Health Plan Updates
- $27M+ Settlement Highlights Fiduciary Risks Plan Sponsors & Fiduciaries Risk If Plan Vendors, Compensation Improperly Set
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- Model Language May Aid Section 83(b) Elections Even As Executive & Other Special Compensation Carry Growing Liability Traps
- IRS To Offer Help For U.S. Citizens Overseas With Foreign Retirement Plans, Dual Citizenship Tax Issues
- New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow
- IRS Changing Individual Taxpayer ID Number Application Requirements
- Insurer Group Health Inc. To Refund $500,00+ & Change Claims Practices To Settle NY AG Charges It Wrongfully Denied Coverage
- NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage
- Making Wellness Work On A Shoestring Budget
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: 401(k), Employee Benefits, Employers, hardship withdrawals, Hurricane Sandy, plan loans |
Permalink
Posted by Cynthia Marcotte Stamer
November 20, 2012
Employers and other health plan sponsors, insurers, and their administrators and service providers should consider the advisability of updating health plan cost projections, plan documents and procedures, communications and other practices in response to new and proposed guidance interpreting federal health plan rules under the Patient Protection and Affordable Care Act (ACA) released today (November 20, 2012).
Solutions Law Press, Inc. plans will host a webex executive study group briefing to update its members and other interested persons on this new and proposed guidance on Tuesday, November 27, 2012 at Noon Central Time. Interested persons wishing details about registration for this briefing should send an e-mail here.
Guidance Released Today
Earlier today, the Departments of Labor and Health & Human Services issued guidance implementing ACA provisions that make it illegal for insurance companies to discriminate against people with pre-existing conditions, as well as guidance impacting wellness and disease management programs and the “essential health benefits” definition that plays a key role in defining the benefits package mandates applicable to exchange and other health plans and policies required to comply with ACA’s mandates. This guidance includes:
- A proposed rule that, beginning in 2014, prohibits health insurance companies from discriminating against individuals because of a pre-existing or chronic condition. Under the rule, insurance companies would be allowed to vary premiums within limits, only based on age, tobacco use, family size and geography. Health insurance companies would be prohibited from denying coverage to any American because of a pre-existing condition or from charging higher premiums to certain enrollees because of their current or past health problems, gender, occupation, and small employer size or industry that the agencies intend to ensure that people for whom coverage would otherwise be unaffordable and young adults have access to a catastrophic coverage plan in the individual market. See HHS Proposed Regulation – Health Insurance Market Rules available here;
- A proposed rule outlining policies and standards for coverage of essential health benefits, while giving states more flexibility to implement the Affordable Care Act. Essential health benefits are a core set of benefits that would give consumers a consistent way to compare health plans in the individual and small group markets. A companion letter on the flexibility in implementing the essential health benefits in Medicaid was also sent to states. Related to Essential Health Benefits, Actuarial Value, and Accreditation available here; and
- A proposed rule implementing and expanding employment-based wellness programs that the agencies intend to promote health and help control health care spending, while prohibiting what the agencies consider unfair underwriting practices that impermissibly discriminate based on health status. See Proposed regulations here; Study available here; Fact Sheet available here.
With this guidance impacting key plan design and cost concerns, employers and other health plan sponsors, plan fiduciaries and administrators, insurers and their vendors will need to act quickly to evaluate the potential implications of this guidance in light of already existing rules and enforcement positions, their plan design and costs, and market and other factors.
Today’s Guidance Just Tip of Iceberg
The guidance published today is the first in an expected deluge of regulatory pronouncements that HHS, DOL, the Internal Revenue Service and state insurance agencies are expected to issue as the rush to finalize arrangements and guidance governing the implementation and enforcement of the ACA health care reforms scheduled to take effect and to tweek guidance on provisions already effective under the law. This guidance adds to the extensive list of previously issued guidance previously published by the Agencies since Congress passed ACA. With the election behind the US and the Supreme Court having rejected initial challenges by businesses and individuals to the employer and individual mandates last Summer, employers and insurers now must get cracking to update their programs and cost estimates to comply with both existing and new guidance while keeping a close eye out for potential changes to ACA or other federal or state health coverage laws as the new Congress is expected to continue to discuss refinements or other changes when the new Congress begins work in January 2013.
What Should Employers Do To Cope With These & Other Health Plan Mandates?
Facing the operational and financial challenges of meeting these mandates, many business leaders continue report significant concern about what they should do to respond to these requirements. For some practical steps that businesses confronting these issues should take to cope with ACA and other health plan responsibilities, check out the “12 Steps Every Employer With A Health Plan Should Do Now” article by Cynthia Marcotte Stamer in the October 26, 2012 online edition of Texas CEO Magazine. To read the full article, see here.
Clearly in light of the new guidance, employers, insurers, health plan fiduciaries and their service providers need to act quickly to familiarize themselves with the guidance and make any need adjustments to their plans, communications, practices and budgets warranted by the new guidance and remain vigilent for and prepared to do the same with other guidance and reform proposals as it is released.
Beyond responding to the new guidance and other future developments, most health plan sponsors, insurers, administrators and other fiduciaries, and their vendors also should consider conducting this specific analysis and update of their health benefit programs in the context of a broader strategy.
In her 12-Steps Article, Ms. Stamer writes, “While most employers and insurers of employment-based group health plans view with great concern radically expanded health plan responsibilities taking effect in 2014, many are failing to take steps critical to manage exposures and costs already arising from the Affordable Care Act (ACA) and other federal health plan regulations.”
In the article, Ms Stamer discusses the following 12 steps that she suggests most businesses consider to help catch up with current responsibilities and to help their business manage future costs and responsibilities:
- Know The Cast Of Characters & What Hat(s) They Wear
- Know What Rules Apply, and How They Affect a Group Health Plan
- Review and Update Health Plan Documents to Meet Requirements and Manage Exposure
- Update the Plan For Changing Compliance Requirements and Enhanced Defensibility
- Consistency Matters: Build Good Plan Design, Documentation and Processes, and Follow Them
- Ensure the Correct Party Carefully Communicates About Coverage and Claims in a Compliant, Timely, Prudent, Provable Manner
- Prepare For ACA’s Expanded Data Gathering and Reporting Requirements
- Select, Contract and Manage Vendors With Care
- Help Plan Members Build Their Health Care Coping Skills With Training and Supportive Tools
- Pack The Parachute and Locate The Nearest Exit Doors
- Get Moving On Compliance and Risk Management Issues
- Provide Input On Affordable Care Act Rules
For Help or More Information
If you need help reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
About Ms. Stamer
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and registerto receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
- Supreme Court Decision Puts Health Plans Under Fire To Complete ACA-Required Summary of Benefits & Communications & Other Health Plan Updates
- $27M+ Settlement Highlights Fiduciary Risks Plan Sponsors & Fiduciaries Risk If Plan Vendors, Compensation Improperly Set
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- Model Language May Aid Section 83(b) Elections Even As Executive & Other Special Compensation Carry Growing Liability Traps
- IRS To Offer Help For U.S. Citizens Overseas With Foreign Retirement Plans, Dual Citizenship Tax Issues
- New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow
- IRS Changing Individual Taxpayer ID Number Application Requirements
- Insurer Group Health Inc. To Refund $500,00+ & Change Claims Practices To Settle NY AG Charges It Wrongfully Denied Coverage
- NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage
- Making Wellness Work On A Shoestring Budget
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
1 Comment |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
October 29, 2012
Business leaders concerned about what to do to manage health benefit costs, responsibilities and liabilities over the next year and to position to cope with impending shifts in the health plan regulatory landscape ahead should check out the “12 Steps Every Employer With A Health Plan Should Do Now” article by Cynthia Marcotte Stamer in the October 26, 2012 online edition of Texas CEO Magazine.
Nationally recognized for quarter century of work advising businesses and governments about health benefit and other employee benefits and human resources matters, Ms. Stamer says regardless of who wins the Presidential election next week, employers need to get moving to deal with current health plan obligations and exposures and brace for new future challenges.
Ms. Stamer writes, “While most employers and insurers of employment-based group health plans view with great concern radically expanded health plan responsibilities taking effect in 2014, many are failing to take steps critical to manage exposures and costs already arising from the Affordable Care Act (ACA) and other federal health plan regulations.”
In the article, Ms Stamer discusses the following 12 steps that she suggests most businesses consider to help catch up with current responsibilities and to help position their business to anticipate and manage future costs and responsibilities:
- Know The Cast Of Characters & What Hat(s) They Wear
- Know What Rules Apply, and How They Affect a Group Health Plan
- Review and Update Health Plan Documents to Meet Requirements and Manage Exposure
- Update the Plan For Changing Compliance Requirements and Enhanced Defensibility
- Consistency Matters: Build Good Plan Design, Documentation and Processes, and Follow Them
- Ensure the Correct Party Carefully Communicates About Coverage and Claims in a Compliant, Timely, Prudent, Provable Manner
- Prepare For ACA’s Expanded Data Gathering and Reporting Requirements
- Select, Contract and Manage Vendors With Care
- Help Plan Members Build Their Health Care Coping Skills With Training and Supportive Tools
- Pack The Parachute and Locate The Nearest Exit Doors
- Get Moving On Compliance and Risk Management Issues
- Provide Input On Affordable Care Act Rules
For Help or More Information
If you need help reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer. To read the full article, see here. To learn more, check out some of Ms. Stamer’s upcoming speaking engagements, her many publications or contact Ms. Stamer directly at (469) 767-8872.
About Ms. Stamer
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and registerto receive future updates about developments on these and other concerns see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
October 5, 2012
Severance Deals Get Hotel Bel-Air Nailed By NLRB For Labor Law Violations
A National Labor Relations Board (NLRB) decision that nails Hotel Bel-Air (Hotel) for offering severance packages to unionized workers highlights one of a range of potentially costly missteps that businesses conducting reductions in force or other re-engineering risk if they fail to properly understand and manage legal requirements when designing and implementing the change.
Since labor and other workforce-related risks are long-standing, some businesses, their leaders and consultants may be tempted to assume that prior experience means these are handled. The fact specific nature of the risks and changing rules and enforcement, however, makes it critical not to be over-confident. Legal and operational mismanagement of these risks can disrupt achievement of the purpose of the change and add significant added cost and exposure for the business and its management. Proper use of qualified legal counsel as part of the process is important both to help identify and properly manage risk and to leverage attorney-client privilege to help shield sensitive communications in the planning and implementation of these activities from discovery.
Employer’s Obligations To Negotiate & Deal With Union
Once a union is recognized as the certified representative of employees in a workplace, the National Labor Relations Act (NLRA) generally prohibits the employer from unilaterally changing term and conditions of employment or from going around the union to bargain directly with employees over layoffs, the effects of layoffs and other material terms and conditions of employment. As part of this responsibility, the NLRA and other federal and state laws generally require that employers provide notification to the union of planned reductions in force, plant closings or other operational changes that might impact the workforce and bargain in good faith with the union before conducting layoffs, or offering or making in work rules, compensation, severance or other benefits or other terms or conditions of employment.
In general, an employer’s duty to bargain with a union generally also continues to apply when the collective bargaining agreement between the union and the employer expires unless and until the parties reach agreement or impasse. While negotiations continue, the employer’s obligation to refrain from making unilateral changes generally encompasses a duty to refrain from implementation unless and until an overall impasse has been reached on bargaining for the agreement as a whole. See Pleasantview Nursing Home, 335 NLRB 96 (2001) citing Bottom Line Enterprises, 302 NLRB 373 (1991). The NLRB considers negotiations to be in progress, and will not find a genuine impasse to exist, until the parties are warranted in assuming that further bargaining would be “futile” or that there is “no realistic possibility that continuation of discussion . . . would be fruitful.” Saint-Gobain Abrasives, Inc., 343 NLRB 542 556 (2004).
Because the existence of impasse is a factual determination that depends on a variety of factors, including the contemporaneous understanding of the parties as to the state of negotiations, the good faith of the parties, the importance of the disputed issues, the parties’ bargaining history, and the length of their negotiations, Taft Broadcasting Co., 163 NLRB 475, 478 (1967), parties to the negotiation often do not necessarily agree when they have reached impasse. As the September 28 decision by the NLRB against the Hotel shows, employers that act unilaterally based on an overly optimistic determination of impasse suffer significant financial and other operational and legal risks for engaging in unfair labor practices in violation of Section 8 of the NLRA.
NLRB Nails Hotel Bel-Air For Failing To Bargain, Offering Severance Around Union
In its September 28, 2012 Bel-Air Hotel Decision, the NLRB ruled the Hotel engaged in unfair labor practices in violation of the NLRA when it offered severance packages to laid off workers in return for the workers’ waiver of recall rights without bargaining to impasse with the union representing its workers, UNITE HERE Local 11 (Union), about the effects of the temporary shutdown.
The NLRB also ruled the Hotel engaged in unlawful direct dealing by contacting the employees about severance packages without going through the Union even though the Hotel’s contract with the union had expired when the Hotel contacted the laid off union employees to offer severance in return for waivers. As a result, the NLRB ordered the Hotel to rescind the waiver and release forms signed by the Union members and to meet and bargain with the Union on these terms.
Bel-Air Hotel Decision Background
The NLRB order against the Hotel resulted from unfair labor practice charges that the Union filed against the Hotel after the Hotel offered severance packages directly to workers in exchange for the workers’ waiver of their recall rights while the workers were laid off during the Hotel’s temporary closure for renovations in 2009.
Before the Hotel offered the severance package directly to the laid off workers, the Hotel and the Union bargained for nine months about the terms of a separation agreement and recall rights for employees who would lose their jobs during a planned 2-year shutdown of the facility for renovation. In April, 2010, the Hotel gave the Union what it said was the “last, best, and final offer” on severance pay for unit employees laid off during the temporary renovation closure. While the Union and the Hotel did talk after the Hotel made this final offer. Unfortunately, the parties did not reach an agreement before their existing collective bargaining agreement expired or before the Hotel shut down the facility for renovation. After the shutdown, the Union and the Hotel stopped formal negotiations but had some “off the record” informal communications until June. With no resolution by the end of June, the Hotel moved forward unilaterally to offer severance directly to the laid off employees as outlined in its final offer.
Although the facility was closed and the employees already laid off when the Hotel’s contract with the Union expired, the Union claimed the Hotel remained obligated to negotiate with the Union. The Union said a flurry of “off-the-record” discussions between the Hotel and the Union leading up to and after the termination showed the parties had not reached impasse. The Union also separately charged that the Hotel violated the NLRA by going around the Union to directly contact employees to offer severance payments in exchange for waiving their right to return to their jobs when the Hotel reopened after renovation.
In response to unfair labor practices charges filed by the Union, Hotel management among other things argued that the Union no longer represented the employees when it offered severance and because the parties’ contract had expired and the parties were at impasse when the Hotel made the offer.
- Union Remained Representative Despite Layoff & Temporary Facilities Shutdown
The NLRB found “meritless” the Hotel’s effort to rely upon the NLRB’s decision in Sterling Processing Corp., 291 NLRB 208 (1988) to support the Hotel’s claim that it had no duty to bargain or extend the severance offers through the Union because it made the unilateral severance offer when the facility was closed and the employees were already laid off.
In Sterling, the NLRB found the employer’s unilateral modification of preclosure wages and working conditions did not violate Section 8(a)(5) of the NLRA because when the employer acted unilaterally, there were no employees for the union to represent because when the employer took its unilateral action, the employer already had permanently closed the facility and terminated all employees with no reasonable expectation of reemployment.
The NLRB ruled that the circumstances when the Hotel acted were distinguishable from Sterling because the unit employees on layoff from the Hotel retained a reasonable expectation of recall from layoff since the Hotel’s closure was only temporary and the Hotel had only laid off, and not yet discharged the employees when it made the unilateral severance offers. According to the NLRB, the terms of the severance offer evidenced the existence of an expectation of recall because under the terms of that offer, employees who accepted a severance payment waived their recall rights. See, Rockwood Energy & Mineral Corp., 299 NLRB 1136, 1139 fn. 11 (1990), enfd. 942 F.2d 169 (3d Cir. 1991)(finding that lengthy suspension of production did not relieve employer of its bargaining obligation where laid off employees had “some expectation of recall,” and distinguishing Sterling).
- No Impasse Because Of Informal “Off The Record” Communications
The Hotel also separately and unsuccessfully argued that its direct offer of severance benefits to laid off employees was not an unfair labor practice because the parties had bargained to impasse before the offer was made. In response to the Union’s claim that a series of “off-the-record” exchanges between the Union and Hotel after the contract expired reflected a continuation of bargaining, the Hotel argued that an impasse existed because the Union was not engaged in good faith negotiations and there was not any possibility that the informal discussions between the Union and the Hotel would result in any fruitful change in the parties positions.
In an effort to support its position, the Hotel management argued that the Union’s negotiation behavior with other Los Angeles hotels showed the Union had a practice of “artificially extend[ing] negotiations in bad faith” that supported the Hotel’s claim that continued negotiation would be futile. The NLRB rejected this argument too. It said evidence that the Union did not bargain in good faith to string out negotiations when negotiating with other businesses as part of a campaign to coerce all hotels city wide to agree to a standard contract had no probative relevance for purposes of determining if the Hotel and the Union had bargained to impasse in their negotiations and did not prove bad faith by the Union for purposes of its negotiation with the Hotel.
Having rejected these and other Hotel arguments and evidence of impasse, the NLRB ruled that the evidence indicated that the parties continued communications had narrowed their differences before and after the Hotel made its last final offer on April 9. Given this progress, the NLRB ruled that parties’ participation in informal off the record discussions well into June were sufficient to show the existence of some possibility that continued negotiations might result in a fruitful change in the parties position sufficient to obligate the Hotel to continue to bargain with the Union.
NLRB Order Carries Heavy Cost for Bel-Air Hotel
Complying the NLRB’s orders to remedy the breach will be painful and expensive for the Hotel, particularly since by the time the order was issued, the renovation was substantially completed.
To fulfill the requirements of the Order, the Hotel must, among other things:
- Bargain with the Union as the recognized and exclusive collective-bargaining representative of the employees about the effects on bargaining unit employees of the temporary shutdown of the hotel for renovation and, if an understanding is reached, embody the understanding in a signed collective bargaining agreement;
- Not deal directly with bargaining unit employees about severance, waiver and release or other terms or arrangements relating to the impact of the temporary shutdown on the bargaining unit employees
- Rescind the waiver and release agreements signed by individual bargaining unit employees which included the waiver of rehire rights; and
- Post a NLRB-mandated written notice in the workplace for 60 consecutive days in conspicuous places.
This means that the Hotel will have to work through issues about how to find positions for employees, if any, who originally agreed to waive their rehire rights who now wish to be rehired, as well as engage in expensive bargaining and the implementation of the terms of any resulting collective bargaining agreement.
Union Duties One of Many Potential HR RIF & Deal Traps
The NLRB’s prounion ruling is unsurprising. Since the Obama Administration took office, its NLRB appointments, rule changes and other activism are intended to and are promoting the strength and efforts of labor. See e.g. Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge : HR Article by Ms. Cynthia Marcotte Stamer .
Collective bargaining responsibilities like those that resulted in the NLRB order against the Hotel are only one of many potential labor, human resources and benefits-related traps that businesses need to negotiate carefully when planning and executing layoffs or other workforce restructurings in connection with cost or other restructurings, business transactions or other activities impacting the workforce.
Some examples of other issues and risks that businesses involved in changes impacting their workforce also may need to manage include but are not limited to the need to manage discrimination, federal and state leave, whistleblower and retaliation, and other general employment-related legal risks and responsibilities; to give Worker Adjustment and Retraining Act (WARN) or state law required plant closing or other notifications to workers, unions, government officials, vendors, customers, lenders or other creditors, insurers or others; to disclose, review, modify or terminate contracts, employee benefit plan documents, communications and other materials; to modify fiduciary, officer, board or other assignments and other related insurance, indemnification, bonding and related arrangements; to comply with employee benefit and compensation related plan document, fiduciary responsibility, discrimination, communication, benefit funding or distribution, reporting and disclosure and other Employee Retirement Income Security Act, Internal Revenue Code, securities and other laws and regulations; privacy, trade secret, and other data integration, confidentiality, and information security and management concerns; Sarbanes-Oxley and other securities, accounting or related requirements; system and data integration; and many others.
Because improper handling of these or other responsibilities in connection with these responsibilities can significantly undermine the businesses’ ability to realize the financial and operational goals behind the action, as well as expose the business to potentially costly liability, businesses anticipating or conducting reductions in the force or other activities that will impact their workforce should seek advice and help from qualified legal counsel experienced with these concerns early to mitigate these concerns.
If you have any questions or need help with these or other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Cynthia Marcotte Stamer.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 25 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources, Management, NLLRB, NLRA, reductions in force, Severance, unfair labor practices, Union |
Permalink
Posted by Cynthia Marcotte Stamer
October 1, 2012
President Obama’s declaration today (October 1, 2012) of October as National Disability Employment Awareness Month reminds business that U.S. businesses and their leaders need to tighten their disability discrimination risk management and compliance in light of the Obama Administration’s emphasis on aggressively interpreting and enforcing disability discrimination laws, rising private plaintiff lawsuits and other recent regulatory and judicial changes.
In his proclaimation today, President Obama reaffirmed his often stated commitment to the aggressive enforcement of disability laws and other efforts to promote opportunities for disabled individuals, stating:
“[My Administration remains committed to helping our businesses, schools, and communities support our entire workforce. To meet this challenge,… we are striving to make it easier to get and keep those jobs by improving compliance with Section 508 of the Rehabilitation Act.
As the administration marks the month, U.S. employers and other business leaders can expect the Obama Administration will be stepping up its already aggressive outreach to disabled Americans to promote awareness of their disability law rights and tools for asserting and enforcing these rights.
Business Faces Growing Employment Disability Exposures
As part of his administration’s commitment, the Obama Administration has moved to aggressively enforce the disability and accommodations of teh Americans With Disabilities Act, Section 508 of the Rehabilitation Act, and other federal disability discrimination laws. The reach and effectiveness of these efforts has been enhanced by statutory and regulatory changes that require employers to exercise greater efforts to meet their compliance obligations and manage their disability and other discrimination risks.
ADA Exposures Heightened
The ADA, for instance, generally prohibits disability discrimination and requires employers to make reasonable accommodations to employees’ and applicants’ disabilities as long as this does not pose an undue hardship. Violations of the ADA can expose businesses to substantial liability. Violations of the ADA may be prosecuted by the EEOC or by private lawsuits. Employees or applicants that can prove they were subjected to prohibited disability discrimination under the ADA generally can recover actual damages, attorneys’ fees, and up to $300,000 of exemplary damages (depending on the size of the employer).
In recent years, amendments to the original provisions of the ADA have made it easier for plaintiffs and the EEOC to establish disabled status of an individual. Businesses should exercise caution to carefully document legitimate business justification for their hiring, promotion and other employment related decisions about these and other individuals who might qualify as disabled. Provisions of the ADA Amendments Act (ADAAA) that expand the definition of “disability” under the ADA, As signed into law on September 25, 2008, the ADAAA amended the definition of “disability” for purposes of the disability discrimination prohibitions of the ADA to make it easier for an individual seeking protection under the ADA to establish that that has a disability within the meaning of the ADA. The ADAAA retains the ADA’s basic definition of “disability” as an impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment. However, provisions of the ADAAA that took effect January 1, 2009 change the way that these statutory terms should be interpreted in several ways. Most significantly, the Act:
- Directs EEOC to revise that portion of its regulations defining the term “substantially limits;”
- Expands the definition of “major life activities” by including two non-exhaustive lists: (1) The first list includes many activities that the EEOC has recognized (e.g., walking) as well as activities that EEOC has not specifically recognized (e.g., reading, bending, and communicating); and (2) The second list includes major bodily functions (e.g., “functions of the immune system, normal cell growth, digestive, bowel, bladder, neurological, brain, respiratory, circulatory, endocrine, and reproductive functions”);
- States that mitigating measures other than “ordinary eyeglasses or contact lenses” shall not be considered in assessing whether an individual has a disability;
- Clarifies that an impairment that is episodic or in remission is a disability if it would substantially limit a major life activity when active;
- Changes the definition of “regarded as” so that it no longer requires a showing that the employer perceived the individual to be substantially limited in a major life activity, and instead says that an applicant or employee is “regarded as” disabled if he or she is subject to an action prohibited by the ADA (e.g., failure to hire or termination) based on an impairment that is not transitory and minor; and
- Provides that individuals covered only under the “regarded as” prong are not entitled to reasonable accommodation.
The ADAAA also emphasizes that the definition of disability should be construed in favor of broad coverage of individuals to the maximum extent permitted by the terms of the ADA and generally shall not require extensive analysis.In adopting these changes, Congress expressly sought to overrule existing employer-friendly judicial precedent construing the current provisions of the ADA and to require the EEOC to update its existing guidance to confirm with the ADAAA Amendments. Under the leadership of the Obama Administration, the EEOC and other federal agencies have embraced this charge and have sigificantly stepped up enforcement of the ADA and other federal discrimination laws.
Recent enforcement, regulatory and other activities by the EEOC demonstrate that the EEOC is enthusiastically moving forward to exercise its regulatory and enforcement powers under these enhanced ADA provisions to tighten requirements for employers and to enforce its rules. See e.g., Leprino Foods To Pay $550K To Settle OFCCP Charge Pre-Hire Screening Test Illegally Discriminated « As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released; Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries; Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s.
Rehabilitation Act Risks For Government Contractors
Beyond the generally applicable risks applicable to all employers of more than 15 employees under the ADA, federal and state government contractors face additional responsibilities and risks.
Subject to limited exceptions, government contractors providing services or supplies on ARRA or other government funded contracts or projects must comply both with generally applicable employment discrimination requirements and special statutory and contractual nondiscrimination, affirmative action, and recordkeeping requirements applicable government contractors. For instance, federal law generally requires government contractors to comply with the special equal employment opportunity requirements of Executive Order 11246 (EO 11246); Section 503 of the Rehabilitation Act of 1973 (Section 503); and the Vietnam Veterans’ Readjustment Assistance Act of 1974 (VEVRAA). Pursuant to these laws, business with the federal government, both contractors and subcontractors, generally must follow a number of statutory and contractual requirements to follow the fair and reasonable standard that they not discriminate in employment on the basis of sex, race, color, religion, national origin, disability or status as a protected veteran. OFCCP generally audits and enforces these requirements. Memo to Funding Recipients: Compliance with Applicable Nondiscrimination and Equal Opportunity Statutes, Regulations, and Executive Orders.
OFCCP has made clear that it will conduct compliance evaluations and host compliance assistance events to ensure that federal contractors comply and are aware of their responsibilities under EO 11246, Section 503 and VEVRAA.
While many government contractors may be tempted to become complacent about OFCCP exposures based on reports of the OFCCP’s relatively low enforcement in the past, see Report Says OFCCP Enforcement Data Show Infrequent Veteran, Disability Bias Findings | Bloomberg BNA recent enforcement data documents OFCCP is getting much more serious and aggressive about auditing and enforcing compliance with its affirmative action and other requirements against government contractors under the Obama Administration. See, OFCCP Enforcement Data is Available on a New DOL Website. See also, Affirmative Action Update: OFCCP Enforcement Statistics Show Increase in Violations. The readiness of OFCCP to enforce its rules is illustrated by the settlement of an OFCCP action filed against federal contractor Nash Finch Co. (Nash Finch) announceed last week. Under the settlement, Nash Finch to pay $188,500 in back wages and interest and offer jobs to certain women applicants who OFCCP charged Nash rejected for the entry-level position of order selector at the company’s distribution facility in Lumberton, Minnesota. See Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks.
These government contractor disability discrimination risks are particularly acute where the government contractor works on or provides supplies on contacts or projects funded in whole or in part by monies provided under the American Recovery and Reinvestment Act of 2009 (“ARRA”). When the contract or project in question receives any funding out of the $787 billion of stimulus funding provided by ARRA, special OFCCP rules applicable to ARRA funded projects necessitates that federal contractors exercise special care to understand and meet their responsibilities and manage associated exposures. See, e.g. Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks.
Businesses Should Act To Manage Risks
The ADAAA amendments, the Rehabilitation Act’s expanded reach, and the Obama Administration’s emphasis on enforcement make it likely that businesses generally will face more disability claims from a broader range of employees and will possess fewer legal shields to defend themselves against these claims. These changes will make it easier for certain employees to qualify and claim protection as disabled under the ADA, the Rehabilitation Act, and other disability discrimination laws.
In light of these and other developments and risks, businesses generally should act cautiously when dealing with applicants or employees with actual, perceived, or claimed physical or mental impairments to minimize exposures under the ADA, the Rehabilitation Act and other laws. Management should exercise caution to carefully and appropriate the potential legal significance of physical or mental impairments or conditions that might be less significant in severity or scope, correctable through the use of eyeglasses, hearing aids, daily medications or other adaptive devices, or that otherwise have been assumed by management to fall outside the ADA’s scope.
Likewise, businesses should be prepared for the EEOC, OFCCP and the courts to treat a broader range of disabilities, including those much more limited in severity and life activity restriction, to qualify as disabling for purposes of the Act. Businesses should assume that a greater number of employees with such conditions are likely to seek to use the ADA as a basis for challenging hiring, promotion and other employment decisions. For this reason, businesses generally should tighten job performance and other employment recordkeeping to enhance their ability to demonstrate nondiscriminatory business justifications for the employment decisions made by the businesses.
Businesses also should consider tightening their documentation regarding their procedures and processes governing the collection and handling records and communications that may contain information regarding an applicant’s physical or mental impairment, such as medical absences, worker’s compensation claims, emergency information, or other records containing health status or condition related information. The ADA generally requires that these records be maintained in separate confidential files and disclosed only to individuals with a need to know under circumstances allowed by the ADA.
As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under the new genetic information nondiscrimination and privacy rules enacted as part of the Genetic Information and Nondiscrimination Act (GINA) signed into law by President Bush on May 21, 2008. Effective November 21, 2009, Title VII of GINA amends the Civil Rights Act to prohibit employment discrimination based on genetic information and restricts the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws. For instance, GINA’s employment related provisions include rules that will:
- Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
- Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
- Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
- Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
- Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
- Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
- Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
- Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.
These employment provisions of GINA are in addition to amendments to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the Rehabilitation Act, ADA, GINA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Board Certified Labor and Employment Attorney and Management Consultant Cynthia Marcotte Stamer at 469..
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 25 years human resource, employee benefits and management experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in numerous human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 214.270.2402 or via e-mail here.
Other Helpful Resources & Other Information
If you found these updates of interest, you also be interested in one or more of the following other recent articles published in this electronic Solutions Law publication available for review here including:
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- ARRA, Other Government Contractors Face Growing Enforcement & Audit Risks
- Disability Exposures Big US Business Risk; New DOD App Helps ID Resources
- Personal Consumer Information Protection in Hospital/Healthcare Setting At HIMSS November 11
- Obama Administration Continues War On Management Despite NLRB’s Tempoary Setback In Suit Against Arizona Secret Ballot Law
- Companies, Officers, Directors, Fiduciaries & Vendors Urged To Confirm ERISA Credentials & Bonding For Internal Staff, Plan Fidiciaries, Vendors Dealing With Benefits
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Stamer Speaks On HIPAA Developments On 9/14 At ABA Joint Tax/RPTE Fall Meeting In Boston
- Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training. Register Now For August 14 HIPAA Update Workshop!
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here.
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@solutionslawyer.net.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc. All other rights reserved.
Comments Off on Tighten Employment Disability Risk Management As Obama Declares 12/10 National Disability Employment Awareness Month |
ADA, Affirmative Action, Corporate Compliance, Disability, Disability, Disability Plans, EEOC, EEOC, Employers, FMLA, GINA, Government Contractors, Human Resources, Labor Management Relations, OFCCP, Retaliation, USERRA, VEVRRA | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
October 1, 2012
President Obama’s declaration today (October 1, 2012) of October as National Disability Employment Awareness Month reminds business that U.S. businesses and their leaders need to tighten their disability discrimination risk management and compliance in light of the Obama Administration’s emphasis on aggressively interpreting and enforcing disability discrimination laws, rising private plaintiff lawsuits and other recent regulatory and judicial changes. With the Administration expected to step up further its already substantial educational outreach to the disabled and their advocates, U.S. employers should brace for this month’s celebration to fuel even more disability discrimination claims and other activity by the disabled and their activists.
Since taking office, President Obama has make enforcing and expanding the rights of the disabled in employment and other areas a leading priority.
In his proclamation today, President Obama reaffirmed his often stated commitment to the aggressive enforcement of disability laws and other efforts to promote opportunities for disabled individuals, stating:
“[My Administration remains committed to helping our businesses, schools, and communities support our entire workforce. To meet this challenge,… we are striving to make it easier to get and keep those jobs by improving compliance with Section 508 of the Rehabilitation Act.”
As the administration marks the month, U.S. employers and other business leaders can expect the Obama Administration will be stepping up its already aggressive outreach to disabled Americans to promote awareness of their disability law rights and tools for asserting and enforcing these rights. See, e.g. October Is National Disability Employment Awareness Month (NDEAM).
Business Faces Growing Employment Disability Exposures
As part of his administration’s commitment, the Obama Administration has moved to aggressively enforce the disability and accommodations of the Americans With Disabilities Act (ADA), Section 508 of the Rehabilitation Act, and other federal disability discrimination laws. The reach and effectiveness of these efforts has been enhanced by statutory and regulatory changes that require employers to exercise greater efforts to meet their compliance obligations and manage their disability and other discrimination risks.
ADA Exposures Heightened
The ADA, for instance, generally prohibits disability discrimination and requires employers to make reasonable accommodations to employees’ and applicants’ disabilities as long as this does not pose an undue hardship. Violations of the ADA can expose businesses to substantial liability. Violations of the ADA may be prosecuted by the EEOC or by private lawsuits. Employees or applicants that can prove they experienced prohibited disability discrimination under the ADA generally can recover actual damages, attorneys’ fees, and up to $300,000 of exemplary damages (depending on the size of the employer).
In recent years, amendments to the original provisions of the ADA have made it easier for plaintiffs and the EEOC to prove disabled status of an individual. Businesses should exercise caution to carefully document legitimate business justification for their hiring, promotion and other employment related decisions about these and other individuals who might qualify as disabled. Provisions of the ADA Amendments Act (ADAAA) that expand the definition of “disability” under the ADA, As signed into law on September 25, 2008, the ADAAA amended the definition of “disability” for purposes of the disability discrimination prohibitions of the ADA to make it easier for an individual seeking protection under the ADA to establish that that has a disability within the meaning of the ADA. The ADAAA retains the ADA’s basic definition of “disability” as an impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment. However, provisions of the ADAAA that took effect January 1, 2009 change the way that these statutory terms should be interpreted in several ways. Most significantly, the Act:
- Directs EEOC to revise that part of its regulations defining the term “substantially limits;”
- Expands the definition of “major life activities” by including two non-exhaustive lists: (1) The first list includes many activities that the EEOC has recognized (e.g., walking) as well as activities that EEOC has not specifically recognized (e.g., reading, bending, and communicating); and (2) The second list includes major bodily functions (e.g., “functions of the immune system, normal cell growth, digestive, bowel, bladder, neurological, brain, respiratory, circulatory, endocrine, and reproductive functions”);
- States that mitigating measures other than “ordinary eyeglasses or contact lenses” shall not be considered in assessing whether an individual has a disability;
- Clarifies that an impairment that is episodic or in remission is a disability if it would substantially limit a major life activity when active;
- Changes the definition of “regarded as” so that it no longer requires a showing that the employer perceived the individual to be substantially limited in a major life activity, and instead says that an applicant or employee is “regarded as” disabled if he or she is subject to an action prohibited by the ADA (e.g., failure to hire or termination) based on an impairment that is not transitory and minor; and
- Provides that individuals covered only under the “regarded as” prong are not entitled to reasonable accommodation.
The ADAAA also emphasizes that the definition of disability should be construed in favor of broad coverage of individuals to the maximum extent permitted by the terms of the ADA and generally shall not require extensive analysis.In adopting these changes, Congress expressly sought to overrule existing employer-friendly judicial precedent construing the current provisions of the ADA and to require the EEOC to update its existing guidance to confirm with the ADAAA Amendments. Under the leadership of the Obama Administration, the EEOC and other federal agencies have embraced this charge and have significantly stepped up enforcement of the ADA and other federal discrimination laws.
Recent enforcement, regulatory and other activities by the EEOC show that the EEOC is enthusiastically moving forward to exercise its regulatory and enforcement powers under these enhanced ADA provisions to tighten requirements for employers and to enforce its rules. See e.g., Leprino Foods To Pay $550K To Settle OFCCP Charge Pre-Hire Screening Test Illegally Discriminated « As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released; Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries; Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s.
Rising Rehabilitation Act Risks For Government Contractors
Beyond the generally applicable risks applicable to all employers of more than 15 employees under the ADA, federal and state government contractors face more responsibilities and risks.
Subject to limited exceptions, government contractors providing services or supplies on ARRA or other government-funded contracts or projects must comply both with generally applicable employment discrimination requirements and special statutory and contractual nondiscrimination, affirmative action, and recordkeeping requirements applicable government contractors. For instance, federal law generally requires government contractors to comply with the special equal employment opportunity requirements of Executive Order 11246 (EO 11246); Section 503 of the Rehabilitation Act of 1973 (Section 503); and the Vietnam Veterans’ Readjustment Assistance Act of 1974 (VEVRAA). Pursuant to these laws, business with the federal government, both contractors and subcontractors, generally must follow a number of statutory and contractual requirements to follow the fair and reasonable standard that they not discriminate in employment on the basis of sex, race, color, religion, national origin, disability or status as a protected veteran. OFCCP generally audits and enforces these requirements. Memo to Funding Recipients: Compliance with Applicable Nondiscrimination and Equal Opportunity Statutes, Regulations, and Executive Orders.
OFCCP has made clear that it will conduct compliance evaluations and host compliance assistance events to ensure that federal contractors comply and are aware of their responsibilities under EO 11246, Section 503 and VEVRAA.
While many government contractors may be tempted to become complacent about OFCCP exposures based on reports of the OFCCP’s relatively low enforcement in the past, see Report Says OFCCP Enforcement Data Show Infrequent Veteran, Disability Bias Findings | Bloomberg BNA recent enforcement data documents OFCCP is getting much more serious and aggressive about auditing and enforcing compliance with its affirmative action and other requirements against government contractors under the Obama Administration. See, OFCCP Enforcement Data is Available on a New DOL Website. See also, Affirmative Action Update: OFCCP Enforcement Statistics Show Increase in Violations. The readiness of OFCCP to enforce its rules is illustrated by the settlement of an OFCCP action filed against federal contractor Nash Finch Co. (Nash Finch) announceed last week. Under the settlement, Nash Finch to pay $188,500 in back wages and interest and offer jobs to certain women applicants who OFCCP charged Nash rejected for the entry-level position of order selector at the company’s distribution facility in Lumberton, Minnesota. See Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks.
These government contractor disability discrimination risks are particularly acute where the government contractor works on or provides supplies on contacts or projects funded in whole or in part by monies provided under ARRA. When the contract or project in question receives any funding out of the $787 billion of stimulus funding provided by ARRA, special OFCCP rules applicable to ARRA funded projects necessitates that federal contractors exercise special care to understand and meet their responsibilities and manage associated exposures. See, e.g. Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks.
GINA & Other Medical Information Nondiscrimination & Privacy Risks
Employers also need to use care to ensure that their hiring and other employment practices, as well as their employee benefits, workers’ compensation and wellness practices are up to date and properly managed to mitigate exposures under laws like the Genetic Information and Nondiscrimination Act (GINA), the ADA’s medical information privacy requirements, as well as the privacy and nondiscrimination rules of the Health Insurance Portability & Accountability Act and other relevant federal and state laws.
Signed into law by President Bush on May 21, 2008 and in effect since November 21, 2009, for instance, Title VII of GINA amended the Civil Rights Act to prohibit employment discrimination based on genetic information and to restrict the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like now available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws. For instance, GINA’s employment related provisions include rules that:
- Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
- Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
- Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
- Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
- Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
- Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
- Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
- Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.
These employment provisions of GINA are in addition to amendments to HIPAA, the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009. Under these HIPAA and GINA rules, health plans generally may not make certain medical inquiries or discriminate against employees or their family members based on family or individual medical history or genetic information. In addition, health plans and others are required to safeguard personal medical information and may only share that information only under very limited circumstances requiring specific documentation be in place and that the parties can prove that the access and use of that information is appropriately restricted. Violation of these and other rules can have significant civil and in some cases even criminal liabilities for companies, plans, plan fiduciaries and company officials that take part in violations of these rules.
Businesses Should Act To Manage Risks
The ADAAA amendments, the Rehabilitation Act’s expanded reach, and the Obama Administration’s emphasis on enforcement make it likely that businesses generally will face more disability claims from a broader range of employees and will have fewer legal shields to defend themselves against these claims. These changes will make it easier for certain employees to qualify and claim protection as disabled under the ADA, the Rehabilitation Act, and other disability discrimination laws.
All U.S. businesses should review and tighten the adequacy of their existing compliance and risk management practices to promote and document compliance. These efforts should focus on all relevant hiring, recruitment, promotion, compensation, recordkeeping and reporting policies and practices internally, as well as those of any recruiting agencies, subcontractors or other business partners whose actions might impact on compliance.
In light of these and other developments and risks, businesses generally should act cautiously when dealing with applicants or employees with actual, perceived, or claimed physical or mental impairments to minimize exposures under the ADA, the Rehabilitation Act and other laws. Management should exercise caution to carefully and appropriately assess and identify the potential legal significance of physical or mental impairments or conditions that might be less significant in severity or scope, correctable through the use of eyeglasses, hearing aids, daily medications or other adaptive devices, or that management might be tempted to assume fall outside the ADA’s scope.
Likewise, businesses should be ready for the EEOC, OFCCP and the courts to treat a broader range of disabilities, including those much more limited in severity and life activity restriction, to qualify as disabling for purposes of the Act. Businesses should assume that a greater number of employees with such conditions are likely to seek to use the ADA as a basis for challenging hiring, promotion and other employment decisions. For this reason, businesses generally should tighten job performance and other employment recordkeeping to enhance their ability to demonstrate nondiscriminatory business justifications for the employment decisions made by the businesses.
Businesses also should consider tightening their documentation regarding their procedures and processes governing the collection and handling records and communications that may contain information regarding an applicant’s physical or mental impairment, such as medical absences, worker’s compensation claims, emergency information, or other records containing health status or condition related information. The ADA generally requires that these records be maintained in separate confidential files and disclosed only to individuals with a need to know under circumstances allowed by the ADA.
As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under the genetic information nondiscrimination and privacy rules enacted as part of GINA, the health care privacy rules of the HIPAA, and the medical record privacy rules of the ADA. Particular care should be used when planning wellness, health risk assessment, work-related injury, family or other medical leave or related programs, all of which raise particular risks and concerns.
In the face of the rising emphasis of OFCCP, the EEOC and other federal and state agencies on these audit and enforcement activities, government contractors should exercise additional compliance and risk management efforts beyond these generally recommended steps. Among other things, these steps should include the following:
- Government contractors and subcontractors should specifically review their existing or proposed contracts and involvements to identify projects or contracts which may involve federal or state contracts or funding that could trigger responsibility. In this respect, businesses should conduct well-documented inquiries when proposing and accepting contracts to ensure that potential obligations as a government contractor are not overlooked because of inadequate intake procedures. Businesses also should keep in mind that ARRA and other federal program funds often may be filtered through a complex maze of federal grants or program funding to states or other organizations, which may pass along government contractor status and liability when subcontracting for services as part of the implementation of broader programs. Since the existence of these obligations often is signaled by contractual representations in the contracts with these parties, careful review of contractual or bid specifications and commitments is essential. However, it also generally is advisable also to inquire about whether the requested products or services are provided pursuant to programs or contracts subject to these requirements early in the process.
- In addition to working to identify contracts and arrangements that are covered by OFCCP or other requirements, government contractors and other businesses also should reconfirm and continuously monitor the specific reporting, affirmative action, and other requirements that apply to any programs that may be subject to OFCCP requirements to ensure that they fully understand and implement appropriate procedures to comply with these conditions as well as pass along the obligation to make similarly necessary arrangements to any subcontractors or suppliers that the government contractor involves as a subcontractor.
- Throughout the course of the contract, the government contractor also should take steps to maintain and file all required reports and monitor and audit operational compliance with these and other requirements.
- The organization should develop and administer appropriate procedures for monitoring and investigating potential compliance concerns and maintaining documentation of that activity. Any known potential deficiencies or complaints should be promptly investigated and redressed with the assistance of qualified counsel in a prompt manner to mitigate potential risks.
- Documentation should be carefully retained and organized on a real time and continuous basis to faciliate efficiency and effectiveness in completing required reports, monitoring compliance indicators and responding to OFCCP, EEOC or private plaintiff charges as well as other compliance inquiries.
- Any audit inquiries or charges should be promptly referred to qualified legal counsel for timely evaluation and response.
- When available and affordable, management should consider securing appropriate employment practices liability coverage, indemnification from business partners and other liability protection and assurance to help mitigate investigagtion and defense costs.
- Board members or other senior management should include periodic review of compliance in their agenda.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the Rehabilitation Act, ADA, GINA or other applicable laws, or if we may be of help with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Board Certified Labor and Employment Attorney and Management Consultant Cynthia Marcotte Stamer at 469.767.8872.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to meet their business and operational goals and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 25 years human resource, employee benefits and management experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail here.
Other Helpful Resources & Other Information
If you found these updates of interest, you also be interested in one or more of the following other recent articles published in this electronic Solutions Law publication available for review here including:
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- ARRA, Other Government Contractors Face Growing Enforcement & Audit Risks
- Disability Exposures Big US Business Risk; New DOD App Helps ID Resources
- Personal Consumer Information Protection in Hospital/Healthcare Setting At HIMSS November 11
- Obama Administration Continues War On Management Despite NLRB’s Tempoary Setback In Suit Against Arizona Secret Ballot Law
- Companies, Officers, Directors, Fiduciaries & Vendors Urged To Confirm ERISA Credentials & Bonding For Internal Staff, Plan Fidiciaries, Vendors Dealing With Benefits
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Stamer Speaks On HIPAA Developments On 9/14 At ABA Joint Tax/RPTE Fall Meeting In Boston
- Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training. Register Now For August 14 HIPAA Update Workshop!
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here.
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@solutionslawyer.net.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc. All other rights reserved.
Comments Off on Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness |
ADA, Affirmative Action, Civil Rights, Corporate Compliance, Data Security, Disability Plans, Discrimination, EEOC, Employers, GINA, Government Contractors, VEVRRA | Tagged: ADA, Disability, Disability Discrimination, EEOC, Employer, GINA, Human Resources, Rehabilitation Act, Risk Management |
Permalink
Posted by Cynthia Marcotte Stamer
September 29, 2012
Federal contractor Nash Finch Co. (Nash Finch) will pay $188,500 in back wages and interest and offer jobs to certain women applicants who the U.S Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) charged Nash rejected for the entry-level position of order selector at the company’s distribution facility in Lumberton, Minnesota under a consent decree approved by an OFCCP administrative law judge this week.
Nash Finch Settlement Highlights
Minneapolis-based and the second-largest wholesale food distributor in the U.S., Nash Finch distributes food products to military commissaries around the world. Since the start of the OFCCP review period on May 1, 2005, Nash Finch has received payments of more than $14 million from the U.S. Department of Defense.
The consent decree resolves an OFCCP administrative action commenced after OFCCP investigators conducted a review of Nash Finch’s employment practices at the Lumberton facility from May 1, 2005, to Dec. 31, 2006. OFCCP asserted that Nash Finch had failed to ensure qualified female job applicants received equal consideration for employment without regard to sex as required by Executive Order 11246. OFCCP filed a complaint with the Labor Department’s Office of Administrative Law Judges on Nov. 30, 2010, alleging that Nash Finch systematically had discriminated against women who applied for jobs as order selectors during a nine-month period in 2006. See Solis v. Nash Finch Co., OFCCP Case Number: 2011-OFC-00004. Under the consent decree, Nash Finch will pay $188,500 in back pay and interest to the 84 women. In addition to the financial remedies, the settlement requires Nash Finch to extend job offers to up to 12 women in the original class as order selector positions become available. The company must also submit progress reports to OFCCP for the next two years.
Reflective of the growing emphasis of OFCCP and other federal agencies on audit and enforcement of compliance with federal employment discrimination and affirmative action laws, the Nash Finch charges and resultant settlement highlight that the Obama Administration’s emphasis on employment discrimination and other civil rights laws expansion and enforcement is resulting in increased liability for employers that fail to take appropriate steps to manage compliance related risks.
Settlements Remind ARRA & Other Federal Government Contractors To Act To Defend Against Heightened Requirements & Enforcement
The OFCCP action and settlement against Nash Finch and other recent OFCCP and other employment discrimination law enforcement actions and settlements against government contractors and other U.S. employers remind U.S. businesses that provide services or supplies directly or as subcontractors on federally funded projects or contracts to review and tighten their employment discrimination, affirmative action and other employment practices in light of the Obama Administration’s heightened emphasis on auditing and enforcing OFCCP and other nondiscrimination and affirmative action rules.
While all U.S businesses face heightened exposures to discrimination-related enforcement risks and liability under the Obama Administration’s enforcement policies, businesses providing services or supplies directly or as subcontractors on projects funded in whole or in part by monies provided under the American Recovery and Reinvestment Act of 2009 (“ARRA”) or other federally funded projects or contracts are particularly at risk. See e.g., Leprino Foods To Pay $550K To Settle OFCCP Charge Pre-Hire Screening Test Illegally Discriminated « As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released; Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries; Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s.
Subject to limited exceptions, government contractors providing services or supplies on ARRA or other government funded contracts or projects must comply both with generally applicable employment discrimination requirements and special statutory and contractual nondiscrimination, affirmative action, and recordkeeping requirements applicable government contractors. For instance, federal law generally requires government contractors to comply with the special equal employment opportunity requirements of Executive Order 11246 (EO 11246); Section 503 of the Rehabilitation Act of 1973 (Section 503); and the Vietnam Veterans’ Readjustment Assistance Act of 1974 (VEVRAA). Pursuant to these laws, business with the federal government, both contractors and subcontractors, generally must follow a number of statutory and contractual requirements to follow the fair and reasonable standard that they not discriminate in employment on the basis of sex, race, color, religion, national origin, disability or status as a protected veteran. OFCCP generally audits and enforces these requirements. Memo to Funding Recipients: Compliance with Applicable Nondiscrimination and Equal Opportunity Statutes, Regulations, and Executive Orders. OFCCP has made clear that it will conduct compliance evaluations and host compliance assistance events to ensure that federal contractors comply and are aware of their responsibilities under EO 11246, Section 503 and VEVRAA. While many government contractors may be tempted to become complacent about OFCCP exposures based on reports of the OFCCP’s relatively low enforcement in the past, see Report Says OFCCP Enforcement Data Show Infrequent Veteran, Disability Bias Findings | Bloomberg BNA recent enforcement data documents OFCCP is getting much more serious and aggressive about auditing and enforcing compliance with its affirmative action and other requirements against government contractors under the Obama Administration. See, OFCCP Enforcement Data is Available on a New DOL Website. See also, Affirmative Action Update: OFCCP Enforcement Statistics Show Increase in Violations.
- Government Contractors On ARRA Funded Projects Particularly Exposed
When the contract or project in question receives any funding out of the $787 billion of stimulus funding provided by ARRA, special OFCCP rules applicable to ARRA funded projects necessitates that federal contractors exercise special care to understand and meet their responsibilities and manage associated exposures.
For one thing, the range of businesses required to comply with OFCCP’s equal employment opportunity requirements for government contractors is broader. Government contractors who sometimes qualify as exempt from certain OFCCP rules may not qualify as exempt when working on ARRA funded projects. Government contractors that on other types of federally-funded projects might qualify as exempt from certain OFCCP requirements often are unaware that the range of federal contractors required to comply with the OFCCP equal employment opportunity and related rules of ARRA is much broader than often applies for federal projects funded from other sources. Smaller government contractors run the risk of unknowingly incurring liability by mistakenly assuming that the small size of their contract exempts them from otherwise applicable OFCCP requirements. Consequently, before relying on any assumed exemption, a government contractor providing goods or services for ARRA-funded project directly or as a subcontractor should specifically verify the applicability of those exemptions and document that analysis.
Furthermore, all government contractors on ARRA-funded projects need to understand that they operate subject to heightened compliance and enforcement scrutiny. The OFCCP particularly scrutinizes government contractor equal employment opportunity and other civil rights requirements on ARRA funded projects. The “Procedures for Scheduling and Conducting Compliance Evaluations of American Recovery and Reinvestment Act of 2009 (ARRA) Funded Contractors” issued July 7, 2009. See OFCCP Order No. ADM 0901/SEL the “ARRA Procedures”) subject government contractors on ARRA funded projects to special rules and heightened OFCCP oversight. OFCCP has established separate scheduling procedures to provide for compliance evaluations of ARRA funded contractors separate from those usually applicable to government contractors because ARRA also obligates OFCCP separately to track its ARRA-related and non-ARRA-related enforcement activities.
The ARRA Procedures require that Regional, District and Area offices conduct a full compliance evaluation, including a full desk audit and onsite review, of every ARRA funded contractor establishment scheduled, even in the absence of systemic discrimination indicators. Normally applied by OFCCP to non-ARRA government contract reviews, Active Case Management (ACM) procedures normally allow OFCCP to conduct only an abbreviated desk audit in the absence of systematic discrimination indicators in non-ARRA compliance evaluations. These ACM procedures will not be used in ARRA compliance evaluations.
Due to the special nature of ARRA, OFCCP also has indicated that the ARRA compliance evaluations will not apply the following scheduling exceptions typically applicable in non-ARRA contract compliance reviews. For instance, OFCCP ARRA procedures state:
- No more than 25 establishments per contractor exception: Presently, for contractors with multiple establishments, the Federal Contractor Scheduling System (FCSS) limits the number of compliance evaluations scheduled to 25 new evaluations during a scheduling cycle. The 25-establishment limit does not apply to ARRA compliance evaluations.
- Two year exception: Traditionally, contractor establishments that have been reviewed by OFCCP are excepted from further review for a 24-month period. Under ARRA scheduling procedures, ARRA funded contractor establishments may be eligible for an ARRA compliance evaluation even if they have been reviewed within the previous 24 months. However, pre-award clearance is not required for contractor establishments reviewed by OFCCP within the past 24 months.
However, ARRA scheduling procedures will apply the following scheduling exceptions:
- ARRA funded contractor establishments that have undergone an FCSS compliance evaluation will be excepted from scheduling and review under ARRA procedures for six months from the date of the FCSS case closure.
- ARRA funded contractor establishments that have undergone an ARRA compliance evaluation will not be subject to another ARRA evaluation.
- ARRA funded contractor establishments that have undergone an ARRA evaluation will also be excepted from scheduling for a standard OFCCP compliance evaluation, pursuant to FCSS, for 24 months from the date of closure of the ARRA compliance evaluation.
ARRA funded contractors also are subject to other special pre-award clearance, pre-award intake, pre-award classification and other special procedures. The ARRA Procedures also set for special requirements particularly applicable to construction contracts funded by ARRA.
The special procedures and heightened compliance review procedures provided for under the ARRA Procedures indicate that government contractors or subcontractors providing services or supplies on projects funded with ARRA funds will want to place special attention on compliance with OFCCP and other federal equal employment opportunity and other employment regulation compliance.
Government Contractors, Other US Employers Urged To Act To Manage Exposures
In the face of the rising emphasis of OFCCP, the EEOC and other federal and state agencies on these audit and enforcement activities, government contractors and other U.S. businesses should act to position themselves to defend against likely challenges and scrutiny. All government contractors and other businesses should review and tighten the adequacy of their existing compliance and risk management practices to promote and document compliance. These efforts should focus on all relevant hiring, recruitment, promotion, compensation, recordkeeping and reporting policies and practices internally, as well as those of any recruiting agencies, subcontractors or other business partners whose actions might impact on compliance. Among other things, these steps should include the following:
- Government contractors and subcontractors should specifically review their existing or proposed contracts and involvements to identify projects or contracts which may involve federal or state contracts or funding that could trigger responsibility. In this respect, businesses should conduct well-documented inquiries when proposing and accepting contracts to ensure that potential obligations as a government contractor are not overlooked because of inadequate intake procedures. Businesses also should keep in mind that ARRA and other federal program funds often may be filtered through a complex maze of federal grants or program funding to states or other organizations, which may pass along government contractor status and liability when subcontracting for services as part of the implementation of broader programs. Since the existence of these obligations often is signaled by contractual representations in the contracts with these parties, careful review of contractual or bid specifications and commitments is essential. However, it also generally is advisable also to inquire about whether the requested products or services are provided pursuant to programs or contracts subject to these requirements early in the process.
- In addition to working to identify contracts and arrangements that are covered by OFCCP or other requirements, government contractors and other businesses also should reconfirm and continuously monitor the specific reporting, affirmative action, and other requirements that apply to any programs that may be subject to OFCCP requirements to ensure that they fully understand and implement appropriate procedures to comply with these conditions as well as pass along the obligation to make similarly necessary arrangements to any subcontractors or suppliers that the government contractor involves as a subcontractor.
- Throughout the course of the contract, the government contractor also should take steps to maintain and file all required reports and monitor and audit operational compliance with these and other requirements.
- The organization should develop and administer appropriate procedures for monitoring and investigating potential compliance concerns and maintaining documentation of that activity. Any known potential deficiencies or complaints should be promptly investigated and redressed with the assistance of qualified counsel in a prompt manner to mitigate potential risks.
- Documentation should be carefully retained and organized on a real time and continuous basis to faciliate efficiency and effectiveness in completing required reports, monitoring compliance indicators and responding to OFCCP, EEOC or private plaintiff charges as well as other compliance inquiries.
- Any audit inquiries or charges should be promptly referred to qualified legal counsel for timely evaluation and response.
- When available and affordable, management should consider securing appropriate employment practices liability coverage, indemnification from business partners and other liability protection and assurance to help mitigate investigagtion and defense costs.
- Board members or other senior management should include periodic review of compliance in their agenda.
If you have any questions or need help reviewing and updating your organization’s employment, employee benefits, contracting or other risk management or internal controls compliance practices, responding to an OFCCP, EEOC or other government or private plaintiff charge or investigation, or if we may be of assistance with regard to any other workforce or compliance management, employee benefits, compensation matters, please do not hesitate to contact the author of this update, Cynthia Marcotte Stamer.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA RisksLabor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Stamer Speaks On HIPAA Developments On 9/14 At ABA Joint Tax/RPTE Fall Meeting In Boston
- Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training. Register Now For August 14 HIPAA Update Workshop!
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- 96% Employers of 50+ Employees, 36% Employers of Smaller Employers Provide Health Coverage
- 12 Steps Every Employer With A Health Plan Should Do Now To Manage 2012-14 Health Plan Risks & Liabilities
- Congress Gives Defined Benefit Plan Sponsors Welcome Funding Relief, Raises PBGC Premiums & Makes Other Reforms
- New Health Plan Partnership, Data Sharing With Federal Health Care Fraud Enforcers Promises Greater Federal Oversight of Providers & Health Plans
- Essential Health Benefit Definition Built On Expensive Mandated Benefit Plan Likely To Be Expensive For Employers, States & Individuals
- Leprino Foods To Pay $550K To Settle OFCCP Charge Pre-Hire Screening Test Illegally Discriminated
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
September 23, 2012
California nursing home buyer must pay estimated $1.25 million in backpay and interest, recognize union & hire 50 employees of seller following purchase
Last week’s National Labor Relations Board (NLRB) order requiring the buyer of a California nursing home to pay approximately $1.25 million in backpay and interest, rehire 50 employees and recognize the seller’s union reminders buyers of union-organized businesses of some of the significant risks of mishandling union-related obligations in merger and acquisition, bankruptcy and other corporate transactions under the National Labor Relations Act (NLRA) and other federal labor laws.
Buyer’s Obligations To Honor Seller’s Collective Bargaining Obligations
Under the NLRA, new owners of a union facility that are “successors” of the seller generally must recognize and bargain with the existing union if “the bargaining unit remains unchanged and a majority of employees hired by the new employer were represented by a recently certified bargaining agent.” See NLRB v. Burns Sec. Servs., 406 U.S. 272, 281 (1972).
In assembling its workforce, a successor employer also generally “may not refuse to hire the predecessor’s employees solely because they were represented by a union or to avoid having to recognize a union.” U.S. Marine Corp., 293 NLRB 669, 670 (1989), enfd., 944 F.2d 1305 (7th Cir. 1991).
Nasaky, Inc. NLRB Order
Last week’s NLRB Order requires Nasaky, Inc., the buyer of the Yuba Skilled Nursing Center in Yuba City, California, to recognize and honor collective bargaining obligations that the seller Nazareth Enterprises owed the before the sale and rehire and pay backpay and interest to make whole 50 of the seller’s former employees who the NLRB determined Nasaky, Inc. wrongfully refused to hire when it took over the facility from the prior owner, Nazareth Enterprises.
Before Nasaky, Inc. bought the nursing home, many of the employees at the nursing home were represented by the Service Employees International Union, United Healthcare Workers West (Union). After Nasaky, Inc. agreed to buy the facility but before it took control of its operations, Nasaky, Inc. advertised in the media for new workers to staff the facility and told existing employees at the facility that they must reapply to have a chance of keeping their jobs under the new ownership.
When Nasaky, Inc. took operating control of the Facility, facility operations continued as before with the same patients receiving the same services. The main difference was the workforce. The new staff included 90 employees in erstwhile bargaining unit positions, of which forty were former employees of the predecessor employer and fifty were newcomers. Nasaky, Inc. then took the position that the change in the workforce excused it from responsibility for recognizing or bargaining with the Union or honoring the collective bargaining agreement between the Union and seller Nazareth Enterprises.
When the union demanded that Nasaky, Inc. recognize the Union and honor the Union’s collective bargaining agreement with Nazareth Enterprises, Nasaky, Inc. refused. Instead, Nasaky, Inc. notified the union that it would not allow the Union on its premises, would not honor the Union’s collective bargaining agreement with the seller, and did not accept any of the predecessor’s terms and conditions of employment. The Union then filed charges with the NLRB, charging that Nazareth Enterprises had breached its obligations as a successor under the NLRA.
After NLRB Regional Director Joseph F. Frankl agreed and issued a complaint, California Administrative Law Judge Gerald Etchingham found all the allegations true based on a two-day hearing. He rejected all of Nasaky’s explanations for why it declined to hire most of those who had worked for the previous employer. See ALJ Decision. Since Nasaky, Inc did not file exceptions, the NLRB ordered Nasaky, Inc. immediately to recognize and bargain with the Union, hire the former employees and make them whole. The amount of backpay and interest is expected to approximate $1.25 million.
Managing Labor Exposures In Business Transactions
The NLRB’s order against Nasaky, Inc. highlights some of the business and operational risks that buyers and sellers can face if labor-management relations are misperceived or mismanaged in connection with business transactions. Because the existence of collective bargaining agreements or other labor obligations can substantially affect the operational flexibility of a buyer, buyers need to investigate and carefully evaluate the potential existence and nature of their obligations as part of their due diligence strategy before the transaction. A well-considered understanding of whether the structure of the transaction is likely to result in the buyer being considered a successor for purposes of union organizing and collective bargaining obligations also is very important so that the buyer and seller can properly appreciate and deal with any resulting responsibilities.
Beyond the potential duty to recognize a seller’s collective bargaining obligations, buyers and sellers also should consider the potential consequences of the proposed transaction on severance, pension, health, layoff and recall and other rights and obligations that may arise. At minimum, the existence of these responsibilities and their attendant costs are likely to impact the course of the negotiations.
When a worksite is union organized, for instance, additional obligations may arise in the handling of reductions in force or other transactions as a result of the union presence. For example, in addition to otherwise applicable responsibilities applicable to non-union affected transaction, the Worker Adjustment Retraining Act (WARN) and other plant closing laws and/or collective bargaining agreements may impose special notification or other requirements before a reduction in force or other transaction related activities.
Similarly, the existence of collective bargaining agreements also may trigger obligations for one or both parties to engage in collective bargaining over contemplated changes in terms and conditions of employment, to provide severance, to accellerate or fund severance, benefits or other obligations, to provide continued health or other coverage, to honor seniority, recall or other rights or deal with a host of other special contractual obligations.
Where the collective bargaining arrangements of the seller currently or in the past have included obligations to contribute to a multiemployer, collectively bargained pension or welfare plan, the buyer and seller also need to consider both the potential for withdrawal liability or other obligations and any opportunities to minimize these exposures in structuring the allocation of the arrangement. In this case, both parties need to recognize that differences exist between the federals for determining when successor liability results under the withdrawal liability rules than typically apply other labor and employment law purposes. While buyers and sellers often presume that the stock versus assess sale distinction that typically applies for many other legal purposes will apply, this can be an expensive mistake in the case of determining a buyer’s obligation to honor the seller’s collective bargaining obligations post deal. Likewise, buyers can be exposed to multiemployer successor liability from asset transactions, although it may be possible to mitigate or avoid such liabilities by incorporating appropriate representations in the sale documents or through other steps. Since these multiemployer withdrawal and contribution liabilities generally attach on a controlled group basis, both parties need to properly appreciate and address these concerns early in the transaction to mitigate their risks and properly value the transaction.
In light of these and other potential labor-related risks that may affect corporate and other business transactions, parties contemplating or participating in these transactions are urged to engage and consult with competent legal counsel with specific experience in such labor management relations and multiemployer benefit plan matters early in the process.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 25 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate labor and employment, human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer’s experience includes significant experience advising and representing buyers, sellers, their commonly controlled and affiliated entities, lenders, bankruptcy trustees and committees and others regarding labor-management relations, employment, compensation, employee benefits and other human resources related exposures, strategies and negotiations. She also has served as counsel to multiemployer and single employer pension, profit-sharing and other retirement, health and welfare, severance and other plans and their fiduciaries and sponsors in relation to these and other transactions.
Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Stamer Speaks On “The Practical Nitty Gritty For Coping With Health Care Reform NOW” 9/25 At DFW Web Meeting
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
- Wal-Mart Settlement Shows ADA Risks When Considering Employee Return To Work Accommodation Requests & Inquiries
- Stamer Speaks On HIPAA Developments On 9/14 At ABA Joint Tax/RPTE Fall Meeting In Boston
- Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s
- Employers & Plan Fiduciaries Reminded To Confirm Credentials & Bonding For Internal Staff, Plan Fidiciaries & Vendors Dealing With Benefits
- HIPAA & Texas Law Require HIPAA Training. Register Now For August 14 HIPAA Update Workshop!
- EBSA Updates Guidance On Fee Disclosure Requirements For 401(k) Plan Brokerage Window Arrangements
- Federal Mandate That Employer Health Plans Must Cover 100% Of Contraceptive, Other Women’s Health Services With No Cost Sharing Now Effective
- Use NIH & Other Free Government Resources To Help Round Out Wellness Programs
- 96% Employers of 50+ Employees, 36% Employers of Smaller Employers Provide Health Coverage
- 12 Steps Every Employer With A Health Plan Should Do Now To Manage 2012-14 Health Plan Risks & Liabilities
- Congress Gives Defined Benefit Plan Sponsors Welcome Funding Relief, Raises PBGC Premiums & Makes Other Reforms
- New Health Plan Partnership, Data Sharing With Federal Health Care Fraud Enforcers Promises Greater Federal Oversight of Providers & Health Plans
- Essential Health Benefit Definition Built On Expensive Mandated Benefit Plan Likely To Be Expensive For Employers, States & Individuals
- Leprino Foods To Pay $550K To Settle OFCCP Charge Pre-Hire Screening Test Illegally Discriminated
- Update Health Plans For Expanded MHPAEA & Health Care Reform Mental Health Mandates
- Record $2.3 Million+ H-2A Backpay Order Plus Civil Money Penalty Reminds Businesses Employing Foreign Workers To Manage Compliance
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
1 Comment |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Collective Bargaining, collectively bargained, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources, Labor-Management, multiemployer health plans, multiemployer pension plans, NLRA, NLRB, Union, withdrawal liability |
Permalink
Posted by Cynthia Marcotte Stamer
September 18, 2012
With the Equal Employment Opportunity Commission (EEOC) and other federal agencies prioritizing disability discrimination law enforcement, businesses and individuals looking to find solutions to help accommodate persons with disabilities may find a new free app for Apple Devices from the Department of Defense (DOD) Computer/Electronic Accommodations Program helpful.
New DOD Accommodation Apple App & Other Accommodation Aids
The DOD Apple application is an example of the many new resources that the federal government is providing to promote compliance with disability discrimination laws and to help people with disabilities under the Obama Administration.
The DOD Apple application now available in the iTunes App Store lets users browse the latest news and tips on assistive technology, scan CAP’s calendar of events and stay connected to the disability community. DOD says an Android version is coming soon.
CAP works to make the Federal Government a model employer of people with disabilities by providing job accommodations and equal access to electronic and information technology. With disabilities and other discrimination law compliance audit and enforcement rising, this new application provides another timely resource for government contractors and agencies, and other businesses looking to provide accommodations and manage disability risks.
The DOD application is just one of many emerging training and other tools that the agencies are rolling out to promote employment and other opportunities for people with disabilities. The Federal Government is devoting increasing resources to educating the disabled about resources including employment discrimination protections and other aids. The October 10 Work Incentive Seminar Event webinar is another example. To be held on October 10, 2012 from 3 – 4:30 p.m. Eastern Time, the webinar is for people who receive Social Security disability benefits and want to learn how the Ticket to Work program can help them earn money and become financially independent. It also will discuss writing a resume, job interview tips, whether or not to discuss your disability with a potential employer and tips for on the job success. Officials invites interested parties to register online or call 1-866-968-7842 (V) or 1-866-833-2967 (TTY/TDD).
Rising Liability & Enforcement Make Accommodation & Other Disability Law Risk Management Critical
Managing disability risks and meeting accommodation obligations is increasingly important as US government agencies place growing emphasis on enforcing disability discrimination laws and regulations that increasingly result in significant liability for U.S. businesses.
For instance, in June, 2012, the U.S. Justice Department announced a $10,250,000 settlement with JPI Construction L.P. (JPI) and six other JPI firms is the largest-ever disability-based housing discrimination settlement. The settlement resolves Justice Department charges the JPI and its affiliates illegally discriminated on the basis of disability in the design and construction of multifamily housing complexes.
Under the settlement of disability charges initiated against JPI a few years ago, JPI will pay $10,250,000 into an accessibility fund to update properties so they comply with the Americans with Disabilities Act and the Fair Housing Act (FHA), and to increase the availability of housing that is accessible to people with disabilities.
The record settlement follows the reaffirmation of the Obama Administration’s continuing committment to find and punish companies that illegally discriminate or fail to provide required accommodations in violation of Federal disability discrimination laws made by President Obama and others to mark the 13th Anniversary of the June 22, 1999 Supreme Court decision in Olmstead v. L.C.
As part of that anniversary celebration of Olmstead, the Obama Administration reaffirmed its continuing commitment to fight disability discriminated and touted the success of its “significant progress continuing to enforce Olmstead as well as more broadly helping to level the playing field for people with disabilities.”
In Olmstead, the Supreme Court ruled in that the unjustified institutional isolation of people with disabilities is a form of unlawful discrimination under the ADA.
In marking the 13th anniversary of this decision, President Obama said, “As we mark the anniversary of this historic civil rights decision, we reaffirm our commitment to fighting discrimination, and to addressing the needs and concerns of those living with disabilities.”
In reaffirming this commitment, the Administration highlighted its past and continuing efforts to enforce disability discrimination laws, as well as other activities to support individuals with disability.
As part of its significant commitment to disability discrimination enforcement, the Civil Rights Division at the Department has been involved in more than 40 Olmstead matters in 25 states. Recently, in Virginia, the Department entered into a landmark settlement agreement with the Commonwealth, which will shift Virginia’s developmental disabilities system from one heavily reliant on large, state-run institutions to one focused on safe, individualized, and community-based services that promote integration, independence and full participation by people with disabilities in community life. The agreement expands and strengthens every aspect of the Commonwealth’s system of serving people with intellectual and developmental disabilities in integrated settings, and it does so through a number of services and supports. The Department has a website dedicated to Olmstead enforcement, which includes links to settlements, briefs, findings letters, and other materials. The settlement agreements are a reminder that private businesses and state and local government agencies alike should exercise special care to prepare to defend their actions against potential disability or other Civil Rights discrimination challenges. All organizations, whether public or private need to make sure both that their organizations, their policies, and people in form and in action understand and comply with current disability and other nondiscrimination laws. When reviewing these responsibilities, many state and local governments and private businesses may need to update their understanding of current requirements. The scope and applicability of disability and various other federal nondiscrimination and other laws have been expanded or modified in recent years by statutory, regulatory or enforcement changes.
These Justice Department efforts also are reflected in the companion enforcement efforts to investigate and prosecute disability discrimination by the Labor Department Equal Employment Opportunity Commission in employment, the HUD and related areas, the Department of Education in education and related fields and a host of other agencies.
The enforcement of disability discrimination and accommodation requirements in the employment space is even more zealous making big dollar EEOC and private plaintiff judgements and settlements increasingly common. See, e.g. Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s.
Where the entity is a private or government agency that is a government contractor or receiving other federal funds or grants, compliance with the ADA and other nondiscrimination and civil rights laws is particularly important as the contracts or regulations pursuant to which these funds are granted typically require compliance with these and other special nondiscrimination rules. In the case of funds provided under the 2009 Stimulus Bill, the scope of businesses subject to these requirements and the likelihood of audits was specifically increased in many ways, making recipients of these funds at particular risk for failing to fulfill requirements.
These Federal enforcement activities are further heightened by rising private litigation of disability claims. These public and private actions are encouraged by changes made by Congress to the ADA, which make it easier for plaintiff’s bringing disabilities claims to win, as well as the proactive agenda of the Obama Administration in enforcing disability discrimination laws.
In light of these continuing enforcement efforts, businesses should continue and heighten their diligence against possible disability discrimination exposures by strengthening policies, practices, training and documentation to keep up compliance and to position to defend against possible charges.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
1 Comment |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
September 6, 2012
Businesses concerned about Obama Administration-backed efforts to promote its pro-labor agenda must stay diligent despite the set back suffered by the National Labor Relations Board (NLRB) in its attempt to a Federal Judge to challenge state laws that purport to require secret balloting in union elections in NLRB v. State of Arizona.
Federal District Judge Frederick J. Martone handed the NLRB a temporary setback in its campaign to prevent states from enacting legislation that would interfere with NLRB efforts to strengthen labor organizing powers by restricting secret ballot protections when he rejected the NLRB claims that an Arizona Constitutional Amendment mandating secret balloting in union elections was an unconstitutional infringement on the NLRB’s powers in his September 5, 2012 decision in NLRB v. State of Arizona, the Court left the door open for a potentially successful challenge to the Arizona secret ballot amendment in the future depending on how Arizona applies the law. Furthermore, considered in the context of the Obama Administration’s broader pro-union regulatory and enforcement agenda, the NLRB’s challenge to the Arizona and other state secret ballot laws reminds businesses that their operation face a minefield of mounting labor-management relations risks icluding many that create traps for management sometimes even in the case of non-union workplaces. In light of these expanding exposures, business leaders should update their policies and practices to mitigate the rising risks while keeping a close eye on the Obama Administration’s ongoing effort to expand the power of organized labor by challenging secret ballot mandates in Arizona and other states and the plethora of other pro-union regulatory and enforcement efforts.
NLRB Attacks On Workers’ Secret Balloting Rights
Undermining worker’s secret ballot rights is a key initiative that organized labor with the support of the Obama Administration has promoted to help union organization efforts.
Secret balloting of workers in union organizing elections is designed to promote the ability of worker’s to vote their wishes free from the fear of retaliation by unions or management. It has been a key element of the NLRA since its enactment.
The current method for workers to form a union in a particular workplace generally is a two-step process that begins with the submission by organizers to the NLRB of a petition or authorization card signed by at least 30% of the employees requesting recognition of the union. Under existing law, once the NLRB verifies that the organizers have met the petition or authorization card requirement, it generally orders a secret ballot election unless more than 50% of the workers have signed authorization cards and either:
- The employer notifies the NLRB that it is waiving the secret ballot and voluntarily recognizing the union; or
- The NLRB orders the employer to recognize a union based on the NLRB’s determination that the employer has engaged in unfair labor practices that make a fair election unlikely.
Since the Obama Administration came to power, however, labor with the support of the NLRB and the Obama Administration have included efforts to eliminate or get around secret balloting as part of their broader campaign to strengthen and promote unions and their power. These efforts are reflected in the sharp increase in orders by the NLRB with new Obama appointees that employers recognize unions without balloting, the Obama Administration and Congressional Democrats are pushing to enact the Employee Free Choice Act, which would make union recognition mandatory without any balloting when the NLRB verifies that over 50% of the employees signed authorization cards, and challenges to state laws that would impede these efforts like that brought against the State of Arizona. While Congressional Democrats and the Administration have thus far failed to get the legislation passed, they continue to voice their support for and intention to pursue its enactment after the elections in November.
NLRB’s Challenge To Arizona Constitution’s Secret Ballot Provision
In NLRB v. State of Arizona, Judge Frederick J. Martone on September 5, 2012 handed the NLRB a temporary setback in its campaign to prevent states from enacting legislation that would interfere with its efforts to avoid or cut secret ballot protection when it granted the State of Arizona’s motion to dismiss the case but left the door open for future action.
As Federal legislation and enforcement actions that would limit workers’ rights to vote in a secret ballot rights have continued, Arizona and various other states have enacted laws to protect secret ballot rights in their states.
In January 2011, the NLRB advised Arizona and three other states that recently adopted “secret-ballot amendments” conflicted with longstanding federal labor law by restricting the methods by which employees can choose a union. When no agreement could be reached, the NLRB filed suit to have the Arizona amendment declared unconstitutional.
The Arizona lawsuit challenged a 2010 constitutional amendment to the Arizona Constitution that states”[t]he right to vote by secret ballot for employee representation is fundamental and shall be guaranteed where local, state or federal law permits or requires elections, designations or authorizations for employee representation.” Arizona Constitution, Article 2 § 37. In its lawsuit, the NLRB asked the Federal Court to declare Article 2 § 37 unconstitutional and preempted to the extent that it applies to private employers, private employees, and labor organizations subject to the NLRA on the grounds that the state secret ballot rule “creates a state forum to protect employee representation rights, a task which Congress assigned exclusively to the NLRB.
Among its other efforts to defend the statute, Arizona argued there was no preemption because the state’s “guarantee” of a secret ballot election would only apply if the voluntary recognition option is not selected.
In reaching its ruling, the Federal Court hung its hat on this argument. “It is possible that state litigation invoking (the amendment) may impermissibly clash with the NLRB’s jurisdiction to resolve disputes over employee recognition, conduct secret ballot elections, and address unfair labor practices,” Judge Martone wrote. However, because the amendment has not yet been applied, Judge Martone wrote that he could not assume that it would conflict with the NLRA.
Arizona Decision A Temporary Victory In Battle In Labor-Management Relations War
While the court rejected the NLRB challenge of the Arizona secret ballot requirement this week, the NLRB’s announced disagreement with the decision coupled with the limited scope of the ruling makes clear that businesses watch for another NLRB challenge based on the implementation of the law as well as other new regulatory and enforcement traps for employers.
The court battle over Arizona’s secret ballot amendment is just one of the many areas where the NLRB under the Obama Administration is pursuing a pro-union agenda. In addition to challenging state laws that might operate to restrict union organizing or other activities, the NLRB also has adopted and is promoting the adoption of other pro-labor rules as well as stepping up enforcement on behalf of labor. See e.g., NLRB Moves To Promote Non-Union Employee Use of Collective Action Rights By Launching Webpage; NLRB Report Shows Rise In Unfair Labor Practice Complaints Formal Proceedings Comments Feed; NLRB Settlement Shows Care Necessary When Using Social Networking & Other Policies Restricting Employee Communications. As part of these efforts, for instance, the NLRB increasingly is challenging the authority of employers to enforce mandatory arbitration provisions in employee handbooks or employment agreements, to regulate social media, and to engage in a broad range of other common employer practices while at the same time, it is using its regulatory powers to promote employer posting and other requirements designed to educate workers about their organizational rights. As many of these new rules apply both to unionized workplaces and ununionized workplace, these and other evolving rules often leave all employers to significant and often underappreciated labor law risks in a broad range of circumstances. This risk tends to take on particular significance for unorganized workforces due to a low awareness or appreciation of these changes or their implications on unorganized workforces by their management team. Mistakes are increasingly costly in the current enforcement environment.
Costly Consequences For Employers
The statistics show the cost of management mishandling of labor relations in today’s environment is expensive and growing. This pro-labor regulatory and enforcement agenda as resulted in a significant rise in NLRB unfair labor practice charges in recent years. According to NLRB statistics, the number of unfair labor practice charges brought by the NLRB steadily rose from 2009 to 2011. The number of charges filed by was 1,342 in 2011, 1,242 in 2010, 1,166 in 2009 and 1,108 in 2008. Moreover, NLRB statistics also document that backpay and other remedies also have risen sharply during this period. For instance, in 2008, the NLRB ordered a total of $68,800,000 in backpay, fees, dues and fines in 9,400 cases. In contrast, in 2009, the NLRB ordered $77,700,000 in backpay, fees, dues and fines against employers even though the number of cases dropped to 8,700,000 cases. This trend continued in 2010, where out of 8,300 cases, the NLRB ordered employers to pay $86,100,000 in backpay, fees, dues and fines. See NLRB Statistics. See also NLRB Case Decisions.
In light of this increased activism, employers should exercise care when using mandatory arbitration, compensation gag rule, or other similar provisions; dealing with requests for employee representation by union and non-union employees in organizing, contracting and even disciplinary actions; establishing and administering social networking, communication and other policies; and a wide range of other situations. In addition, employers concerned about these or other labor activities should consult competent counsel for advice about appropriate options and risks for dealing with these activities.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the NLRA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Cynthia Marcotte Stamer.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks.
Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource, labor and employment and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, labor management, outsourcing and risk management strategies domestically and internationally.
Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net
If you find this of interest, you also be interested reviewing some of Ms. Stamer’s other recent updates, including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc. All other rights reserved.
1 Comment |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, Labor Management Relations, OFCCP, Retaliation | Tagged: Collective Bargaining, Corporate Compliance, Employers, Employment, Health Plans, Human Resources, Labor, Labor-Management, Risk Management, Unfair Labor Practice, Union |
Permalink
Posted by Cynthia Marcotte Stamer
August 23, 2012
From handling requests for light duty or other modifications follow a leave to investigating the medical justification for leaves or the fitness of an employee to return to work following a medical absence, employers need to use care to manage disability discrimination exposures.
Today’s announcement by the Equal Employment Opportunity Commission (EEOC) that Wal-Mart Stores, Inc. and Wal-Mart Stores East, L.P. (Wal-Mart) will pay $50,000 in back pay and damages to settle an EEOC disability discrimination lawsuit highlights the potential disability discrimination risks that employers can face when deciding not to provide a requested accommodation to a worker returning from medical leave while other recent enforcement actions show ADA risks from simply making medical inquiries to a worker on or returning from medical leave.
In its lawsuit against Wal-Mart, Case No. 2:11-CV-00834, filed in the U.S. District Court for the District of New Mexico, the EEOC charged that a Carlsbad, N.M Wal-Mart store violated the Americans With Disabilities Act (ADA) by firing a part-time sales clerk, Marcia Arney because the store refused to provide temporary accommodations ordered by her physician following a period of medical leave.
According to the EEOC lawsuit, when Arney, a 22-year Wal-Mart employee, showed the store manager a note from her doctor requesting an accommodation involving periodic breaks off her feet, the manager refused to return her to her job unless she obtained a medical release with no restrictions. The EEOC claims that had Wal-Mart inquired further, it would have known the accommodation need was temporary and in any case, that Wal-Mart easily could have accommodated the restriction.
Under the consent decree settling the suit, Wal-Mart will conduct annual live ADA training of management officials at its Carlsbad store and post a notice on its agreement with the EEOC so that employees are aware of procedures for reporting disability discrimination. Wal-Mart also committed to not require disabled workers to produce a full release from their doctor upon returning from a medical leave. Further, Wal-Mart agreed to engage in an interactive process with disabled employees to find a reasonable accommodation to assist them in performing their jobs and to report future requests for accommodation, as well as charges and lawsuits alleging disability discrimination to the EEOC for the duration of the decree.
Title I of the ADA prohibits employers from discriminating against individuals on the basis of disability in various aspects of employment. The ADA’s provisions on disability-related inquiries and medical examinations reflect Congress’s intent to protect the rights of applicants and employees to be assessed on merit alone, while protecting the rights of employers to make sure that individuals in the workplace can efficiently perform the essential functions of their jobs. An employer generally violates the ADA if it requires its employees to undergo medical examinations or submit to disability-related inquiries that are not related to how the employee performs his or her job duties, or if it requires its employees to disclose overbroad medical history or medical records. Title I of the ADA also generally requires employers to make reasonable accommodations to employees’ and applicants’ disabilities as long as this does not pose an undue hardship or the employer the employer otherwise proves employing a disabled person with reasonable accommodation could not eliminate significant safety concerns. Employers generally bear the burden of proving these or other defenses. Employers are also prohibited from excluding individuals with disabilities unless they show that the exclusion is consistent with business necessity and they are prohibited from retaliating against employees for opposing practices contrary to the ADA. Violations of the ADA can expose businesses to substantial liability.
As reflected by the Wal-Mart, violations of the employment provisions of the ADA may be prosecuted by the EEOC or by private lawsuits and can result in significant judgments. Disabled employees or applicants that can prove they fully were denied reasonable accommodations or otherwise subjected to prohibited disability discrimination under the ADA generally can recover actual damages, attorneys’ fees, and up to $300,000 of exemplary damages (depending on the size of the employer).
The lawsuit against Wal-Mart is part of a wave of lawsuits in which the EEOC or other agencies under the Obama Administration are aggressively challenging medical examination and other medical screenings by private and public employers. In the Wal-Mart case, the suit challenged an employer’s refusal to provide requested accommodations. In other cases, however, the EEOC or other agencies under the Obama Administration also have challenged medical inquiries made by an employer to employees during or returning from leave. Both types of suits send clear signals that employers should use care in making medical inquiries and responding to requests for accommodation from employees taking or returning from medical leaves. See, e.g., Employer Pays $475,000 To Settle ADA Discrimination Lawsuit Challenging Medical Fitness Testing For EMTs, Firefighters & Other Public Safety Worker’s.
To help mitigate the expanded employment liability risks , businesses generally should act to manage their exposures. Management needs to recognize the likely need to defend medical inquiries, decisions to refuse accommodation requests or other similar actions that arise when dealing with employees taking or returning from medical leave due to a disability, illness or injury. Employers need to critically check and document the legitimate business justification for making a medical inquiry or refusing a requested accommodation based on a well-documented investigation and analysis tailored to the specific situation of each requesting employee.
Businesses also should consider tightening their documentation regarding their procedures and processes governing the collection and handling records and communications that may contain information that could be helpful or hurtful in the event of a discrimination charge. Businesses need to ensure that all required records and statistics are collected. In addition, businesses also should consider strengthening record creation and retention efforts to help preserve other evidence that could be invaluable to defending charges and change the way that decisions are made and documented to position their organizations to more effectively demonstrate the defensibility of their employment and other business activities against potential nondiscrimination charges.
As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under the new genetic information nondiscrimination and privacy rules enacted as part of the Genetic Information and Nondiscrimination Act (GINA) signed into law by President Bush on May 21, 2008. Effective November 21, 2009, Title VII of GINA amends the Civil Rights Act to prohibit employment discrimination based on genetic information and restricts the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws. For instance, GINA’s employment related provisions include rules that will:
- Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
- Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
- Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
- Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
- Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
- Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
- Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
- Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.
These employment provisions of GINA are in addition to amendments to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the ADAAA, GINA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Cynthia Marcotte Stamer.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mailto cstamer@solutionslawyer.net
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
1 Comment |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
August 13, 2012
Employers that require employees to submit to medical examinations, question employees about physician or mental conditions or disabilities while on medical leave or for other fitness for duty assessments, or engage in other similar activities should evaluate the defensibility of those practices in light of the growing challenges to these and other employee screening practices by the Obama Administration and private plaintiff attorneys like the Justice Department disability discrimination complaint that lead to a $475,000 settlement against Baltimore County, Maryland.
Baltimore County Nailed For Health Screening of Public Safety Workers
On August 7, 2012, the Justice Department announced that Baltimore County, Maryland will pay $475,000 and change its hiring procedures to resolve a Justice Department lawsuit filed that charged the county violated the Americans with Disabilities Act (ADA) by requiring employees to submit to medical examinations and disability-related inquiries without a proper reason, and by excluding applicants from emergency medical technician (EMT) positions because of their diabetes. The prosecution is notable both for the Justice Department’s challenge of health screenings of EMTs and other workers in key safety positions generally as well as the Justice Department’s challenges to the employer’s medical inquiries to workers on medical leave.
Title I of the ADA prohibits employers from discriminating against individuals on the basis of disability in various aspects of employment. The ADA’s provisions concerning disability-related inquiries and medical examinations reflect Congress’s intent to protect the rights of applicants and employees to be assessed on merit alone, while protecting the rights of employers to ensure that individuals in the workplace can efficiently perform the essential functions of their jobs. An employer generally violates the ADA if it requires its employees to undergo medical examinations or submit to disability-related inquiries that are not related to how the employee performs his or her job duties, or if it requires its employees to disclose overbroad medical history or medical records. Title I of the ADA also generally requires employers to make reasonable accommodations to employees’ and applicants’ disabilities as long as this does not pose an undue hardship or the employer the employer otherwise proves employing a disabled person with reasonable accommodation could not eliminate significant safety concerns. Employers generally bear the burden of proving these or other defenses. Employers are also prohibited from excluding individuals with disabilities unless they show that the exclusion is consistent with business necessity and they are prohibited from retaliating against employees for opposing practices contrary to the ADA. Violations of the ADA can expose businesses to substantial liability.
As reflected by the Baltimore County settlement, violations of the employment provisions of the ADA may be prosecuted by the EEOC or by private lawsuits and can result in significant judgments. Employees or applicants that can prove they were subjected to prohibited disability discrimination under the ADA generally can recover actual damages, attorneys’ fees, and up to $300,000 of exemplary damages (depending on the size of the employer).
The U.S. Justice Department lawsuit against Baltimore County, Maryland is one in a growing series of lawsuits in which the Justice Department or Equal Employment Opportunity Commission (EEOC) is aggressively challenging medical examination and other medical screenings by private and public employers. In its lawsuit against the County, the Justice Department complaint identified 10 current and former police officers, firefighters, EMTs, civilian employees and applicants who were allegedly subjected to inappropriate and intrusive medical examinations and/or other disability-based discrimination. Justice Department officials claimed the County required some employees to undergo medical examinations or respond to medical inquiries that were unrelated to their ability to perform the functions of their jobs. The complaint also alleged the County required employees to submit to medical examinations that were improperly timed, such as requiring an employee who was on medical leave and undergoing medical treatment to submit to a medical exam even though the employee was not attempting to return to work yet.
According to the complaint, numerous affected employees – some of whom had worked for the County for decades – submitted to the improper medical exams for fear of discipline or termination if they refused. The complaint also alleges that the county retaliated against an employee who tried to caution against the unlawful medical exams and refused to hire two qualified applicants for EMT positions because they had diabetes.
In the proposed consent decree filed on August 7, 2012 and awaiting District Court approval, the County seeks to resolve the lawsuit by agreeing to:
- Pay $475,000 to the complainants and provide additional work-related benefits (including retirement benefits and back pay, plus interest);
- Adopt new policies and procedures regarding the administration of medical examinations and inquiries;
- Refrain from using the services of the medical examiner who conducted the overbroad medical examinations in question;
- End the automatic exclusion of job applicants who have insulin-dependent diabetes mellitus; and
- Give ADA training to all current supervisory employees and all employees who participate in making personnel decisions.
Obama Administration Aggressively Enforcing & Interpreting Employment & Other Disability Discrimination Laws
The Baltimore County suit is reflective of the aggressive emphasis that the Obama Administration is placing on challenging employers that require employees to undergo medical screening, respond to medical inquiries or engage in other practices that the EEOC, Justice Department or other Obama Administration officials under Title I of the ADA, as well as its heavy emphasis upon enforcement of the ADA and other disability discrimination laws against U.S. businesses and state and local government agencies generally.
The Justice Department action against Baltimore County is part of the Obama Administration’s sweeping effort to enforce employment and other disability discrimination laws against businesses and state and local government agencies alike. While the Administration’s disability law enforcement reaches broadly, disability discrimination enforcement is particularly notable in the area of employment law. This enforcement targets both public employers like Baltimore County, and private employers. In the private employer arena, for instance, the EEOC earlier this year sued Wendy’s franchisee, CTW L.L.C., (Texas Wendy’s) for allegedly violating the ADA by denying employment to a hearing-impaired applicant. In its suit against Texas Wendy’s, the EEOC seeks injunctive relief, including the formulation of policies to prevent and correct disability discrimination as well as an award of lost wages and compensatory damages for Harrison and punitive damages against CTW L.L.C. In the suit, the EEOC charged that the general manager of a Killeen, Texas Wendy’s refused to hire Michael Harrison, Jr. for a cooker position, despite his qualifications and experience, upon learning that Harrison is hearing-impaired.
According to the EEOC, Harrison, who had previously worked for a different fast-food franchise for over two years, was denied hire by the general manager. Harrison said that after successfully interviewing with the Wendy’s shift manager, he attempted to complete the interview process by interviewing with Wendy’s general manager via Texas Relay, a telephonic system used by people with hearing impairments. Harrison’s told the EEOC that during the call he was told by the general manager that “there is really no place for someone we cannot communicate with.”
As illustrated by the suits against Baltimore County, Texas Wendy’s and many other public and private employers, employers must exercise care when making hiring, promotion or other employment related decisions relating to persons with hearing or other conditions that could qualify as a disability under the ADA.
Defending disability discrimination charges has become more complicated due to both the aggressive interpretation and enforcement of the ADA under the Obama Administration and amendments to the ADA that aid private plaintiffs, the EEOC, the Justice Department and others to prove their case. Provisions of the ADA Amendments Act (ADAAA) that expand the definition of “disability” under the ADA, signed into law on September 25, 2008, broadened the definition of “disability” for purposes of the disability discrimination prohibitions of the ADA to make it easier for an individual seeking protection under the ADA to establish that a person has a disability within the meaning of the ADA. The ADAAA retains the ADA’s basic definition of “disability” as an impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment. However, provisions of the ADAAA that took effect January 1, 2009 change the way that these statutory terms should be interpreted in several ways. Most significantly, the ADAAA:
- Directs EEOC to revise that portion of its regulations defining the term “substantially limits;”
- Expands the definition of “major life activities” by including two non-exhaustive lists: (1) The first list includes many activities that the EEOC has recognized (e.g., walking) as well as activities that EEOC has not specifically recognized (e.g., reading, bending, and communicating); and (2) The second list includes major bodily functions (e.g., “functions of the immune system, normal cell growth, digestive, bowel, bladder, neurological, brain, respiratory, circulatory, endocrine, and reproductive functions”);
- States that mitigating measures other than “ordinary eyeglasses or contact lenses” shall not be considered in assessing whether an individual has a disability;
- Clarifies that an impairment that is episodic or in remission is a disability if it would substantially limit a major life activity when active;
- Changes the definition of “regarded as” so that it no longer requires a showing that the employer perceived the individual to be substantially limited in a major life activity, and instead says that an applicant or employee is “regarded as” disabled if he or she is subject to an action prohibited by the ADA (e.g., failure to hire or termination) based on an impairment that is not transitory and minor; and
- Provides that individuals covered only under the “regarded as” prong are not entitled to reasonable accommodation.
The ADAAA also emphasizes that the definition of disability should be construed in favor of broad coverage of individuals to the maximum extent permitted by the terms of the ADA and generally shall not require extensive analysis. In adopting these changes, Congress expressly sought to overrule existing employer-friendly judicial precedent construing the current provisions of the ADA and to require the EEOC to update its existing guidance to confirm with the ADAAA Amendments. Under the leadership of the Obama Administration, the EEOC and other federal agencies have embraced this charge and have significantly stepped up enforcement of the ADA and other federal discrimination laws.
The ADAAA amendments coupled with the Obama Administration’s emphasis on enforcement make it likely that businesses generally will face more disability claims from a broader range of employees and will possess fewer legal shields to defend themselves against these claims. These changes will make it easier for certain employees to qualify as disabled under the ADA. Consequently, businesses should act strategically to mitigate their ADA exposures in anticipation of these changes. Given the Obama Administration’s well-documented, self-touted activism of the EEOC, Justice Department and other federal agencies in prosecuting disability discrimination and promoting a pro-disability enforcement agenda, businesses are encouraged to review and tighten their employment disability discrimination compliance procedures and documentation.
Likewise, businesses should be prepared for the EEOC and the courts to treat a broader range of disabilities, including those much more limited in severity and life activity restriction, to qualify as disabling for purposes of the Act. Businesses should assume that a greater number of employees with such conditions are likely to seek to use the ADA as a basis for challenging hiring, promotion and other employment decisions. For this reason, businesses should exercise caution to carefully document legitimate business justification for their hiring, promotion and other employment related decisions about these and other individuals who might qualify as disabled taking into account both the broadened disability definition and the aggressive interpretative stance of the Obama Administration. Businesses also generally should tighten job performance and other employment recordkeeping to promote the ability to prove nondiscriminatory business justifications for the employment decisions made by the businesses.
Businesses also should consider tightening their documentation regarding their procedures and processes governing the collection and handling records and communications that may contain information regarding an applicant’s physical or mental impairment, such as medical absences, worker’s compensation claims, emergency information, or other records containing health status or condition related information. The ADA generally requires that these records be maintained in separate confidential files and disclosed only to individuals with a need to know under circumstances allowed by the ADA.
As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under the new genetic information nondiscrimination and privacy rules enacted as part of the Genetic Information and Nondiscrimination Act (GINA) signed into law by President Bush on May 21, 2008. Effective November 21, 2009, Title VII of GINA amends the Civil Rights Act to prohibit employment discrimination based on genetic information and restricts the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws. For instance, GINA’s employment related provisions include rules that will:
- Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
- Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
- Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
- Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
- Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
- Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
- Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
- Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.
These employment provisions of GINA are in addition to amendments to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009. Added together, employment related disability discrimination are large and growing, meriting stepped up risk assessment and management.
Obama Administration Also Aggressively Prosecutes Disability Discrimination In Other Business Operations
Guarding against disability discrimination in employment is not the only area that businesses need to prepare to defend against. The Obama Administration also has trumpeted its commitment to the aggressive enforcement of the public accommodation provisions of the ADA and other federal disability discrimination laws. In June, 2012, for instance, President Obama himself made a point of reaffirming his administration’s “commitment to fighting discrimination, and to addressing the needs and concerns of those living with disabilities.”
As part of its significant commitment to disability discrimination enforcement, the Civil Rights Division at the Justice Department has aggressively enforced the public accommodation provisions of the ADA and other federal disability discrimination laws against state agencies and private businesses that it perceives to have improperly discriminated against disabled individuals. For instance, the Justice Department entered into a landmark settlement agreement with the Commonwealth of Virginia, which will shift Virginia’s developmental disabilities system from one heavily reliant on large, state-run institutions to one focused on safe, individualized, and community-based services that promote integration, independence and full participation by people with disabilities in community life. The agreement expands and strengthens every aspect of the Commonwealth’s system of serving people with intellectual and developmental disabilities in integrated settings, and it does so through a number of services and supports. The Justice Department has a website dedicated to disabilities law enforcement, which includes links to settlements, briefs, findings letters, and other materials. The settlement agreements are a reminder that private businesses and state and local government agencies alike should exercise special care to prepare to defend their actions against potential disability or other Civil Rights discrimination challenges. All organizations, whether public or private need to make sure both that their organizations, their policies, and people in form and in action understand and comply with current disability and other nondiscrimination laws. When reviewing these responsibilities, many state and local governments and private businesses may need to update their understanding of current requirements. Statutory, regulatory or enforcement changes have expanded the scope and applicability of disability and various other federal nondiscrimination and other laws and risks of charges of discrimination.
To help mitigate the expanded employment liability risks created by the ADAAA amendments, businesses generally should act cautiously when dealing with applicants or employees with actual, perceived, or claimed physical or mental impairments to decrease exposures under the ADA. Management should exercise caution to carefully and proper the potential legal significance of physical or mental impairments or conditions that might be less significant in severity or scope, correctable through the use of eyeglasses, hearing aids, daily medications or other adaptive devices, or that otherwise have been assumed by management to fall outside the ADA’s scope. Employers should no longer assume, for instance, that a visually impaired employee won’t qualify as disabled because eyeglasses can substantially correct the employee’s visual impairment.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the ADAAA, GINA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Cynthia Marcotte Stamer.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mail to cstamer@solutionslawyer.net
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
1 Comment |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
June 26, 2012
Tables Present Employment Discrimination Statistics in User-Friendly Format
New employment discrimination charge statistics made available online by the U.S. Equal Employment Opportunity Commission (EEOC) in May, 2012 provide a helpful risk assessment tool for private sector employers looking to understand and decide where to deploy resources to management their employment discrimination exposures.
In May, the EEOC put private sector workplace discrimination charge statistics for each of the nation’s 50 states and U.S. Territories for fiscal years 2009-2011 online. These data provide a look at EEOC charge receipts, broken down by the basis of discrimination, as well as the percent of total state and national charges. The state data tables are available online at http://www1.eeoc.gov/eeoc/statistics/enforcement/charges_by_state.cfm.
The EEOC plans to update the state data each fiscal year.
The availability of these statistics comes at an opportune time. Disability and other discrimination challenges are rising. Since taking office, President Obama has made enforcement of disability and other employment discrimination laws a top priority by both pursing enforcement directly and stepping up public outreach and education efforts to promote awareness and encourage private enforcement. These efforts have been further strengthened by statutory and regulatory amendments to disability discrimination and other discrimination laws. As a result of these developments and a tightening job market, discrimination claims are on the rise.
To help mitigate the expanded employment liability risks , businesses generally should act to manage their exposures. Management should exercise caution to carefully design and implement employment discrimination and related employment policies. They should implement exit interview, hotline and other practices to help detect and resolve potential discrimination exposures early. They also should carefully document legitimate disciplinary and other non-discriminatory justifications for employment related activities and conduct regular training for management and employees.
Businesses also should consider tightening their documentation regarding their procedures and processes governing the collection and handling records and communications that may contain information that could be helpful or hurtful in the event of a discriminatioj charge. Businesses need to ensure that all required records and statistics are collected. In addition, businesses also should consider strengthing record creation and retention efforts to help preserve other evidence that could be invaluable to defending charges and change the way that decisions are made and documented to position their organizations to more effectively demonstrate the defensibility of their employment and other business activities against potential nondiscrimination charges.
As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under the new genetic information nondiscrimination and privacy rules enacted as part of the Genetic Information and Nondiscrimination Act (GINA) signed into law by President Bush on May 21, 2008. Effective November 21, 2009, Title VII of GINA amends the Civil Rights Act to prohibit employment discrimination based on genetic information and restricts the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws. For instance, GINA’s employment related provisions include rules that will:
- Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
- Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
- Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
- Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
- Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
- Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
- Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
- Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.
These employment provisions of GINA are in addition to amendments to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the ADAAA, GINA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Cynthia Marcotte Stamer.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mailto cstamer@solutionslawyer.net
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on New EEOC State Discrimination Charge Data Helpful Employer Risk Assessment Tool Discrimination Exposures Grow |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
June 22, 2012
Statements of President Obama made today (June 22, 2012) in celebration of the 13th anniversary of the June 22, 1999 Supreme Court decision in Olmstead v. L.C. are a reminder that U.S. businesses face a continuing and growing need to be on guard to defend against potential disability discrimination liabilities. Coupled with the well-documented activism of the Equal Employment Opportunity Commission and other agencies in prosecuting disability discrimination and promoting a pro-disability enforcement agenda, businesses are encouraged to review and tighten their disability discrimination compliance procedures and documentation.
In Olmstead, the Supreme Court ruled in that the unjustified institutional isolation of people with disabilities is a form of unlawful discrimination under the Americans with Disabilities Act (ADA).
In marking the 13th anniversary of this decision, President Obama said, “As we mark the anniversary of this historic civil rights decision, we reaffirm our commitment to fighting discrimination, and to addressing the needs and concerns of those living with disabilities.”
In reaffirming this commitment, the Administration highlighted its past and continuing efforts to enforce disability discrimination laws, as well as other activities to support individuals with disability.
As part of its significant commitment to disability discrimination enforcement, the Civil Rights Division at the Department has been involved in more than 40 Olmstead matters in 25 states. Recently, in Virginia, the Department entered into a landmark settlement agreement with the Commonwealth, which will shift Virginia’s developmental disabilities system from one heavily reliant on large, state-run institutions to one focused on safe, individualized, and community-based services that promote integration, independence and full participation by people with disabilities in community life. The agreement expands and strengthens every aspect of the Commonwealth’s system of serving people with intellectual and developmental disabilities in integrated settings, and it does so through a number of services and supports. The Department has a website dedicated to Olmstead enforcement, which includes links to settlements, briefs, findings letters, and other materials. The settlement agreements are a reminder that private businesses and state and local government agencies alike should exercise special care to prepare to defend their actions against potential disability or other Civil Rights discrimination challenges. All organizations, whether public or private need to make sure both that their organizations, their policies, and people in form and in action understand and comply with current disability and other nondiscrimination laws. When reviewing these responsibilities, many state and local governments and private businesses may need to update their understanding of current requirements. The scope and applicability of disability and various other federal nondiscrimination and other laws have been expanded or modified in recent years by statutory, regulatory or enforcement changes.
These Justice Department efforts also are reflected in the companion enforcement efforts to investigate and prosecute disability discrimination by the Labor Department Equal Employment Opportunity Commission in employment, the Department of Housing & Urban Development in housing and related areas, the Department of Education in education and related fields and a host of other agencies.
While the Administration’s disability law enforcement reaches broadly, disability discrimination enforcement is particularly notable in the area of employment law. For instance, the Equal Employment Opportunity Commission recently sued Wendy’s franchisee, CTW L.L.C., (Texas Wendy’s) for allegedly violating the Americans With Disabilities Act by denying employment to a hearing-impaired applicant. In its suit against Texas Wendy’s, the EEOC seeks injunctive relief, including the formulation of policies to prevent and correct disability discrimination as well as an award of lost wages and compensatory damages for Harrison and punitive damages against CTW L.L.C. An example of a growing number of disability discrimination enforcement actions taken against employers and others on behalf of hearing impaired or other persons with disabilities under the Obama Administration, the case against Texas Wendy’s highlights the growing enforcement exposures of U.S. businesses to disability discrimination claims under the Obama Administration. In the suit, the EEOC charged that the general manager of a Killeen, Texas Wendy’s refused to hire Michael Harrison, Jr. for a cooker position, despite his qualifications and experience, upon learning that Harrison is hearing-impaired.
According to the EEOC, Harrison, who had previously worked for a different fast-food franchise for over two years, was denied hire by the general manager. Harrison said that after successfully interviewing with the Wendy’s shift manager, he attempted to complete the interview process by interviewing with Wendy’s general manager via Texas Relay, a telephonic system used by people with hearing impairments. Harrison’s told the EEOC that during the call he was told by the general manager that “there is really no place for someone we cannot communicate with.”
Expanding Disability Discrimination Exposures
As illustrated by the suit against Texas Wendy’s, employers must exercise care when making hiring, promotion or other employment related decisions relating to persons with hearing or other conditions that could qualify as a disability under the ADA.
The ADA generally prohibits disability discrimination and requires employers to make reasonable accommodations to employees’ and applicants’ disabilities as long as this does not pose an undue hardship.
In recent years, amendments to the original provisions of the ADA have made it easier for plaintiffs and the EEOC to establish disabled status of an individual. Businesses should exercise caution to carefully document legitimate business justification for their hiring, promotion and other employment related decisions about these and other individuals who might qualify as disabled. Provisions of the ADA Amendments Act (ADAAA) that expand the definition of “disability” under the ADA, As signed into law on September 25, 2008, the ADAAA amended the definition of “disability” for purposes of the disability discrimination prohibitions of the ADA to make it easier for an individual seeking protection under the ADA to establish that a person has a disability within the meaning of the ADA. The ADAAA retains the ADA’s basic definition of “disability” as an impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment. However, provisions of the ADAAA that took effect January 1, 2009 change the way that these statutory terms should be interpreted in several ways. Most significantly, the Act:
- Directs EEOC to revise that portion of its regulations defining the term “substantially limits;”
- Expands the definition of “major life activities” by including two non-exhaustive lists: (1) The first list includes many activities that the EEOC has recognized (e.g., walking) as well as activities that EEOC has not specifically recognized (e.g., reading, bending, and communicating); and (2) The second list includes major bodily functions (e.g., “functions of the immune system, normal cell growth, digestive, bowel, bladder, neurological, brain, respiratory, circulatory, endocrine, and reproductive functions”);
- States that mitigating measures other than “ordinary eyeglasses or contact lenses” shall not be considered in assessing whether an individual has a disability;
- Clarifies that an impairment that is episodic or in remission is a disability if it would substantially limit a major life activity when active;
- Changes the definition of “regarded as” so that it no longer requires a showing that the employer perceived the individual to be substantially limited in a major life activity, and instead says that an applicant or employee is “regarded as” disabled if he or she is subject to an action prohibited by the ADA (e.g., failure to hire or termination) based on an impairment that is not transitory and minor; and
- Provides that individuals covered only under the “regarded as” prong are not entitled to reasonable accommodation.
The ADAAA also emphasizes that the definition of disability should be construed in favor of broad coverage of individuals to the maximum extent permitted by the terms of the ADA and generally shall not require extensive analysis.In adopting these changes, Congress expressly sought to overrule existing employer-friendly judicial precedent construing the current provisions of the ADA and to require the EEOC to update its existing guidance to confirm with the ADAAA Amendments. Under the leadership of the Obama Administration, the EEOC and other federal agencies have embraced this charge and have sigificantly stepped up enforcement of the ADA and other federal discrimination laws.
Violations of the ADA can expose businesses to substantial liability. Violations of the ADA may be prosecuted by the EEOC or by private lawsuits. Employees or applicants that can prove they were subjected to prohibited disability discrimination under the ADA generally can recover actual damages, attorneys’ fees, and up to $300,000 of exemplary damages (depending on the size of the employer).
The ADAAA amendments coupled with the Obama Administration’s emphasis on enforcement make it likely that businesses generally will face more disability claims from a broader range of employees and will possess fewer legal shields to defend themselves against these claims. These changes will make it easier for certain employees to qualify as disabled under the ADA. Consequently, businesses should act strategically to mitigate their ADA exposures in anticipation of these changes.
To help mitigate the expanded employment liability risks created by the ADAAA amendments, businesses generally should act cautiously when dealing with applicants or employees with actual, perceived, or claimed physical or mental impairments to decrease exposures under the ADA. Management should exercise caution to carefully and proper the potential legal significance of physical or mental impairments or conditions that might be less significant in severity or scope, correctable through the use of eyeglasses, hearing aids, daily medications or other adaptive devices, or that otherwise have been assumed by management to fall outside the ADA’s scope. Employers should no longer assume, for instance, that a visually impaired employee won’t qualify as disabled because eyeglasses can substantially correct the employee’s visual impairment.
Likewise, businesses should be prepared for the EEOC and the courts to treat a broader range of disabilities, including those much more limited in severity and life activity restriction, to qualify as disabling for purposes of the Act. Businesses should assume that a greater number of employees with such conditions are likely to seek to use the ADA as a basis for challenging hiring, promotion and other employment decisions. For this reason, businesses generally should tighten job performance and other employment record keeping to enhance their ability to prove nondiscriminatory business justifications for the employment decisions made by the businesses.
Businesses also should consider tightening their documentation regarding their procedures and processes governing the collection and handling records and communications that may contain information regarding an applicant’s physical or mental impairment, such as medical absences, worker’s compensation claims, emergency information, or other records containing health status or condition related information. The ADA generally requires that these records be maintained in separate confidential files and disclosed only to individuals with a need to know under circumstances allowed by the ADA.
As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under the new genetic information nondiscrimination and privacy rules enacted as part of the Genetic Information and Nondiscrimination Act (GINA) signed into law by President Bush on May 21, 2008. Effective November 21, 2009, Title VII of GINA amends the Civil Rights Act to prohibit employment discrimination based on genetic information and restricts the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws. For instance, GINA’s employment related provisions include rules that will:
- Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
- Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
- Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
- Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
- Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
- Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
- Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
- Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.
These employment provisions of GINA are in addition to amendments to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the ADAAA, GINA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Cynthia Marcotte Stamer.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in many human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 469.767.8872 or via e-mailto cstamer@solutionslawyer.net
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Obama’s Reaffirms Commitment Prosecute Disability Discrimination To Mark Omlstead Anniversary |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
May 25, 2012
Employers, job banks, recruiters and other parties that conduct and rely upon criminal background checks for purposes of screening applicants or making other employment decisions should check and update their practices in response to the announced plans of the U.S. Department of Labor to expand and enforce limitations on employment discrimination against individuals with criminal records as well as the criminal background check requirements of the Fair Credit Reporting Act and other applicable laws.
While criminal or other background checks often are mandated or otherwise business justified, employers and others conducting or using background check information need to understand and comply with legal requirements about the use and administration of criminal or other background checks.
Potential Employment Discrimination Exposures From Criminal Background Checks
Over the past several months, Labor Department officials have identified protection of individuals with criminal backgrounds against employment discrimination as a policy and enforcement priority.
In keeping with this goal, the Labor Department Employment and Training Administration (ETA), with the Civil Rights Center (CRC). on May 25, 2012 published updated training guidance for about exclusions based on criminal records, and how they are relevant to the existing nondiscrimination obligations for the public workforce system and certain other entities that receive federal financial assistance to operate Job Banks, to provide assistance to job seekers in locating and obtaining employment, and to assist employers by screening and referring qualified applicants in Training and Employment Guidance Letter No. 31-11 (TEGL) along with the following accompanying guidance documents:
Meet FCRA Criminal & Other Background Check Requirements
When conducting such a criminal or other background check using a third-party or the internet, care should be taken to comply with the applicable purpose, notice and consent requirements for conducting third-party conducted background checks under the Fair Credit Reporting Act (FCRA) and otherwise applicable law.
Since criminal and other background investigations generally qualify as a credit check for purposes of the FCRA, employers, recruiters, job banks and other parties conducting background checks for employment related purposes risk significant liability for conducting these activities without providing the proper notifications and obtaining necessary consents. Additional requirements often also may apply under applicable state laws, labor-management contracts, government contracting requirements or other similar requirements. Consequently, before doing any credit or other background check, employers or others should ensure that they have the policies, disclosures, data security and written consents required to comply with the FCRA and other laws.
With these procedures in place, employers or others planning to use criminal or other background checks then should work to manage discrimination and other potential risks associated with potential challenges to their use of the information.
Among other things, businesses should carefully document the business justification for their use of the background check and restrict the data they request and receive to information relevant to that purpose. The collection and receipt of this information should be structured and managed in such a way to mitigate employment discrimination, privacy and other legal risks and to promote defensibility. For instance, proper procedures should be used to lower the risk of a pattern of prohibited discrimination on race, national origin, disability or other similar employment discrimination laws. Likewise, collection or receipt of information such as bankruptcy history or other liability sensitive information should be avoided unless a legally defensible need and appropriate procedures governing use can be demonstrated in operation. Care also should be taken to apply the criteria uniformly. Given ADA, GINA, FACTA and other privacy concerns, employers also should specifically check their data collection and protection procedures for adequacy.
To help with these and other concerns, consider defining and documenting in advance the relevant criteria for the position and why it is relevant. Where possible, try to avoid getting information beyond that defined as relevant which could raise sensitivities. Since the FCRA requires notice if adverse hiring decisions are made, employers also should carefully evaluate and document the basis of their decisions when deciding not to hire or promote individuals based on this information and appropriately safeguard this information against improper use or disclosure.
For Help Or Additional Information
If you need help reviewing and updating, administering or defending your background check or other employee benefits, human resources, health care or insurance matters, please contact the author of this update, Cynthia Marcotte Stamer.
Board Certified in Labor and Employment Law, a Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on human resources, recruitment, employee benefits, compensation, credentialing, promotion and discipline and related workforce and risk management matters.
Widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend employment and other services arrangements and assocaited employee benefit, compensation, reductions in force and other severance and other human resources, employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s r management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials about regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available at ww.solutionslawpress.com.
THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2012 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Tighten Defensibility of Criminal & Other Background Check Practices In Light of Labor Department Non-Discrimination Regulation & Enforcement Emphasis |
ADA, Affirmative Action, Bankruptcy, Civil Rights, Corporate Compliance, Disability, EEOC, Employee Benefits, Employers, GINA, Government Contractors, Internal Controls, Labor Management Relations, Mental Health, Mental Health Parity, Nonresident aliens, OFCCP, Rehabilitation Act, Tax | Tagged: background check, criminal background check, Discrimination, Employer, FCRA, job bank |
Permalink
Posted by Cynthia Marcotte Stamer
April 18, 2012
Killeen Fast-Food Restaurant Refused to Hire Hearing-Impaired Applicant Despite His Qualifications, Federal Agency Charges
Wendy’s franchisee, CTW L.L.C., (Texas Wendy’s) is being sued by the U.S. Equal Employment Opportunity Commission (EEOC) for allegedly violating the Americans With Disabililties Act by denying employment to a hearing-impaired applicant. In its suit against Texas Wendy’s, the EEOC seeks injunctive relief, including the formulation of policies to prevent and correct disability discrimination as well as an award of lost wages and compensatory damages for Harrison and punitive damages against CTW L.L.C. An example of a growing number of disability discrimination enforcement actions taken against employers and others on behalf of hearing impaired or other persons with disabilities under the Obama Administration, the case against Texas Wendy’s highlights the growing enforcement exposures of U.S. businesses to disability discrimination claims under the Obama Administration.
Wendy’s Suit
The EEOC charges in its suit against Texas Wendy’s, Case No. 6:12-CV-00091-WSS in U.S. District Court for the Western District of Texas, Waco Division, that the general manager of a Killeen, Texas Wendy’s refused to hire Michael Harrison, Jr. for a cooker position, despite his qualifications and experience, upon learning that Harrison is hearing-impaired.
According to the EEOC, Harrison, who had previously worked for a different fast-food franchise for over two years, was denied hire by the general manager. Harrison said that after successfully interviewing with the Wendy’s shift manager, he attempted to complete the interview process by interviewing with Wendy’s general manager via Texas Relay, a telephonic system utilized by people with hearing impairments. Harrison’s told the EEOC that during the call he was told by the general manager that “there is really no place for someone we cannot communicate with.”
Expanding Disability Discrimination Exposures
As illustrated by the suit against Texas Wendy’s, employers must exercise care when making hiring, promotion or other employment related decisions relating to persons with hearing or other conditions that could qualify as a disability under the ADA.
The ADA generally prohibits disability discrimination and requires employers to make reasonable accommodations to employees’ and applicants’ disabilities as long as this does not pose an undue hardship.
In recent years, amendments to the original provisions of the ADA have made it easier for plaintiffs and the EEOC to establish disabled status of an individual. Businesses should exercise caution to carefully document legitimate business justification for their hiring, promotion and other employment related decisions about these and other individuals who might qualify as disabled. Provisions of the ADA Amendments Act (ADAAA) that expand the definition of “disability” under the ADA, As signed into law on September 25, 2008, the ADAAA amended the definition of “disability” for purposes of the disability discrimination prohibitions of the ADA to make it easier for an individual seeking protection under the ADA to establish that that has a disability within the meaning of the ADA. The ADAAA retains the ADA’s basic definition of “disability” as an impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment. However, provisions of the ADAAA that took effect January 1, 2009 change the way that these statutory terms should be interpreted in several ways. Most significantly, the Act:
- Directs EEOC to revise that portion of its regulations defining the term “substantially limits;”
- Expands the definition of “major life activities” by including two non-exhaustive lists: (1) The first list includes many activities that the EEOC has recognized (e.g., walking) as well as activities that EEOC has not specifically recognized (e.g., reading, bending, and communicating); and (2) The second list includes major bodily functions (e.g., “functions of the immune system, normal cell growth, digestive, bowel, bladder, neurological, brain, respiratory, circulatory, endocrine, and reproductive functions”);
- States that mitigating measures other than “ordinary eyeglasses or contact lenses” shall not be considered in assessing whether an individual has a disability;
- Clarifies that an impairment that is episodic or in remission is a disability if it would substantially limit a major life activity when active;
- Changes the definition of “regarded as” so that it no longer requires a showing that the employer perceived the individual to be substantially limited in a major life activity, and instead says that an applicant or employee is “regarded as” disabled if he or she is subject to an action prohibited by the ADA (e.g., failure to hire or termination) based on an impairment that is not transitory and minor; and
- Provides that individuals covered only under the “regarded as” prong are not entitled to reasonable accommodation.
The ADAAA also emphasizes that the definition of disability should be construed in favor of broad coverage of individuals to the maximum extent permitted by the terms of the ADA and generally shall not require extensive analysis.In adopting these changes, Congress expressly sought to overrule existing employer-friendly judicial precedent construing the current provisions of the ADA and to require the EEOC to update its existing guidance to confirm with the ADAAA Amendments. Under the leadership of the Obama Administration, the EEOC and other federal agencies have embraced this charge and have sigificantly stepped up enforcement of the ADA and other federal discrimination laws.
Violations of the ADA can expose businesses to substantial liability. Violations of the ADA may be prosecuted by the EEOC or by private lawsuits. Employees or applicants that can prove they were subjected to prohibited disability discrimination under the ADA generally can recover actual damages, attorneys’ fees, and up to $300,000 of exemplary damages (depending on the size of the employer).
The ADAAA amendments coupled with the Obama Administration’s emphasis on enforcement make it likely that businesses generally will face more disability claims from a broader range of employees and will possess fewer legal shields to defend themselves against these claims. These changes will make it easier for certain employees to qualify as disabled under the ADA. Consequently, businesses should act strategically to mitigate their ADA exposures in anticipation of these changes.
To help mitigate the expanded employment liability risks created by the ADAAA amendments, businesses generally should act cautiously when dealing with applicants or employees with actual, perceived, or claimed physical or mental impairments to minimize exposures under the ADA. Management should exercise caution to carefully and appropriate the potential legal significance of physical or mental impairments or conditions that might be less significant in severity or scope, correctable through the use of eyeglasses, hearing aids, daily medications or other adaptive devices, or that otherwise have been assumed by management to fall outside the ADA’s scope. Employers should no longer assume, for instance, that a visually impaired employee won’t qualify as disabled because eyeglasses can substantially correct the employee’s visual impairment.
Likewise, businesses should be prepared for the EEOC and the courts to treat a broader range of disabilities, including those much more limited in severity and life activity restriction, to qualify as disabling for purposes of the Act. Businesses should assume that a greater number of employees with such conditions are likely to seek to use the ADA as a basis for challenging hiring, promotion and other employment decisions. For this reason, businesses generally should tighten job performance and other employment recordkeeping to enhance their ability to demonstrate nondiscriminatory business justifications for the employment decisions made by the businesses.
Businesses also should consider tightening their documentation regarding their procedures and processes governing the collection and handling records and communications that may contain information regarding an applicant’s physical or mental impairment, such as medical absences, worker’s compensation claims, emergency information, or other records containing health status or condition related information. The ADA generally requires that these records be maintained in separate confidential files and disclosed only to individuals with a need to know under circumstances allowed by the ADA.
As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under the new genetic information nondiscrimination and privacy rules enacted as part of the Genetic Information and Nondiscrimination Act (GINA) signed into law by President Bush on May 21, 2008. Effective November 21, 2009, Title VII of GINA amends the Civil Rights Act to prohibit employment discrimination based on genetic information and restricts the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws. For instance, GINA’s employment related provisions include rules that will:
- Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
- Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
- Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
- Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
- Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
- Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
- Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
- Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.
These employment provisions of GINA are in addition to amendments to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009.
If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the ADAAA, GINA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Curran Tomko Tarksi LLP Labor & Employment Practice Chair Cynthia Marcotte Stamer at 214.270.2402.
About The Author
Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in numerous human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 214.270.2402 or via e-mail here.
Other Helpful Resources & Other Information
If you found these updates of interest, you also be interested in one or more of the following other recent articles published in this electronic Solutions Law publication available for review here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here.
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@solutionslawyer.net.
©2012 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc. All other rights reserved.
Comments Off on EEOC Sues Wendy’s Franchisee For Disability Discrimination |
ADA, Corporate Compliance, EEOC, Employers, GINA, Human Resources, OFCCP, Retaliation | Tagged: ADA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
December 23, 2011
This week’s announcement by the U.S. Justice Department of the largest residential fair lending settlement in history on December 21, 2011 highlights the widening scope of exposures that U.S. businesses face under a broad range of federal Civil Rights and other discrimination laws. The settlement shows that discrimination risks are rising and that employment discrimination is only part of the problem. In addition to managing employment discrimination exposures in their employment practices, many businesses and business leaders also need to take steps to adequately recognize and provide policies, management controls and training to maintain compliance with federal disability and other discrimination laws prohibiting discrimination against disabled or other customers or others with whom they do business.
Human resources and other management leaders should move quickly to help their organizations manage these risks and responsibilities.
Countrywide Settlement
This week’s Justice Department settlement with Countrywide Financial Corporation and its subsidiaries (Countrywide) provides for payment of $335 million in compensation to the more than 200,000 qualified African-American and Hispanic borrowers that Federal officials allege were victims of the widespread pattern or practice of illegal discrimination against qualified African-American and Hispanic borrowers by Countrywide while Countrywide served as one of the nation’s largest single-family mortgage lenders and originated more than 4 million residential mortgage loans. Bank of America now owns Countrywide.
Federal officials charged Countrywide engaged in discriminatory mortgage lending practices against more than 200,000 qualified African-American and Hispanic borrowers from 2004 through 2008. The Justice Department claimed it uncovered a pattern or practice of discrimination involving victims in more than 180 geographic markets across 41 states and the District of Columbia. These discriminatory acts allegedly included widespread violations of the Fair Housing Act and the Equal Credit Opportunity Act, and resulted in African-American and Hispanic borrowers being charged higher rates for mortgage loans – solely because of their race or national origin.
According to Attorney General Eric Holder, today’s settlement will compensate the more than 200,000 African-American and Hispanic borrowers who were victims of discriminatory conduct, including more than 10,000 African-American or Hispanic borrowers who – despite the fact that they qualified for prime loans – were steered into subprime loans. Subprime borrowers pay higher penalties and higher interest rates, have a greater likelihood of default and foreclosure than with prime loans, and other damages.
When announcing the settlement, Attorney General Holder reaffirmed the Obama Administration’s commitment to finding and prosecuting businesses that engage in illegal discriminatory practices. To read Attorney General Eric Holder’s remarks, click here.
Discrimination Obama Administration Priority
Enforcing disability discrimination laws is a high priority of the Obama Administration Business leaders increasingly recognize the need to tighten procedures to manage disability discrimination risks.
Human resources and other business leaders often recognize human resource related discrimination risks as requiring management. The heightened emphasis of the Obama Administration on disability regulation and enforcement clearly is raising business responsibilities and exposures under these employment laws. In order to manage these exposures effectively, however, it is important that businesses and their human resources leaders do not take for granted the adequacy of their current compliance and risk management efforts in light of the Obama Administration’s aggressive regulatory and enforcement agenda in this area. See e.g., Affordable Care Act To Require Health Plans Cover Contraception & Other Women’s Health Procedures In 2012; EEOC Finalizes Updates To Disability Regulations In Response to ADA Amendments Act; Update Employment Practices To Manage Genetic Info Discrimination Risks Under New EEOC Final GINA Regulations; EEOC Attacks Medical Leave Denials As Prohibited Disability Discrimination; Labor Secretary Comments Highlight Federal Protections & Resources To Support Veteran’s Employment Rights.
Employment discrimination risks are not the only discrimination exposures that U.S. organizations need to be concerned about, however. The Countrywide settlement joins a lengthy list of settlements and other actions by the Obama Administration against businesses and government entities for alleged violations of U.S. civil rights and other nondiscrimination laws. See, e.g. Businesses Face Rising Disability Discrimination Enforcement Risks; New Obama Administration Affirmative Action Guidance Highlights Organization’s Need To Tighten Nondiscrimination Practices; OFCCP Proposed Increased Disability Hiring Targets, Other Tougher Government Contractor Rules another Sign Of Rising Employment Discrimination Risks; Incentives To Get Employee Into Wellness Education Requires Legal Risk Management; New School Racial Accommodation Guidance Gives Important Insights For Schools & Other Organizations On Obama Administration Affirmative Action Enforcement; Justice Department Landlord Suit Shows Businesses Face Rising Disability Discrimination Enforcement Risks; Big Penalty for Lender Shows Risks of Violating Military Service or Vets Rights; OCR Requires Rhode Island DHS To Provide Translation, Other Services For Limited English, Other Language Impaired Accommodations.
These regulatory, audit, enforcement and other actions show that private businesses and state and local government agencies alike should exercise special care to prepare to defend their employment and other business practices against potential disability or other Civil Rights discrimination challenges on a broad range of fronts.
HR Key Player
Human resources professionals are key players to efforts to effectively manage their organization’s overall discrimination risks and responsibilities by managing compliance throughout the organization.
All organizations, whether public or private need to make sure both that their organizations, their policies, and people in form and in action understand and comply with current disability and other nondiscrimination laws. When reviewing these responsibilities, many state and local governments and private businesses may need to update their understanding of current requirements.
Federal nondiscrimination and other laws have been expanded or modified in recent years by statutory, regulatory or enforcement changes, risk management efforts should begin with an assessment of the adequacy of existing policies and practices in light of the latest rules and enforcement actions. Based on this assessment, business and governmental organizations should update policies and procedures as required, tighten documentation, and conduct ongoing, well-documented audits and training to mitigate exposures.
Human resources and other management leaders should position their organizations to guard against rising enforcement of these laws by updating policies, oversight and training to ensure that their workers and business partners recognize and know how to conduct themselves properly to fulfill responsibilities to persons with disabilities or others with whom the business deals who may be protected under Federal or state disability discrimination laws. In addition to adopting and training workers on policies requiring compliance with these laws, businesses should include contractual provisions requiring compliance with these laws in leases and other relevant business contracts. Most businesses also may want to provide and post information about processes that customers or others who may have a concern about the needs of persons with these special needs to position the business to address concerns that otherwise might go unnoticed until they arise to the level of an agency or other legal complaint.
If you need assistance in conducting a risk assessment of or responding to a challenge to your organization’s existing policies or practices for dealing with the issues addressed in these publications or other compliance, labor and employment, employee benefit, compensation, internal controls or other management practices, contact attorney Cynthia Marcotte Stamer.
For Help With Compliance, Risk Management & Defense
If you need help in auditing or assessing, updating or defending your organization’s compliance, risk manage or other internal controls practices or actions, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469)767-8872. If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available at www.cynthiastamer.com.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 24 years of work helping employers and other management; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work helping employers carry out, audit, manage and defend union-management relations, wage and hour, discrimination and other labor and employment laws, privacy and data security, internal investigation and discipline and other workforce and internal controls policies, procedures and actions. The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer works, publishes and speaks extensively on management, re-engineering, investigations, human resources and workforce, employee benefits, compensation, internal controls and risk management, federal sentencing guideline and other enforcement resolution actions, and related matters. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
©2011 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.. All other rights reserved.
Comments Off on HR Key Player In Managing Countrywide & Other US Discrimination Exposures |
ADA, Affirmative Action, Child Labor, Civil Rights, Corporate Compliance, Disability, EEOC, Employers, GINA, Government Contractors, OFCCP, Rehabilitation Act, Retaliation, USERRA, VEVRRA | Tagged: ADA, civil rights, Discrimination, employment discrimination, Risk Management |
Permalink
Posted by Cynthia Marcotte Stamer
September 29, 2011
The Employer Assistance and Resource Network (EARN) will be hosting four weekly webinars in celebration of National Disability Employment Awareness Month on Thursdays in October from 2:00 – 2:30 p.m. Eastern Time. Topics will include Employer Preparedness to Include Veterans with Disabilities in the Workplace; the Employment of Persons with Disabilities; the Work Opportunity Tax Credit; and the Workforce Recruitment Program. To learn more, see Free Webinar Series for Employers Beginning October 6.
For Help With These Or Other Matters
If you would like help reviewing or defending your organization’s labor and employment, health or other employee benefit or insurance programs, need legal representation on health plan or other employment, employee benefits, or other management controls or risk management matters or wish to discuss arranging for Ms. Stamer to conduct training or speak for your organization, please contact Ms Stamer here.
Immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on labor and employment, employee benefit and related workforce, insurance and health care matters.
A board certified labor and employment attorney widely known for her extensive practical knowledge and experienced with human resources and other workforce staffing and management matters, Ms. Stamer has extensive experience helping employer and other management organizations manage and resolve risks arising under employment discrimination and other employment laws. She also works with employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources programs and practices. She works extensively with employers, plan sponsors, insurers, administrators, technology and other service providers and others to develop and operate legally defensible programs, practices and policies that promote the client’s human resources, employee benefits or other management goals. Ms. Stamer also is a widely published author and highly regarded speaker on these and other human resources, employee benefit, and internal controls matters who is active in many human resources, employee benefits, and other management focused organizations.
You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here. For important information concerning this communication click here.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available at www.solutionslawpress.com.
THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2011 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Employer Assistance and Resource Network Offers Free Webinars For Employers During October In Honor of Disability Employment Awareness Month on Thursdays in October from 2:00 – 2:30 p.m. Eastern Time. Topics will include Employer Preparedness to Include Veterans with Disabilities |
ADA, Disability, Disability, Employee Benefits, Employers, ERISA, GINA, Military Leave, Retirement Plans, Tax, VEVRRA | Tagged: ADA, disability law, employment law, reasonable accommodation |
Permalink
Posted by Cynthia Marcotte Stamer
August 2, 2011
Affordable Care Act To Require Health Plans Cover Contraception & Other Women’s Health Procedures Beginning In 2012
Contraception Mandate Might Not Apply To Certain Religious Employer Plans
Starting with plan years beginning after July 31, 2011, most employer and union sponsored group health plans and group and individual health insurers generally must cover contraceptive and certain other preventive services for women (“Women’s Preventive Services”) at no cost to comply with federal rules that these programs cover preventive care for members with no cost sharing enacted as part of the Patient Protection and Affordable Care Act (“ACA”).
On Monday, August 1, 2011, the Department of Health & Human Services (“HHS”) on Monday, August 1, 2011 announced guidelines (Women’s Preventive Services Guidelines”) that add contraception and a list of women’s health procedures to the preventive care procedures that ACA requires covered health plans and health insurance policies covered by the Affordable Care Act to cover without cost to members. ACA’s general preventive coverage rules generally have required covered health plans and policies to cover without cost a broad list of other preventive care procedures since the first plan year beginning after September 22, 2009.
Interim Final Regulations implementing ACA’s new preventive care mandate published July 14, 2010 interpreted this ACA preventive care mandate broadly to dictate that ACA covered health plans and health insurers cover as preventive services at no member cost hundreds of procedures.
Concerning the Women’s Preventive Services, however, the Interim Final Regulations delayed implementation of requirements to cover Women’s Preventive Services until August 1, 2011 to give time to HRSA time to issue its recommendations about what procedures should qualify as Women’s Preventive Services. When HRSA failed to finalize its input by August 1, 2011, HHS finalized its list of required Women’s Preventive Services now rather than to continue waiting for HRSA’s final input.
Finalization of the list of required Women’s Preventive Services now means covered health plans and policies must add coverage for these listed procedures with no co-pay beginning with all post-July 31, 2012 plan years.
While the published list of required Women’s Preventive Services generally mandates that ACA-covered health plans and policies cover contraceptive services for women at no cost beginning in 2012, some plans sponsored by religious employers and group health policies covering these groups may be exempt from the duty to coverage contraception under a new regulation that HHS, along with the Department of Labor Employee Benefit Services Administration (“EBSA) and the Department of Treasury Internal Revenue Service (“IRS”)(collectively, the “Agencies”) will jointly publish in the Federal Register on August 3, 2011. See here for more detailed information.
Plans & Insurers Should Review & Update Preventive Care & Other Wellness Benefits
Non-grandfathered health plans and policies, their sponsors, insurers, fiduciaries and administrators should carefully review and update their health plans for compliance with the existing preventive care mandates and other evolving rules about disease management and wellness benefits and coverages, as well as to consider the impending requirement to comply with additional Women’s Preventive Services coverage requirements in 2012 as part of their plan design and cost projections.
Existing health plans and health insurance should be reviewed to ensure that the programs appropriately cover all preventive services currently required by the applicable ACA mandates or other laws and re-reviewed for compliance with any updated rules before each plan year to identify any additional costs, changes to plan documents, communications, administrative procedures and vendor contracts required to administer the health plan in accordance with existing rules. For 2012, this should specifically consider the need to comply with the new Women’s Preventive Services coverage requirements that take effect next plan year also should be considered.
In addition to specifically planning for compliance with ACA’s preventive services coverage mandates, all health plans and policies, their sponsors, insurers, fiduciaries and administrators should review the other wellness and disease management components of their plans. In addition to ACA compliance, these arrangements may need redesign to minimize emerging exposures to challenge by the Equal Employment Opportunity Commission (“EEOC”) or private plaintiffs under the Americans With Disabilities Act (“ADA”). Since the Obama Administration took office, the EEOC has taken the position that many common wellness and disease management programs violate the ADA. In addition to these exposures, amendments to the nondiscrimination requirements of the Health Insurance Portability & Accountability Act (“HIPAA”), new nondiscrimination rules added by the Genetic Information & Nondiscrimination Act (“GINA”), federal mental health parity rules, evolving Affordable Care Act claims, coverage and other rules and guidance about essential benefits and other statutory, regulatory and enforcement changes often require updates to common disease management and wellness programs as well as other health plan provisions. Appropriate steps should be taken to review and update these and other plan terms, procedures, communications and practices to maintain compliance and support the ability to enforce plan terms and rely on plan cost projections.
The author of this update, attorney Cynthia Marcotte Stamer frequently conducts training and publishes on these and other matters. She is scheduled to speak about these and other changing health plan requirements in light of health care reform at the September 14, 2011 Houston WEB Chapter lunch and will be conducting briefings on preventive care, wellness and disease management and other rules for several other organizations over the next few months. You can find out about upcoming training or other events and get updates at www.CynthiaStamer.com.
For Help With These Or Other Health Plan Or Employee Benefit Matter
If you would like help reviewing or defending your organizations health plan or other insurance or employee benefit and employment practices in light of these or other laws, please contact attorney Cynthia Marcotte Stamer.
Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 23 years of work, advocacy, education and publications on employee benefit and related matters.
A board certified labor and employment attorney Ms. Stamer continuously advises and assists employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources programs and practices. She works extensively with plan sponsors, insurers, administrators, technology and other service providers and others to develop and operate legally defensible programs, practices and policies that promote the client’s human resources, employee benefits or other management goals. Ms. Stamer also is a widely published author and highly regarded speaker on these and other employee benefit and human resources matters who is active in many other employee benefits, human resources and other management focused organizations.
You can review other recent human resources, employee benefits and internal controls publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here. Some recent publications and programs that may be of interest include:
Ms. Stamer is scheduled to conduct training on these and other health benefit requirements for a number of organizations over the upcoming month. For information about these and other training opportunities or for other resources and information, see here or contact Ms. Stamer directly.
For Help or More Information
If you have questions or need help understanding or responding to the Regulations, with other health benefit design, administration or operations concerns, or with other employee benefits, compensation, labor or employment or other workforce management concerns, please contact the author of this update, Board Certified Labor and Employment attorney and management consultant Cynthia Marcotte Stamer here or at (469)767-8872.
Past Chair of the American Bar Association (ABA) Health Law Section Managed Care & Insurance Interest Group, Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, and a council member of the ABA Joint Committee on Employee Benefits, Ms. Stamer is nationally recognized for her more than 23 years pragmatic and innovative health program work.
Board certified in labor and employment law by the Texas Board of Legal Specialization with extensive leading edge health plan experience, Ms. Stamer has worked continuously throughout her career helping health plan sponsors, fiduciaries, administrators, insurers and others design, administer and defend health and other employee benefit and insurance programs domestically and internationally. She is widely recognized for her experience helping design and implement legally compliant self-insured and insured health reimbursement, mini-med, high-deductible health plans, limited benefit plans, 24-hour and occupational medicine, ex-pat and medical tourism, deductible reimbursement and other creative health benefit programs to solve a wide range of financial and other challenges while coping with changing regulatory and market realities. Her work includes both working with clients to design, document, implement and administer these and other arrangements, as well as the development of wellness and disease management, claims administration and appeals, eligibility, and other administrative services, processes and technologies. She also works with plan fiduciaries, plan sponsors, insurers, administrators, brokers and advisors, bankruptcy trustees, creditors, debtors, service providers and their officers and directors about the prevention, investigation, mitigation and resolutions of civil and criminal liability arising from suspected or known benefit administration claims, breaches of fiduciary duty, privacy and data security breach, vendor disputes and other disputes arising in relation to employee benefit and insurance arrangements. As a continuing part of this representation, Ms. Stamer regularly represents and defends plan sponsors, fiduciaries, third party administrators and other service providers and management officials in dealings with the Department of Labor, Department of Justice, Department of Health & Human Services, Department of Defense, Securities and Exchange Commission, state insurance regulators, state attorneys general and other federal and state regulators and prosecutors and private plaintiffs in connection with investigations, prosecutions, audits and other actions arising from employee benefit, insurance and related arrangements and products.
Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble Premier AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters. Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. In addition to her many ABA leadership involvements, she also serves in leadership positions in numerous human resources, corporate compliance, and other professional and civic organizations. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, World At Work, the ICEBS, SHRM and many other national and local publications. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2011 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on New Affordable Care Act Guidance Helps Some Health Plans Stay Grandfathered |
105(h), ADA, Affordable Care Act, Claims Administration, Corporate Compliance, Discrimination, Disease Management, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, GINA, Health Care Reform, Health Plans, Human Resources, Insurance, Public Policy | Tagged: Affordable Care Act, Employee Benefits, grandfathered health plan, grandfathered plan, Health Care Reform, Health Insurance, Health Plans, Insurance, medical insurance |
Permalink
Posted by Cynthia Marcotte Stamer
May 20, 2011
The National Labor Regulations Board (NLRB)’s announcement of a settlement against a Connecticut nursing home operator this week in conjunction with a series of other enforcement actions highlight the need for businesses to tighten defenses and exercise other caution to minimize their organization’s exposure to potential NLRB charges or investigation. As reflected by many of these enforcement acts, the exposures arise both from active efforts by businesses to suppress union organizing or contracting activities, as well as the failure to identify and manage hidden labor law exposures in the design and administration of more ordinary human resources, compliance, business operations and other policies and practices.
On May 17, 2011, the NLRB announced here that Connecticut nursing home operator Spectrum Healthcare has agreed to settle a NLRB case involving multiple allegations of unlawful suspensions, discharges and unilateral changes in violation of the National Labor Relations Act and other federal labor laws by offering reinstatement and back pay to all discharged and striking workers and signing a new three-year collective bargaining agreement with its employees’ union, New England Health Care Employees Union District 1199, SEIU.
Along with the contract and reinstatement of all employees, the company agreed to pay $545,000 in back pay and pension benefits to employees who were harmed by the unfair labor practices, and to expunge any disciplinary records related to the case. As a result, all NLRB charges against the company have been withdrawn. Spectrum admits to no wrongdoing in the settlement.
The settlement, reached midway through a hearing before an NLRB administrative law judge in Connecticut and approved by the judge yesterday, ends a long-running dispute which grew into a strike by almost 400 employees at four nursing homes in Connecticut operated by Spectrum Healthcare, LLC. Complaints issued by the NLRB Regional Office in Hartford alleged that, beginning in the fall of 2009, several months after the prior collective bargaining agreement expired, Spectrum discharged seven employees and suspended three others to retaliate against their union activities and to discourage other employees from supporting the union. In addition, one employee was discharged and seven others were suspended after the employer unilaterally changed its tardiness discipline policy without first bargaining with the union.
The complaints further alleged that in April 2010, employees at the four nursing homes — in Derby, Ansonia, Winsted, and Hartford — went on strike to protest the unfair labor practices. When the strikers offered unconditionally to return to work in late August, the employer refused to take them back. Under federal labor law, if a strike is called because of an unfair labor practice, employees are entitled to reinstatement after an unconditional offer to return to work.
The reinstated employees are due to return to the facilities this week.
The Spectrum Healthcare settlement is reflective of the growing number of NLRB enforcement orders against employers generally and health care providers specifically under the Obama Administration. The Obama Administration has close ties and has expressed its strong and open support for union and union organizing activities. The adoption of a series of union friendly labor law reforms was one of the key campaign promises of President Obama during his election campaign. While other legislative priorities and the change in the leadership of the House of Representatives appears to have slowed efforts to push through this agenda, it has not slowed the Administration’s efforts to support unions with strong enforcement activities. Empowered by a difficult economic and job situation and an awareness of the Obama Administration’s strong support for union organizing and other activities, unions are stepping up organizing efforts and more aggressively challenging employers actions.
Over the past few months, public awareness of the Obama Administration’s aggressive enforcement agenda on behalf of unions has drawn new attention as a result of the widespread media coverage of NLRB actions challenging Boeings planned relocation of certain manufacturing jobs intervention in a planned relocation of certain manufacturing operations. See, e.g., Acting General Counsel Lafe Solomon releases statement on Boeing complaint; National Labor Relations Board issues complaint against Boeing Company for unlawfully transferring work to a non-union facility. However, the Boeing and Spectrum Healthcare actions represent only the tip of the iceberg of the rising number of NLRB enforcement activities, most of which take place with little media or public attention.
Along side the Spectrum Healthcare and Boeing actions, in recent weeks, the NLRB also has been busy with several other enforcement activities. For instance:
- On May 9 2011, the NLRB issued a complaint against Hispanics United of Buffalo (HUB), a nonprofit that provides social services to low-income clients, that alleges that HUB unlawfully discharged five employees after they took to Facebook to criticize working conditions, including work load and staffing issues. The case involves an employee who, in advance of a meeting with management about working conditions, posted to her Facebook ; and
- On May 17, the NLRB secured a temporary injunction from a U.S. District Court in San Jose California against San Jose area waste hauling company OS Transport LLC, charged with engaging in unfair labor practices including the termination of a lead organizer and another Union supporter, retaliation against Union efforts in the form of unfavorable assignments, threats to Union supporters, and promises of improved treatment of employees who disavow the Union for the alleged purpose of defeating a union. o offer reinstatement to two drivers and restore full assignments to other drivers who had expressed support for a union during an organizing campaign. More Details here.,
In addition, in recent weeks, the NLRB also has:
Amid this difficult enforcement environment, business leaders should exercise special care to prepare to defend their actions against both potential organizing efforts, to understand the types of actions and activities that may help fuel charges, and take steps to manage these and other union organization and other labor risks.
For Help With Labor & Employment, Employee Benefits Or Other Risk Management and Defense
If you need assistance in auditing or assessing, updating or defending your labor and employment, employee benefits, compliance, risk manage or other internal controls practices or actions, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469)767-8872.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 23 years of work helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work helping employers implement, audit, manage and defend wage and hour and other workforce and internal controls policies, procedures and actions. The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer works, publishes and speaks extensively on wage and hour, worker classification and other human resources and workforce, employee benefits, compensation, internal controls and related matters. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here .
©2011 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Spectrum Healthcare NLRB Charge Settlement Highlights Need To Defend Against Possible Unfair Labor Practices & Other Union Exposures |
105(h), Absenteeism, ADA, Affirmative Action, Affordable Care Act, ARRA, Bankruptcy, Cafeteria Plans, Child Labor, CHIP, Claims Administration, COBRA, COBRA Subsidy, Corporate Compliance, Data Security, Defined Benefit Plans, Defined Contribution Plans, Disability, Disability, Disability Plans, Discrimination, Disease Management, Drug & Alcohol, E-Verify, EEOC, Employee Benefits, Employers, Employment Agreement, Employment Tax, ERISA, Excise Tax, Fair Labor Standards Act, family leave, Fiduciary Responsibility, FMLA, GINA, Government Contractors, H.R. 4872, Health Care Reform, Health Plans, HIPAA, Human Resources, I-9, Immigration, Income Tax, Insurance, Internal Controls, Internal Investigations, Labor Management Relations, Leave, Malpractice, medical leave, Medicare Part D, Mental Health, Mental Health Parity, Military Leave, Non-Compete, Non-Competition Agreement, Nonresident aliens, OFCCP, OSHA, Pandemic, Patient Empowerment, Patient Protection and Affordable Care Act, Payroll Tax, Preemption, Prescription Drugs, Privacy, Professional Liability, Protected Health Information, Public Policy, Refunds, Rehabilitation Act, Reporting & Disclosure, Restructuring, Retaliation, Retirement Plans, Risk Management, Safety, Sexual Harassment, Stimulus Bill, Swine Flu, Tax, Tax Credit, Tax Qualification, Telecommuting, Uncategorized, Unemployment Benefits, Unemployment Insurance, Union, USERRA, VEVRRA, Wage & Hour, Wellness, Wellness Programs, Whistleblower | Tagged: ADAAA, Americans With Disabiltiies Act, Employer, employment discrimination, facebook, HR, Human Resources, NLRA, social medial, unfair labor practices, Union |
Permalink
Posted by Cynthia Marcotte Stamer
May 10, 2011
The National Institute of Standards and Technology (NIST) and the Department of Health and Human Services (HHS), Office for Civil Rights (OCR) are making presentations from the 4th annual conference on “Safeguarding Health Information: Building Assurance through HIPAA Security” co-hosted in Washington, D.C. on May 10 & 11, 2011 available on line for review. The training is part of a series of continuing efforts by the agencies to outreach to various parties on the Privacy and Security Rules of the Health Insurance Portability & Accountability Act of 1996, as amended (HIPAA). Meanwhile, OCR’s Susan McAndrew is scheduled to share insights on OCR’s HIPAA regulatory and enforcement agenda at a teleconference to be hosted by the American Bar Association Joint Committee on Employee Benefits at Noon Central on May 16, 2011.
The Security Rule sets federal standards to protect the confidentiality, integrity and availability of electronic protected health information by requiring HIPAA covered entities and their business associates to implement and maintain administrative, physical and technical safeguards. Presentations cover a variety of current topics including updates on HHS health information privacy and security initiatives, OCR’s enforcement of health information privacy and security activities, integrating security safeguards into health IT and security automation, insider threat trends and safeguards, and more.
The conference is designed to explore the current health information technology security landscape and the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, the agencies share their practical strategies, tips and techniques for implementing the HIPAA Security Rule.
For details about reviewing the May 10-11 presentations, see the 2011 HIPAA Conference website here. For details about the May 16 teleconference, see here.
For Help With Monitoring Developments, Compliance, Investigations Or Other Needs
If you need assistance monitoring federal health reform, policy or enforcement developments, or to review or respond to these or other health care or health IT related risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer, can help. Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 23 years experience advising health industry clients about these and other matters. Ms. Stamer has extensive experience advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical privacy and other compliance and risk management policies, to health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, On May 3, 2011, Ms. Stamer served as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR and will moderate a teleconference featuring comments by OCR’s Susan McAndrew for the Joint Committee on Employee Benefits scheduled for May 16. Her insights on the required “culture of compliance” with HIPAA also recently were quoted in medical privacy related publications of the Atlantic Information Service. Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, employee benefit and other clients, trade and professional associations and others.
You can get more information about her HIPAA and other experience here.
If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here. For important information concerning this communication click here.
THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2011 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on OCR’s McAndrew Speaks At 5/16 JCEB HIPAA Teleconference; OCR/NIST To Share Other HIPAA Training On Line |
Data Security, GINA, Health Plans, HIPAA, Human Resources, Privacy, Uncategorized, Wellness Programs | Tagged: Health Care, Health Care Provider, Health Plans, HIPAA, OCR, Protected Health Information |
Permalink
Posted by Cynthia Marcotte Stamer
March 24, 2011
Employers Urged To Tighten Disability Related Discrimination Risk Management
Employers should review and update their existing employment and employee benefit practices in response to updated regulations (Final Regulations) governing the disability discrimination rules of the Americans With Disabilities Act as amended by the ADA Amendments Act (ADAAA) that the Equal Employment Opportunity Commission (EEOC) will publish in the Friday, March 25, 2011 Federal Register.
On Thursday, March 24, 2011, the EEOC released an advance copy of the Final Regulations along with two Question-and-Answer documents about the Final Regulations to aid the public and employers – including small business – in understanding the law and new regulations. The Final Regulations, accompanying Question and Answer documents and a fact sheet are available on the EEOC website here .
The changes contained in the updated Final Regulations update the EEOC’s disability regulations in response to amendments made to the ADA by Congress as part of the ADAAA. Like the ADAAA they implement, the Final regulations are designed to simplify the determination of who has a “disability” and make it easier for people to establish that they are protected by the Americans with Disabilities Act (ADA).
The Final Regulations and the ADAAA amendments they implement make it likely that businesses generally will face more disability claims from a broader range of employees and will possess fewer legal shields to defend themselves against these claims. Since these changes make it easier for certain employees to qualify as disabled under the ADA, businesses should act strategically to mitigate their ADA exposures in response to the Final Regulations. Learn more about the Final Regulations and get suggestions for risk management of expanding disabilities discrimination exposures here.
For Help With Disability Discrimination Risk Management or Other Needs
If you need assistance in auditing or assessing, updating or defending your disability management or with other labor and employment, employee benefit, compensation or internal controls practices, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469)767-8872.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 23 years of work helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work helping employers implement, audit, manage and defend wage and hour and other workforce and internal controls policies, procedures and actions. The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer works, publishes and speaks extensively on wage and hour, worker classification and other human resources and workforce, employee benefits, compensation, internal controls and related matters. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here .
©2011 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on EEOC Finalizes Updates To Disability Regulations In Response to ADA Amendments Act |
Absenteeism, ADA, Affirmative Action, Corporate Compliance, Disability, Disability, Disability Plans, Discrimination, Drug & Alcohol, EEOC, Employee Benefits, Employers, GINA, Government Contractors, Health Plans, Human Resources, Insurance, Internal Controls, Internal Investigations, Leave, Military Leave, Non-Compete, Rehabilitation Act, Retaliation, Union | Tagged: ADA, ADAAA, Americans With Disabiltiies Act, Disability Discrimination, Employer, employment discrimination, HR, Human Resources |
Permalink
Posted by Cynthia Marcotte Stamer
November 9, 2010
The U.S. Equal Employment Opportunity Commission (EEOC) today issued final regulations (“Final Regulations”) implementing the employment provisions (Title II) of the Genetic Information Nondiscrimination Act of 2008 (GINA). Employers, employment agencies, labor organizations, joint labor-management committees, and others impacted by GINA should carefully review and update their hiring and background check, sick and family leave, disability accommodation, and other existing policies and practices to comply with the updated guidance provided by the Final Regulations to avoid liability under new GINA’s rules governing genetic information collection, use, protection and disclosure
Effective since November 21, 2009, Title II of GINA prohibits employers of 15 or more employees from discriminating in employment based on genetic information and restricts the acquisition and disclosure of genetic information by covered employers and certain other parties.
Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Under GINA, employees and individuals can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws.
Meanwhile, Title I of GINA prohibits group health plans and health insurers from discriminating in eligibility or premium based on genetic information and requires these plans and insurers to protect the privacy of genetic information (Title I) for plan years beginning after May 20, 2009.
When assessing potential GINA risks and exposures, employers and others covered by its provisions must exercise care not to overlook or underestimate the genetic information collected or possessed by their organizations and the risks attendant to collecting or using this information. Many employers will be surprised by the breadth of the depth of “genetic information.” Because of GINA’s broad definition of “genetic information,” its provisions create potential liability concerns for a surprisingly wide range of employment and health plan practices.
The Final Regulations published today implement the employment discrimination rules of GINA Title II. The EEOC previously published proposed regulations interpreting Title II of GINA in March, 2009. Concurrent with its release of the Final Regulations, the Commission also issued two question-and-answer documents on the final GINA regulations. For links to today’s guidance and more details, see here.
Failing to properly address GINA compliance could expose employers to substantial risk. Violation of the employment provisions of Title II subjects an employer to potentially significant civil judgments like those that generally are available for race, sex, and other federal employment discrimination claims covered by the Civil Rights Act. Accordingly, employers and others who have not already done so should act quickly to review and update their policies and procedures to manage their new compliance and liability exposures under GINA. Employers and others covered by GINA also should assess their leave and other records and practices for data that could be considered genetic information and take appropriate steps to safeguard this information to comply with the confidentiality, nondiscrimination and anti-retaliation rules of GINA, the Americans with Disabilities Act and other applicable laws.
For More Information Or Assistance
If you need assistance evaluating or defending existing or proposed practices under GINA or with other workforce, employee benefit, compensation, internal controls or risk management practices, please contact the author of this update, Board Certified Labor & Employment attorney Cynthia Marcotte Stamer at (469) 767-8872 or via e-mail here.
About Ms. Stamer
Board Certified in Labor and Employment Law by the Texas Board of Legal Specialization, Chair of the American Bar Association (ABA) RPTE Employee Benefit & Other Compensation Group, a Council Member of the ABA Joint Committee on Employee Benefits, Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, management attorney and consultant Cynthia Marcotte Stamer has more than 23 years experience advising and representing employers, health and other employee benefit plans, their sponsors, fiduciaries and plan administrators, consultants, vendors, outsourcers, insurers, governments and others about employment, employee benefit, compensation, and a wide range of other performance, legal and operational risk management practices and concerns. As a part of this work, Ms. Stamer has worked extensively with client to manage risks and defend practices under GINA, the ADA and a wide range of employment discrimination, privacy and other laws. A prolific author and popular speaker, Ms. Stamer also publishes, conducts client and other training, speaks and consults extensively on GINA and other employment and employee benefit risk management practices and concerns for the ABA, World At Work, SHRM, American Health Lawyers Association, Institute of Internal Auditors, Society for Professional Benefits Administrators, HCCA, Southwest Benefits Association and many other organizations. Her insights on these and related topics have appeared in Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, Managed Healthcare, Health Leaders, various ABA publications and a many other national and local publications. To learn more about Ms. Stamer, her experience, involvements, programs and publications, see here or contact Ms. Stamer.
Other Resources & Developments
If you found this information of interest, you also may be interested in reviewing other recent Solutions Law Press updates including:
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available for review here. If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. For important information concerning this communication click here.
If you or someone else you know would like to receive future updates and notices about upcoming programs and events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. To unsubscribe, send an e-mail with “Unsubscribe” in the subject here. For important information concerning this communication click here.
©2010 Cynthia Marcotte Stamer PC. Reprint Permission Granted To Solutions Law Press. All other rights reserved.
Comments Off on Update Employment Practices To Manage Genetic Info Discrimination Risks Under New EEOC Final GINA Regulations |
Disability, Discrimination, EEOC, Employee Benefits, Employers, GINA, Human Resources, Privacy, Risk Management, Union | Tagged: ADA, EEOC, Emloyment Discrimination, Employment, GINA, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
August 5, 2010
Register Now For 8/24 2010 Health Plan Update Briefing
Employer and other group health plan sponsors and insurers, fiduciaries and administrators of group health must update their health plans and practices to comply with new federal rules imposed by the Affordable Care Act and a host of other evolving federal health plan rules. In the meantime, health plan sponsors, fiduciaries, insurers and administrators looking to catch up on the most significant new requirements for employer and union sponsored health plans for the upcoming year also should consider registering to participate in the Solutions Law Press Health Plan Update Briefing scheduled for August 24, 2010.
October 13 NBI Teleconference Focuses On Eligibility Requirements
Catch up on the evolving federal health plan eligibility rules that employer and union sponsored group health plans must meet by listening in as attorney Cynthia Marcotte Stamer speaks about “Health Plan Eligibility Update”” on a live teleconference to be hosted by National Business Institutes on Wednesday, October 13, 2010 from 1:00 p.m.- 2:30 Central Time. To register or for additional information on the October 13 NBI Teleconference , visit http://www.nbi-sems.com.
During the October 13, 2010 Health Plan Eligibility Teleconference, Ms. Stamer will share:
ü Core Requirements Of Federal Group Health Plan Eligibility Rules Including Evolving Requirements of:
- The Affordable Care Act
- COBRA
- HIPAA
- GINA
- Family Leave
- Military Leave
- Michelle’s Law & Other Dependent Coverage
- Medicare Secondary Payer
ü Implications On Cafeteria Plan & Other Common Enrollment Strategies
ü Tips to Keep Health Plans Complaint
August 24 SLP Internet Briefing Overviews Latest Core Federal Rules For Group Health Plans Generally
Solutions Law Press invites you to catch up on the latest guidance about the new group health plan mandates imposed under the Patient Protection and Affordable Care Act (Affordable Care Act) and other federal health plan regulations by participating in a live “2010 Health Plan Update” internet[i] broadcast briefing on Tuesday, August 24 2010. The briefing will be conducted via live video broadcast from 11:00 A.M.-1:30 P.M. Central Time. The August 24, 2010 “2010 Health Plan Update” briefing will cover the latest guidance on Affordable Care Act and other federal health plan regulatory changes impacting employment-based group health plans and their sponsors for plan years beginning between September 23, 2010 and September 22, 2011 and other key information to help employers, group health plans, insurers, plan administrators, fiduciaries, broker and others working with these plans to understand and respond to these new requirements. Register/Get Details Here!
About The Presenter
Both programs will be conducted by attorney Cynthia Marcotte Stamer. With more than 23 years of experience advising employers, group health plans, plan fiduciaries, plan administrators and vendors, insurers and others about health plan and managed care matters, Ms. Stamer is nationally known for her work, publications and presentations on health plan and other employee benefit, health care and insurance matters.
Current Chair of the American Bar Association (ABA) RPTE Employee Benefit & Other Compensation Committee, a Council Member of the ABA Joint Committee on Employee Benefits and Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer continuously advises employers, health plans, plan sponsors, fiduciaries, plan administrators, plan vendors, insurers and others about health program related legal, operational, documentation, public policy, enforcement, privacy, technology, litigation and risk management and other concerns. Ms. Stamer also publishes and speaks extensively on these and other health and managed care program concerns and practices. Her insights on these and related topics have appeared in Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, Managed Healthcare, Health Leaders, various ABA publications and a many other national and local publications. To contact Ms. Stamer or for additional information about Ms. Stamer, her experience, involvements, programs or publications, contact Ms. Stamer at (469) 767-8872 or via e-mail here, or see here.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available for review here. If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. For important information concerning this communication click here.
If you found this of interest, you also may be interested in the following recent Solutions Law Press publications by Ms. Stamer:
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Stamer To Conduct“Health Plan Eligibility Update” Teleconference For NBI October 13, 2010 |
ADA, CHIP, COBRA, Employee Benefits, Employers, ERISA, family leave, Fiduciary Responsibility, FMLA, GINA, Health Plans, HIPAA, Human Resources, Insurance, Leave, medical leave, Medicare Part D, Mental Health, Mental Health Parity, Patient Protection and Affordable Care Act | Tagged: Affordable Care Act, Emploeyrs, GINA, Group Health plans, Health Plans, HIPAA, Insurers |
Permalink
Posted by Cynthia Marcotte Stamer
August 1, 2010
Register Now For 8/24 Health Plan Update Briefing
Group health plans and insurers risk are prohibited from dumping or engaging in other actions designed to drive individuals with pre-existing high risk conditions to enroll in coverage under high risk pool plans established under the “Pre-Existing Condition Insurance Plan” (PCIP) program established by the Patient Protection and Affordable Care Act of 2010 (Affordable Care Act) in lieu of maintaining existing private coverage.
Section 1101 of the Affordable Care Act requires HHS to set up the PCIP program to ensure that a temporary high risk health insurance pool program exists to provide affordable health insurance coverage to uninsured individuals with pre-existing conditions until January 1, 2014, when Exchanges established under sections 1311 and 1321 of the Affordable Care Act take effect.
Interim final rules implementing the PCIP program (Regulations) issued by the Department of Human Services on Friday, July 30, 2010 prohibit group health plans and insurers from dumping individuals with high risk conditions from coverage. The Regulations also identify the individuals that will qualify for enrollment in PCIP plans and detail the rules governing the establishment, implementation and administration of the PCIP program.
Dumping High Risk Patients Prohibited
In addition to already-existing liability for any violation of existing prohibitions against discrimination based on health history under the Health Insurance Portability & Accountability Act, the Genetic Information Nondiscrimination Act, and the Affordable Care Act, the Regulations provide that a health insurance issuer or group health plan found to have illegally discouraged an individual from remaining enrolled in its coverage or engaging in other actions considered “dumping” based on the individual’s health status will be responsible for any medical expenses incurred by the PCIP to provide coverage for a dumped individual who subsequently enrolls in the PCIP plan. Additionally, HHS also may refer the insurer or the plan to Federal and State authorities for other enforcement actions that may be warranted based on the behavior at issue. In light of these exposures, group health plans and insurers should review and tighten their eligibility terms, processes and procedures to avoid prohibited conduct. In this respect, plans and insurer should pay particular attention to managing the conduct of individuals involved in communicating with members or prospective members. Insurers and plans should adopt policies clearly prohibiting eligibility discrimination in violation of these and other rules and back up these rules by clear operating policies and training that makes clear to individuals involved in enrollment and other enrollment activities what conduct is prohibited.
More OnThe PCIP Program & Regulations
The Regulations provide an individual will be eligible to enroll in a PCIP if he or she:
- Is a citizen or national of the United States or lawfully present in the United States;
- Has not been covered under creditable coverage for a continuous 6-month period of time prior to the date on which such individual is applying for PCIP;
- Has a pre-existing condition within the meaning of the Affordable Care Act;
- Is a current resident of one of the 50 States or the District of Columbia which constitutes or is within the service area of the PCIP; and
- Meets other criteria established by the PCIP with HHS approval.
- PCIP Plans will be required to cover eligible individuals without any pre-existing condition limitation or waiting period.
The Regulations outline the process that a State or nonprofit private entity to pursue and enter into a contract with HHS to set up and run a PCIP program. The PCIP program generally anticipates that each State will contract with HHS to maintain a qualifying PCIP program directly or by subcontracting with another party. If a State elects not to or fails to maintain a PCIP program, however, the Regulation states HHS will contract with a nonprofit private entity to offer a PCIP program in that State.
PCIP program operates must have enrollment and disenrollment rules and processes that meet the applicable standards in the Regulations. The Regulations dictate that as part of this process, a PCIP verify that an individual is a United States citizen or national or lawfully present in the United States in accordance with the Regulations. The Regulations also allow PCIPS to employ certain strategies to manage enrollment over the course of the program that may include enrollment capacity limits, phased-in (delayed) enrollment, and other measures, as defined by the PCIP and approved by HHS to manage the PCIP program’s compliance with funding and other allowable requirements.
The Regulations specify that each benefit plan offered by a PCIP cover at least the following categories and the items and services:
- Hospital inpatient services
- Hospital outpatient services
- Mental health and substance abuse services
- Professional services for the diagnosis or treatment of injury, illness, or condition
- Non-custodial skilled nursing services
- Home health services
- Durable medical equipment and supplies
- Diagnostic x-rays and laboratory tests
- Physical therapy services (occupational therapy, physical therapy, speech therapy)
- Hospice
- Emergency services and ambulance services
- Prescription drugs
- Preventive care
- Maternity care
The Regulations also prohibit PCIP Plans from offering certain benefits. Benefit plans offered by a PCIP cannot cover the following services:
- Cosmetic surgery or other treatment for cosmetic purposes except to restore bodily function or correct deformity resulting from disease.
- Custodial care except for hospice care associated with the palliation of terminal illness.
- In vitro fertilization, artificial insemination or any other artificial means used to cause pregnancy.
- Abortion services except when the life of the woman would be endangered or when the pregnancy is the result of an act of rape or incest.
- Experimental care except as part of an FDA-approved clinical trial.
The Regulations regulate the premiums and cost sharing that PCIP programs can use. The Regulations limit the premium a PCIP may charge to 100 percent of the premium for the applicable standard risk rate that would apply to the coverage offered in the State determined in accordance with the Regulations using HHS-approved reasonable actuarial techniques. Premiums charged to enrollees in the PCIP may vary on the basis of age by a factor not greater than 4 to 1. Also, the PCIP program’s average share of the total allowed costs of the PCIP benefits must be at least 65 percent of such costs. Furthermore, the out-of-pocket limit of coverage for cost-sharing for covered services under the PCIP cannot exceed the Internal Revenue Code § 223(c)(2) limit. If the plan uses a network of providers, this limit may be applied only for in-network providers, consistent with the terms of PCIP benefit package.
The Regulations allow a PCIP program to require that covered persons use network providers for non-emergency services if that the PCIP has sufficient providers to ensure that all covered services are reasonably available and accessible to its enrollees. Out-of-network coverage for emergency services will be required under certain conditions. The Regulations also will require PCIPst o process and administer claims and appeals in compliance with the Regulations.
The Regulations also require PCIPs to develop and apply operating procedures to prevent, detect, report to HHS and law enforcement and recover (when applicable or allowable) incidences of waste, fraud, and abuse and to cooperate with Federal law enforcement and oversight authorities in cases involving waste, fraud and abuse.
Register For 8/24 Internet Briefing To Learn If Your Plan Will Be Grandfathered Plan & What Health Plan Updates Your Plan Will Require To Meet 2010/2011 Affordable Care Act & Other Federal Health Plan Compliance Deadlines
Solutions Law Press invites you to catch up on the latest guidance about the new group health plan mandates imposed under the Patient Protection and Affordable Care Act (Affordable Care Act) and other federal health plan regulations by participating in a live “2010 Health Plan Update” internet[*] broadcast briefing on Tuesday, August 24 2010. The briefing will be conducted via live video broadcast from 11:00 A.M.-1:30 P.M. Central Time. Register & Get More Details Here.
For Assistance or More Information
If your organization needs assistance updating your heath care program documentation, policies or procedures in response to these or other requirements or with other employee benefit, insurance or human resources matters, please contact the author of this update, Board Certified Labor & Employment attorney Cynthia Marcotte Stamer at (469) 767-8872 or via e-mail here.
Current Chair of the American Bar Association (ABA) RPTE Employee Benefit & Other Compensation Group, a Council Member of the ABA Joint Committee on Employee Benefits and Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer continuously advises employers, health and other employee benefit plans, plan sponsors, fiduciaries, plan administrators, plan vendors, insurers and others about health program related legal, operational, documentation, public policy, enforcement, privacy, technology, litigation and risk management and other concerns. Ms. Stamer also publishes, conducts client and other training, speaks and consults extensively on these and other health and managed care program concerns and practices. She regularly speaks and conducts training for the ABA, American Health Lawyers Association, Institute of Internal Auditors, Society for Professional Benefits Administrators, Southwest Benefits Association and many other organizations. Her insights on these and related topics have appeared in Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, Managed Healthcare, Health Leaders, various ABA publications and a many other national and local publications. To contact Ms. Stamer or for additional information about Ms. Stamer, her experience, involvements, programs or Publishers of her many highly regarded writings on health industry and human resources matters include the Bureau of National Affairs, Aspen Publishers, ABA, AHLA, Aspen Publishers, Schneider Publications, Spencer Publications, World At Work, SHRM, HCCA, State Bar of Texas, Business Insurance, James Publishing and many others. You can review other highlights of Ms. Stamer’s experience here.
If you need help with human resources or other management, concerns, wish to ask about compliance, risk management or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer here or (469)767-8872.
Other Resources
If you found this information of interest, you also may be interested in reviewing other recent Solutions Law Press updates including:
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available for review here. If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. For important information concerning this communication click here.
©2010 Solutions Law Press. All rights reserved.
Comments Off on New Affordable Care Act Mandated High Risk Pre-Existing Condition Insurance Pool Program Regulations Prohibit Plan Dumping of High Risk Members, Set Other Rules |
Affordable Care Act, Corporate Compliance, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, Human Resources, Insurance |
Permalink
Posted by Cynthia Marcotte Stamer
July 30, 2010
Learn If Your Plan Will Be Grandfathered Plan & What You Must Do Now To Meet Key 2010/2011 Affordable Care Act & Other Federal Health Plan Compliance Deadlines
A Solutions Law Press Live Internet Broadcast Briefing
August 24, 2010
10:00 A.M.-12:30 P.M. Eastern
11:00 A.M.- 1:30 P.M. Central
9:00 A.M-11:30 A.M. Pacific
Solutions Law Press invites you to catch up on the latest guidance about the new group health plan mandates imposed under the Patient Protection and Affordable Care Act (Affordable Care Act) and other federal health plan regulations by participating in a live “2010 Health Plan Update” internet[*] broadcast briefing on Tuesday, August 24 2010. The briefing will be conducted via live video broadcast from 11:00 A.M.-1:30 P.M. Central Time. Register here for a registration fee of $150.00[†] per participant.
Affordable Care Act Requires Prompt Action By Group Health Plans, Sponsors, Fiduciaries & Administrators
The Affordable Care Act and other impending federal health plan changes will require employment-based group health plans, their employer and other plan sponsors, plan fiduciaries, plan administrators and other service providers and insurers to make quick decisions and to act quickly to meet impending federal compliance deadlines while preserving flexibility. All employer and other group health plan sponsors, fiduciaries, insurers and administrators must act quickly to update their health plan documents, communications, insurance and vendor agreements and other practices to comply with new federal requirements that become effective under the Affordable Care Act on the first day of the plan year beginning after September 22, 2010 and various other changes in federal health plan rules effective or scheduled to take effect during 2010 or 2011 plan years. Many plan sponsors also may need to act quickly to cancel or revise plan design or vendor changes planned or already implemented since March 23, 2010 to position their health plan to qualify for grandfather status. Quick action also may be needed to claim small employer tax credits, retiree medical subsidies or other benefits.
Register Now To Get Key Information In August 24 Internet Briefing
The August 24, 2010 “2010 Health Plan Update” briefing will cover the latest guidance on Affordable Care Act and other federal health plan regulatory changes impacting employment-based group health plans and their sponsors for plan years beginning between September 23, 2010 and September 22, 2011 and other key information to help employers, group health plans, insurers, plan administrators, fiduciaries, broker and others working with these plans to understand and respond to these new requirements including:
- How to qualify your health plan as a grandfathered plan under Affordable Care act
- How to decide if maintaining grandfathered plan status is worthwhile
- Claims & appeals requirements for grandfathered & non-grandfathered plans
- Preventive care coverage mandates & wellness program requirements & rules under Affordable Care Act & other federal regulations
- Updated dependent child eligibility, pre-existing condition & other requirements for grandfathered & non-grandfathered plans
- Special enrollment, preexisting condition & other eligibility mandates for grandfathered & non-grandfathered plans under new Affordable Care Act, new FMLA, COBRA, Michelle’s Law, HIPAA & other federal regulations
- Mental health & substance abuse, provider choice & other benefit mandates under Affordable Care Act, Mental Health Parity & other federal rules
- Update on other recent & pending Affordable Care Act group health plan rule guidance
- Tips to review & update your plans, vendor agreements & processes to meet Affordable Care Act & other federal group health plan dictates
- Expected future Affordable Care Act & other federal rule changes & tips for preparing
- Practical strategies for responding to new requirements & changing rules
- Participant questions
About The Presenter
The program will be conducted by attorney Cynthia Marcotte Stamer. With more than 23 years of experience advising employers, group health plans, plan fiduciaries, plan administrators and vendors, insurers and others about health plan and managed care matters, Ms. Stamer is nationally known for her work, publications and presentations on health plan and other employee benefit, health care and insurance matters.
Current Chair of the American Bar Association (ABA) RPTE Employee Benefit & Other Compensation Committee, a Council Member of the ABA Joint Committee on Employee Benefits and Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer continuously advises employers, health plans, plan sponsors, fiduciaries, plan administrators, plan vendors, insurers and others about health program related legal, operational, documentation, public policy, enforcement, privacy, technology, litigation and risk management and other concerns. Ms. Stamer also publishes and speaks extensively on these and other health and managed care program concerns and practices. Her insights on these and related topics have appeared in Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, Managed Healthcare, Health Leaders, various ABA publications and a many other national and local publications. To contact Ms. Stamer or for additional information about Ms. Stamer, her experience, involvements, programs or publications, contact Ms. Stamer at (469) 767-8872 or via e-mail here, or see here.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available for review here. If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word ©2010 Solutions Law Press. All rights reserved.
[*] A limited number of participants on a space available basis will have the opportunity to participate in the briefing as a member of the live studio audio audience in Plano, Texas. Interested persons should e-mail support@solutionslawyer.net.
[†] Discounts available for groups registering three or more participants. Sponsorship opportunities also available. For information, E-mail support@solutionslawyer.net.
Comments Off on Register Now For 8/24 2010 Health Plan Update Briefing |
ADA, Affordable Care Act, COBRA, Disease Management, Employee Benefits, Employers, ERISA, Excise Tax, family leave, Fiduciary Responsibility, FMLA, GINA, HIPAA, Human Resources, Insurance, Internal Controls, Leave, medical leave, Mental Health, Patient Protection and Affordable Care Act, Payroll Tax, Privacy, Protected Health Information, Risk Management, Tax, Wellness | Tagged: Affordable Care Act, COBRA, FLSA, GINA, grandfathered plan, Health Plan, HIPAA, Mental Health Parity, Michelle's Law |
Permalink
Posted by Cynthia Marcotte Stamer
July 23, 2010
August 24, 2010
10:00 A.M.-12:30 P.M. Eastern ¨ 11:00 A.M.- 1:30 P.M. Central ¨ 9:00 A.M-11:30 A.M. Pacific
Solutions Law Press invites you to catch up on the latest guidance about the new group health plan mandates imposed under the Patient Protection and Affordable Care Act (Affordable Care Act) and other federal health plan regulations by participating in a live “2010 Health Plan Update” internet[*] broadcast briefing on Tuesday, August 24 2010. The briefing will be conducted via live video broadcast from 11:00 A.M.-1:30 P.M. Central Time. Register here for a registration fee of $150.00[†] per participant.
Affordable Care Act Requires Prompt Action By Group Health Plans, Sponsors, Fiduciaries & Administrators
The Affordable Care Act and other impending federal health plan changes will require employment-based group health plans, their employer and other plan sponsors, plan fiduciaries, plan administrators and other service providers and insurers to make quick decisions and to act quickly to meet impending federal compliance deadlines while preserving flexibility. All employer and other group health plan sponsors, fiduciaries, insurers and administrators must act quickly to update their health plan documents, communications, insurance and vendor agreements and other practices to comply with new federal requirements that become effective under the Affordable Care Act on the first day of the plan year beginning after September 22, 2010 and various other changes in federal health plan rules effective or scheduled to take effect during 2010 or 2011 plan years. Many plan sponsors also may need to act quickly to cancel or revise plan design or vendor changes planned or already implemented since March 23, 2010 to position their health plan to qualify for grandfather status. Quick action also may be needed to claim small employer tax credits, retiree medical subsidies or other benefits.
August 24 Live Briefing Provides Key Information By Internet Broadcast
The August 24, 2010 “2010 Health Plan Update” briefing will cover the latest guidance on Affordable Care Act and other federal health plan regulatory changes impacting employment-based group health plans and their sponsors for plan years beginning between September 23, 2010 and September 22, 2011 and other key information to help employers, group health plans, insurers, plan administrators, fiduciaries, broker and others working with these plans to understand and respond to these new requirements. The briefing will include:
- How to qualify your health plan as a grandfathered plan under Affordable Care Act
- How to decide if maintaining grandfathered plan status is worthwhile
- Claims & appeals requirements for grandfathered & non-grandfathered plans
- Preventive care coverage mandates & wellness program requirements & rules under Affordable Care Act & other federal regulations
- Updated dependent child eligibility, pre-existing condition & other requirements for grandfathered & non-grandfathered plans
- Special enrollment, preexisting condition & other eligibility mandates for grandfathered & non-grandfathered plans under new Affordable Care Act, new FMLA, COBRA, Michelle’s Law, HIPAA & other federal regulations
- Mental health & substance abuse, provider choice & other benefit mandates under Affordable Care Act, Mental Health Parity & other federal rules
- Update on other recent & pending Affordable Care Act group health plan rule guidance
- Tips to review & update your plans, vendor agreements & processes to meet Affordable Care Act & other federal group health plan dictates
- Expected future Affordable Care Act & other federal rule changes & tips for preparing
- Practical strategies for responding to new requirements & changing rules
- Participant questions
About The Presenter
The program will be conducted by attorney Cynthia Marcotte Stamer. With more than 23 years of experience advising employers, group health plans, plan fiduciaries, plan administrators and vendors, insurers and others about health plan and managed care matters, Ms. Stamer is nationally known for her work, publications and presentations on health plan and other employee benefit, health care and insurance matters.
Current Chair of the American Bar Association (ABA) RPTE Employee Benefit & Other Compensation Committee, a Council Member of the ABA Joint Committee on Employee Benefits and Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer continuously advises employers, health plans, plan sponsors, fiduciaries, plan administrators, plan vendors, insurers and others about health program related legal, operational, documentation, public policy, enforcement, privacy, technology, litigation and risk management and other concerns. Ms. Stamer also publishes and speaks extensively on these and other health and managed care program concerns and practices. Her insights on these and related topics have appeared in Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, Managed Healthcare, Health Leaders, various ABA publications and a many other national and local publications. To contact Ms. Stamer or for additional information about Ms. Stamer, her experience, involvements, programs or publications, contact Ms. Stamer at (469) 767-8872 or via e-mail here, or see here.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available for review here. If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word ©2010 Solutions Law Press. All rights reserved.
[*] A limited number of participants on a space available basis will have the opportunity to participate in the briefing as a member of the live studio audio audience in Plano, Texas. Interested persons should e-mail support@solutionslawyer.net.
[†] Discounts available for groups registering three or more participants. E-mail support@solutionslawyer.net.
Comments Off on 2010 Health Plan Update: Learn What You Must Do Now To Meet Key 2010/2011 Affordable Care Act & Other Federal Health Plan Deadlines |
ADA, Affordable Care Act, Disease Management, EEOC, Employee Benefits, Employers, ERISA, Excise Tax, family leave, Fiduciary Responsibility, FMLA, GINA, H.R. 4872, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, Leave, medical leave, Medicare Part D, Mental Health, Mental Health Parity, Military Leave, Patient Protection and Affordable Care Act, Payroll Tax, Prescription Drugs, Public Policy, Reporting & Disclosure, Union, USERRA, Wellness, Wellness Programs | Tagged: Affordable Care Act, broker, Employers, grandfathered plan, Group Health plans, health coverage, Health Plans, Insurer, Mental Health Parity, Patient Protection and Affordable Care Act, plan sponsor, pre-existing conditions, preventive care |
Permalink
Posted by Cynthia Marcotte Stamer
May 15, 2010
By Cynthia Marcotte Stamer
New analysis released Tuesday, May 11 by the non-partisan Congressional Budget Office shows H.R. 3590, the Patient Protection and Affordable Care Act, Public Law 111-148 (Health Care Reform Law) passed in March will cost $115 Billion more than originally estimated in the CBO’s March 15, 2010 discretionary spending analysis. News of the cost estimate increase comes as U.S. employer and other health plan sponsors, insurers and others are bracing for the first wave of new federal health plan mandates enacted as part of the Health Care Reform Law to take effect in September and a host of other federal mandates previously enacted that take effect in the 2009 and 2010 plan years.
Projected Cost of Health Care Reform Increased
According to CBO, additional information about the potential effects of the Health Care Reform Law on spending funded through the annual appropriation process (discretionary spending). By their nature all such potential effects on discretionary spending are subject to future appropriation actions, which could result in greater or smaller costs than the sums authorized by the legislation. While still limited in certain respects, the updated CBO analysis provides information on the major components of such costs in three general categories:
- The costs that will be incurred by federal agencies to implement the new policies established by the Health Care Reform Law, such as administrative expenses for the Department of Health and Human Services and the Internal Revenue Service for carrying out key requirements of the legislation.
- Explicit authorizations for future appropriations for a variety of grant and other program spending for which the act identifies the specific funding levels it envisions for one or more years. (Such cases include provisions where a specified funding level is authorized for an initial year along with the authorization of such sums as may be necessary for continued funding in subsequent years.)
- Explicit authorizations for future appropriations for a variety of grant and other program spending for which no specific funding levels are identified in the legislation. That type of provision generally includes legislative language that authorizes the appropriation of “such sums as may be necessary,” often for a particular period of time.
According to the updated analysis, CBO estimates that total authorized costs in the first two categories probably exceed $115 billion over the 2010-2019 period. CBO still does not have an estimate of the potential costs of authorizations in the third category.
CBO previously issued an estimate of the Health Care Reform Law’s direct spending and revenue effects in combination with the Reconciliation Act of 2010 (Public Law 111-152), which amended it. (Direct spending effects are those that do not require subsequent appropriation action.) CBO estimated that those two laws, in combination, would produce a net reduction in federal deficits of $143 billion over the 2010-2019 period as a result of changes in direct spending and revenues.
Impending Federal Health Plan Mandate Changes Bring New Costs, Risks Now
CBO’s adjustment to its cost projections comes as U.S. employers and insurers already are bracing to cope with a host of new federally imposed health plan mandates and accompanying costs that already have or will in the next 12-months impact their existing health benefit programs. Examples of these new mandates include:
- COBRA Stimulus Bill Premium Subsidy and Other Mandates
- New FMLA and USERRA Coverage Continuation Mandates
- Dependent Care Coverage Extension Mandates For Students Requiring Medical Leave Effective
- Genetic and Other Disability Discrimination Mandates under GINA, ADA Amendments Act of 2008, HIPAA Portability and Other Federal Mandates
- Expanded Mental Health Parity Mandates
- HIPAA Data Breach and Other Protected Health Information Privacy and Data Security Mandates
- New IRS Excise Tax Self-Assessment & Reporting Mandates For Plans Violating COBRA, Mental Health Parity and Wide Range of Other Federal Mandates
- Changes To Retiree Medical Subsidy Rules
- Early Retiree Medical Reinsurance Program For Employers Providing Qualifying Retiree Coverage
- New Small Employer Tax Credit Rules
- Mandated extension of dependent coverage to age 26
- Prohibition of Pre-Existing Condition Limits on Dependent Coverage
- New restrictions on annual and lifetime benefit limitations
- Mandate to cover 100% of preventative care
- Prohibition against coverage rescissions
- Primary Care Physician choice mandates
- Restrictions on coverage limitations for emergency and obstetrical care
- Extension of Internal Revenue Code Section 105(h) nondiscrimination mandates to certain insured health plans
- Many others
Employer and other health plan sponsors, their insurers, administrators and others responsible for updating and administering group and other health plans must move immediately to meet these evolving mandates while bracing for anticipated increased costs and other obligations expected to result as the Health Care Reform Law takes effect over the next few years. Employers, administrators and insurers needing additional information about these changes can review the resources and training materials available here and/or contact the author of this update, attorney and consultant Cynthia Marcotte Stamer, for assistance at (469) 767-8872 or here
Responsible & Prompt Action Needed
Employer and other health plan sponsors, administrators, fiduciaries and insurers both should act quickly to update their programs, plan documents, communications and practices to comply with federal mandates that have and are scheduled to take effect and stay involved with regulators and Congress as the regulatory rules and processes to implement the Health Care Reform Law are developing. Ultimately, the cost and other implications of the Health Care Reform Law will depend largely upon how its provisions are construed and implemented by federal and state regulators, along with any subsequent adjustments, if any that Congress may elect to enact. With federal officials hard at work preparing implementing regulations and other guidance and procedures, health industry leaders and other concerned Americans should stay informed and continue to share their input on these critical issues as these decisions are shaped. Join the discussion by participating in the Coalition For Responsible Health Care Policy linked in group and/or its subgroup, Project COPE: Coalition for Patient Empowerment and/or register to receive updates Coalition for Responsible Heath Care Policy by RSS Feed.Coalition for Responsible Health Care PolicyCoalition for Responsible Health Care PolicyCoalition for Responsible Health Care Policy
The author of this update, Cynthia Marcotte Stamer, recently has conducted briefings on the implications of the Affordable Care Act and other regulatory changes impacting health plans and their employer and other sponsors, insurers, administrators and others for the Society of Professional Benefits Administrators, the Dallas Bar Association and others. Several other presentations and update are scheduled in the upcoming months. For information about these programs or to register to receive information about these programs, see here.
About Ms. Stamer
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 22 years of work helping businesses manage labor and employment, employee benefits, performance management and discipline, compliance and internal controls, risk management, and public policy matters including significant, cutting edge experience advising employer and other health plan sponsors, fiduciaries, insurers, administrators and others design, administer, and defend defensible, cost-effective health and other employee benefit programs.
The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, and the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications Ms. Stamer also is recognized for her publications, industry leadership, workshops and presentations on these and other health industry and human resources concerns. She regularly speaks and conducts training for the ABA, American Health Lawyers Association (AHLA), Health Care Compliance Association, Institute of Internal Auditors, Harris County Medical Society, the Medical Group Management Association, Society for Professional Benefits Administrators, Southwest Benefits Association, Harris County Medical Society, Medical Group Management Association, Society of Human Resources Management, and many other organizations. Publishers of her many highly regarded writings on health industry and human resources matters include the Bureau of National Affairs, Aspen Publishers, ABA, AHLA, Aspen Publishers, Schneider Publications, Spencer Publications, World At Work, SHRM, HCCA, State Bar of Texas, Business Insurance, James Publishing and many others. You can review other highlights of Ms. Stamer’s experience here. Her insights on these and other matters appear in Managed Care Executive, Modern Health Care, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, MDNews, Kentucky Physician, and many other national and local publications.
If you need help with human resources or other management, concerns, wish to ask about compliance, risk management or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer here or (469)767-8872.
Other Resources
If you found this information of interest, you also may be interested in reviewing other updates and publications by Ms. Stamer including:
- Join Project COPE: Help Develop Real Tools To Meaningfully Empower Patients & Improve Health Care Access, Affordability & Quality
- Unemployment, COBRA Premium Subsidy Temporarily Extended As Congress Mulls Passing Longer Relief
- Agencies Invite Public To Share Input About Insurer Obligation To Report About Health Premium Use Under Health Care Reform Law
- TSHHRAE Provides Health Industry HR & Other Managers Employment Law Update & Other Timely Management Training At April Barnstorm 2010: Creating Effective Leaders Programs
- New Study Shares Data On Migrant Health Care Challenges Along The Border
- Getting Your Health Care Reform Message Heard By Key Congressional Leaders
- Extension of Unemployment Benefits Signed Into Law & Immediately Effective As Filibuster Ends
- COBRA Premium Subsidy Requirements Expanded & Extended Under Newly Signed Unemployment Extension Legislation
- Employers Concerned About New Union Powers As NLRB Orders Union Elections In 31 California Health Care Facilities To Proceed
- Privacy Rule Changes & Posting of Breach Notices On OCR Website Signal New Enforcement Risks For Health Plans, Their Sponsors & Business Associates
- Stamer To Present “2010 Health Plan Checkup” At Annual DFW ISCEBS Employee Benefits Fundamentals Workshop
- SouthWest Benefits e-Connections Highlights Stamer Article About Importance For Health Plans, Their Sponsors & Business Associates To Update HIPAA Policies, Practices & Agreements
- Health Plan Liability Heats Up As Plans & Businesses Face New Obligations, Costs & Exposures under New HIPAA Privacy Rules Effective 2/17 & Other Expanding Federal Health Plan Mandates
- Employers, Group Health Plans Subject To New CHIP/Medicaid Notice, Coordination of Benefits & Special Enrollment Requirements
- Health Plans & Business Associates Face 2/17 Deadline To Update Policies, Contracts & Procedures For HIPAA Privacy Rule Changes
- St. Louis Employer’s OSHA Violations Trigger Contempt Order and Penalties
- Labor Department Final H-2A Certification Procedures Tighten Requirements For Employment Of Temporary Agricultural Employment Of Workers
- COBRA, HIPAA, GINA, Mental Health Parity or Other Group Health Plan Rule Violations Trigger New Excise Tax Self-Assessment & Reporting Obligations
- Inapplicability of HIPAA Privacy To Disability Insurer Not License To Impose Unreasonable Claims Requirements
- New Mental Health Parity Regulations Require Health Plan Review & Updates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to receive our Solutions Law Press distributions here. For important information about this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to here.
©2010 Solutions Law Press. All rights reserved.
Comments Off on CBO Raises Estimated Cost of Health Care Reforms As Employers, Health Plans Brace Costs Of Newly Effective & Impending Mandates |
Affordable Care Act, ARRA, CHIP, COBRA, COBRA Subsidy, Disease Management, Employee Benefits, Employers, Employment Tax, ERISA, Excise Tax, family leave, Fiduciary Responsibility, FMLA, GINA, H.R. 4872, Health Plans, HIPAA, Human Resources, Income Tax, Leave, medical leave, Medicare Part D, Mental Health, Mental Health Parity, Military Leave, Payroll Tax, Prescription Drugs, Privacy, Protected Health Information, Public Policy, Risk Management, Stimulus Bill, Tax, Uncategorized, Wellness | Tagged: Affordable Care Act, dependent coverage, Employer, Health Care Reform, Health Plans, Insurer, Mental Health Parity, preexisting condition |
Permalink
Posted by Cynthia Marcotte Stamer
March 22, 2010
Cynthia Marcotte Stamer will discuss “Health Care Reform: Implications for Employers, Health Plans and Employee Benefits Practitioners” at the May 5, 2010 meeting of Dallas Bar Association Employee Benefits/Executive Compensation Section to be held from 12:00 noon – 1:00 p.m. in the Haynes & Boone Ballroom of Dallas Bar Association Belo Mansion located at 2101 Ross Avenue in Dallas, Texas.
Narrowly passed by Congress in March after a year of contentious debate, the comprehensive health care reform legislation imposes a complex array of reforms impacting employment based health plans, employers, and the insurers and other vendors and administrators of these programs. Ms. Stamer will explore key elements of these reforms impacting employers and employment based health coverage and their implications for employers, employment based health plans, and employee benefits and other attorneys providing advice about these arrangements.
Chair of the American Bar Association RPTE Employee Benefits & Compensation Committee, an ABA Joint Committee on Employee Benefits Council member, Chair of the Curran Tomko Tarski Labor, Employment & Employee Benefits Practice and former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and the Dallas Bar Association Employee Benefits & Executive Compensation Section, Ms. Stamer is nationally recognized for more than 22 years of work with employer and other health plan sponsors, fiduciaries, administrative and other service providers, insurers, and other clients on health benefit program and product design, documentation, administration, compliance, risk management, and public policy matters. The publisher of Solutions Law Press, Ms. Stamer also publishes, conducts training and speaks extensively on these and related concerns for the ABA, the Bureau of National Affairs and many other organizations. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
If you need assistance with evaluating or responding to this new legislation or other employee benefits, employment, compensation or other management concerns, wish to inquire about compliance, risk management or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer at cstamer@cttlegal.com, 214.270.2402; or your other preferred Curran Tomko Tarski LLP attorney.
If you found this information of interest, you also may be interested in reviewing other updates and publications by Ms. Stamer including:
- House Could Vote On Obama Health Care Reform Sunday
- Stamer To Speak About TPA & Other Plan Services Agreement Contracting Strategies For Managing Risks & Improving Effectiveness At 2010 Great Lakes Benefits Conference
- Extension of Unemployment Benefits Signed Into Law & Immediately Effective As Filibuster Ends
- COBRA Premium Subsidy Requirements Expanded & Extended Under Newly Signed Unemployment Extension Legislation
- Employers Concerned About New Union Powers As NLRB Orders Union Elections In 31 California Health Care Facilities To Proceed
- Privacy Rule Changes & Posting of Breach Notices On OCR Website Signal New Enforcement Risks For Health Plans, Their Sponsors & Business Associates
- Stamer To Present “2010 Health Plan Checkup” At Annual DFW ISCEBS Employee Benefits Fundamentals Workshop
- SouthWest Benefits e-Connections Highlights Stamer Article About Importance For Health Plans, Their Sponsors & Business Associates To Update HIPAA Policies, Practices & Agreements
- Health Plan Liability Heats Up As Plans & Businesses Face New Obligations, Costs & Exposures under New HIPAA Privacy Rules Effective 2/17 & Other Expanding Federal Health Plan Mandates
- Employers, Group Health Plans Subject To New CHIP/Medicaid Notice, Coordination of Benefits & Special Enrollment Requirements
- Health Plans & Business Associates Face 2/17 Deadline To Update Policies, Contracts & Procedures For HIPAA Privacy Rule Changes
- St. Louis Employer’s OSHA Violations Trigger Contempt Order and Penalties
- Labor Department Final H-2A Certification Procedures Tighten Requirements For Employment Of Temporary Agricultural Employment Of Workers
- COBRA, HIPAA, GINA, Mental Health Parity or Other Group Health Plan Rule Violations Trigger New Excise Tax Self-Assessment & Reporting Obligations
- Inapplicability of HIPAA Privacy To Disability Insurer Not License To Impose Unreasonable Claims Requirements
- New Mental Health Parity Regulations Require Health Plan Review & Updates
You can review other recent human resources, employee benefits and internal controls publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here and learn more about other Curran Tomko Tarski LLP attorneys here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information to Cstamer@CTTLegal.com or registering to participate in the distribution of these and other updates on our Solutions Law Press distributions here. For important information concerning this communication click here.
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Stamer To Discuss “Health Care Reform’s Implications For Employers, Health Plans & Employee Benefits Practitioners” At May 5 Dallas Bar Association Meeting |
Corporate Compliance, Disease Management, Employers, Employment Tax, ERISA, Excise Tax, GINA, Health Plans, Human Resources, Income Tax, Insurance, Internal Controls, Payroll Tax, Risk Management, Tax | Tagged: COBRA, Corporate Compliance, Disability Discrimination, Disease Management, Employee Benefits, Employer, Employment, ERISA, GINA, Health Care Reform, Health Insurance, Health Plans, HIPAA, Human Resources, Insurance, Insurer, Managed Care, Medical Coverage, Risk Management, Wellness |
Permalink
Posted by Cynthia Marcotte Stamer
February 23, 2010
By Cynthia Marcotte Stamer
The Department of Health and Human Services Office of Civil Rights (OCR) has begun disclosing on its website the employer and other health plans, health care providers, health care clearinghouses and their business associates (Covered Entities) that report breaches of unsecured protected health information (UPIC) affecting more than 500 individuals as required by new rules enacted as part of the Health Information Technology for Economic and Clinical Health Act (HITECH Act). This posting of Covered Entities reporting breaches comes just days after these and other Covered Entities became subject on February 17, 2010 to a host of other tighter federal requirements for the use, access, protection and disclosure of protected health information under Privacy & Security Standards of the Health Insurance Portability & Accountability Act (HIPAA) also enacted as part of the HITECH Act. As failing to comply with the amended rules effective February 17, 2010 can trigger obligations under the Breach Regulations and other exposures, prompt action to manage risk under both the Breach Regulations and the revised HIPAA rules is critical to minimize Covered Entity and business associate exposures under both these rules. With criminal, administrative and civil prosecutions of such violations increasing and likely to expand, timely action to manage compliance and other risks is warranted. Health plans and their business associates also should prepare for increased awareness and oversight of the adequacy of their medical information safeguards as these disclosures and other enforcement actions heighten interest and awareness of employees and others in these rules.
Covered Entity Breach Notification Requirements
OCR posted the initial list of Covered Entities disclosing these breaches on its website for the first time yesterday (February 22, 2010) to comply with breach notification requirements imposed by Section 164.408 of the interim “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) published here.
The Breach Regulation requires Covered Entities subject to the Health Insurance Portability & Accountability Act (HIPAA) to notify affected individuals, OCR and certain other parties following a “breach” of “unsecured” protected health information occurring on or after September 23, 2009. The Breach Regulation implements new breach notification requirements added to HIPAA by Section 13402(e)(3) of the Health Information Technology for Economic and Clinical Health Act (HITECH Act). It and the posting of Covered Entities reporting breaches of protected health information are part of the ongoing implementation and enforcement of new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under provisions of the HITECH Act and expanded remedies for violations signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).
You can review the list of Covered Entities that have reported breaches on the OCR website here. Learn more about the Breach Regulation requirements here.
Broader & Stricter Medical Privacy Mandates Effective 2/17/210
Just last Wednesday (February 17, 2010) Covered Entities and their business associates also became subject to tighter federal requirements for the use, access, protection and disclosure of protected health information under amendments to HIPAA’s Privacy & Security Standards enacted by the HITECH Act. The changes that became effective on February 17, 2010 generally require that Covered Entities and their business associates make specific changes to update their written policies, operational procedures, privacy notices, business associate agreements, training, and other management procedures in several respects. For more details, see here.
While the HITECH Act gave Covered Entities and business associates a year to complete the necessary arrangements to comply with these HITECH Act changes, many Covered Entities and business associates have remain unnecessarily exposed under these new requirements by not completing or otherwise failing to adequately implement the necessary arrangements despite expanding liability exposures that can result from noncompliance. To mitigate these exposures, Covered Entities and their business associates should act quickly to review and update their policies, procedures, training, business associate and other services agreements, and other practices and procedures, as well as to implement the training, oversight, and other management necessary to comply with the HITECH Act changes and to mitigate other HIPAA risks.
Exposures Significant & Growing
Covered Entities and business associates failing to devote adequate attention and resources to managing HIPAA compliance and associated risks risk increasing peril. Aside from the potential implications that disclosures of violations may have on patients and others impacting their business, the legal risks of noncompliance for Covered Entities, business associates and others mishandling protected health information are real and growing.
Timely action to comply with the amended HIPAA requirements and Breach Regulations is important both to preserve critical trust in the business, to avoid triggering breach notifications that can undermine this trust and fuel legal complaints, and to avoid exposure to an expanding range of sanctions that can result when a violation occurs.
Amendments made under the HITECH Act have expanded the size and availability of remedies that can be imposed for HIPAA violations as well as the parties empowered to pursue these remedies. Wrongful use, access or disclosure of protected health information in violation of HIPAA subjects participating health plans, health care providers, health care clearinghouses, their business associates and other workforce members and others to civil penalties, criminal prosecution and, since February 17, 2009, civil lawsuits brought by state attorneys general on behalf of citizens of their states whose HIPAA rights were violated. Since September 23, 2009, health plans and other HIPAA Covered Entities as well as their business associates also became obligated to provide breach notification under new mandates imposed by the HITECH Act. Coupled with increased enforcement emphasis by regulators, these expansions to HIPAA’s remedy provisions increase the risk that Covered Entities or business associates violating HIPAA face investigation and sanction. Furthermore, the wrongful use, access or disclosure of protected health information or other confidential information also increasingly is the basis of civil or criminal actions brought under a variety of other federal and state laws.
Expanded HIPAA & Other Federal Prosecutions & Remedies
The expanded requirements imposed under the Breach Regulation and the other HITECH Act changes that took effect on February 17, 2010 follow the implementation changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, when President Obama signed the HITECH Act into law. The HITECH Act amendments to HIPAA’s remedies significantly increase the risk that health plans and other Covered Entities and their business associates will face civil lawsuits, civil or criminal penalties or other consequences for violating HIPAA. Noncompliance with these and other HIPAA requirements subjects Covered Entities and business associates to civil penalties, criminal prosecution, civil damage awards under lawsuits brought by state attorneys general, and other legal remedies. In addition, timely update written policies, procedures, business associate agreements, training and documentation is imperative in order for Covered Entities and their business associates to fulfill their breach notification obligations under new rules enacted as part of the HITECH Act.
HITECH Amendments Expand Liability Exposures
The expanded risks stem in part from the HITECH Act’s amendments to HIPAA’s remedy provisions. Among other things, the HITECH Act amended HIPAA to:
- Allow a State Attorney General to sue health plans or other Covered Entities, business associates or both that harm state citizens by committing HIPAA violations after February 16, 2009;
- Expand the mandate by OCR to investigate violations and audit compliance with HIPAA;
- Require Office of Civil Rights to impose civil sanctions against Covered Entities and business associates involved in violations of HIPAA in accordance with tightened standards added to HIPAA by the HITECH Act;
- Revise the criminal sanctions that the Department of Justice can seek against Covered Entities, their business associates and others for violations of HIPAA; and
- Amend HIPAA to make clear that HIPAA’s criminal sanctions also can imposed on business associates, workforce members and other persons that improperly use, access and disclose protected health information in violation of HIPAA.
State Attorney General Lawsuit Exposures
Covered Entities and their business associates now also need to be concerned about the potential that a state Attorney General may bring civil suit to remedy damages caused to state citizens by a breach of HIPAA.
The HITECH Act empowers a state attorney general to sue Covered Entities or business associates engaging in HIPAA violations that harms citizens of the state for statutory damages equal to the sum of the number of violations multiplied by 100 up to a maximum of $25,000 per calendar year plus attorneys fees and costs
A HIPAA civil lawsuit filed on January 13, 2010 demonstrates the willingness of at least some states to exercise the new authority created by the HITECH Act on February 17, 2009 to sue Covered Entities and business associates that violate HIPAA for civil damages.
On January 13, 2010 Connecticut Attorney General Richard Blumenthal sued Health Net of Connecticut, Inc. (Health Net) for failing to secure private patient medical records and financial information involving 446,000 Connecticut enrollees and promptly notify consumers endangered by the security breach. The suit also names UnitedHealth Group Inc. and Oxford Health Plans LLC, who have acquired Health Net. The first attorney general enforcement action brought based on amendments made to HIPAA under the HITECH Act, Connecticut charges that Health Net violated HIPAA by failing to safeguard protected medical records and financial information on almost a half million Health Net enrollees in Connecticut then allowing this information to remain exposed for at least six months before notifying authorities and consumers.
Stepped Up Federal Enforcement
Even before the HITECH Act amendments, however, OCR and Department of Justice already were stepping up HIPAA investigation and enforcement. The Department of Justice has obtained a variety of criminal convictions against violators of HIPAA. See, e.g., 2 New HIPAA Criminal Actions Highlight Risks From Wrongful Use/Access of Health Information. Meanwhile, OCR also is emphasizing HIPAA enforcement. In February, 2009, for instance, OCR announced that CVS Pharmacies, Inc. would pay $2.25 million to resolve HIPAA charges. This announcement followed OCR’s announcement in July, 2008 that Providence Health Care would pay $100,000 to resolve HIPAA violation charges. OCR also has taken HIPAA enforcement actions against a broad range of other Covered Entities to redress HIPAA violations or other compliance concerns. To review examples of these other actions, see here. While not resulting in the significant payments involved in CVS or Providence, all Covered Entities involved in these and other enforcement actions or investigations have incurred significant legal and other defense costs, loss of community trust, or both.
In addition to these HIPAA-specific exposures, wrongful use, access or disclosure of medical information also can give rise to liability for health plans and other Covered Entities, business associates, employees and other members of their workforce and others improperly using, accessing or disclosing protected health information. Federal and state prosecutions may and increasingly do criminally prosecute individuals for improperly accessing or using medical or other personal information under a variety of other federal or state laws . See e.g., Cybercrime & Identity Theft: Health Information Security Beyond HIPAA; NY AG Cuomo Announcement of 1st Settlement For Violation of NY Security Breach Notification Law; Woman Who Revealed AIDs Info Gets A Year. Additionally, State courts also increasingly are permitting individuals harmed by HIPAA violations to use HIPAA as the foundation of state law duties used to maintain state negligence, invasion of privacy, retaliation or other claims for damages. Read more here.
State Civil Lawsuits
Along side these governmental actions, state courts also increasingly are willing to allow individual plaintiffs to rely on violations of HIPAA as the basis for bringing state privacy, retaliation or other actions. While prior to the recent HITECH Act amendments, federal courts had ruled that private plaintiffs could not sue under HIPAA for damages they incurred from a Covered Entity’s violation of HIPAA, state courts have allowed private plaintiffs to use the obligations imposed by HIPAA as the basis of a Covered Entity’s duty for purposes of certain state law lawsuits. In Sorensen v. Barbuto, 143 P.3d 295 (Utah Ct. App. 2006), for example, a Utah appeals court ruled a private plaintiff could use HIPAA standards to establish that a physician owed a duty of confidentiality to his patients for purposes of maintaining a state law damages claim. Similarly, the Court in Acosta v. Byrum, 638 S.E. 2d 246 (N.C. Ct. App. 2006) ruled that a plaintiff could use HIPAA to establish the “standard of care” in a negligence lawsuit.
Meanwhile, disgruntled employees or other business partners also increasingly raise alleged HIPAA misconduct as a basis of their legal complaints. For instance, private plaintiffs employed by Covered Entities also are increasingly pointing to HIPAA as the basis for their retaliation or wrongful discharge claims. See, e.g., Retaliation For Filing HIPAA Complaint Recognized As Basis For State Retaliatory Discharge Claim. Coupled with the HITECH Act changes, these and other enforcement actions signal growing potential hazards for Covered Entities and their business associates that fail to properly manage their HIPAA compliance obligations and risks.
Given these and other developments, Covered Entities and their business associates generally should resist the temptation to underestimate their potential HIPAA exposure for a variety of reasons. In fact, a number of factors demonstrate that the risks are significant and growing for Covered Entities, business associates and others that breach HIPAA’s mandates or otherwise inappropriately access protected health information.
Covered Entities & Business Associates Urged To Act Promptly To Manage Expanded HIPAA Risks & Obligations
As a consequence of these collective HITECH Act changes and growing HIPAA-related and other exposures, Covered Entities, their business associates and business associates generally will find it necessary or advisable among other things to:
- Conduct well-documented due diligence within the scope of attorney-client privilege on their own practices and procedures;
- Review the adequacy of the practices, policies and procedures of the Covered Entities, business associates, and others that may come into contact with protected health information;;
- Renegotiate their service provider agreements to detail the specific compliance obligations of each party relating to for auditing compliance, investigating potential breaches; providing required breach notifications; specify leadership and required cooperation in the event of a breach, charge, or other concern; indemnification and other liability allocations; and other related matters;
- Update policies, privacy and other notices, practices, procedures, training and other practices as needed to promote compliance and defensibility;
- Conduct well-documented training as necessary to ensure that business associates and other members of the Covered Entity’s workforce understand and are prepared to comply with the expanded requirements of HIPAA, can detect potential breaches or other compliance concerns, and understand and are prepared to follow appropriate procedures for reported suspected violations; and
- Pursue appropriate liability and other protection as appropriate to improve their ability to demonstrate both their commitment to compliance and their realistic efforts to ensure that these commitments are both appropriately documented on paper and operationalized in performance.
As part of these compliance and risk management efforts, most Covered Entities and their business associates will find it advisable to devote significant attention to the business associate relationship and its associated business associate agreements. Proper management of the expanded compliance obligations and liability exposures created by the HITECH Act generally will necessitate that Covered Entities and their business associates focus significant attention on the reworking of their operating and contractual relationships including the definition of detailed procedures for monitoring, reporting, investigating, and resolving potential breaches or other compliance concerns.
Even before the impending HIPAA changes scheduled to take effect on February 17, 2010, a strong need for more detailed contracting and planning of these relationships already existed. Since the enactment of HIPAA, the practice of many Covered Entities and their business associates of appending generic “business associate” representations onto existing services contracts without specific tailoring and planning has created undesirable ambiguities in these agreements. Further updating and tailoring of these and other provisions of services agreements has become even more important over the past year in light of the new breach notification mandates that took effect under the HITECH Act in September, 2009, changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, and the impending extension by the HITECH Act to business associates of direct liability for compliance with HIPAA scheduled to occur on February 17, 2010.
These and other stepped up oversight and enforcement activities make it critical that all Covered Entities and their business associates update their policies and practices, conduct training, tighten their compliance and data breach monitoring processes, strengthen their internal controls and documentation, and take other steps to prepare to defend their actions under the newly strengthened Privacy Rules. Covered Entities and their business associates more than ever must ensure their ability to demonstrate to federal regulators the effectiveness of their HIPAA compliance efforts by both adopting the written policies and procedures required by HIPAA and continuously monitoring and administering these safeguards. Covered Entities should consider reviewing the adequacy of their current HIPAA Privacy and Security compliance practices taking into consideration the Corrective Action Plan, published OCR noncompliance and enforcement statistics, their own and reports of other security and privacy breaches and near misses, and other developments to determine if additional steps are necessary or advisable.
For Assistance With Compliance Or Other Concerns
If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting the author of this article, Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer at (214) 270-2402 or via e-mail here.
Ms. Stamer is nationally known for her work, training and presentations, and publications on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts.
Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 22 years experience advising clients about health and other privacy and security matters. A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters. Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications. For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.
Other Recent Developments
If you found this information of interest, you also may be interested in information about upcoming programs to be presented by Ms. Stamer, acquiring a copy of a recording or materials from previous programs she has presented, or arranging training for your organization. For more information about these opportunities, contact Ms. Stamer directly.
If you found this information of interest, you also may be interested in reviewing some of the following recent Updates available online by clicking on the article title:
Curran Tomko Tarski LLP Can Help
If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.
A widely published author and speaker on HIPAA and other employee benefit and human resources related matters, Ms. Stamer has extensive experience advising health plans, their employer and other sponsors, health insurers, TPAs and other business associates and others about HIPAA and other health plan and privacy matters. Currently serving as both Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and as an ABA Joint Committee on Employee Benefits Council representative and Former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer has more than 23 years experience assisting employers, insurers, plan administrators and fiduciaries and others to design, implement, draft and administer health and other employee benefit plans and to defend audits, litigation or other disputes by private parties, the IRS, Department of Labor, Office of Civil Rights, Medicare, state insurance regulators and other federal and state regulators. A nationally recognized author and lecturer, Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates that may be of interest include:
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Privacy Rule Changes & Posting of Breach Notices On OCR Website Signal New Enforcement Risks For Health Plans, Their Sponsors & Business Associates |
Corporate Compliance, Data Security, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Privacy, Risk Management, Wellness Programs | Tagged: Corporate Compliance, Employee Benefits, Employer, ERISA, GINA, Health Care Reform, Health Insurance, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Medical Coverage, Privacy, Risk Management |
Permalink
Posted by Cynthia Marcotte Stamer
February 17, 2010
Today (February 17, 2010), employer and other health plans and health insurers (“covered entities”) and service providers performing functions on behalf of these entities (“business associates”) must begin complying with tighter federal requirements for the use, access, protection and disclosure of protected health information under Privacy & Security Standards of the Health Insurance Portability & Accountability Act (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH Act). Coming as U.S. employers continue to struggle to provide health benefits in the face of skyrocketing health benefit costs, these and other new federal regulations impacting employment-based health plans and their sponsoring businesses, fiduciaries and administrators are forcing U.S. business leaders to make appropriate health plan cost and compliance management a key management priority.
2/17/10 & Other HIPAA Privacy Rule Changes Require Prompt Attention
The HIPAA Privacy Rule changes scheduled to take effect February 17, 2010 are likely to require that health plans and their business associates update their written policies, operational procedures, privacy notices and business associate agreements in several respects.
While the HITECH Act gave covered entities and business associates a year to complete the necessary arrangements to comply with these impending HITECH Act changes, many health plans and business associates have not completed the necessary arrangements despite expanding liability exposures that can result from noncompliance. To mitigate these exposures, covered entities and their business associates should act quickly both to update their services agreements, plans and policies, practices, and procedures, and to implement the training, oversight, and other management procedures necessary to comply with the HITECH Act changes and to mitigate other HIPAA risks.
The risks of noncompliance for health plans, business associates and others mishandling protected health information are real and growing. Wrongful use, access or disclosure of protected health information in violation of HIPAA subjects participating health plans, health care providers, health care clearinghouses, their business associates and other workforce members and others to civil penalties, criminal prosecution and, since February 17, 2009, civil lawsuits brought by state attorneys general on behalf of citizens of their states whose HIPAA rights were violated. Since September 23, 2009, health plans and other HIPAA covered entities as well as their business associates also became obligated to provide breach notification under new mandates imposed by the HITECH Act.
In addition to these HIPAA-specific exposures, wrongful use, access or disclosure of medical information also can give rise to liability for health plans and other covered entities, business associates, employees and other members of their workforce and others improperly using, accessing or disclosing protected health information. Federal and state prosecutions may and increasingly do criminally prosecute individuals for improperly accessing or using medical or other personal information under a variety of other federal or state laws . See e.g., Cybercrime & Identity Theft:Health Information Security Beyond HIPAA; NY AG Cuomo Annoucment of 1st Settlement For Violation of NY Security Breach Notification Law; Woman Who Revealed AIDs Info Gets A Year. Additionally, State courts also increasingly are permitting individuals harmed by HIPAA violations to use HIPAA as the foundation of state law duties used to maintain state negligence, invasion of privacy, retaliation or other claims for damages. Read more here.
To manage these and other HIPAA-related risks, sponsoring employers, fiduciaries, administrators, insurers and their vendors should begin with carefully and timely reviewing and updating existing plan documents, vendor agreements, privacy notices and other communications and associated practices and policies. The focus of these efforts definitely should seek both to adopt the specific technical changes necessary to make the health plans and their contracts technically comply on paper with these and other HIPAA mandates, and to tailor these documents, communications and practices promote operational compliance and minimize exposure to associated risks. In relation to these efforts, sponsoring employers, insurers, fiduciaries and administrators also should ensure that required certifications from employers and other plan sponsors, representations from business associates, training and other compliance conditions are properly in place. In this respect, employers sponsoring health plans should not overlook the potential need to adopt appropriate policies and implement needed training and safeguards to enable the health plan and the employer demonstrate, if necessary that HIPAA’s requirements for sharing protected health information with members of the employer’s workforce for plan administration, underwriting or certain other purposes have been satisfied.
Other Health Plan Updates Also Required
The HIPAA Privacy Rule changes effective today are only part of the ever-growing list of federal mandates that group health plan sponsors, fiduciaries, insurers, administrators and service providers need to be concerned about. In addition to the new HIPAA Privacy Rule requirements taking effect today, health plans, their sponsors, administrators, fiduciaries, insurers, business associates and other service providers face a host of other new federal health plan and privacy mandates that have taken effect over the past year, and will become subject to additional mandates in upcoming months. Consequently, while focusing on HIPAA compliance, health plans, their employer or other sponsors, insurers, fiduciaries, administrators and service providers also should not overlook the need to review and update their health plans in response to a host of other changes in federal health plan mandates.
In addition to otherwise applicable civil damage awards and civil penalty exposures that can result from violations of these requirements, new Internal Revenue Service regulations that took effect January 1, 2010 also require that employers, health plans or others self-report violations of certain of these requirements and self assess and pay resulting excise taxes arising under the Internal Revenue Code. See, e.g., COBRA, HIPAA, GINA, Mental Health Parity or Other Group Health Plan Rule Violations Trigger New Excise Tax Self-Assessment & Reporting Obligations.
The highly volatile health plan regulatory environment makes it likely that many health plans are not appropriately updated to comply with these and other federal requirements. In recent months, health plans, their employer or other sponsors, administrators and others also have become obligated to comply with a host of other expanded federal health plan rules and requirements. See e.g., New Mental Health Parity Regulations Require Health Plan Review & Updates; New Labor Department Rule Allows Employers 7 Days To Deliver Employee Contributions To Employee Benefit Plans; Newly Extended COBRA Subsidy Rules Require Employers, Administrators Send Required Notices & Update Health Plan Documents & Procedures Quickly; Employer & Other Health Plans & Other HIPAA-Covered Entities & Their Business Associates Must Comply With New HHS Health Information Data Breach Rules By September 23.
These and other developments make it imperative that health plans, their employer or other sponsors, administrators, insurers, fiduciaries and service providers get serious about complying with these and other federal health plan mandates and managing health plan related liabilities and costs. Sponsors, insurers, fiduciaries and administrators should ensure that health plan documents, insurance and other vendor contracts, policies, procedures and communications are timely updated to comply with these and other emerging mandates. When implementing these updates, parties concerned about costs or liabilities also should exercise care to ensure that plan documents, communications, contracts, administrative forms and procedures are optimally designed and drafted not only to be technically compliant, but also to support the enforceability of plan design and cost expectations, minimize administrative and other avoidable costs, and minimize liability exposures. In furtherance of these efforts, employer and other plan sponsors also should consider tightening their practices and requirements for credentialing, selection, oversight and contracting with administrators and vendors, and take other prudent steps to manage health plan related risks.
Curran Tomko Tarski LLP Can Help
If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.
A widely published author and speaker on HIPAA and other employee benefit and human resources related matters, Ms. Stamer has extensive experience advising health plans, their employer and other sponsors, health insurers, TPAs and other business associates and others about HIPAA and other health plan and privacy matters. Currently serving as both Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and as an ABA Joint Committee on Employee Benefits Council representative and Former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer has more than 23 years experience assisting employers, insurers, plan administrators and fiduciaries and others to design, implement, draft and administer health and other employee benefit plans and to defend audits, litigation or other disputes by private parties, the IRS, Department of Labor, Office of Civil Rights, Medicare, state insurance regulators and other federal and state regulators. A nationally recognized author and lecturer, Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates that may be of interest include:
For important information concerning this communication click here.
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Health Plan Liability Heats Up As Plans & Businesses Face New Obligations, Costs & Exposures under New HIPAA Privacy Rules Effective 2/17 & Other Expanding Federal Health Plan Mandates |
COBRA, Corporate Compliance, Data Security, ERISA, Fiduciary Responsibility, FMLA, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Prescription Drugs, Privacy, Wellness Programs | Tagged: Corporate Compliance, Employer, Health Plans, HIPAA, internal control, Mental Heatlh Parity, Privacy, Privacy Standards, Risk Management |
Permalink
Posted by Cynthia Marcotte Stamer
February 15, 2010
Connecticut AG Lawsuit Highlights Expanding Civil Damage Exposure Risks Of Noncompliance
By Cynthia Marcotte Stamer
By Wednesday, February 17, 2010, employer and other health plans and health insurers (“covered entities”) and service providers performing functions on behalf of these entities (“business associates”) must begin complying with tighter federal requirements for the use, access, protection and disclosure of protected health information under Privacy & Security Standards of the Health Insurance Portability & Accountability Act (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH Act). The changes scheduled to take effect February 17, 2010 are likely to require that health plans and their business associates update their written policies, operational procedures, privacy notices and business associate agreements in several respects.
While the HITECH Act gave covered entities and business associates a year to complete the necessary arrangements to comply with these impending HITECH Act changes, many health plans and business associates have not completed the necessary arrangements despite expanding liability exposures that can result from noncompliance. To mitigate these exposures, covered entities and their business associates should act quickly both to update their services agreements, plans and policies, practices, and procedures, and to implement the training, oversight, and other management procedures necessary to comply with the HITECH Act changes and to mitigate other HIPAA risks.
2/17/10 Deadline To Comply With HITECH Act HIPAA Amendments
On February 17, 2010, health plans and other covered entities and their business associates will become subject to the latest to take effect in a series of amendments to the HIPAA enacted under the HITEC Act. The new rules are part of a broader series of changes to HIPAA made by the HITECH Act that collectively both significantly expand the obligations of covered entities and their business associates to regarding the use, protection and disclosure of protected health information and the liability exposures that can result when covered entities or business associates violate these requirements.
The changes scheduled to take effect February 17, 2010 are likely to require that health plans and their business associates update their written policies, operational procedures, privacy notices and business associate agreements in several respects. For instance, effective February 17, 2010, the HITECH Act generally requires that covered entities and their business associates revise their written privacy policies, privacy notices and operating procedures:
- To meet expanded requirements to honor individual’s requests for special restrictions on uses and disclosures of protected health information to health plans for payment purposes
- To restrict protected health information disclosures to the minimum necessary required to accomplish otherwise allowable purpose;
- To comply with new rules that require that the covered entity and its business associates treat any use, access or disclosure of any protected health information made for purposes of making communications about products or services as made for marketing, rather than operational, purposes which are prohibited by HIPAA except where HIPAA’s requirements are met;
- To comply with new restrictions on certain fundraising communications made for operational purposes including expanded obligations to allow recipients to opt out of further fundraising communications;
- To prohibit covered entities or business associates from selling protected health information without meeting the amended requirements of HIPAA that a valid HIPAA authorization from the subject of the information and specific reassurances from the purchaser concerning its subsequent use of the protected health information except as otherwise permitted by HIPAA;
- To take into account these tightened restrictions on the use, access or disclosure of protected health information for purposes of complying with new HITECH Act breach notification requirements that took effect in September, 2009, which apply when a covered entity or its business associate knows or should know a breach of “unsecured protected health information” has occurred and for purposes of making the necessary changes in written policies and business associate agreements, training and operational procedures necessary to comply with these rules;
- To directly require business associates comply with HIPAA’s requirements in the same manner as other covered entities and make it necessary or advisable that that service provider agreements between health plans and business associates be updated to reflect these and other changes to HIPAA; and
- To implement the necessary written policy changes, notification updates, business associate agreement amendments, training, management oversight and other procedural changes necessary to demonstrate fulfillment with these requirements.
Noncompliance with these and other HIPAA requirements subjects covered entities and business associates to civil penalties, criminal prosecution, civil damage awards under lawsuits brought by state attorneys general, and other legal remedies. In addition, timely update written policies, procedures, business associate agreements, training and documentation is imperative in order for covered entities and their business associates to fulfill their breach notification obligations under new rules enacted as part of the HITECH Act.
Under the HITECH Act, health plans and other covered entities and their business associates have been obligated since September 23, 2009 to notify individuals who are the subject of protected health information, the Department of Health & Human Services and in some cases the media if and when a breach of “unsecured protected health information occurs. Failing to timely update written policies, procedures and training increases the likelihood that health plans, other covered entities or business associates will be obligated to provide breach notifications under these new rules, in addition to their otherwise applicable exposures under HIPAA.
HIPAA Enforcement & Liability Exposures Real and Rising
Health plans and other covered entities, their business associates and others involved in health plan design and operations generally should resist the temptation to underestimate their potential HIPAA exposure based on the limited enforcement of HIPAA by the Office of Civil Rights between 2003 and 2009 for a variety of reasons.
First, the changes taking effect on February 17, 2010 follow the implementation changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, when President Obama signed the HITECH Act into law and the new breach notification requirements added by the HITECH Act that took effect on September 23, 2009. The HITECH Act amendments to HIPAA’s remedies significantly increase the risk that health plans and other covered entities and their business associates will face civil lawsuits, civil or criminal penalties or other consequences for violating HIPAA.
The expanded risks stem in part from the HITECH Act’s amendments to HIPAA’s remedy provisions. Among other things, the HITECH Act amended HIPAA to:
- Allow a State Attorney General to sue health plans or other covered entities, business associates or both that harm state citizens by committing HIPAA violations after February 16, 2009;
- Expand the mandate by the Office of Civil Rights to investigate violations and audit compliance with HIPAA;
- Require Office of Civil Rights to impose civil sanctions against health plans and other covered entities and their business associates involved in violations of HIPAA in accordance with tightened standards added to HIPAA by the HITECH Act;
- Revise the criminal sanctions that the Department of Justice can seek against health plans and other covered entities, their business associates and others for violations of HIPAA;
- Amend HIPAA to make clear that HIPAA’s criminal sanctions also can imposed on business associates, workforce members and other persons that improperly use, access and disclose protected health information in violation of HIPAA.
A HIPAA civil lawsuit filed on January 13, 2010 demonstrates the willingness of at least some states to exercise the new authority created by the HITECH Act on February 17, 2009 to sue covered entities and business associates that violate HIPAA for civil damages.
The HITECH Act empowers a state attorney general to sue covered entities or business associates engaging in HIPAA violations that harms citizens of the state for statutory damages equal to the sum of the number of violations multiplied by 100 up to a maximum of $25,000 per calendar year plus attorneys fees and costs
On January 13, 2010 Connecticut Attorney General Richard Blumenthal sued Health Net of Connecticut, Inc. (Health Net) for failing to secure private patient medical records and financial information involving 446,000 Connecticut enrollees and promptly notify consumers endangered by the security breach. The suit also names UnitedHealth Group Inc. and Oxford Health Plans LLC, who have acquired Health Net. The first attorney general enforcement action brought based on amendments made to HIPAA under the HITECH Act, Connecticut charges that Health Net violated HIPAA by failing to safeguard protected medical records and financial information on almost a half million Health Net enrollees in Connecticut then allowing this information to remain exposed for at least six months before notifying authorities and consumers.
Even before the HITECH Act amendments, however, the Office of Civil Rights and Department of Justice already were stepping up HIPAA investigation and enforcement. The Department of Justice has obtained a variety of criminal convictions against violators of HIPAA. See, e.g., 2 New HIPAA Criminal Actions Highlight Risks From Wrongful Use/Access of Health Information. Meanwhile, the Office of Civil Rights in February, 2009 announced that CVS Pharmacies, Inc. would pay $2.25 million to resolve HIPAA charges. This announcement followed the Office of Civil Rights announcement in July, 2008 that Providence Health Care would pay $100,000 to resolve HIPAA violation charges. While not resulting in the significant payments involved in CVS or Providence, the Office of Civil Rights also taken HIPAA enforcement actions against a broad range of other covered entities to redress HIPAA violations or other compliance concerns. To review examples of these other actions, see here.
Along side these governmental actions, state courts also increasingly are willing to allow individual plaintiffs to rely on violations of HIPAA as the basis for bringing state privacy, retaliation or other actions. While prior to the recent HITECH Act amendments, federal courts had ruled that private plaintiffs could not sue under HIPAA for damages they incurred from a covered entity’s violation of HIPAA, state courts have allowed private plaintiff’s to use the obligations imposed by HIPAA as the basis of a covered entity’s duty for purposes of certain state law lawsuits. In Sorensen v. Barbuto, 143 P.3d 295 (Utah Ct. App. 2006), for example, a Utah appeals court ruled a private plaintiff could use HIPAA standards to establish that a physician owed a duty of confidentiality to his patients for purposes of maintaining a state law damages claim. Similarly, the Court in Acosta v. Byrum, 638 S.E. 2d 246 (N.C. Ct. App. 2006) ruled that a plaintiff could use HIPAA to establish the “standard of care” in a negligence lawsuit. Meanwhile, private plaintiffs employed by covered entities also are increasingly pointing to HIPAA as the basis for their retaliation claims. See, e.g., Retaliation For Filing HIPAA Complaint Recognized As Basis For State Retaliatory Discharge Claim. Coupled with the HITECH Act changes, these and other enforcement actions signal growing potential hazards for covered entities and their business associates that fail to properly manage their HIPAA compliance obligations and risks.
Health Plans & Business Associates Should Take Timely Action To Comply & Manage Risks
As a consequence of these collective HITECH Act changes and growing HIPAA-related exposures, both health plans and business associates generally will find it necessary or advisable among other things to:
- Conduct well-documented due diligence on each other’s practices and procedures to improve their ability to demonstrate both their commitment to compliance and their realistic efforts to ensure that these commitments are operationalized in performance;
- Renegotiate their service provider agreements to detail the specific compliance obligations of each party relating to for auditing compliance, investigating potential breaches; providing required breach notifications; specify leadership and required cooperation in the event of a breach, charge, or other concern; indemnification and other liability allocations; and other related matters; and
- Pursue appropriate liability and other protection as appropriate.
As part of these compliance and risk management efforts, most covered entities and their business associates will find it advisable to devote significant attention to the business associate relationship and its associated business associate agreements.
Proper management of the expanded compliance obligations and liability exposures created by the HITECH Act generally will necessitate that health plans and other covered entities and their business associates focus significant attention on the reworking of their operating and contractual relationships.
Even before the impending HIPAA changes scheduled to take effect on February 17, 2010, a strong need for more detailed contracting and planning of these relationships already existed. Since the enactment of HIPAA, the practice of many covered entities and their business associates of appending generic “business associate” representations onto existing services contracts without specific tailoring and planning has created undesirable ambiguities in these agreements.
Further updating and tailoring of these and other provisions of services agreements has become even more important over the past year in light of the new breach notification mandates that took effect under the HITECH Act in September, 2009, changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, and the impending extension by the HITECH Act to business associates of direct liability for compliance with HIPAA scheduled to occur on February 17, 2010.
Given these changes and the associated obligations and risks, both health plans and other covered entities and their business associates generally should act quickly to manage their own compliance and to minimize exposures that may result from the other’s compliance deficiencies. As part of these efforts, both covered entities and their business associates generally should review and tighten business associate and other service agreement provisions to provide for more specific and comprehensive HIPAA-related contractual assurances, as well as improved cooperation, coordination, management and oversight.
Curran Tomko Tarski LLP Can Help
If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.
A widely published author and speaker on HIPAA and other related matter, Ms. Stamer has extensive experience advising health plans, their employer and other sponsors, health insurers, TPAs and other business associates and others about HIPAA and other health plan and privacy matters. Currently serving as both Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and as an ABA Joint Committee on Employee Benefits Council representative and Former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer has more than 23 years experience assisting employers, insurers, plan administrators and fiduciaries and others to design, implement, draft and administer health and other employee benefit plans and to defend audits, litigation or other disputes by private parties, the IRS, Department of Labor, Office of Civil Rights, Medicare, state insurance regulators and other federal and state regulators. As part of this work, she regularly assists clients to review and update policies, practices, contracts, notices and procedures to comply with HIPAA and other requirements. A nationally recognized author and lecturer, Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates that may be of interest include:
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Health Plans & Business Associates Face 2/17 Deadline To Update Policies, Contracts & Procedures For HIPAA Privacy Rule Changes |
ARRA, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Protected Health Information, Risk Management, Stimulus Bill | Tagged: Breach Notice, Corporate Compliance, Data Breach, Employee Benefits, Employers, ERISA, GINA, Health Insurance, Health Plans, HIPAA, Human Resources, Insurance, Insurer, Internal Controls, Internal Investigations, Managed Care, Medical Coverage, PHI, Privacy, Privacy Rule, Risk Management, Security Rule |
Permalink
Posted by Cynthia Marcotte Stamer
January 25, 2010
By Cynthia Marcotte Stamer
New American Academy of Pediatrics recommendations calling for early intervention and intensive behavioral therapy to treat childhood obesity promise to increase demands for employer sponsored and other health plans to reimburse the costs of these treatments.
With health care providers and government officials increasingly emphasizing the need for prevention and intervention, employers and health insurers face greater pressure to offer health benefit coverage for weight management and other obesity prevention and treatment. Aside from determining what treatments to coverage generally, recent changes in the Americans With Disabilities Act statute and its enforcement and interpretation by the Equal Employment Opportunity Commission, the recently effective employment and health plan nondiscrimination rules of the Genetic Information and Nondiscrimination Act, health information and other privacy rules and other legal changes make the appropriate design and administration of obesity and other wellness, disease management and other programs targeting obesity or other chronic conditions legally and operationally challenging. Employers and insurers concerned with these issues should exercise care to properly understand and appropriately manage the legal and operational complexities, risks, costs and benefits when designing health and other programs to manage health care, disability and other costs of obesity and other chronic diseases.
Read the report and about discrimination and other issues that employers and insurers may need to manage under evolving federal rules when deciding how to design and manage obesity and other wellness and disease management programs here.
If you have questions about wellness, disease management or other health and wellness benefit, disability prevention and management, or other employee benefit, employment, compensation, workplace health and safety, corporate ethics and compliance practices, concerns or claims, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment Practice Group Chair Cynthia Marcotte Stamer.
Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group, an ABA Joint Committee on Employee Benefits Council Member, Past Chair of the ABA Managed Care & Insurance Group and RPTE Welfare Benefits Committee and Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, Ms. Stamer is experienced advising and assisting government leaders, employers, health and other employee benefit plans and their fiduciaries, insurers, financial advisory services, and administrators, health care providers, and others about obesity and other disease management and wellness programs, as well as other related employee benefit and employment matters. A widely published author on these and other health and disability benefit and management concerns, Ms. Stamer has advised and represented employers, health plans and others on these and other matters for more than 20 years. Author of the Personal Health Care Toolkit, Ms. Stamer also has lead the development of wellness and disease management initiatives for the National Kidney Foundation of North Texas and other organizations. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience, see here or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Some other recent updates that may be of interested include the following, which you can access by clicking on the article title:
- Homeland Security Updates List of Nations Whose Nationals Are Eligible for H-2A or H-2B Visas
- New Labor Department Rule Allows Employers 7 Days To Deliver Employee Contributions To Employee Benefit Plans
- Certain Workforce Reductions Trigger Plant Closing Notice & Other Obligations
- Newly Extended COBRA Subsidy Rules Require Employers, Administrators Send Required Notices & Update Health Plan Documents & Procedures Quickly
- Comments Invited On Burdensomeness of Requirements To Obtain DOL Determination That Benefit Plan Qualifies as As Collectively Bargained Plan
- Rising Enforcement and Changing Rules Require Prompt Review & Update of Health Plan Privacy & Data Security Policies & Procedures
- President Signs Law Extending & Expanding Temporary AARA COBRA Subsidy Requirements For Group Health Plans
- Mishandling Employee Benefit Obligations Creates Big Liabilities For Distressed Businesses & Their Business Leaders
- DOL Plans To Tighten Employment Protections For Disabled Veterans & Other Disabled Employees Signals Need For Businesses To Tighten Defenses
- GINA Discussion Topic At February HHS Advisory Committee on Genetics, Health & Society Meeting G
- Employee Benefit Plan Sponsors & Fiduciaries Urged To Review Bonding, Credentials of Staff & Service Providers Under ERISA
- Added IRS Guidance For Correcting Employment Tax Overpayments Released
- Labor Department To Expand Employee Benefits, Wage & Hour, OSHA & Other Reporting & Disclosure Requirements & To Implement Other New Employee Benefit Regulations
- PBGC Expands Pension Benefit Protection For Military Service Members As Justice Department Files 22nd USERRA Military Leave Lawsuit Against An Employer Since January
- Rising Defined Benefit Plan Underfunding & Changing Rules Create New Obligations & Risks For Business
- ADAAA Amendment Broader ADA “Disability” Definition Not Retroactive, Employer Action Needed To Manage Post 1/1/2009 Risks
- New Study Shares Data On Migrant Health Care Challenges Along The Border
- Employer & Other Health Plans & Other HIPAA-Covered Entities & Their Business Associates Must Comply With New HHS Health Information Data Breach Rules By September 23
- Stamer, Others To Discuss Technology Use/Risks in Employee Benefits, Tax & HR Consulting & Administration
- Businesses Cautioned To Strengthen Investigation & Employment Practices To Minimize Potential Exposure To Retaliation Claims In Light Of Recent Supreme Court Retaliation Decision
- OFCCP To Apply Special Procedures, Heightened Scrutiny To Equal Employment Practices of Government Contractors, Subcontractors On ARRA Funded Projects
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Health Plans & Employers Can Expect Pressure To Pay For Childhood Obesity Counseling From New American Academy of Pediatrics Report |
Corporate Compliance, EEOC, Employee Benefits, ERISA, Fiduciary Responsibility, GINA, Health Plans, Human Resources, Internal Investigations, Leave, Mental Health, Rehabilitation Act, Wellness, Wellness Programs | Tagged: ADA, Disability, Disease Management, EEOC, GINA, Health Care, Health Insurance, Health Plans, HIPAA, Obesity, Wellness |
Permalink
Posted by Cynthia Marcotte Stamer
December 28, 2009
Accountants and their clients face increasing regulatory and business pressures to protect the sensitive business and personal information collected and maintained in the course of their operation to minimize their exposure to personal identity theft and other cybercrime scams by employees, business partners and others. Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer will speak about “Privacy & Information Security: Managing Your Accounting Practice’s Liabilities & Counseling Your Clients” to members of the Dallas CPA Society on January 12, 2010 beginning at 2:00 p.m.
Part of the Dallas CPA Society Member Appreciation CPE Series Meeting, Ms. Stamer’s presentation will be part of four hours of free CPE training to be provided at a program open to members only at the Hilton Lincoln Centre Hotel located at 5410 LBJ Freeway, Dallas TX 75240 from 1 p.m. to 4:50 p.m. Central Time. (Parking at the facility costs $5.00). To register or for additional information, see here.
If you need help responding to these developments or other legislative, regulatory or enforcement concerns, Curran Tomko Tarski LLP can help. Curran Tomko and Tarski LLP and its attorneys have significant experience assisting businesses and business leaders to manage and defend privacy, data security, tax employee benefit, employment, health care, environmental, safety, securities and other compliance and risk management concerns.
Curran Tomko Tarksi LLP Partner Cynthia Marcotte Stamer has more than 22 years experience helping businesses to use the law, process and technology to manage people and processes, and to manage technology, privacy and data security, employment and other legal and operational risks affecting their businesses. Author of “Privacy & Securities Standards-A Brief Nutshell,” “Privacy Invasions of Medical Care-An Emerging Perspective,” and “E-Health Business and Transactional Law Other Liability-Tort and Regulatory;” published by The Bureau of National Affairs, Inc., and many other publications, Ms. Stamer has extensive experience advising a accounting firms, law firms, banks and financial services organizations, insurers, consultants, health plans, health care providers and others about HIPAA, FACTA, and other privacy, trade secret and other information security and data breach risk management and compliance concerns. Ms Stamer also speaks, publishes and provides public policy input extensively on data security, technology and other internal controls and risk management matters. Chair of the American Bar Association RPTE Employee Benefits & Compensation Committee, an ABA Joint Committee on Employee Benefits Council member, and Chair of the Curran Tomko Tarski Labor, Employment & Employee Benefits Practice, Ms. Stamer also is Board Certified in Labor & Employment law. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
If you need assistance with these or other compliance concerns, wish to inquire about federal or state regulatory compliance audits, risk management or training, assistance investigating or responding to a known or suspected compliance or risk management concern, or need legal representation on other matters please contact the author of this update, Cynthia Marcotte Stamer, CTT Labor & Employment Practice Chair at cstamer@cttlegal.com, 214.270.2402; or your other preferred Curran Tomko Tarski LLP attorney.
You can review other recent human resources, employee benefits and internal controls publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here /the Curran Tomko Tarski LLP attorneys here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information to Cstamer@CTTLegal.com or registering to participate in the distribution of these and other updates on our Solutions Law Press HR & Benefits Update distributions here. For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to here.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Stamer Speaks To CPAs About “Privacy & Information Security: Managing Your Accounting Practice’s Liabilities & Counseling Your Clients” January 12, 2010 |
Corporate Compliance, Data Security, EEOC, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, Human Resources, Internal Controls, Malpractice, Privacy, Professional Liability, Protected Health Information, Risk Management | Tagged: Acountant's Liability, Corporate Compliance, CPA, CPE, Employee Benefits, Employer, GINA, Health Insurance, Health Plans, Human Resources, Internal Controls, Medical Coverage, Privacy, Risk Management, Tax |
Permalink
Posted by Cynthia Marcotte Stamer
December 8, 2009
By Cynthia Marcotte Stamer
The U.S. Department of Labor (Labor Department) plans to implement a host of new employee benefit and employment regulations seeking to strengthen employee benefit, wage and hour, safety and other protections with greater transparency and disclosure, the Labor Department announced yesterday.
Employee Benefits, Wage & Hour, OSHA & Other Rules Seek To Protect Workers With Transparency
Employee Benefits Security Administration (EBSA) plans to implement a host of new rules designed to strengthen retirement security by expanding the private employee benefit plan disclosure requirements and enhancing the availability of information to pension plan participants and beneficiaries and employers, according to the Department of Labor (DOL) 2009 Regulatory Agenda (the “Regulatory Agenda”) announced yesterday.
According to the Regulatory Agenda, EBSA plans to promote these goals through the implementation of a host of new rules including:
- Fiduciary Requirements for Disclosure in Participant-Directed Individual Account Plans, which would increase transparency between individual account pension plans and their participants and beneficiaries by ensuring that participants and beneficiaries are provided the information they need, including information about fees and expenses, to make informed investment decisions.
- Amendment of Standards Applicable to General Statutory Exemption for Services, which would require service providers to disclose to plan fiduciaries services, fees, compensation and conflicts of interest information.
- Annual Funding Notice for Defined Benefit Plans, which would require defined benefit plan administrators to provide all participants, beneficiaries and other parties with detailed information regarding their plan’s funding status.
- Periodic Pension Benefits Statements, which would require pension plans to provide participants and certain beneficiaries with periodic benefit statements.
- Multiemployer Plan Information Made Available on Request, which would require pension plan administrators to provide copies of financial and actuarial reports to participants and beneficiaries, unions and contributing employers on request.
The 2009 Regulatory Agenda highlights the most noteworthy and significant regulatory projects that the Labor Department has established for the EBSA, the Employment Standards Administration (ESA), Mine Safety and Health Administration (MSHA), Occupational Safety and Health Administration (OSHA), and Employment and Training Administration (ETA) for the upcoming year. In addition to the transparency rules planned for EBSA, the 2009 Regulatory Agenda also indicates that employers can expect new Labor Department regulations targeting transparency in other areas. These include:
- The MSHA to propose a rule on Notification of Legal Identity, which would require mine operators to provide increased identification information, would allow the agency to better target the most egregious and persistent violators and deter future violations.
- The Office of Labor-Management Standards’ to propose regulations on Notification of Employee Rights Under Federal Labor Laws, which would implement Executive Order 13496 and require all Government contracting agencies to include a contract clause requiring contractors to inform workers of their rights under Federal labor laws.
- The Wage and Hour Division to update its regulations about Records to be Kept by Employers Under the Fair Labor Standards Act to enhance the transparency and disclosure to workers as to how their wages are computed and to allow for new workplace practices such as telework and flexiplace arrangements.
- OSHA to modify its Hazard Communication Standard to require standardized labeling requirements and order of information for safety data sheets and to update its Occupational Injury and Illness Recording and Reporting Requirements rule, which would propose the collection of additional data to help employers and workers track injuries at individual workplaces, improve the Nation’s occupational injury and illness information data, and assist the agency in its enforcement of the safety and health workplace requirements.
Other Employee Benefit Regulations Planned
Beyond its planned EBSA transparency initiative, the 2009 Regulatory Agenda reflects that other EBSA regulatory priorities for the year ahead include:
- Issue guidance implementing the group health plan Genetic Information Nondiscrimination Act of 2008 (GINA) amendments to ERISA which generally prohibit group health plans from discriminating in health coverage based on genetic information and from collecting genetic information. This will be a joint rulemaking action with the Departments of Health and Human Services and the Treasury.
- Provide guidance regarding the Paul Wellstone and Pete Domenici Mental Health Parity and Addiction Equity Act of 2008 (MHPAEA) amendments to ERISA. MHPAEA creates parity for mental health and substance use disorder benefits under group health plans by mandating that any financial requirements and treatment limitations applicable to mental health and substance abuse disorder benefits to be no more restrictive than predominant requirements or limitations applied to substantially all medical and surgical benefits covered by a plan.
- Issue guidance clarifying the circumstances under which health care arrangements established or maintained by state or local governments for the benefit of non-governmental employees do not constitute an employee welfare benefit plan for purposes of ERISA.
- Propose amendments to its regulations to clarify the circumstances under which a person will be considered a fiduciary when providing investment advice to employee benefit plans and their participants and beneficiaries of such plans.
- Explore steps it can take by regulation, or otherwise, to encourage the offering of lifetime annuities or similar lifetime benefits distribution options for participants and beneficiaries of defined contribution plans.
Employers and employee benefit plan sponsors, fiduciaries, and service providers should take into account these planned regulatory changes for budgeting and program design purposes and keep alert for announcements of proposed or final regulations or other guidance in these and other areas.
If your organization needs assistance with monitoring, assessing, managing or defending these or other labor and employment, compensation or benefit practices, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment Practice Group Chair Cynthia Marcotte Stamer or another Curran Tomko Tarski LLP attorney of your choice. Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization and Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group and a nationally recognized author and speaker, Ms. Stamer is experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, risk management and internal controls matters. Ms. Stamer is experienced with assisting employers and others about compliance with federal and state equal employment opportunity, compensation, health and other employee benefit, workplace safety, and other labor and employment laws, as well as advising and defending employers and others against tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the IRS, Department of Labor and other federal and state regulators. She has counseled and represented employers on these and other workforce matters for more than 22 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates you may have missed include:
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Labor Department To Expand Employee Benefits, Wage & Hour, OSHA & Other Reporting & Disclosure Requirements & To Implement Other New Employee Benefit Regulations |
Absenteeism, ADA, Affirmative Action, Corporate Compliance, Defined Benefit Plans, EEOC, Employee Benefits, Employers, ERISA, family leave, GINA, Government Contractors, Human Resources, Military Leave, OFCCP, OSHA, Retirement Plans, Risk Management, Safety, Uncategorized, Wellness | Tagged: COBRA, Corporate Compliance, defined benefit plan, Disability Discrimination, Disease Management, Employee Benefits, Employers, Employment, ERISA, GINA, Human Resources, Insurance, Internal Controls, Medical Coverage, Military Leave, Minimum Wage, Occupational Injury, Overtime, Privacy, Retirement Plans, Risk Management, Wellness |
Permalink
Posted by Cynthia Marcotte Stamer
December 5, 2009
Get a peek at the U.S. Department of Labor’s (DOL’s) regulatory plans for 2010 on Monday, December 10, 2009.
On Monday, Dec. 7, the DOL will release its annual regulatory agenda for the upcoming year. The same day, it also will video cast remarks by Secretary Hilda L. Solis outlining the department’s regulatory agenda beginning at 10 a.m. EST. From 2 to 3 p.m. EST Ssecretary Solis alsowill host a live Web chat open to the public to discuss the contents of the agenda. Questions may be submitted in advance of the chat following the video presentation. Register to join the chat on Monday here.
If your organization needs assistance with assessing, managing or defending labor and employment, compensation or benefit practices, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment Practice Group Chair Cynthia Marcotte Stamer or another Curran Tomko Tarski LLP attorney of your choice. Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization and Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group and a nationally recognized author and speaker, Ms. Stamer is experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, risk management and internal controls matters. Ms. Stamer is experienced with assisting employers and others about compliance with federal and state equal employment opportunity, compensation, health and other employee benefit, workplace safety, and other labor and employment laws, as well as advising and defending employers and others against tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the IRS, Department of Labor and other federal and state regulators. She has counseled and represented employers on these and other workforce matters for more than 22 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates you may have missed include:
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on DOL Shares 2010 Regulatory Plans Monday, December 7; Get A Sneak Peek on Its Plans |
Absenteeism, Affirmative Action, COBRA, Corporate Compliance, Disease Management, EEOC, Employee Benefits, Employers, Employment Agreement, ERISA, family leave, FMLA, GINA, Government Contractors, Health Plans, HIPAA, Human Resources, Internal Controls, Internal Investigations, Leave, medical leave, Military Leave, Nonresident aliens, OFCCP, OSHA, Public Policy, Reporting & Disclosure, Retaliation, Safety, USERRA, Wage & Hour, Wellness, Whistleblower | Tagged: ADA, COBRA, Compensation, Corporate Compliance, defined benefit plan, Disease Management, EEOC, Employee Benefits, Employer, Employers, Employmemnt Liability, Employment, Employment Agreements, employment discrimination, ERISA, GINA, Health Care Reform, Health Insurance, Health Plans, Human Resources, Internal Controls, Internal Investigations, Labor, Light Duty, Managed Care, Medical Coverage, Military Leave, Minimum Wage, Occupational Injury, Overtime, Risk Management, Wellness |
Permalink
Posted by Cynthia Marcotte Stamer
You must be logged in to post a comment.